Skip to content

Product1 publisher3 min readPublished

45Drives lets the storage server sever a user's connection when file activity crosses a threshold

The SnapShield expansion adds detection for data being read and moved out, on top of encryption. Founder Douglas Milburn says containment can fire on activity across a few files, and that legitimate work sometimes trips it.

The Product Desk · Product desk

Illustration accompanying 45Drives lets the storage server sever a user's connection when file activity crosses a threshold

What happened

  • 45Drives announced an expansion of its SnapShield platform, adding protection against data exfiltration and centralized management spanning multiple servers and locations, in an exclusive to SiliconANGLE.
  • SnapShield sits on the storage server, analyzes file activity, and once configured thresholds are reached can sever the suspected user's or client's connection while unaffected users keep working.
  • The exfiltration feature looks for spikes in file access and for interaction with decoy honey files, then either notifies administrators or automatically isolates the offending user or IP address.
  • 45Drives built the product after its own ransomware attack, which arrived through a socially engineered email; Milburn said working out which machines and files to restore was disruptive and slow.
  • The new Centralized Management System puts deployments, live events, user activity, analytics and audit logs in one console, aimed at large enterprises and managed service providers running many sites.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Switching on automatic isolation trades a user's dropped session against an attacker's dwell time, and the person choosing that setting is now whoever administers storage.
  • constraint Since the acknowledged remedy for a false positive is a manual exception for a user or a window, every routine bulk-read job in the estate turns into scheduling work for the storage admin.
  • capability Detection that fires on read-and-move behaviour brings theft-only intrusions, the kind that never encrypt anything, within reach of a control that lives on the storage server.
  • exposure A managed service provider can now cut connections inside several customer environments from one login. Access to that console is an availability risk across tenants.

A full backup crawl reads a lot of files quickly. So does an editor pulling a four-year-old project off the archive share, and so does an rsync job moving a department onto new hardware. 45Drives' new Data Exfiltration Protection looks for that shape of activity: repeated file reads followed by data moving outward [5]. Milburn acknowledged that legitimate activity can occasionally produce a false positive, and said administrators can switch protection off for a specific user or a set period when maintenance or another unusual task would resemble an attack [11].

Agentless is the honest selling point. Nothing goes on every workstation [4]. But that is a claim about installation only. Users export whole folders, and they sync an archive share to a laptop the night before they travel.

Milburn said containment can be triggered by activity across just a few files, in environments that may hold hundreds of thousands or millions of files [9]. Take "a few" as five and the estate as one million files, and the trigger sits at 0.0005 percent of the file count [16]. Against an encryptor chewing through a share, that sensitivity is the whole value. The same handful of file operations can also come from a user having an unusual Tuesday.

The pitch is storage as a security layer. "The storage servers is an excellent point to add a new layer of defense," said founder Douglas Milburn [6]. What ships is narrower and more useful to name accurately: a behavioural threshold, an automatic connection cut, notifications, an audit trail, and Precision Restore, which flags the files touched during an attack so a rollback can be selective [12]. 45Drives says the product is meant to complement firewalls, endpoint security, network monitoring and backups [7]. "The objective is containment," Milburn said. "If something malicious gets through the traditional defenses, we want to stop the compromised system from continuing to damage or access the data" [15].

SiliconANGLE's report does not include a price, a customer count, or any measured false-positive rate [17].

The rollout mode can be settled before the software is installed. One question is whether you can name every routine job in your estate that reads thousands of files in minutes. The other is whether the people behind those jobs can absorb a dropped session without losing work. If both hold, automatic isolation is a reasonable default for that group of users. If you can name the jobs but the users cannot take a drop mid-write, notify-only is the setting, with a person on the pager. If you cannot name the jobs, notify-only is the only defensible setting, and the audit log is how you build the list. SnapShield runs on Rocky Linux and Ubuntu, on single servers and on multinode Ceph clusters installed with an Ansible playbook, so a pilot can be one cluster with notifications on and isolation off [14].

What to watch

  • Whether 45Drives publishes tuning guidance for read-heavy workloads such as backup crawls, media archives and migrations.
  • Whether the shared console gets role-based limits on who can trigger or clear an isolation inside a customer environment.
  • Whether Precision Restore can still identify affected files when an attack also reaches snapshot data.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories