Storage-Level Intrusion Detection via Host Behavior Profiling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data center administrators face challenges in predicting and detecting intrusions, particularly at the storage level, where existing methods consume significant resources or are slow, allowing potential data breaches to go undetected for hours, days, or weeks.
Innovation Solution
A two-part detection system comprising a machine learning component to create behavior profiles of hosts and a centrally-located database for known intrusion signatures, combined with a multi-level autonomous proactive intrusion-detection approach to identify and mitigate anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional intrusion detection methods are used at the storage level, then detection capability is provided, but resource consumption increases significantly and detection speed decreases
Solution Approach 1:
The patent extracts the intrusion detection function from traditional network-level monitoring and implements it specifically at the storage level through behavioral profiling of storage hosts. This targeted approach detects intrusions directly where data breaches occur, eliminating the need for resource-intensive network-wide inspection while maintaining high detection speed and accuracy.
Solution Approach 2:
The patent introduces behavioral profiles as an intermediary mechanism that mediates between storage operations and intrusion detection. These profiles establish baseline normal behavior patterns, allowing the system to detect anomalies efficiently without requiring complex real-time analysis of all storage transactions, thus resolving the contradiction between detection reliability and speed.
2Reliability
If traditional intrusion detection methods are used, then intrusion detection is attempted, but the detection process consumes significant computing resources
Solution Approach 1:
The patent performs preliminary action by establishing behavioral profiles that capture normal storage host behavior patterns in advance. During operation, the system compares actual behavior against these pre-established profiles to detect intrusions, avoiding the need for resource-intensive real-time analysis and significantly reducing computing resource consumption while maintaining detection reliability.
3Loss of time
If monitoring is performed at network or host level, then intrusion detection is possible, but detection is slow and allows data breaches to go undetected for hours, days, or weeks
Solution Approach 1:
The patent segments the intrusion detection function from network-level and host-level monitoring and implements it independently at the storage level. This segmentation allows the system to detect intrusions directly at the data breach point with minimal delay, significantly reducing detection time from hours or days to near-real-time while maintaining high reliability through storage-specific behavioral analysis.
Data Source
AI summary
Techniques are provided for intrusion detection on a computer system. In an example, a computer host device is configured to access data storage of the computer system via a communications network. It can be determined that the computer host device is behaving anomalously because a first current access by the computer host device to the data storage deviates from a second expected access by the computer host device to the data storage by more than a predefined amount. Then, in response to determining that the computer host device is behaving anomalously, the computer system can mitigate against the computer host device behaving anomalously.


