IP Library › Granted Patent US 12,299,118
Granted Patent B2
US 12,299,118 · App. 17/732,620 · Granted May 13, 2025

Host multi-path layer with IO analytics for malware defense

Inventors: Sanjib Mallick (Bangalore, IN); Arieh Don (Newton, MA); Elik Levin (Modi'ln, IL); Kundan Kumar (Bangalore, IN); Gaurav Singh (Satna, IN)
Assignee: Dell Products L.P.
G06F21/554G06F21/552G06F21/564G06F21/568G06F21/78
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,299,118
App. No.
17/732,620
Granted
May 13, 2025
Kind
B2
Abstract

An apparatus comprises at least one processing device configured to implement a multi-path layer in a host device, wherein the multi-path layer controls delivery of input-output (IO) operations from the host device to a storage system over selected ones of a plurality of paths through a network. The multi-path layer is configured, for each of at least a subset of the IO operations, to store at least a process identifier, a user identifier and an access type for the IO operation. The multi-path layer is further configured to perform analytics on the stored process identifiers, user identifiers and access types to detect an access pattern, and responsive to the detected access pattern having one or more designated characteristics associated with malware, to generate an alert. The alert may be generated by inserting security alert indicators into respective ones of the IO operations, for extraction therefrom by the storage system.

Claims (72)

1. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured:

to implement a multi-path layer in a host device, the multi-path layer controlling delivery of input-output (IO) operations from the host device to a storage system over selected ones of a plurality of paths through a network, the multi-path layer being within the host device;

wherein the multi-path layer is configured:

for each of at least a subset of the IO operations, to store at least a process identifier, a user identifier and an access type for the IO operation;

to perform analytics on the stored process identifiers, user identifiers and access types to detect an access pattern; and

responsive to the detected access pattern having one or more designated characteristics associated with malware, to generate an alert and to send the alert from the host device to the storage system, the alert comprising a malware alert for the storage system from the host device;

wherein generating the alert comprises inserting security alert indicators into respective ones of the IO operations delivered from the host device to the storage system to indicate that the detected access pattern for those IO operations has one or more designated characteristics associated with malware.

2. The apparatus of claim 1 wherein the at least one processing device comprises at least a portion of the host device.

3. The apparatus of claim 2 wherein the at least one processing device comprises at least a first processing device of the host device and at least a second processing device of the storage system.

4. The apparatus of claim 1 wherein the multi-path layer comprises one or more multi- path IO (MPIO) drivers of the host device.

5. The apparatus of claim 1 wherein the process identifiers indicate respective ones of one or more application processes that generated the IO operations on the host device, the user identifier indicates a particular user for which the application processes are executed in the host device, and the access type indicates for a given one of the IO operations whether the IO operation is a read operation or a write operation.

6. The apparatus of claim 1 wherein the multi-path layer is further configured to insert the process identifiers into respective ones of the IO operations in conjunction with controlling delivery of the IO operations from the host device to the storage system over selected ones of the plurality of paths through the network.

7. The apparatus of claim 1 wherein the at least one processing device is further configured:

to receive the IO operations from the host device over the network;

to extract the security alert indicators from respective ones of the received IO operations; and

to perform a particular malware defense action for at least one logical storage volume based at least in part on the extracted security alert indicators.

8. The apparatus of claim 7 wherein performing a particular malware defense action for at least one logical storage volume based at least in part on the extracted security alert indicators comprises generating a snapshot of the logical storage volume.

9. The apparatus of claim 7 wherein performing a particular malware defense action for at least one logical storage volume based at least in part on the extracted security alert indicators comprises preventing the IO operations from modifying the logical storage volume.

10. The apparatus of claim 1 wherein performing analytics on the stored process identifiers, user identifiers and access types to detect an access pattern comprises:

determining a number of read operations directed to a particular logical storage volume within a given time interval;

determining a number of write operations directed to the particular logical storage volume within the given time interval; and

detecting the access pattern based at least in part on the determined number of read operations and the determined number of write operations.

11. The apparatus of claim 1 wherein performing analytics on the stored process identifiers, user identifiers and access types to detect an access pattern comprises identifying an access pattern characterized by at least one of the following:

a newly-created process performing both read operations and write operations directed to a particular logical storage volume;

a process that utilizes one or more scripts to perform both read operations and write operations directed to the particular logical storage volume;

a sequential access pattern comprising both read operations and write operations directed to the particular logical storage volume;

a substantial increase in usage of computation and memory resources; and

a particular type of correlation between one or more original files and one or more modified files.

12. The apparatus of claim 1 wherein the at least one processing device is further configured:

to identify one or more suspect accesses based at least in part on the detected access pattern;

to determine an entropy of one or more files targeted by the one or more suspect accesses; and

to block further access of a corresponding process and user identifier responsive to the determined entropy being greater than a threshold entropy level.

13. The apparatus of claim 1 wherein performing analytics on the stored process identifiers, user identifiers and access types to detect an access pattern comprises:

training a machine learning model; and

utilizing the trained machine learning model to detect the access pattern.

14. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code, when executed by at least one processing device comprising a processor coupled to a memory, causes the at least one processing device:

to implement a multi-path layer in a host device, the multi-path layer controlling delivery of input-output (IO) operations from the host device to a storage system over selected ones of a plurality of paths through a network, the multi-path layer being within the host device;

wherein the multi-path layer is configured:

for each of at least a subset of the IO operations, to store at least a process identifier, a user identifier and an access type for the IO operation;

to perform analytics on the stored process identifiers, user identifiers and access types to detect an access pattern; and

responsive to the detected access pattern having one or more designated characteristics associated with malware, to generate an alert and to send the alert from the host device to the storage system, the alert comprising a malware alert for the storage system from the host device;

wherein generating the alert comprises inserting security alert indicators into respective ones of the IO operations delivered from the host device to the storage system to indicate that the detected access pattern for those IO operations has one or more designated characteristics associated with malware.

15. The computer program product of claim 14 wherein the program code, when executed by the at least one processing device, further causes the at least one processing device:

to receive the IO operations from the host device over the network;

to extract the security alert indicators from respective ones of the received IO operations; and

to perform a particular malware defense action for at least one logical storage volume based at least in part on the extracted security alert indicators.

16. A method comprising:

implementing a multi-path layer in a host device, the multi-path layer controlling delivery of input-output (IO) operations from the host device to a storage system over selected ones of a plurality of paths through a network, the multi-path layer being within the host device;

wherein steps performed by the multi-path layer comprise:

for each of at least a subset of the IO operations, storing at least a process identifier, a user identifier and an access type for the IO operation;

performing analytics on the stored process identifiers, user identifiers and access types to detect an access pattern; and

responsive to the detected access pattern having one or more designated characteristics associated with malware, generating an alert and sending the alert from the host device to the storage system, the alert comprising a malware alert for the storage system from the host device;

wherein generating the alert comprises inserting security alert indicators into respective ones of the IO operations delivered from the host device to the storage system to indicate that the detected access pattern for those IO operations has one or more designated characteristics associated with malware.

17. The method of claim 16 further comprising:

receiving the IO operations from the host device over the network;

extracting the security alert indicators from respective ones of the received IO operations; and

performing a particular malware defense action for at least one logical storage volume based at least in part on the extracted security alert indicators.

18. The method of claim 16 wherein performing analytics on the stored process identifiers, user identifiers and access types to detect an access pattern comprises identifying an access pattern characterized by at least one of the following:

a newly-created process performing both read operations and write operations directed to a particular logical storage volume;

a process that utilizes one or more scripts to perform both read operations and write operations directed to the particular logical storage volume;

a sequential access pattern comprising both read operations and write operations directed to the particular logical storage volume;

a substantial increase in usage of computation and memory resources; and

a particular type of correlation between one or more original files and one or more modified files.

