Anomalies
Good or bad?
Daniel.Olkowski@dell.com
Copyright © Dell Inc. All Rights Reserved.
1
Internal Use - Confidential
Agenda
Copyright © Dell Inc. All Rights Reserved.
2
Internal Use - Confidential
Anomalies
CYBER ANOMALY THREAT DETECTION
Copyright © Dell Inc. All Rights Reserved.
3
Internal Use - Confidential
What is important?
Cyber Anomaly �Threat Detection
Copyright © Dell Inc. All Rights Reserved.
4
Internal Use - Confidential
Anomalies
Cyber Anomaly �Threat Detection
Copyright © Dell Inc. All Rights Reserved.
5
Internal Use - Confidential
Anomalies
Cyber Anomaly �Threat Detection
Copyright © Dell Inc. All Rights Reserved.
6
Internal Use - Confidential
Anomalies
Cyber Anomaly �Threat Detection
Copyright © Dell Inc. All Rights Reserved.
7
Internal Use - Confidential
Anomalies
Cyber Anomaly �Threat Detection
Copyright © Dell Inc. All Rights Reserved.
8
Internal Use - Confidential
Detecting anomalies
CYBER ANOMALY THREAT DETECTION
Copyright © Dell Inc. All Rights Reserved.
9
Internal Use - Confidential
Data Protection Advisor
Monitor selected appliance and systems with suitable set of rules
Detect anomalous behavior as soon as it happens via Alerts
Data Protection Advisor Analysis Engine is stateful
Easy to configure and setup default and new rules
© Copyright 2022 Dell Inc.
© Copyright 2021 Dell Inc.
What is DPA?
Data Protection Advisor
Copyright © Dell Inc. All Rights Reserved.
11
Internal Use - Confidential
Data Protection Advisor
Cyber Anomaly �Threat Detection
Copyright © Dell Inc. All Rights Reserved.
12
Internal Use - Confidential
Introduction
Rules
Rules is the logic used to detect an anomaly and/or breach
Analysis Policy
Collection of one or more rules assigned to an object or group.
Alerts
Alert tab will show the alert and can also trigger a variety of external alerts if defined/configured
Dell Data Protection Advisor Analysis Engine
Analysis Engine
Detects state changes in the data defined in the Rules that have been assigned and triggers alerts
© Copyright 2022 Dell Inc.
© Copyright 2021 Dell Inc.
DPA Analysis Engine
Cyber Anomaly �Threat Detection
Copyright © Dell Inc. All Rights Reserved.
14
Internal Use - Confidential
Rules & Policy
Analysis Engine
Copyright © Dell Inc. All Rights Reserved.
15
Internal Use - Confidential
Rules & Policy
Analysis Engine
Copyright © Dell Inc. All Rights Reserved.
16
Internal Use - Confidential
Rules & Policy
Analysis Engine
Copyright © Dell Inc. All Rights Reserved.
17
Internal Use - Confidential
Data Protection Advisor Analysis Engine Workflow
Setup Policy
Data Protection Advisor
Define Rules
Assign policies or rules Objects
1
2
3
4
Analysis Engine
Analysis Engine starts monitoring
Anomaly
5
Detects Anomaly
6
Send Alerts
SNMP Trap
Message via local script
Event log Entry
© Copyright 2022 Dell Inc.
© Copyright 2021 Dell Inc.
How to setup anomalies detection?
Data Protection Advisor User Interface
1. Setup Analysis Engine Policy�An analysis policy is a collection of one or more rules that is assigned to an object or group.�
2. Define a Rule �Rules contain the logic for when to issue an alert.�
3. Assign policies or rules to an Object
4. & 5.�The analysis engine compares monitored data to the conditions in a rule, and triggers alerts when a rule is matched. Event-based rules trigger an alert in response to data that is streaming into the Data Protection Advisor server. Schedule-based rules periodically compare data in the Data Protection Advisor Datastore against rules to detect a match.�
6. The alerts can be sent via SNMP trap, local script e.g send text message , Event log Entry or Email.
Copyright © Dell Inc. All Rights Reserved.
19
Internal Use - Confidential
Examples
CYBER ANOMALY THREAT DETECTION
Copyright © Dell Inc. All Rights Reserved.
20
Internal Use - Confidential
Rule – Full backup larger than average time window
Cyber Attack Vector: Ransomware
Typical modus operandi: Data Encryption
An increase in deviation of “Size” of data sent to server based on that job’s historical average may indicate “encryption” at play
As a start, we can use this rule to detect a 50% increase in the current job to its 2 week historical size and trigger an alert if true.
