Threat detection is becoming pervasive across many products in the enterprise storage software stack. Speaking to customers and sellers alike, the inconsistent language and marketing hype is causing some confusion. I regularly hear questions like “What’s the difference between scanner X and scanner Y?”, “I already have XDR, why do I need another solution?” and “If I have a scanner, why do I need a clean room?”
Let’s embrace the choice and understand the value on offer from IBM Storage and the IBM Storage Defender suite.
Threat Scanners
All scanners have the same goal – to detect threats – but they can work in very different ways. IBM offers both quick detection – think of this as a burglar alarm for your business - as well as deep scans to pinpoint the attack and understand what actions you should take next – more like CCTV to find out why the burglar alarm has triggered.
The beauty of combining these technologies is that you can get quick detection, but you can then increase your confidence that you’re being attacked by doing a scan of the data – hopefully eliminating any false positives that previously would have caused you to shut down your business.
Quick Detection
The IBM Storage FlashSystem FlashCore Modules are the gold standard in quick threat detection. Analysing the IO across all the drives in the primary storage system, the algorithms have been trained to spot threat activity patterns, flagging up anomalous activity in under a minute.
IBM Storage Defender Data Resiliency Service offers an alternative in the shape of sensors that run on the hosts. These sensors, also trained on real-world threats, analyse file access patterns every 30 seconds to spot anomalies.
These are both always-on technologies that are working on your active workloads, not copies or backups, to spot anomalies as quickly as possible.
Deep Scan
Another approach to threat scanning is to periodically take a backup or snapshot of the data and then scanning that copy for evidence of threat activity. This can be part of a strategy for establishing and storing a known clean copy.
Using IBM Storage Defender Sentinel to take a snapshot (or a Safeguarded Copy on the FlashSystem) will allow an application consistent point-in-time copy to be validated. File meta-data and contents are checked and compared to the previous snapshot, database corruption is tested for, and ransomware signatures and any YARA rules are then used. By looking for patterns of change over time, and identifying the files where the changes are happening, this allows for pinpointing of any suspicious activity and selected recovery of affected files.
The same technology can also be used from within IBM Storage Defender Data Resiliency Service. It contains a scan environment which allows for the scanning of any snapshot, either on a schedule or manually. This can be run to establish clean copies, or in reaction to an anomaly being detected.
For backups taken by IBM Storage Defender Data Protect, IBM Storage Defender Data Protect Threat Scanner can offer deep scanning within that environment. It will look for Indicators of Compromise and threat signatures, also allowing YARA rules to be used.
These are all content aware, deep scan technologies designed to confirm that you have clean data from which you can restore your workloads.
Vaults
A vault is a way of adding increased security to your backup data with physical and logical separation, and a heightened level of user access. Copies are stored with immutability and encrypted. Much like with Safeguarded Copy on primary storage, the idea is that if your environment is subjected to a cyber-attack, your backups cannot be compromised.
The IBM Storage Defender Data Protect Vault works in conjunction with Data Protect, allowing you to scan backups, and then store them securely without fear of modification or deletion. Backups will need to be recovered from the vault either to a clean room or other environment to then begin to use that data.
Clean Rooms
If you’ve established known clean copies, then why do you need a Clean Room? A Clean Room, such as Predatar Cyber Recovery Orchestration, is trying to do something different. It’s an orchestrated, isolated environment into which you can restore a workload or application without risking your wider infrastructure.
It’s an opportunity to test that your workloads copies or backups can be recovered to a known, good running state. It’s an opportunity to test that running system – ensuring everything is functioning as expected – before returning a workload to production. And it’s an opportunity to scan that system with the latest malware signatures to ensure you’re not reintroducing dormant threats back into your environment.
With frequent scheduling of these tests, it’s also a way of periodically PROVING that a backed-up application can be recovered. A clean room offers a way of automating seldom performed and resource intensive manual recovery tests.
Conclusion
Hopefully this explains how these different technologies operate in a complimentary way to keep your business safe. Although there are overlaps, they’re working in different ways, using different algorithms, and operating at different points in the stack. SIEMs are also still in the picture, pulling in threats from other sensors outside of the storage stack. All of the technologies within Defender also work with SIEMs to share knowledge with the wider security infrastructure.
For Defender though, IBM Storage Defender Data Resiliency Service is the point of integration, bringing together Quick Detection, Deep Scan and Clean Room technologies. Combining the signals and overlapping them with knowledge of the environment will give you the best chance of both detection, and safe and fast recovery.