IP Library Granted Patent US 11,451,574
Granted Patent B2
US 11,451,574 · App. 16/914,599 · Granted Sep 20, 2022

Detecting security threats in storage systems using artificial intelligence techniques

Inventors: Deepak Gowda (Cary, NC); Bina K. Thakkar (Cary, NC); Wenjin Liu (Cary, NC)
Assignee: EMC IP Holding Company LLC
H04L63/1433G06N3/02G06N20/00H04L63/1416H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,451,574
App. No.
16/914,599
Granted
Sep 20, 2022
Kind
B2
Abstract

Methods, apparatus, and processor-readable storage media for detecting security threats in storage systems using AI techniques are provided herein. An example computer-implemented method includes obtaining historical performance data and historical capacity data pertaining to one or more storage objects within a storage system; determining supervised datasets pertaining to security threat-related data and non-security threat-related data by processing at least a portion of the obtained data using a first set of AI techniques; configuring a second set of AI techniques based at least in part on the determined supervised datasets; detecting one or more security threats in connection with at least one storage object within the storage system by processing input data from the at least one storage object using the second set of AI techniques; and performing at least one automated action based at least in part on the one or more detected security threats.

Claims (39)

1. A computer-implemented method comprising:

obtaining historical performance data and historical capacity data pertaining to one or more storage objects within at least one storage system;

determining supervised datasets pertaining to security threat-related data and non-security threat-related data by processing at least a portion of the obtained historical performance data and historical capacity data using a first set of one or more artificial intelligence techniques, wherein the first set of one or more artificial intelligence techniques comprises at least one long short-term memory neural network comprising multiple hidden units, and wherein determining the supervised datasets comprises using the at least one long short-term memory neural network to determine multiple patterns, associated with multiple distinct intervals of time, in the at least a portion of the obtained historical performance data and historical capacity data;

configuring a second set of one or more artificial intelligence techniques based at least in part on the determined supervised datasets;

detecting one or more security threats in connection with at least one storage object within the at least one storage system by processing input data from the at least one storage object using the second set of one or more artificial intelligence techniques; and

performing at least one automated action based at least in part on the one or more detected security threats;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The computer-implemented method of claim 1 , wherein determining the multiple patterns associated with multiple distinct intervals of time comprises determining, for each of one or more metrics within the at least a portion of the obtained historical performance data and historical capacity data, an upper bound value for non-security threat-related data and a lower bound value for non-security threat-related data.

3. The computer-implemented method of claim 1 , wherein the one or more storage objects comprises one or more of at least one file system within the at least one storage system and at least one logical unit number within the at least one storage system.

4. The computer-implemented method of claim 1 , wherein the second set of one or more artificial intelligence techniques comprises a machine learning model which uses at least one deep learning technique comprising a recurrent neural network, and wherein configuring the second set of one or more artificial intelligence techniques comprises learning one or more threat-related patterns in the determined supervised datasets based at least in part on a number of layers in the recurrent neural network.

5. The computer-implemented method of claim 1 , wherein performing the at least one automated action comprises generating and outputting an alert regarding the one or more detected security threats to at least one entity associated with the at least one storage system.

6. The computer-implemented method of claim 1 , wherein performing the at least one automated action comprises training the second set of one or more artificial intelligence techniques using at least a portion of the one or more detected security threats.

7. The computer-implemented method of claim 1 , further comprising:

implementing a closed-loop feedback mechanism responsive to one or more conditions related to at least a portion of the one or more detected security threats.

8. The computer-implemented method of claim 1 , wherein the historical performance data comprise data related to one or more of latency, input/output operations per second, bandwidth, central processing unit utilization, read percentage, and queue length.

9. The computer-implemented method of claim 1 , wherein the input data comprise real-time performance data and real-time capacity data from the at least one storage object.

10. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device:

to obtain historical performance data and historical capacity data pertaining to one or more storage objects within at least one storage system;

to determine supervised datasets pertaining to security threat-related data and non-security threat-related data by processing at least a portion of the obtained historical performance data and historical capacity data using a first set of one or more artificial intelligence techniques, wherein the first set of one or more artificial intelligence techniques comprises at least one long short-term memory neural network comprising multiple hidden units, and wherein determining the supervised datasets comprises using the at least one long short-term memory neural network to determine multiple patterns, associated with multiple distinct intervals of time, in the at least a portion of the obtained historical performance data and historical capacity data;

to configure a second set of one or more artificial intelligence techniques based at least in part on the determined supervised datasets;

to detect one or more security threats in connection with at least one storage object within the at least one storage system by processing input data from the at least one storage object using the second set of one or more artificial intelligence techniques; and

to perform at least one automated action based at least in part on the one or more detected security threats.

11. The non-transitory processor-readable storage medium of claim 10 , wherein determining the multiple patterns associated with multiple distinct intervals of time comprise determining, for each of one or more metrics within the at least a portion of the obtained historical performance data and historical capacity data, an upper bound value for non-security threat-related data and a lower bound value for non-security threat-related data.

12. The non-transitory processor-readable storage medium of claim 10 , wherein the one or more storage objects comprises one or more of at least one file system within the at least one storage system and at least one logical unit number within the at least one storage system.

13. The non-transitory processor-readable storage medium of claim 10 , wherein the second set of one or more artificial intelligence techniques comprises a machine learning model which uses at least one deep learning technique comprising a recurrent neural network, and wherein configuring the second set of one or more artificial intelligence techniques comprises learning one or more threat-related patterns in the determined supervised datasets based at least in part on a number of layers in the recurrent neural network.

14. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured:

to obtain historical performance data and historical capacity data pertaining to one or more storage objects within at least one storage system;

to determine supervised datasets pertaining to security threat-related data and non-security threat-related data by processing at least a portion of the obtained historical performance data and historical capacity data using a first set of one or more artificial intelligence techniques, wherein the first set of one or more artificial intelligence techniques comprises at least one long short-term memory neural network comprising multiple hidden units, and wherein determining the supervised datasets comprises using the at least one long short-term memory neural network to determine multiple patterns, associated with multiple distinct intervals of time, in the at least a portion of the obtained historical performance data and historical capacity data;

to configure a second set of one or more artificial intelligence techniques based at least in part on the determined supervised datasets;

to detect one or more security threats in connection with at least one storage object within the at least one storage system by processing input data from the at least one storage object using the second set of one or more artificial intelligence techniques; and

to perform at least one automated action based at least in part on the one or more detected security threats.

15. The apparatus of claim 14 , wherein determining the multiple patterns associated with multiple distinct intervals of time comprise determining, for each of one or more metrics within the at least a portion of the obtained historical performance data and historical capacity data, an upper bound value for non-security threat-related data and a lower bound value for non-security threat-related data.

16. The apparatus of claim 14 , wherein the one or more storage objects comprises one or more of at least one file system within the at least one storage system and at least one logical unit number within the at least one storage system.

17. The apparatus of claim 14 , wherein the second set of one or more artificial intelligence techniques comprises a machine learning model which uses at least one deep learning technique comprising a recurrent neural network, and wherein configuring the second set of one or more artificial intelligence techniques comprises learning one or more threat-related patterns in the determined supervised datasets based at least in part on a number of layers in the recurrent neural network.

18. The apparatus of claim 14 , wherein performing the at least one automated action comprises generating and outputting an alert regarding the one or more detected security threats to at least one entity associated with the at least one storage system.

19. The apparatus of claim 14 , wherein the historical performance data comprise data related to one or more of latency, input/output operations per second, bandwidth, central processing unit utilization, read percentage, and queue length.

20. The apparatus of claim 14 , wherein the input data comprise real-time performance data and real-time capacity data from the at least one storage object.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053578/0183) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060332/0864 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053574/0221) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060333/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053573/0535) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060333/0106 →
RELEASE OF SECURITY INTEREST AT REEL 053531 FRAME 0108 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0371 →
SECURITY INTEREST Recorded Aug 21, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 053578/0183 →
SECURITY INTEREST Recorded Aug 21, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 053573/0535 →
SECURITY INTEREST Recorded Aug 21, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 053574/0221 →
SECURITY AGREEMENT Recorded Aug 18, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 053531/0108 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2020
From: GOWDA, DEEPAK; THAKKAR, BINA K.; LIU, WENJIN
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 053070/0442 →