IP Library Granted Patent US 11,720,714
Granted Patent B2
US 11,720,714 · App. 17/039,556 · Granted Aug 8, 2023

Inter-I/O relationship based detection of a security threat to a storage system

Inventors: Ethan L. Miller (Santa Cruz, CA); Ronald Karr (Palo Alto, CA); Alexandre Xavier Duchâteau (Bellevue, WA); Constantine P Sapuntzakis (Palo Alto, CA)
Assignee: Pure Storage, Inc.
G06F21/78G06F3/0604G06F3/067G06F3/0622G06F3/0653G06F3/0659G06F21/566G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,720,714
App. No.
17/039,556
Filed
Sep 30, 2020
Granted
Aug 8, 2023
Kind
B2
Art Unit
2499
USPC
726/26
Abstract

An illustrative method includes a data protection system identifying one or more input operations and one or more output operations performed between a source and a storage system, identifying an anomaly in a relationship between the one or more input operations and the one or more output operations, and determining, based on the identifying of the anomaly, that the storage system is possibly being targeted by a security threat.

Claims (53)

1. A method comprising:

determining, by a data protection system, that a total amount of read traffic and write traffic processed by a storage system during a time period exceeds a threshold;

determining, by the data protection system, a first compressibility metric associated with the write traffic, the first compressibility metric indicating an amount of storage space saved if the write traffic is compressed;

determining, by the data protection system, a second compressibility metric associated with the read traffic, the second compressibility metric indicating an amount of storage space saved if the read traffic is compressed;

determining, by the data protection system based on a comparison of the first compressibility metric with the second compressibility metric, that the write traffic is less compressible than the read traffic;

identifying, by the data protection system, an anomaly in a relationship between one or more input operations and one or more output operations performed between a source and the storage system; and

determining, by the data protection system based on the identifying of the anomaly and based on the total amount of read traffic and write traffic exceeding the threshold and based on the write traffic being less compressible than the read traffic, that the storage system is possibly being targeted by a security threat.

2. The method of claim 1 , wherein the identifying of the anomaly in the relationship between the one or more input operations and the one or more output operations further comprises:

identifying a timing between the one or more input operations and the one or more output operations; and

determining, based on the timing, that the one or more input operations and the one or more output operations are correlated.

3. The method of claim 1 , wherein the identifying of the anomaly in the relationship between the one or more input operations and the one or more output operations further comprises determining that the one or more input operations and the one or more output operations are performed in accordance with an identifiable pattern.

4. The method of claim 3 , wherein the determining that the one or more input operations and the one or more output operations are performed in accordance with the identifiable pattern comprises determining that the one or more input operations and the one or more output operations progress through sequentially numbered logical storage units of a storage structure within the storage system.

5. The method of claim 4 , wherein the sequentially numbered logical storage units comprise sectors of the storage structure.

6. The method of claim 3 , wherein the determining that the one or more input operations and the one or more output operations are performed in accordance with the identifiable pattern comprises determining that the one or more input operations and the one or more output operations are continuous from a beginning of a partition within a storage structure of the storage system.

7. The method of claim 1 , wherein the identifying of the anomaly in the relationship between the one or more input operations and the one or more output operations further comprises:

determining that the one or more output operations include read operations that cause data stored by the storage system for more than a predetermined amount of time to be transmitted from the storage system to the source;

identifying a total amount of the data transmitted from the storage system to the source;

determining that the one or more input operations include write operations that write new data to the source; and

determining that a total amount of the new data is within a threshold amount of the total amount of the data transmitted from the storage system to the source.

8. The method of claim 7 , wherein the identifying of the anomaly in the relationship between the one or more input operations and the one or more output operations further comprises determining that the data transmitted from the storage system to the source has not been read from the storage system for more than a threshold amount of time prior to the read operations being performed.

9. The method of claim 7 , wherein the identifying of the anomaly in the relationship between the one or more input operations and the one or more output operations further comprises determining that each data instance included in the data transmitted from the storage system to the source is only transmitted one time to the source.

10. The method of claim 1 , further comprising performing, by the data protection system in response to the determining that the storage system is possibly being targeted by the security threat, a remedial action with respect to the storage system.

