drj logo
drj logo

Welcome to DRJ

Already registered user? Please login here

Create new account
(it's completely free). Subscribe

x

NAS or Object Storage: Make the Best Backup Target Decision

Data Protection: Backup & Recovery

Twenty years ago, organizations started to choose between disk and tape as their primary backup target. Now that disk has become the primary backup target for many organizations, they face a new choice. They must choose the most appropriate storage networking protocols or S3 APIs for their backup target to use. This choice often boils down to selecting one which supports file storage networking protocols or object storage S3-compliant APIs.

How We Got Here

The impetus to use disk in lieu of tape as a backup target first gained momentum in the early 2000s. Disk-based backup targets almost always shortened backup windows, increased backup success rates, and improved the overall backup experience.

The introduction of data reduction algorithms such as compression and deduplication into disk-based backup targets further drove this trend. These algorithms could, and still do achieve 20:1 or greater backup data reduction ratios. These algorithms contributed to making disk as cost-effective as tape and solidifying disk’s role as a backup target.

Introducing disk-based backup target welcomed a new risk into IT infrastructures organizations have only recently begun to quantify.

When ransomware first came on the scene, it primarily attacked data residing on production systems. To deal with these attacks, organizations quickly figured out they could recover their data from these attacks using their backups.

This, in turn, led to hackers developing ransomware that attacks disk-based targets. By deleting or encrypting data residing on backup targets or compromising the backup target itself, ransomware can impede organizational recovery abilities.

This prompted organizations to seek out backup targets better equipped to withstand these ransomware attacks. In response, more storage providers offer cybersecurity and data immutability features in their disk-based backup targets.

Cybersecurity Advances in NAS Backup Targets

Network-attached storage (NAS) has for years represented the common storage networking interface used by many disk-based backup targets. Using NFS or CIFS/SMB file storage networking protocols, they facilitate easy, fast deployments into many corporate IT infrastructures.

Backup software easily recognizes and uses any of these file protocols in communicating with the NAS backup target. These protocols facilitate fast recoveries and even hosting a recovery on the NAS backup target itself. However, this same ease of deployment and use makes NAS backup targets prone to ransomware attacks.

To mitigate these concerns about their vulnerability to ransomware attacks, NAS backup targets have introduced multiple new cybersecurity measures. Most if not all include:

  • Data immutability. Data immutability, or storing data in an unchangeable format, represents one feature nearly every backup target supports. When enabled, this feature prevents ransomware attacks from either deleting or encrypting backups stored on the NAS backup target. Exactly how each NAS backup target supports data immutability does vary. Some permit data immutability at the folder level. However, some NAS backup targets copy backups off it to an immutable storage tier, such as cloud object storage.
  • Encryption. Many NAS backup targets have offered at-rest encryption for years. However, few organizations used it due to the performance overhead that encryption incurs. This organizational mindset toward using at-rest encryption has changed due to the reality most ransomware attempts to do data exfiltration. Encrypting backups does not prevent ransomware from copying backups. However, hackers will find it almost impossible to decrypt and read any encrypted backups they obtain.
  • Multi-factor authentication (MFA). Requiring MFA to log into a NAS backup target repre­sents perhaps one of the most significant enhancements in recent years. Implementing MFA helps ensure only the appropriate administrators access and manage the NAS backup target. Some NAS backup targets even require a second administrator to authenticate and approve certain configuration changes. These may include tasks such as changing folder permissions or deleting backup data, among others.
  •  High availability (HA). HA also appears as a cybersecurity enhancement with more backup targets offering highly available controller configurations. Organizations may not normally view HA in the context of cybersecurity. However, HA has become relevant due to the role NAS backup targets play in helping organizations recover from a ransomware attack. During restores and recoveries, NAS backup targets may have to perform the following tasks, which include:
    • Scanning backups to be used for restores and recoveries for the presence of ransomware.
    • Providing fast response times for instant restores.
    • Hosting recovered applications and/or data.
    • Continuing to serve as a backup target for those parts of the organizations unaffected by ransomware and still operating normally.
    • Retrieving backups from the cloud or offsite locations.

Using a NAS backup target which offers HA better equips it to simultaneously perform some or all these tasks. The HA NAS backup target includes the extra raw resources (computing, memory, and networking) organizations need during these times.

The Need for Object Storage Backup Targets

All these cybersecurity features now available on NAS backup targets, coupled with their ease of deployment, raise a logical question. Why introduce object storage backup targets into the backup environment at all?

