Access control using user behavior profile and storage system-based multi-factor authentication
Techniques are provided for access control using user behavior profiles and storage system-based multi-factor authentication. One method comprises obtaining a behavior profile for a user; obtaining an input/output request from the user; determining whether the input/output request exhibits anomalous user behavior relative to the behavior profile; initiating a multi-factor authentication of the user in response to the input/output request exhibiting anomalous user behavior to obtain a verification result; and processing the input/output request based at least in part on the verification result. The behavior profile for the user may be obtained by obtaining behavioral information from the user and/or monitoring a plurality of input/output requests of the user to learn at least a portion of the behavior profile for the user. The multi-factor authentication may comprise an out-of-band authorization request (e.g., to approve the input/output request) sent to a user associated with the input/output request.
1 . A method, comprising:
obtaining, by a storage controller of a storage system, a behavior profile for a user, wherein the storage system (i) comprises the storage controller, a plurality of storage devices and at least one processing device and (ii) processes one or more of a plurality of read requests and a plurality of write requests directed to one or more of the storage devices, the at least one processing device comprising a processor coupled to a memory, wherein the storage controller learns at least a portion of the behavior profile during a learning period by monitoring one or more of a plurality of the read requests and a plurality of the write requests of the user;
performing the following steps, in response to obtaining, by the storage controller of the storage system, at least one read or write request from the user directed to one or more of the storage devices, of the storage system, that store data associated with the obtained at least one read or write request:
determining, by the storage controller of the storage system, prior to a completion of a processing of the obtained at least one read or write request, whether the obtained at least one read or write request exhibits anomalous user behavior relative to the behavior profile;
initiating, by the storage controller of the storage system, a multi-factor authentication of the user, in response to the determining that the obtained at least one read or write request exhibits anomalous user behavior, to obtain a verification result; and
processing, by the storage controller of the storage system, the obtained at least one read or write request based at least in part on the verification result.
2 . The method of claim 1 , wherein the obtaining the behavior profile for the user comprises obtaining behavioral information from the user.
3 . The method of claim 1 , wherein the multi-factor authentication comprises an out-of-band authorization request sent to at least one user associated with the at least one read or write request.
4 . The method of claim 1 , further comprising updating the behavior profile for the user based at least in part on the verification result.
5 . The method of claim 1 , wherein the obtained at least one read or write request is only completed if the verification result is successful.
6 . The method of claim 1 , wherein the determining whether the obtained at least one read or write request exhibits anomalous user behavior employs machine learning techniques.
7 . The method of claim 1 , further comprising performing one or more automated remedial actions in response to the verification result.
8 . An apparatus comprising:
at least one processing device comprising a processor coupled to a memory;
the at least one processing device being configured to implement the following steps:
obtaining, by a storage controller of a storage system, a behavior profile for a user, wherein the storage system (i) comprises the storage controller, a plurality of storage devices and at least one processing device and (ii) processes one or more of a plurality of read requests and a plurality of write requests directed to one or more of the storage devices, the at least one processing device comprising a processor coupled to a memory, wherein the storage controller learns at least a portion of the behavior profile during a learning period by monitoring one or more of a plurality of the read requests and a plurality of the write requests of the user;
performing the following steps, in response to obtaining, by the storage controller of the storage system, at least one read or write request from the user directed to one or more of the storage devices, of the storage system, that store data associated with the obtained at least one read or write request:
determining, by the storage controller of the storage system, prior to a completion of a processing of the obtained at least one read or write request, whether the obtained at least one read or write request exhibits anomalous user behavior relative to the behavior profile;
initiating, by the storage controller of the storage system, a multi-factor authentication of the user, in response to the determining that the obtained at least one read or write request exhibits anomalous user behavior, to obtain a verification result; and
processing, by the storage controller of the storage system, the obtained at least one read or write request based at least in part on the verification result.
9 . The apparatus of claim 8 , wherein the obtaining the behavior profile for the user comprises obtaining behavioral information from the user.
10 . The apparatus of claim 9 , wherein the multi-factor authentication comprises an out-of-band authorization request sent to at least one user associated with the at least one read or write request.
11 . The apparatus of claim 8 , further comprising updating the behavior profile for the user based at least in part on the verification result.
12 . The apparatus of claim 8 , wherein the obtained at least one read or write request is only completed if the verification result is successful.
13 . The apparatus of claim 8 , wherein the determining whether the obtained at least one read or write request exhibits anomalous user behavior employs machine learning techniques.
14 . A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:
obtaining, by a storage controller of a storage system, a behavior profile for a user, wherein the storage system (i) comprises the storage controller, a plurality of storage devices and at least one processing device and (ii) processes one or more of a plurality of read requests and a plurality of write requests directed to one or more of the storage devices, the at least one processing device comprising a processor coupled to a memory, wherein the storage controller learns at least a portion of the behavior profile during a learning period by monitoring one or more of a plurality of the read requests and a plurality of the write requests of the user;
performing the following steps, in response to obtaining, by the storage controller of the storage system, at least one read or write request from the user directed to one or more of the storage devices, of the storage system, that store data associated with the obtained at least one read or write request:
determining, by the storage controller of the storage system, prior to a completion of a processing of the obtained at least one read or write request, whether the obtained at least one read or write request exhibits anomalous user behavior relative to the behavior profile;
initiating, by the storage controller of the storage system, a multi-factor authentication of the user, in response to the determining that the obtained at least one read or write request exhibits anomalous user behavior, to obtain a verification result; and
processing, by the storage controller of the storage system, the obtained at least one read or write request based at least in part on the verification result.
15 . The non-transitory processor-readable storage medium of claim 14 , wherein the obtaining the behavior profile for the user comprises obtaining behavioral information from the user.
16 . The non-transitory processor-readable storage medium of claim 14 , wherein the multi-factor authentication comprises an out-of-band authorization request sent to at least one user associated with the at least one read or write request.
17 . The non-transitory processor-readable storage medium of claim 4 , further comprising updating the behavior profile for the user based at least in part on the verification result.
18 . The non-transitory processor-readable storage medium of claim 14 , wherein the obtained at least one read or write request is only completed if the verification result is successful.
19 . The non-transitory processor-readable storage medium of claim 14 , wherein the determining whether the obtained at least one read or write request exhibits anomalous user behavior employs machine learning techniques.
20 . The apparatus of claim 8 , further comprising performing one or more automated remedial actions in response to the verification result.