Storage Intrusion Detection via Point-in-Time Copy Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional intrusion detection systems for computer storage systems are ineffective in large storage environments, as they require time-consuming and costly signature calculations, are not suitable for file systems where file locations can change, and lack periodic point-in-time copies for recent data recovery.
Innovation Solution
A method and system that create time and space efficient point-in-time copies of logical units, allowing for periodic monitoring of these copies to detect unwanted modifications, independent of the host system, ensuring continuous access to original data without interruption and maintaining a recent 'good' copy for recovery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional intrusion detection methods are used in large storage environments, then intrusion detection capability is provided, but the system becomes time-consuming and costly due to signature calculations
Solution Approach 1:
The patent segments the storage system into multiple storage units and divides the monitoring task accordingly. Each storage unit independently monitors its own data changes, eliminating the need for centralized signature calculations across the entire storage system. This segmentation reduces computational overhead and time consumption while maintaining comprehensive intrusion detection coverage.
Solution Approach 2:
The patent implements preliminary action by continuously maintaining point-in-time copies of data before potential intrusions occur. These copies are prepared in advance and can be quickly compared against current data to detect intrusions, eliminating the need for time-consuming post-intrusion analysis or recalibration of detection parameters.
2Reliability
If conventional intrusion detection systems are deployed, then intrusion monitoring is enabled, but periodic point-in-time copies are not maintained for recent data recovery
Solution Approach 1:
The system proactively creates and maintains point-in-time copies of data at regular intervals before intrusions occur. These preliminary copies are stored and maintained as part of the normal operation, ensuring that recent data states are always available for recovery purposes without needing to wait for or respond to an intrusion event first.
Solution Approach 2:
The patent implements beforehand cushioning by maintaining multiple historical point-in-time copies of data as a protective buffer against potential intrusions. These cushioning copies serve as safety nets that can restore data to any previous state, providing a buffer against information loss while requiring minimal additional storage overhead through efficient copy management.
3Measurement precision
If frequent copies are made for intrusion detection, then detection accuracy improves, but storage space and time overhead increase
Solution Approach 1:
The patent segments the data storage and monitoring into discrete storage units, each managing its own point-in-time copies independently. This segmentation allows the system to maintain copies at an optimal frequency for each unit without unnecessarily duplicating copies across the entire system, reducing overall storage overhead while maintaining detection accuracy at the granular level where it matters most.
Solution Approach 2:
The system implements a lifecycle management strategy for point-in-time copies, discarding older copies that are no longer needed for detection purposes and recovering or retaining only those copies necessary for current monitoring needs. This dynamic management of copy retention reduces storage space overhead while maintaining sufficient detection accuracy by keeping relevant historical data available.
Data Source
AI summary
A method (and system) for detecting intrusions to stored data includes creating a point-time-copy of a logical unit, and comparing at least a portion of the point-time-copy with a previous copy of the logical unit. The method (and system) monitors access to a data storage system and detects an intrusion or any other intentional or unintentional, unwanted modification to data stored in the data storage system. The method (and system) also recovers data once an intrusion or other unwanted modification is detected.


