Unauthorized access determination based on burst input/output indicators or network activity scores
In some examples, a system computes read burst indicators of read input/output (I/O) bursts to a storage system at respective time points, and computes encryption burst indicators of encryption I/O bursts at the respective time points. The system calculates a score based on the read burst indicators, the encryption burst indicators, and a distance factor that is based on a time distance between when a burst read I/O burst of the read I/O bursts occurred and when an encryption I/O burst of the encryption I/O bursts occurred. The system determines whether unauthorized access of a computing environment is occurring based on the score.
1 . A non-transitory machine-readable storage medium comprising instructions that upon execution cause a system to:
compute read burst indicators of read input/output (I/O) bursts to a storage system at respective time points;
compute encryption burst indicators of encryption I/O bursts at the respective time points;
calculate a score based on the read burst indicators, the encryption burst indicators, and a distance factor that is based on a time distance between when a read I/O burst of the read I/O bursts occurred and when an encryption I/O burst of the encryption I/O bursts occurred; and
determine whether an unauthorized access of a computing environment is occurring based on the score.
2 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:
compute fragmentation burst indicators of fragmentation I/O bursts at the respective time points,
wherein the score is calculated further based on the fragmentation burst indicators.
3 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:
compute compression burst indicators of compression I/O bursts at the respective time points,
wherein the score is calculated further based on the compression burst indicators.
4 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:
detect transmission of data subject to encryption in the encryption I/O bursts to an external target system that is outside the computing environment,
wherein the determining of whether the unauthorized access of the computing environment is occurring is further based on detecting the transmission to the external target system.
5 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:
identify a communication protocol used to transmit data subject to encryption in the encryption I/O bursts,
wherein the determining of whether the unauthorized access of the computing environment is occurring is further based on the identified communication protocol.
6 . The non-transitory machine-readable storage medium of claim 5 , wherein the instructions upon execution cause the system to:
determine whether the identified communication protocol is part of a collection of expected communication protocols,
wherein the determining of whether the unauthorized access of the computing environment is occurring is further based on whether the identified communication protocol is part of the collection of expected communication protocols.
7 . The non-transitory machine-readable storage medium of claim 1 , wherein the score is calculated based on relative time orders of the read burst indicators and the encryption burst indicators.
8 . The non-transitory machine-readable storage medium of claim 7 , wherein the score is calculated based on aggregating a first read burst indicator at a first time point and a first encryption burst indicator at a second time point that is later than the first time point.
9 . The non-transitory machine-readable storage medium of claim 8 , wherein a second encryption burst indicator at a third time point that is earlier than the first time point second is not aggregated with the first read burst indicator for calculating the score.
10 . The non-transitory machine-readable storage medium of claim 7 , wherein the instructions upon execution cause the system to:
compute fragmentation burst indicators of fragmentation I/O bursts at the respective time points,
wherein the score is calculated further based on relative time orders of the read burst indicators, the fragmentation burst indicators, and the encryption burst indicators.
11 . The non-transitory machine-readable storage medium of claim 7 , wherein the instructions upon execution cause the system to:
compute compression burst indicators of compression I/O bursts at the respective time points,
wherein the score is calculated further based on relative time orders of the read burst indicators, the compression burst indicators, and the encryption burst indicators.
12 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:
compute an encryption activity score representing transfers of encrypted objects over a network,
wherein the determining of whether the unauthorized access of the computing environment is occurring is further based on the encryption activity score.
13 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:
compute a small object activity score representing transfers of small objects with sizes less than a size threshold over a network,
wherein the determining of whether the unauthorized access of the computing environment is occurring is further based on the small object activity score.
14 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:
compute a data rate spike score representing a data rate spike in transfers of objects over a network,
wherein the determining of whether the unauthorized access of the computing environment is occurring is further based on the data rate spike score.
15 . A system comprising:
a hardware processor; and
a non-transitory storage medium storing instructions executable on the hardware processor to:
compute encryption activity scores representing transfers of encrypted objects over a network,
compute small object activity scores representing transfers of small objects with sizes less than a size threshold over the network;
compute a proximity factor based on a time proximity of the transfers of encrypted objects and the transfers of small objects; and
determine, based on the encryption activity scores, the small object activity scores, and the proximity factor, whether an unauthorized access of a computing environment is occurring.
16 . The system of claim 15 , wherein the instructions are executable on the hardware processor to:
compute a data rate spike score representing a data rate spike in transfers of objects over the network,
wherein the proximity factor is computed based on a time proximity of the transfers of encrypted objects, the transfers of small objects, and the data rate spike, and
wherein the determining of whether the unauthorized access of the computing environment is occurring is further based on the data rate spike score.
17 . The system of claim 15 , wherein the instructions are executable on the hardware processor to:
compute an irregular communication score based on one or more of:
detecting transmission of the encrypted objects and the small objects to an external target system outside the computing environment, or
identifying an unexpected communication protocol used to transmit the encrypted objects and the small objects,
wherein the determining of whether the unauthorized access of the computing environment is occurring is further based on the irregular communication score.
18 . The system of claim 15 , wherein the proximity factor is based on a standard deviation of a time index of a maximum encryption activity score of the encryption activity scores and a time index of a maximum small object activity score of the small object activity scores in a time interval.
19 . A method comprising:
computing, by a system comprising a hardware processor, read burst indicators of read input/output (I/O) bursts to a storage system at respective time points;
computing, by the system, encryption burst indicators of encryption I/O bursts at the respective time points;
calculating, by the system, a burst-related attack score based on relative time orders of the read burst indicators and the encryption burst indicators;
computing, by the system, encryption activity scores representing transfers of encrypted objects over a network,
computing, by the system, data rate spike scores representing spikes in data rates over the network;
determining, by the system, whether an unauthorized access of a computing environment is occurring based on the burst-related attack score, the encryption activity scores, and the data rate spike scores.
20 . The method of claim 19 , comprising:
computing, by the system, a network-related attack score based on the encryption activity scores, the data rate spike scores, and a proximity factor based on a time proximity of the transfers of encrypted objects and transfers of small objects,
wherein the determining of whether the unauthorized access of the computing environment is occurring is based on the burst-related attack score and the network-related attack score.