© Copyright 2022 Dell Inc.
© Copyright 2021 Dell Inc.
Am I encrypted?
Examples of rules
Copyright © Dell Inc. All Rights Reserved.
22
Internal Use - Confidential
Rule – Backup Application Configuration Changed
Cyber Attack Vector: Insider attack or remote execution
Modus operandi: Backup Appliance control
During an internal malicious attack (or remote execution), one could make configuration changes to the backup application
Data Protection Advisor can detect changes to a backup application’s configuration and send alerts.
© Copyright 2022 Dell Inc.
© Copyright 2021 Dell Inc.
Is backup being hacked?
Examples of rules
Copyright © Dell Inc. All Rights Reserved.
24
Internal Use - Confidential
Rule – Data Domain capacity high
Cyber Attack Vector: Ransomware
Typical modus operandi: Data Encryption
An encryption threat will cause the creation of a lot of unique data, deduplication rate will drop down filling up PowerProtect DD
Data Protection Advisor collects data directly from the PowerProtect DD and can send an alert if file system utilization is crossing the threshold.
© Copyright 2022 Dell Inc.
© Copyright 2021 Dell Inc.
Am I encrypted?
Examples of rules
Copyright © Dell Inc. All Rights Reserved.
26
Internal Use - Confidential
Rule – Many backups failed
Cyber Attack Vector: Backup Missed or Unavailable
Multiple backups failing within a limited time window can mean clients are offline or under cyber attack and it should be reported immediately.
Data Protection Advisor will send an alert if 5 Backups fail with 30 minutes. This is a default value and can be changed
© Copyright 2022 Dell Inc.
© Copyright 2021 Dell Inc.
Am I being attacked?
Examples of rules
Copyright © Dell Inc. All Rights Reserved.
28
Internal Use - Confidential
Rule – Network Utilization High
Cyber Attack Vector: Network control or unusual traffic
Abnormal network utilization can be caused by cyber attacks
Default value set is 70% but can be customized.
© Copyright 2022 Dell Inc.
© Copyright 2021 Dell Inc.
Am I encrypted?
Examples of rules
Copyright © Dell Inc. All Rights Reserved.
30
Internal Use - Confidential
Rule – Three strike failure
Cyber Attack Vector: Unavailability or Exposures
A backup client failing, or missing backups consecutively for three days is exposed to cyber attacks.
This rule will send alert if a client has failed to run backup atleast three days.
© Copyright 2022 Dell Inc.
© Copyright 2021 Dell Inc.
Am I being attacked?
Examples of rules
Copyright © Dell Inc. All Rights Reserved.
32
Internal Use - Confidential
Rule – Many backup devices unavailable
Cyber Attack Vector: Unavailability of Backup appliance
In case of cyber attacks, attackers will try to target the backup appliances so that recovery of data is restricted.
Backup appliances are monitored by Data Protection Advisor and if more than two (default) are down it will send alert.
© Copyright 2022 Dell Inc.
© Copyright 2021 Dell Inc.
Am I being attacked?
Examples of rules
Copyright © Dell Inc. All Rights Reserved.
34
Internal Use - Confidential
Rule – No NetWorker bootstrap generated
Cyber Attack Vector: Restrict Disaster Recovery
NetWorker bootstrap job is required in order to recover a NetWorker Server in an DR scenario
Alert is generated if no NetWorker bootstrap has been generated for 2 days (default)
© Copyright 2022 Dell Inc.
© Copyright 2021 Dell Inc.
Am I being attacked?
Examples of rules
Copyright © Dell Inc. All Rights Reserved.
36
Internal Use - Confidential
Demo
CYBER ANOMALY THREAT DETECTION
Copyright © Dell Inc. All Rights Reserved.
37
Internal Use - Confidential
Data Protection Advisor Analysis Engine Workflow
Setup Policy
Data Protection Advisor
Define Rules
Assign policies or rules Objects
1
2
3
4
Analysis Engine
Analysis Engine starts monitoring
Anomaly
5
Detects Anomaly
6
Send Alerts
SNMP Trap
Message via local script
Event log Entry
© Copyright 2022 Dell Inc.
© Copyright 2022 Dell Inc.
Steps # 1 – Create a policy
© Copyright 2022 Dell Inc.
Steps # 2-Set up the external alerting (optional) – can update/set later
© Copyright 2022 Dell Inc.
Creating policy
Demo
Under Create Analysis Policy :
● generate an email
● run a script
● send an SNMP trap
● write an event to a Windows Event Log
When an analysis policy finds a matching condition, Data Protection Advisor generates an event. All events are automatically logged in to the Data Protection Advisor Datastore. You can view all events in the Alerts section of the web console.