19. The method of claim 16 further comprising:

identifying one or more suspect accesses based at least in part on the detected access pattern;

determining an entropy of one or more files targeted by the one or more suspect accesses; and

blocking further access of a corresponding process and user identifier responsive to the determined entropy being greater than a threshold entropy level.

20. The method of claim 16 wherein performing analytics on the stored process identifiers, user identifiers and access types to detect an access pattern comprises:

training a machine learning model; and

utilizing the trained machine learning model to detect the access pattern.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2022
From: MALLICK, SANJIB; DON, ARIEH; LEVIN, ELIK; KUMAR, KUNDAN; SINGH, GAURAV
To: DELL PRODUCTS L.P.
Reel/Frame 059770/0086 →
Continuity (1)
Related Publication 20230351013A1 · Nov 2, 2023
References Cited (125)
US 6567397B1 · Campana et al. · 2003 [cited by applicant]
US 6687746B1 · Shuster et al. · 2004 [cited by applicant]
US 6697875B1 · Wilson · 2004 [cited by applicant]
US 7275103B1 · Thrasher et al. · 2007 [cited by applicant]
US 7454437B1 · Lavallee et al. · 2008 [cited by applicant]
US 7617292B2 · Moore et al. · 2009 [cited by applicant]
US 7668981B1 · Nagineni et al. · 2010 [cited by applicant]
US 7770053B1 · Bappe et al. · 2010 [cited by applicant]
US 7809912B1 · Raizen et al. · 2010 [cited by applicant]
US 7818428B1 · Lavallee et al. · 2010 [cited by applicant]
US 7890664B1 · Tao et al. · 2011 [cited by applicant]
US 7904681B1 · Bappe et al. · 2011 [cited by applicant]
US 7925872B2 · Lai et al. · 2011 [cited by applicant]
US 8250256B2 · Ghosalkar et al. · 2012 [cited by applicant]
US 8285825B1 · Nagaraj et al. · 2012 [cited by applicant]
US 8825919B1 · Lim et al. · 2014 [cited by applicant]
US 8832334B2 · Okita · 2014 [cited by applicant]
US 8874746B1 · Gonzalez · 2014 [cited by applicant]
US 9026694B1 · Davidson et al. · 2015 [cited by applicant]
US 9201803B1 · Derbeko et al. · 2015 [cited by applicant]
US 9400611B1 · Raizen · 2016 [cited by applicant]
US 9430368B1 · Derbeko et al. · 2016 [cited by applicant]
US 9594780B1 · Esposito et al. · 2017 [cited by applicant]
US 9647933B1 · Tawri et al. · 2017 [cited by applicant]
US 9672160B1 · Derbeko et al. · 2017 [cited by applicant]
US 9778852B1 · Marshak et al. · 2017 [cited by applicant]
US 10055582B1 · Weaver et al. · 2018 [cited by applicant]
US 10289325B1 · Bono · 2019 [cited by applicant]
US 10353714B1 · Gokam et al. · 2019 [cited by applicant]
US 10439878B1 · Tah et al. · 2019 [cited by applicant]
US 10474367B1 · Mallick et al. · 2019 [cited by applicant]
US 10476960B1 · Rao et al. · 2019 [cited by applicant]
US 10521369B1 · Mallick et al. · 2019 [cited by applicant]
US 10606496B1 · Mallick et al. · 2020 [cited by applicant]
US 10609066B1 · Nossik et al. · 2020 [cited by applicant]
US 10637917B2 · Mallick et al. · 2020 [cited by applicant]
US 10652206B1 · Pusalkar et al. · 2020 [cited by applicant]
US 10754572B2 · Kumar et al. · 2020 [cited by applicant]
