IBM FlashSystem

IBM FlashSystem

Find answers and share expertise on IBM FlashSystem


#Storage
#Datasecurity
#Storage
#FlashSystem
 View Only

Ransomware Detection and alerting with IBM’s 5th Generation FlashCore Modules!

By Christopher Vollmar posted 16 days ago

  
image


In the last few weeks we’ve 

been talking a lot about Cyber Resiliency and the IBM FlashSystem, its integration points and how to improve your recovery posture! I thought it worth circling back to one of the topics that always gets everyone’s attention; IBM 5th Generation FlashCore Modules! 

There’s a lot going on with these drives, so I started out to write a blog about them and I realized that what might be better, is to break down my favorite highlights on the FlashCore Modules and help you pick out the things you want to dig in around for Cyber Resiliency.  


New 5th FlashCore Modules

This is really exciting; earlier this year, we announced the next generation IBM FlashSystem family and they include the new 5th Generation FlashCore modules. I’ve had a chance to hold one, and fact that we increased the native capacity before data reduction and moved to the EDSFF E.3 size, is a lot to take in at once. For those of us who have worked with everything from 3.5” 15K drives to SATA drive and now to hold one of these, is such an interesting leap, especially with an option for a 105.6TB drive!  

This is what I mean by the size!

image

 
That said, there is lots of good material on the 5th Generation FlashCore module that you can use to dig into the details, there is an IBM Redbook (IBM FlashCore Module (FCM) Product Guide: Evolution of FlashCore Technology and Enhancements in 5th Generation FlashCore Modules), as well as a webinar from ATG on the new systems and the new drives!


Ransomware Threat Detection

This is something we do that I think is one of our most innovative additions to IBM Storage. How does it work, what can it do, if you’ve never seen a breakdown on Ransomware Threat Detection, and how we’re checking every I/O to the drive in real time looking for a ransomware corruption, now is the time to look! If you want to see the deep walk through, Matt Key did it here - Exploring FlashCore Modules Across IBM Storage and it starts at about the 47min mark. Or, when in doubt, Its always interesting to see Andy Walls give us his perspective on Ransomware Threat Detection for FlashSystem, and he does it here.


New updates in 9.1.1!

In the IBM FlashSystem / Storage Virtualize release 9.1.1 last year we added a lot of capabilities, including Intelligent snapshot creation triggered during Ransomware Threats that we talked about here. What that means, if a Ransomware alert is detected the latest volume group snapshot is extended such that it will not expire in the 7 days following the attack, and a new snapshot is automatically triggered as the anomaly is detected. I thought Richard Mawson did a great job talking about that and Ransomware detection here if you just need the quick- ‘how do we do it’ version of things. By the way, ATG is doing a webinar specifically on Safeguarded Copy on July 9th.


Storage Insights Integration

Now, once you have the FlashSystem in place, you can enable the alerting through IBM Storage Insights to be able to catch the alerts and integrate them into your Security process and procedures. That integration is usually something we see people do with the SIEM provider and there’s a good blog that highlights how to integrate IBM Storage Insights with Cloud Pak for AIOPs, which follows the same theory as Security integration. However, on the topic of Storage Insights and security integration, I’d also recommend looking at the Ecosystem Integration with IBM Storage Insights Redpaper, Chapter 2 is dedicated to just that topic and how to integrate thinks like Splunk, as well as Storage Defender Data Resiliency Service like I talked about last week
 
From an integration perspective, I also get a lot of questions around ServiceNow, which I think is a really interesting topic, there’s a few good things to look at. If you want to do just a general, how do I connect it?  Well, its here in the documentation guide, as well as a bunch of other integrations like Slack and more. Want a little more on topic of ‘incident management’ services, the same Redbook on Storage Insights and Ecosystem has that. Want an interesting read that does a good job on the summary, there was a great blog post by Akshat Mithal called “Ransomware Alerts on ServiceNow via Storage Insights” that’s worth checking out.

More to come, stay tuned!


#community-stories1
0 comments
38 views

Permalink