IBM Storage Defender

IBM Storage Defender

Early threat detection and secure data recovery

 View Only

Threat Detection with IBM Storage Defender

By Matthew Smith posted 05/26/26 09:48 AM

  

Threat detection is becoming pervasive across many products in the enterprise storage software stack.  Speaking to customers and sellers alike, the inconsistent language and marketing hype is causing some confusion.  I regularly hear questions like “What’s the difference between scanner X and scanner Y?”, “I already have XDR, why do I need another solution?” and “If I have a scanner, why do I need a clean room?”

Let’s embrace the choice and understand the value on offer from IBM Storage and the IBM Storage Defender suite.


Threat Scanners
All scanners have the same goal – to detect threats – but they can work in very different ways.  IBM offers both quick detection – think of this as a burglar alarm for your business - as well as deep scans to pinpoint the attack and understand what actions you should take next – more like CCTV to find out why the burglar alarm has triggered. 

The beauty of combining these technologies is that you can get quick detection, but you can then increase your confidence that you’re being attacked by doing a scan of the data – hopefully eliminating any false positives that previously would have caused you to shut down your business.

Quick Detection
The IBM Storage FlashSystem FlashCore Modules are the gold standard in quick threat detection.  Analysing the IO across all the drives in the primary storage system, the algorithms have been trained to spot threat activity patterns, flagging up anomalous activity in under a minute. 

IBM Storage Defender Data Resiliency Service offers an alternative in the shape of sensors that run on the hosts.  These sensors, also trained on real-world threats, analyse file access patterns every 30 seconds to spot anomalies.

These are both always-on technologies that are working on your active workloads, not copies or backups, to spot anomalies as quickly as possible.

Deep Scan 
Another approach to threat scanning is to periodically take a backup or snapshot of the data and then scanning that copy for evidence of threat activity.  This can be part of a strategy for establishing and storing a known clean copy.

Using IBM Storage Defender Sentinel to take a snapshot (or a Safeguarded Copy on the FlashSystem) will allow an application consistent point-in-time copy to be validated.  File meta-data and contents are checked and compared to the previous snapshot, database corruption is tested for, and ransomware signatures and any YARA rules are then used.  By looking for patterns of change over time, and identifying the files where the changes are happening, this allows for pinpointing of any suspicious activity and selected recovery of affected files.

The same technology can also be used from within IBM Storage Defender Data Resiliency Service.  It contains a scan environment which allows for the scanning of any snapshot, either on a schedule or manually.  This can be run to establish clean copies, or in reaction to an anomaly being detected.

For backups taken by IBM Storage Defender Data Protect, IBM Storage Defender Data Protect Threat Scanner can offer deep scanning within that environment.  It will look for Indicators of Compromise and threat signatures, also allowing YARA rules to be used.

These are all content aware, deep scan technologies designed to confirm that you have clean data from which you can restore your workloads.

Vaults
A vault is a way of adding increased security to your backup data with physical and logical separation, and a heightened level of user access.  Copies are stored with immutability and encrypted.  Much like with Safeguarded Copy on primary storage, the idea is that if your environment is subjected to a cyber-attack, your backups cannot be compromised.

The IBM Storage Defender Data Protect Vault works in conjunction with Data Protect, allowing you to scan backups, and then store them securely without fear of modification or deletion.  Backups will need to be recovered from the vault either to a clean room or other environment to then begin to use that data.

Clean Rooms
If you’ve established known clean copies, then why do you need a Clean Room?  A Clean Room, such as Predatar Cyber Recovery Orchestration, is trying to do something different.  It’s an orchestrated, isolated environment into which you can restore a workload or application without risking your wider infrastructure.

It’s an opportunity to test that your workloads copies or backups can be recovered to a known, good running state.  It’s an opportunity to test that running system – ensuring everything is functioning as expected – before returning a workload to production.  And it’s an opportunity to scan that system with the latest malware signatures to ensure you’re not reintroducing dormant threats back into your environment.

With frequent scheduling of these tests, it’s also a way of periodically PROVING that a backed-up application can be recovered.  A clean room offers a way of automating seldom performed and resource intensive manual recovery tests.

Conclusion
Hopefully this explains how these different technologies operate in a complimentary way to keep your business safe.  Although there are overlaps, they’re working in different ways, using different algorithms, and operating at different points in the stack.  SIEMs are also still in the picture, pulling in threats from other sensors outside of the storage stack.  All of the technologies within Defender also work with SIEMs to share knowledge with the wider security infrastructure.

For Defender though, IBM Storage Defender Data Resiliency Service is the point of integration, bringing together Quick Detection, Deep Scan and Clean Room technologies.   Combining the signals and overlapping them with knowledge of the environment will give you the best chance of both detection, and safe and fast recovery.

2 comments
51 views

Permalink

Comments

05/27/26 12:20 PM

Thanks for the comments Stephan, there's a whole bunch of follow on blog suggestions in here to get to the next level of detail and clear up the confusion experienced by the wider community!

What I'm highlighting here is that the different threat detection mechanisms play a part, some of which, some customers won't feel the need to use.

Data Protect, and the DP market place will only ever cover backups taken with DP.  For SP or other third party backup solutions, DRS and Predatar can fill the void.

For scanning snapshots, Sentinel is the answer, but you can see in the releases earlier this year we're working on bringing that into DRS.

DRS should be viewed primarily as an orchestration and governance layer which is there to prove you can recover.  If you don't have FlashSystem, then you can use the sensors it also delivers.  DRS will never replace the component parts, but it'll work with those components to achieve its goals and drive the recovery process.

Watch for more blogs over the coming weeks to give proper answers to your questions and check out the new Sentinel and DRS/Predatar material on Seismic in the meantime.

05/27/26 07:55 AM

Thanks Matthew for the blog, but now it raises more questions still on my side 😄 

Such as, within DataProtect there is the option to switch to the "Security Center" which provides a dashboard with recommendations and some anomalies detection.  Some menus work, some need a "privilege" to display something we can't see

Then there is Predatar for more in-depth detection on the backups but up to where?  DP and SP?  Can it do Storage as well?

Then Sentinel for another type of detection/automation on the arrays which runs on the CDM infra from what I can gather, which I an not a fan.

Then there is the "Marketplace" in DP providing the option of installing the App "Advanced Data Security Engine" which in itself does what again?  Seems to be a pre-requisite for the "IBM Storage Defender Threat Protection"?  But in itself only gathers info? 

Then we need to talk about DRS, which reports, analyzes, automates and the such but also brings in the option to install Sensors...

oh and let's not forget Insight...so many options, so confusing.  

I'm I the only one in that situation? 🤨🤔  Need to reach out to my local rep ! 😀