US 10757189B2 · Mallick et al. · 2020 [cited by applicant]
US 10764371B2 · Rao et al. · 2020 [cited by applicant]
US 10789006B1 · Gokam et al. · 2020 [cited by applicant]
US 10817181B2 · Mallick et al. · 2020 [cited by applicant]
US 10838648B2 · Sharma et al. · 2020 [cited by applicant]
US 10880217B2 · Mallick et al. · 2020 [cited by applicant]
US 10884935B1 · Doddaiah · 2021 [cited by applicant]
US 10911402B2 · Pusalkar et al. · 2021 [cited by applicant]
US 11030314B2 · Kucherov et al. · 2021 [cited by applicant]
US 11442652B1 · Dailey · 2022 [cited by examiner]
US 11803453B1 · Bunker · 2023 [cited by examiner]
US 20020023151A1 · Iwatani · 2002 [cited by applicant]
US 20020103923A1 · Cherian et al. · 2002 [cited by applicant]
US 20040010563A1 · Forte et al. · 2004 [cited by applicant]
US 20060026346A1 · Kadoiri et al. · 2006 [cited by applicant]
US 20060277383A1 · Hayden et al. · 2006 [cited by applicant]
US 20070174849A1 · Cheung et al. · 2007 [cited by applicant]
US 20080043973A1 · Lai et al. · 2008 [cited by applicant]
US 20080201458A1 · Salli · 2008 [cited by applicant]
US 20080301332A1 · Butler et al. · 2008 [cited by applicant]
US 20090259749A1 · Barrett et al. · 2009 [cited by applicant]
US 20100313063A1 · Venkataraja et al. · 2010 [cited by applicant]
US 20110197027A1 · Balasubramanian et al. · 2011 [cited by applicant]
US 20110296230A1 · Chen et al. · 2011 [cited by applicant]
US 20120102369A1 · Hiltunen et al. · 2012 [cited by applicant]
US 20120246345A1 · Contreras et al. · 2012 [cited by applicant]
US 20130117766A1 · Bax et al. · 2013 [cited by applicant]
US 20130339551A1 · Flanagan et al. · 2013 [cited by applicant]
US 20140105068A1 · Xu · 2014 [cited by applicant]
US 20150222705A1 · Stephens · 2015 [cited by applicant]
US 20150242134A1 · Takada et al. · 2015 [cited by applicant]
US 20160092136A1 · Balakrishnan et al. · 2016 [cited by applicant]
US 20160117113A1 · Li et al. · 2016 [cited by applicant]
US 20160335003A1 · Ahmed et al. · 2016 [cited by applicant]
US 20170235507A1 · Sinha et al. · 2017 [cited by applicant]
US 20180189635A1 · Olarig et al. · 2018 [cited by applicant]
US 20180253256A1 · Bharadwaj · 2018 [cited by applicant]
US 20180317101A1 · Koue · 2018 [cited by applicant]
US 20190095299A1 · Liu et al. · 2019 [cited by applicant]
US 20190108888A1 · Sarkar et al. · 2019 [cited by applicant]
US 20190334987A1 · Mallick et al. · 2019 [cited by applicant]
US 20200021653A1 · Rao et al. · 2020 [cited by applicant]
US 20200097203A1 · Mallick et al. · 2020 [cited by applicant]
US 20200106698A1 · Rao et al. · 2020 [cited by applicant]
US 20200110552A1 · Kumar et al. · 2020 [cited by applicant]
US 20200112608A1 · Patel et al. · 2020 [cited by applicant]
US 20200192588A1 · Kumar et al. · 2020 [cited by applicant]
US 20200204475A1 · Mallick et al. · 2020 [cited by applicant]
US 20200204495A1 · Mallick et al. · 2020 [cited by applicant]
US 20200213274A1 · Pusalkar et al. · 2020 [cited by applicant]
US 20200241890A1 · Mallick et al. · 2020 [cited by applicant]
US 20200314218A1 · Kumar et al. · 2020 [cited by applicant]
