发明名称 DYNAMIC MALICIOUS APPLICATION DETECTION IN STORAGE SYSTEMS
摘要 Improved techniques involve comparing access patterns in a storage system to expected access patterns under similar circumstances. An intrusion detection system, in response to a suspected malicious application workload, collects information about a current session on the storage processor, e.g., application workload s running, users logged in, and timestamp, as well as parameters such as storage allocation requests sampled at prespecified intervals over a period of time. In a database that stores such sampled parameter values by application workload, user, and time, the system extracts the sampled parameter values having the application workload, user, and time corresponding to the current session. The system then compares the extracted sampled parameter values with the current parameter values and computes a difference. Based on the difference, the system determines whether the storage system is accessed by a malicious application workload.
申请公布号 WO2015047126(A1) 申请公布日期 2015.04.02
申请号 WO2013RU00846 申请日期 2013.09.27
申请人 EMC CORPORATION 发明人 NOVOZHILOV, EUGENY ALEXEEVICH;KOZLOVSKY, VITALY STANISLAVOVICH;TYLIK, DMITRY NIKOLAEVICH
分类号 G06F21/56;G06F17/40 主分类号 G06F21/56
代理机构 代理人
主权项
地址