This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

Backup system (SRK)

Infrastructure

A backup system (SRK) is a set of tools for creating, storing and restoring data backup copies, ensuring their safety during failures and attacks.

A backup system (SRK) is a specialized hardware and software solution designed for automatic creation of data backup copies, their secure storage and rapid recovery in case of loss, damage or encryption of information as a result of technical failures, human errors, cyberattacks (in particular, ransomware) or actions of intruders. A backup system is an integral element of any serious IT infrastructure, since even the most modern data storage system cannot guarantee protection from all threats — ransomware can encrypt data both on the main and on the backup array, if backup copies are stored in the same logical environment. That is why backup is built on the 3-2-1 principle: three copies of data on two different types of media, one of which is located outside the main site (offline or in a geographically remote data center).

Ransomware protection Backup systems must protect against encryption and deletion of backups: Immutable Storage (WORM, immutability), MFA (multi-factor authentication for backup management), backup-network isolation, Air-Gap (physical isolation of tape libraries) and integrity monitoring (hashing). Ransomware — Defense and Backup Protection Modern backup systems must protect copies from encryption and deletion Ransomware attacks not only live data but also backup copies ⚠️ Main threats 🔓 Data encryption Ransomware encrypts files 🗑️ Backup deletion Targeted attack on backups ⏳ Delayed attack Activates after backups are deleted 🛡️ Protection technologies 🔒 Immutable Storage Data cannot be modified or deleted Even by a system administrator • Protection for a defined retention period • Guaranteed clean copy for recovery • WORM technology (Write Once, Read Many) 🔑 Multi-factor authentication Backup management access only with MFA Protection against unauthorized access • Password + SMS/App code • Biometric authentication • Hardware tokens Additional protection methods 🌐 Backup network isolation Dedicated network segment Restricted access 💾 Air-Gap Physical isolation Tape libraries, offline media 🔍 Integrity control Data hashing Modification detection An integrated approach guarantees data recovery even after a ransomware attack
Backup system (SRK) — term diagram

Operating principles of a backup system and key metrics

The main task of a backup system is to minimize two key metrics: RPO (Recovery Point Objective) — the maximum acceptable amount of data loss, measured by the time between the last backup copy and the moment of failure, and RTO (Recovery Time Objective) — the maximum acceptable time for restoring system operability after a failure. For critical systems (bank transactions, production management systems), RPO can be seconds, and RTO — minutes, which requires the use of continuous data protection (CDP — Continuous Data Protection). For less critical systems, RPO of several hours and RTO of a day are acceptable. Modern backup systems support various backup methods: full backup — creation of a complete copy of all data; incremental backup — only changes since the last backup of any type are saved; differential backup — changes since the last full backup are saved. By combining these methods, you can build an optimal backup strategy that balances between the speed of creating backup copies and the speed of recovery. To maximize efficiency, the COD technology is used, which allows applying deduplication (removal of duplicate blocks) and compression methods, which significantly reduces the required disk space (up to 10-20 times) and speeds up the process of data transfer over the network.

Architecture, components and deployment of a backup system

A typical architecture of a backup system includes several key components. A backup server is the central coordinator that manages policies, schedules and execution of backup tasks. Backup agents are software modules installed on protected servers and workstations, responsible for reading data and transferring it to the server. A storage target is a repository for storing backup copies, which can be a storage system, a tape library, a cloud storage or a dedicated backup server with a large disk array. For large distributed infrastructures, a multi-level scheme is used with intermediate media servers, which take on the load of data transfer and allow flexibly configuring copy policies. An important component is the backup catalog — a database containing information about all created copies and their contents, necessary for quick search and recovery of the required data. When installing and commissioning a backup system, it is important to properly design the network infrastructure: backup traffic creates a significant load on communication channels, so it is recommended to allocate a separate network (backup network) or use traffic isolation technologies (VLAN, network policies). High-quality installation of the system is ensured with the involvement of installation service specialists, who guarantee correct configuration and integration of all components, including configuring integration with virtual infrastructure (plugins for VMware/Hyper-V) and applications.

Backup systems in import substitution conditions and protection from ransomware

The Russian backup system market is represented both by foreign vendors that have left or limited their activities, and by actively developing domestic products included in the register of Russian software. Domestic backup systems are certified by FSTEC and provide the necessary level of protection for critical information infrastructure (CII). Special attention is paid to protecting backup copies from ransomware: modern backup systems support immutable repositories where data cannot be changed or deleted, even by the system administrator, use multi-factor authentication to access backup management and storage, and also ensure isolation of the backup network from the corporate network. A comprehensive approach to building a backup system includes auditing the current infrastructure, determining RPO and RTO requirements for each criticality, developing backup and recovery regulations, selecting equipment and software, installation, configuration, writing documentation and staff training. Only such an approach allows guaranteeing that in a critical situation the data will be restored in full and within the established deadlines, and the business will not suffer catastrophic losses.

Frequently asked questions

What is a backup system in simple words?

A backup system (SRK) is a set of hardware and software tools for automatically creating backup copies of data and their rapid recovery in case of loss, damage or encryption by ransomware. The key task is to ensure data safety under any failures and cyberattacks. Read more about related aspects in the materials: SAN (storage area network) and Data warehouse.

What causes the need for a backup system?

The need for a backup system arises from the risks of data loss due to technical failures, human errors, hardware failures and cyberattacks, primarily ransomware. Backup protects against such threats by storing copies on separate media. Read more about related aspects in the materials: Data warehouse and installation works.

What helps in building a backup system?

Building an effective backup system requires an integrated approach: determining RPO and RTO, choosing backup methods (full, incremental, differential) and storage (storage system, tape library, cloud). We also recommend familiarizing yourself with Hypervisor, Server virtualization and Postgres Pro for a complete understanding of the topic.

What should not be done when building a backup system?

When building a backup system, you should avoid storing copies in the same logical environment as the main data (this does not protect against ransomware), ignoring the 3-2-1 rule and not testing recovery procedures. In the context of this topic, it is useful to study Containerization (Docker) and SMEV (interdepartmental electronic interaction system).

What can backup copies be confused with?

Backup copies can be confused with archiving: archive stores data for long-term storage, and backup is designed for rapid recovery after failures. These are different tasks with different approaches. For in-depth study, refer to the sections SMEV, COD technology and Hypervisor.

How to confirm that the backup system works?

To confirm that the backup system works, regular test restores are performed — the actual recovery of data from copies in a test environment. Monitoring backup statuses, checking reports and periodic audit of recovery procedures are also used. More detailed information is available in the articles about SAN, Thin client and installation works.

How long does data recovery take?

Data recovery time depends on the RTO set and the recovery method: restoring from a full copy takes longer than from differential or incremental ones. For critical systems, RTO can be minutes, which requires the use of continuous data protection (CDP). Read more about related aspects in the materials: SAN (storage area network) and Hypervisor.

Was this information helpful?

Build reliable IT infrastructure

Build a modern, fault-tolerant IT infrastructure. Design, equipment supply, installation and maintenance turnkey.

Guaranteed result
Selection for your budget
Comprehensive approach
Certified experts

Or contact us:

+7 (499) 238-01-32 sales@fintech.ru

Open from 9:00 am to 6:00 pm