11. A system comprising:

a memory storing instructions;

a processor communicatively coupled to the memory and configured to execute the instructions to:

determine that a total amount of read traffic and write traffic processed by a storage system during a time period exceeds a threshold;

determine a first compressibility metric associated with the write traffic, the first compressibility metric indicating an amount of storage space saved if the write traffic is compressed;

determine a second compressibility metric associated with the read traffic, the second compressibility metric indicating an amount of storage space saved if the read traffic is compressed;

determine, based on a comparison of the first compressibility metric with the second compressibility metric, that the write traffic is less compressible than the read traffic;

identify an anomaly in a relationship between the one or more input operations and the one or more output operations performed between a source and the storage system; and

determine, based on the identifying of the anomaly and based on the total amount of read traffic and write traffic exceeding the threshold and based on the write traffic being less compressible than the read traffic, that the storage system is possibly being targeted by a security threat.

12. The system of claim 11 , wherein the identifying of the anomaly in the relationship between the one or more input operations and the one or more output operations further comprises:

identifying a timing between the one or more input operations and the one or more output operations; and

determining, based on the timing, that the one or more input operations and the one or more output operations are correlated.

13. The system of claim 11 , wherein the identifying of the anomaly in the relationship between the one or more input operations and the one or more output operations further comprises determining that the one or more input operations and the one or more output operations are performed in accordance with an identifiable pattern.

14. The system of claim 13 , wherein the determining that the one or more input operations and the one or more output operations are performed in accordance with the identifiable pattern comprises determining that the one or more input operations and the one or more output operations progress through sequentially numbered logical storage units of a storage structure within the storage system.

15. The system of claim 13 , wherein the determining that the one or more input operations and the one or more output operations are performed in accordance with the identifiable pattern comprises determining that the one or more input operations and the one or more output operations are continuous from a beginning of a partition within a storage structure of the storage system.

16. The system of claim 11 , wherein the identifying of the anomaly in the relationship between the one or more input operations and the one or more output operations further comprises:

determining that the one or more output operations include read operations that cause data stored by the storage system for more than a predetermined amount of time to be transmitted from the storage system to the source;

identifying a total amount of the data transmitted from the storage system to the source;

determining that the one or more input operations include write operations that write new data to the source; and

determining that a total amount of the new data is within a threshold amount of the total amount of the data transmitted from the storage system to the source.

17. The system of claim 16 , wherein the identifying of the anomaly in the relationship between the one or more input operations and the one or more output operations further comprises determining that each data instance included in the data transmitted from the storage system to the source is only transmitted one time to the source.

18. A non-transitory computer-readable medium storing instructions that, when executed, direct a processor of a computing device to:

determine that a total amount of read traffic and write traffic processed by a storage system during a time period exceeds a threshold;

determine a first compressibility metric associated with the write traffic, the first compressibility metric indicating an amount of storage space saved if the write traffic is compressed;

determine a second compressibility metric associated with the read traffic, the second compressibility metric indicating an amount of storage space saved if the read traffic is compressed;

determine, based on a comparison of the first compressibility metric with the second compressibility metric, that the write traffic is less compressible than the read traffic;

identify an anomaly in a relationship between one or more input operations and one or more output operations performed between a source and the storage system; and

determine, based on the identifying of the anomaly, that the storage system is possibly being targeted by a security threat.

19. The non-transitory computer-readable medium of claim 18 , wherein the identifying of the anomaly in the relationship between the one or more input operations and the one or more output operations further comprises:

identifying a timing between the one or more input operations and the one or more output operations; and

determining, based on the timing, that the one or more input operations and the one or more output operations are correlated.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2020
From: MILLER, ETHAN L.; KARR, RONALD; DUCHÂTEAU, ALEXANDRE XAVIER; SAPUNTZAKIS, CONSTANTINE P
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 053939/0092 →
Continuity (4)
Continuation In Part 16711060 · Dec 11, 2019
Provisional Application 62985229 · Mar 4, 2020
Provisional Application 62939518 · Nov 22, 2019
Related Publication 20210216666A1 · Jul 15, 2021
Cited By (2)
US 12,306,941 US 12,499,224