Object storage backup targets offer specific features that contribute to making them more secure than NAS backup targets. In addition to object storage backup targets supporting most or all the cybersecurity features referenced earlier, they also offer the following:

  • Simple storage service (S3) compliant APIs. To access backups stored on an object storage backup target, any application accessing them must use S3-compliant APIs. The use of S3-compliant APIs by applications has certainly increased and become more common in recent years. However, the use of S3-compliant APIs in no way approaches the ubiquitousness of the NFS and CIFS/SMB file networking protocols. As a result, object storage backup targets will not appear visible to any applications that do not use S3-compliant APIs.
  • More granular data immutability options. While both NAS and object storage backup targets offer data immutability, object storage backup targets offer more granular options to administer this feature. For example, NAS backup targets can usually, at best, only granularly manage data immutability permissions at the folder level. In contrast, object storage backup targets may administer data immutability permissions at the folder level, on each individual backup, or both.
  • More scalable than NAS backup targets. The storage software deployed on object storage backup targets often has its origins in technology used by cloud storage providers. This scalable design gives organizations more flexibility to start small and then grow as large as their backup environment requires. Using an object storage backup target, they can essentially create a backup storage cloud. Once they store a backup there, they may never need to formally manage its placement again. The object storage backup target automatically handles each backup’s placement on physical storage media for its life.
  • High levels of performance. Organizations may view the performance of S3-compliant object storage backup targets in the context of Amazon Glacier. While economical, any backups retrieved from Glacier can take lengthy amounts of time to complete. While that scenario can theoretically play out on object storage backup targets, most products offer high levels of performance. Object storage backup targets typically manage multiple tiers of storage, including a performance tier of SSDs. They can then place backups, or copies of backups, on one or more storage tiers to account for both performance demands and cost concerns.

Give Preference to Object Storage, but …

Considering the growing threat ransomware represents, DCIG advises organizations to give preference to object storage backup targets. They offer more cybersecurity options than NAS backup targets and better position organizations to scale their backup infrastructure.

However, organizations must do some due diligence before simply choosing any object storage backup target. They should minimally verify the following:

  1. The amount of backup data they will store once they implement an object storage backup target. Only about 40% of object storage backup targets offer deduplication as a feature. As a result, organizations that currently deduplicate their backup data and then switch to an object storage backup target may see their backup stores mushroom. This storage growth may be a showstopper, or at least throttle how widely an organization implements object storage backups.
  2. Their backup software supports using S3-compliant APIs to store backups. Organizations should not assume their backup software uses or supports S3-compliant APIs. While most enterprise backup software products now support S3 -compliant APIs, support is not yet a given.
  3. Their backup software can interface with the object storage backup target being considered and support its S3 API implementation. Confirming both the backup software and object storage backup target support S3-compliant APIs is only the first step. Organizations should assume both the backup software and the object storage backup target implement the S3 APIs slightly differently. Alternatively, they may not support all available S3 API operations. Differences specifically begin to emerge in how each one supports operations such as data immutability, encryption, and replication. If an organization plans to perform these operations, and many do, confirm they work in the way the organization expects them to work.
  4. Verify the object storage backup target or the backup software offers a certified configuration or reference architecture for how they work together. If either provider provides this type of documentation, organizations can have a higher degree of confidence this solution will work once deployed.

If an organization cannot check all these boxes, it may be better served to select a NAS backup target. NAS backup targets still offer the core cybersecurity features organizations commonly use. Organizations may find NAS backup targets easier to implement and manage after deployment.

Organizations can also consider using backup targets that concurrently support both NAS and object storage. While still uncommon, they do exist and give organizations the flexibility to use either NAS or object storage at their discretion. In this way, organizations may continue using NAS while they acclimate themselves to the nuances of using object storage as a backup target.

ABOUT THE AUTHOR

Jerome Wendt

Jerome Wendt, an AWS Certified Solutions Architect, is the president and founder of DCIG, LLC., a technology analyst firm. DCIG, LLC., focuses on providing competitive intelligence for the enterprise data protection, data storage, disaster recovery, and cloud technology markets.

Latest News
DRJ HOT ITEMS
Webinar Spotlight
Fetching Upcoming Webinars...
Journal Categories

AI: Automation & Innovation

Business Continuity Management

Crisis Management & Emergency Response

Cyber Resilience & IT Disaster Recovery

Leadership: Culture & Workforce Resilience

Operational Resilience

Risk Management & Quantification

Sector-Specific & Critical Infrastructure Resilience

Supply Chain & Third-Party Resilience

Governance: Compliance & Regulatory Readiness

Incident Management & Response Coordination

Resilience Strategy & Program Maturity

Data Protection: Backup & Recovery

Exercises: Testing & Scenario Planning

Emerging Threats: Geopolitical & Climate Risk

Contact Us

Newsletter

The Journal, right in your inbox.