Patent · US Active

Host multi-path layer with IO analytics for malware defense

US12299118B2 · kind B2 · utility

0Cited by
49References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 29, 2022
Grant dateMay 13, 2025
Priority date
Expiry dateMay 26, 2043

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/78
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

An apparatus comprises at least one processing device configured to implement a multi-path layer in a host device, wherein the multi-path layer controls delivery of input-output (IO) operations from the host device to a storage system over selected ones of a plurality of paths through a network. The multi-path layer is configured, for each of at least a subset of the IO operations, to store at least a process identifier, a user identifier and an access type for the IO operation. The multi-path layer is further configured to perform analytics on the stored process identifiers, user identifiers and access types to detect an access pattern, and responsive to the detected access pattern having one or more designated characteristics associated with malware, to generate an alert. The alert may be generated by inserting security alert indicators into respective ones of the IO operations, for extraction therefrom by the storage system.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.