US 20200348860A1 · Mallick et al. · 2020 [cited by applicant]
US 20200348861A1 · Marappan et al. · 2020 [cited by applicant]
US 20200348869A1 · Gokam · 2020 [cited by applicant]
US 20200349094A1 · Smith et al. · 2020 [cited by applicant]
US 20200363985A1 · Gokam et al. · 2020 [cited by applicant]
US 20200372401A1 · Mallick et al. · 2020 [cited by applicant]
US 20210019054A1 · Anchi et al. · 2021 [cited by applicant]
US 20210026551A1 · Tidke et al. · 2021 [cited by applicant]
US 20210026650A1 · Rao et al. · 2021 [cited by applicant]
US 20210157502A1 · Rao et al. · 2021 [cited by applicant]
US 20210181965A1 · Anchi et al. · 2021 [cited by applicant]
US 20210303164A1 · Grunwald · 2021 [cited by examiner]
US 20220092180A1 · Richardson · 2022 [cited by examiner]
US 20230185477A1 · Sillifant · 2023 [cited by examiner]
US 20230229764A1 · Vohra · 2023 [cited by examiner]
CN 103677927B · 2017 [cited by applicant]
EP 1117028A2 · 2001 [cited by applicant]
EP 2667569A1 · 2013 [cited by applicant]
International Search Report and Written Opinion of PCT/US2019/052549 dated Dec. 4, 2019, 13 pages. [cited by applicant]
International Search Report and Written Opinion of PCT/US2019/053204 dated Dec. 16, 2019, 40 pages. [cited by applicant]
International Search Report and Written Opinion of PCT/US2019/053473 dated Dec. 19, 2019, 16 pages. [cited by applicant]
International Search Report and Written Opinion of PCT/US2019/067144 dated May 4, 2020, 26 pages. [cited by applicant]
Kris Piepho, “Dell EMC SC Series Storage: Microsoft Multipath I/O,” Dell EMC Best Practices, Jan. 2017, 57 pages. [cited by applicant]
NVM Express, “NVM Express, Revision 1.3,” NVM Express, May 1, 2017, 282 pages. [cited by applicant]
VMWARE, “Multipathing Configuration for Software iSCSI Using Port Binding,” Technical White Paper, Apr. 25, 2012, 15 pages. [cited by applicant]
Dell EMC, “Dell EMC SC Series Storage: Microsoft Multipath I/O,” Dell EMC Engineering, Jun. 2017, 56 pages. [cited by applicant]
Dell EMC, “Dell EMC PowerPath Family: PowerPath and PowerPath/VE Multipathing,” Data Sheet, 2017, 3 pages. [cited by applicant]
EMC, “EMC PowerPath and PowerPath/VE Family for Windows,” Installation and Administration Guide, Oct. 2018, 102 pages. [cited by applicant]
EMC, “EMC Powerpath Load Balancing and Failover”, Comparison with native MPIO operating system solutions, Feb. 2011, 28 pages. [cited by applicant]
Dell EMC, “PowerMax OS,” Dell EMC PowerMax Family Product Guide, May 2019, 192 pages. [cited by applicant]
Dell EMC, “Dell EMC SC Series Storage and Microsoft Multipath I/O,” CML 1004, Jul. 2018, 36 pages. [cited by applicant]
VMWARE, Inc. “VMware VMFS vol. Management,” 2009, 8 pages. [cited by applicant]
Dell EMC, “Dell EMC Unity: Virtualization Integration,” Technical White Paper, Oct. 2019, 39 pages. [cited by applicant]
Dell EMC, “Dell EMC PowerMax: iSCSI Implementation for Dell EMC Storage Arrays Running PowerMaxOS,” Technical White Paper, Sep. 2019, 35 pages. [cited by applicant]
NVM Express, “NVM Express Base Specification, Revision 2.0a,” NVM Express, Jul. 23, 2021, 454 pages. [cited by applicant]