4. Next Select “Add/Remove Rules”
Copyright © Dell Inc. All Rights Reserved.
41
Internal Use - Confidential
Steps # 3– Add the rule template/s into the policy
© Copyright 2022 Dell Inc.
Rules
Demo
Copyright © Dell Inc. All Rights Reserved.
43
Internal Use - Confidential
Steps # 4 – Set the parameter/s according to customer environment (optional and if relevant)
© Copyright 2022 Dell Inc.
Rules
Demo
Copyright © Dell Inc. All Rights Reserved.
45
Internal Use - Confidential
Steps # 5 – Save it and verify in Analysis policy Library
© Copyright 2022 Dell Inc.
Rules
Demo
Copyright © Dell Inc. All Rights Reserved.
47
Internal Use - Confidential
Steps # 6 – Apply the policy to desired individual objects or Groups
© Copyright 2022 Dell Inc.
Rules
Demo
Copyright © Dell Inc. All Rights Reserved.
49
Internal Use - Confidential
Licensing
CYBER ANOMALY THREAT DETECTION
Copyright © Dell Inc. All Rights Reserved.
50
Internal Use - Confidential
DPS Bundles Offers
Product Name | Power Protect Data Manager | Data Protection Suite | Data Protection Suite + | PowerProtect Data Manager Essentials | DPS for vmware (EMEA ONLY) | |
PowerProtect Data Manager | ✔ | ✔ | ✔ | ✔ | X | |
PowerProtect VM Replication | ✔ | ✔ | ✔ | ✔ | ✔ | |
PowerProtect Cyber Recovery | ✔ | ✔ | ✔ | ✔ | X | |
PowerProtect Storage Direct | ✔ | ✔ | ✔ | ✔ | X | |
PowerProtect Vprotect | ✔ | ✔ | ✔ | ✔ | X | |
NetWorker, Networker Virtual Edition* | X | ✔* | ✔ | X | ✔ (Limited) | |
Avamar (incl. vRealize DP Extension) &AVE | X | ✔ | ✔ | X | ✔ (Limited) | |
Data Protection Central | ✔ | ✔ | ✔ | ✔ | ✔ | |
Data Protection Advisor | ✔ | ✔ | ✔ | ✔ | ✔ | |
DP Search | Embedded | ✔ | ✔ | Embedded | ✔ | |
Boost FS | ✔ | ✔ | ✔ | ✔ | X | |
CloudBoost | X | ✔ | ✔ | X | ✔ | |
Data Domain Virtual Edition | ✔ | X | ✔ | ✔ | X | |
Cloud Tier* | ✔ | X | ✔ | ✔ | X | |
Cloud Snapshot Manager* | ✔ | ✔ | ✔ | ✔ | X | |
Cloud DR | ✔ | X | ✔ | ✔ | X | |
Licensing | Metric | FETB/Socket | FETB/Socket | FETB/Socket | FETB/Socket (Limited to 50) | Socket |
Sales Method | Perpetual & Subscription | Perpetual & Subscription | Perpetual & Subscription | Perpetual & Subscription | Perpetual | |
*Cloud Tier can be used with either DDVE or Physical Appliances
*For perpetual licenses, the entitlement to use Cloud Snapshot Manager is tied to a valid support agreement. The customer is required to enter the end date of the support agreement at the time of activation in the CSM portal.
51
of 23
© Copyright 2019 Dell Inc.
51
of Y
Internal Use - Confidential
Licensing
Cyber Anomaly �Threat Detection
Copyright © Dell Inc. All Rights Reserved.
52
Internal Use - Confidential
Materials
CYBER ANOMALY THREAT DETECTION
Copyright © Dell Inc. All Rights Reserved.
53
Internal Use - Confidential
White papers
Cyber Anomaly �Threat Detection
Advanced Anomaly Detection with Data Protection Advisor
A Cyber Resilient Strategy With Dell Data Protection Solutions
Copyright © Dell Inc. All Rights Reserved.
54
Internal Use - Confidential
Videos
Cyber Anomaly �Threat Detection
Copyright © Dell Inc. All Rights Reserved.
55
Internal Use - Confidential
Materials
Cyber Anomaly �Threat Detection
Copyright © Dell Inc. All Rights Reserved.
56
Internal Use - Confidential
End logo slide
Questions
Daniel.Olkowski@dell.com
Copyright © Dell Inc. All Rights Reserved.
57
Internal Use - Confidential