IP Library Granted Patent US 12701127
Granted Patent B2
US 12701127 · App. 18/754,958 · Granted Aug 4, 2026

Data protection based on intrusion detection

Inventors: Gang Lyu (Shanghai, CN); Jing Zhao (Beijing, CN); Fang Yuan Cheng (Beijing, CN); Fu Long Wang (Beijing, CN); Wei Gong (Beijing, CN); Yun Feng Ma (Bejing, CN)
Assignee: International Business Machines Corporation
H04L63/1416H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12701127
App. No.
18/754,958
Filed
Jun 26, 2024
Granted
Aug 4, 2026
Kind
B2
Art Unit
2491
USPC
726/23
Abstract

A determination is made of whether a network attack is suspected. In response to determining that the network attack is suspected, a generation of a snapshot of volumes of data is requested via a low latency link. The snapshot of the volumes of data is generated while the volumes of data are blocked from access and prior to an occurrence of an effect of the network attack on the volumes of data.

Claims (47)

1 . A computer-implemented method, comprising:

determining whether a network attack is suspected;

in response to determining that the network attack is suspected, requesting, via a low latency link, a generation of a snapshot of volumes of data; and

generating the snapshot of the volumes of data while the volumes of data are blocked from access and prior to an occurrence of an effect of the network attack on the volumes of data, wherein generating the snapshot of the volumes of data comprises:

identifying, from the volumes of data, a plurality of volumes of data affected by the network attack and an identity associated with each of the plurality of affected volumes of data, the identity comprising at least one selected from the group consisting of:

(i) attack severity of the network attack associated with each affected volume of data; and

(ii) data priority of each affected volume of data;

sorting the plurality of affected volumes of data based on the identity of each of the plurality of affected volumes of data; and

sending, via the low latency link, a snapshot request to a storage system according to an order of the sorted volumes of data.

2 . The computer-implemented method of claim 1 , further comprising evaluating a risk of the network attack on a host system, wherein the determining whether the network attack is suspected is based on the evaluating of the risk of the network attack.

3 . The computer-implemented method of claim 1 , further comprising informing a snapshot manager of the plurality of affected volumes of data and the identity associated with each of the plurality of affected volume of data.

4 . The computer-implemented method of claim 1 , further comprising arranging volumes of data that are determined to be safe from attack at a tail of a command queue.

5 . The computer-implemented method of claim 1 , wherein the snapshot request includes at least one selected from the group consisting of a consistency group identifier and identifiers of the volumes of data.

6 . The computer-implemented method of claim 1 , further comprising setting the snapshot request to high priority in the storage system.

7 . The computer-implemented method of claim 1 , further comprising blocking input to and output from the volumes of data in a corresponding consistency group.

8 . The computer-implemented method of claim 7 , further comprising resuming the input to and the output from the corresponding volumes of data after a capture of the snapshot of the volumes of data.

9 . The computer-implemented method of claim 1 , further comprising returning a first completion acknowledgement to a snapshot manager module and returning a second completion acknowledgement from the snapshot manager module to an attack detection module.

10 . The computer-implemented method of claim 1 , further comprising:

verifying that the volumes of data captured by the snapshot is unaffected by the network attack; and

restoring the volumes of data captured by the snapshot after the network attack.

11 . A computer program product, comprising:

one or more tangible computer-readable storage media and program instructions stored on at least one of the one or more tangible computer-readable storage media, the program instructions executable by a processor, the program instructions comprising:

determining whether a network attack is suspected;

in response to determining that the network attack is suspected, requesting, via a low latency link, a generation of a snapshot of volumes of data; and

generating the snapshot of the volumes of data while the volumes of data are blocked from access and prior to an occurrence of an effect of the network attack on the volumes of data, wherein generating the snapshot of the volumes of data comprises:

identifying, from the volumes of data, a plurality of volumes of data affected by the network attack and an identity associated with each of the plurality of affected volumes of data, the identity comprising at least one selected from the group consisting of:

(i) attack severity of the network attack associated with the affected volume of data; and

(ii) data priority of the affected volume of data;

sorting the plurality of affected volumes of data based on the identity of each of the plurality of affected volumes of data; and

sending, via the low latency link, a snapshot request to a storage system according to an order of the sorted volumes of data.

12 . A system comprising:

a memory; and

at least one processor coupled to said memory and operative to:

determine whether a network attack is suspected;

in response to determination that the network attack is suspected, request, via a low latency link, a generation of a snapshot of volumes of data;

generate the snapshot of the volumes of data while the volumes of data are blocked from access and prior to an occurrence of an effect of the network attack on the volumes of data, wherein generation of the snapshot of the volumes of data comprises:

identify, from the volumes of data, a plurality of volumes of data affected by the network attack and an identity associated with each of the plurality of affected volumes of data, the identity comprising at least one selected from the group consisting of:

(i) attack severity of the network attack associated with the affected volume of data; and

(ii) data priority of the affected volume of data;

sort the plurality of affected volumes of data based on the identity of each of the plurality of affected volumes of data; and

send, via the low latency link, a snapshot request to a storage system according to an order of the sorted volumes of data.

13 . The system of claim 12 , wherein the at least one processor is operative to evaluate a risk of the network attack on a host system, wherein the determining whether the network attack is suspected is based on the evaluating of the risk of the network attack.

14 . The system of claim 12 , wherein the at least one processor is operative to inform a snapshot manager of the plurality of affected volumes of data and the identity associated with each of the plurality of affected volumes of data.

15 . The system of claim 12 , wherein the at least one processor is operative to set the snapshot request to high priority in the storage system.

16 . The system of claim 12 , wherein the at least one processor is operative to:

verify that the volumes of data captured by the snapshot is unaffected by the network attack; and

restore the volumes of data captured by the snapshot after the network attack.