IP Library › Granted Patent US 10,530,791
Granted Patent B2
US 10,530,791 · App. 15/238,606 · Granted Jan 7, 2020

Storage environment activity monitoring

Inventors: Tara Astigarraga (Fairport, NY); Christopher V. DeRobertis (Hopewell Junction, NY); Louie A. Dickens (Tucson, AZ); Daniel J. Winarski (Tucson, AZ)
Assignee: International Business Machines Corporation
H04L63/1425H04L63/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,530,791
App. No.
15/238,606
Granted
Jan 7, 2020
Kind
B2
Abstract

A computer-implemented method according to one embodiment includes identifying a storage environment, establishing a baseline associated with input and output requests within the storage environment, monitoring activity associated with the storage environment, comparing the activity to the baseline, and performing one or more actions, based on the comparing.

Claims (46)

1. A computer-implemented method, comprising:

identifying a storage environment;

establishing a baseline indicating an expected input/output (I/O) request pattern to the storage environment, including:

determining a ratio of logged read requests received by the storage environment for a first predetermined time period to logged write requests received by the storage environment for the first predetermined time period, and

determining and logging a source identifier (ID) and a fibre channel identifier (FCID) associated with the ratio of logged read requests to logged write requests received by the storage environment;

monitoring activity including a current I/O request pattern received by the storage environment, the monitoring including determining a source ID and an FCID associated with a ratio of current read requests to current write requests received by the storage environment;

comparing the activity to the baseline, including comparing the source ID and FCID associated with the ratio of current read requests to current write requests received by the storage environment to the logged source ID and FCID associated with the ratio of logged read requests to logged write requests received by the storage environment; and

performing one or more actions, based on the comparing, including blocking the source ID and FCID associated with the ratio of current read requests to current write requests received by the storage environment, in response to determining that the activity is a security threat.

2. The computer-implemented method of claim 1 , wherein the activity further includes:

a volume of current read requests made to the storage environment for a predetermined time period, and

a volume of current write requests made to the storage environment for the predetermined time period.

3. The computer-implemented method of claim 1 , wherein:

comparing the activity to the baseline includes flagging the activity in response to determining that the activity deviates from the baseline by more than a predetermined amount,

performing the one or more actions includes, in response to flagging the activity:

comparing the activity to one or more predetermined threat criteria, and

determining and blocking one or more identifiers associated with the activity, in response to determining that the activity is a security threat in response to comparing the activity to the one or more predetermined threat criteria.

4. The computer-implemented method of claim 1 , wherein the expected input/output (I/O) request pattern includes a ratio of logged read requests to logged write requests for the storage environment, and the current I/O request pattern includes a ratio of current read requests to current write requests received by the storage environment.

5. The computer-implemented method of claim 1 , wherein the one or more actions include one or more security actions.

6. The computer-implemented method of claim 1 , wherein the comparing is performed on a recurring basis according to a predetermined amount of time.

7. The computer-implemented method of claim 6 , wherein performing the one or more actions includes flagging the activity as an anomaly in response to determining that the activity deviates from the baseline by more than a predetermined amount, and comparing the activity to one or more predetermined security threat criteria in response to determining that the activity is flagged as the anomaly.

8. The computer-implemented method of claim 7 , wherein one or more security actions are performed in response to determining that the activity flagged as the anomaly is determined to be a security threat as a result of the comparing of the activity to the one or more predetermined security threat criteria.

9. A computer program product for monitoring activity associated with a storage environment, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, wherein the computer readable storage medium is not a transitory signal per se, the program instructions executable by a processor to cause the processor to perform a method comprising:

identifying the storage environment, utilizing the processor;

establishing, utilizing the processor, a baseline indicating an expected input/output (I/O) request pattern to the storage environment, including:

determining a ratio of logged read requests received by the storage environment for a first predetermined time period to logged write requests received by the storage environment for the first predetermined time period, and

determining and logging a source identifier (ID) and a fibre channel identifier (FCID) associated with the ratio of logged read requests to logged write requests received by the storage environment;

monitoring the activity including a current I/O request pattern received by the storage environment, utilizing the processor, the monitoring including determining a source ID and an FCID associated with a ratio of current read requests to current write requests received by the storage environment;

comparing the activity to the baseline, utilizing the processor, including comparing the source ID and FCID associated with the ratio of current read requests to current write requests received by the storage environment to the logged source ID and FCID associated with the ratio of logged read requests to logged write requests received by the storage environment; and

performing, utilizing the processor, one or more actions, based on the comparing, including blocking the source ID and FCID associated with the ratio of current read requests to current write requests received by the storage environment, in response to determining that the activity is a security threat.

10. The computer program product of claim 9 , wherein the current I/O request pattern includes a ratio of current read requests to current write requests received by the storage environment.

11. The computer program product of claim 9 , wherein the baseline is obtained by performing active monitoring of the storage environment.

12. The computer program product of claim 9 , wherein the baseline indicates predetermined percentages of reads and writes to the storage environment.

13. The computer program product of claim 9 , wherein the activity includes current input and output (I/O) patterns for the storage environment.

14. The computer program product of claim 9 , wherein comparing the activity to the baseline includes determining whether the activity falls above or below the baseline by at least a predetermined amount.

15. The computer program product of claim 9 , wherein performing the one or more actions includes flagging the activity as an anomaly in response to determining that the activity deviates from the baseline by more than a predetermined amount.

16. The computer program product of claim 15 , wherein performing the one or more actions may include comparing the activity to one or more predetermined security threat criteria in response to determining that the activity is flagged as the anomaly.

17. A system, comprising:

a processor; and

logic integrated with the processor, executable by the processor, or integrated with and executable by the processor, the logic being configured to:

identify a storage environment;

establish a baseline indicating an expected input/output (I/O) request pattern to the storage environment, including:

determining a ratio of logged read requests received by the storage environment for a first predetermined time period to logged write requests received by the storage environment for the first predetermined time period, and

determining and logging a source identifier (ID) and a fibre channel identifier (FCID) associated with the ratio of logged read requests to logged write requests received by the storage environment;

monitor activity including a current I/O request pattern received by the storage environment, the monitoring including determining a source ID and an FCID associated with a ratio of current read requests to current write requests received by the storage environment;

compare the activity to the baseline, including comparing the source ID and FCID associated with the ratio of current read requests to current write requests received by the storage environment to the logged source ID and FCID associated with the ratio of logged read requests to logged write requests received by the storage environment; and

perform one or more actions, based on the comparison, including blocking the source ID and FCID associated with the ratio of current read requests to current write requests received by the storage environment, in response to determining that the activity is a security threat.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2016
From: ASTIGARRAGA, TARA; DEROBERTIS, CHRISTOPHER V.; DICKENS, LOUIE A.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 039459/0594 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2016
From: WINARSKI, DANIEL J.
To: COMPUTER TASK GROUP, INC.
Reel/Frame 039459/0666 →
CONFIRMATORY PATENT ASSIGNMENT Recorded Aug 16, 2016
From: COMPUTER TASK GROUP, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 039707/0185 →
Continuity (1)
Related Publication 20180054453A1 · Feb 22, 2018
Cited By (5)
US 12,204,657 US 12,248,566 US 12,411,962 US 12,561,428 US 12,585,760