IP Library Granted Patent US 12,670,006
Granted Patent B2
US 12,670,006 · App. 18/170,375 · Granted Jun 30, 2026

Data protection for short-term and long-term data

Inventors: Shivanshu Agrawal (Sunnyvale, CA); Rahul Das (Bangalore, IN); Dhananjay Mantri (Mountain View, CA); Archit Gupta (Mountain View, CA)
Assignee: Rubrik, Inc.
G06F9/45558H04L63/1416H04L63/1458G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,670,006
App. No.
18/170,375
Granted
Jun 30, 2026
Kind
B2
Abstract

Methods, systems, and devices for data management are described. The initiation or forthcoming initiation of a data protection operation for a computing system may be identified. Short-term information of the computing system, including information stored in the volatile memory of the computing system, network traffic associated with the computing system, or both, may be obtained based on the initiation or forthcoming initiation of the data protection operation. Long-term information of the computing system, including information stored in the non-volatile memory of the computing system, may be obtained based on the data protection operation being initiated. Both the short-term information and the long-term information may be stored for further analysis.

Claims (55)

1 . A method, comprising:

identifying, by a data management system, that a data protection operation for a computing system has been initiated or is to be initiated, the computing system comprising volatile memory and non-volatile memory, wherein the data protection operation corresponds to backing up data stored at the computing system;

obtaining, by the data management system, short-term information of the computing system based at least in part on identifying that the data protection operation has been initiated or is to be initiated, wherein the short-term information comprises information stored in the volatile memory of the computing system, network traffic associated with the computing system, or any combination thereof, and wherein a copy of the short-term information is stored to one or more first locations in the non-volatile memory of the computing system, the one or more first locations excluded from the data protection operation;

obtaining, by the data management system and as part of the data protection operation, long-term information of the computing system based at least in part on the data protection operation being initiated, wherein the long-term information comprises information stored in one or more second locations of the non-volatile memory of the computing system, the one or more second locations of the non-volatile memory being different from the one or more first locations comprising the copy of the short-term information; and

storing, by the data management system, the short-term information and the long-term information obtained from the computing system.

2 . The method of claim 1 , wherein the computing system comprises a virtual machine implemented in a virtual environment that is managed by a hypervisor, the method further comprising:

requesting, from the hypervisor, the information stored in the volatile memory of the computing system based at least in part on identifying that the data protection operation has been initiated or is to be initiated,

wherein the information stored in the volatile memory of the computing system is obtained by the data management system based at least in part on the requesting.

3 . The method of claim 1 , wherein the computing system comprises a physical machine, wherein an agent of the data management system runs on the computing system, and wherein the method further comprises:

introducing, by the agent, based at least in part on identifying that the data protection operation has been initiated or is to be initiated, a kernel into an operating system of the computing system, wherein the kernel is configured to access the volatile memory of the computing system and copy the information stored in the volatile memory of the computing system to a path in the non-volatile memory of the computing system, the path comprising the one or more first locations.

4 . The method of claim 3 , wherein the kernel is further configured to copy, to the path, the information stored in the volatile memory of the computing system at multiple different times during execution of the data protection operation.

5 . The method of claim 3 , further comprising:

configuring, by the agent, the data protection operation to exclude the path in the non-volatile memory of the physical machine; and

initiating, by the agent, the data protection operation, wherein data stored at the path in the non-volatile memory of the computing system is excluded from the long-term information obtained by the data management system.

6 . The method of claim 3 , further comprising:

deleting, by the agent, the path in the non-volatile memory after the information stored in the volatile memory of the computing system is transferred to the data management system, after the data protection operation is completed, or both.

7 . The method of claim 3 , further comprising:

removing, by the agent, the kernel from the operating system after the short-term information is copied to the path in the non-volatile memory, after the short-term information is obtained by the data management system, after the data protection operation is completed, or any combination thereof.

8 . The method of claim 1 , wherein the computing system comprises a physical machine or a virtual machine, wherein an agent of the data management system runs on the computing system, and wherein the method further comprises:

initiating, by the agent, based at least in part on identifying that the data protection operation has been initiated or is to be initiated, a network application configured to generate logs of the network traffic associated with the computing system,

wherein the network traffic associated with the computing system is obtained by the data management system based at least in part on the agent initiating the network application.

9 . The method of claim 8 , wherein the network application is configured to write the logs to a path in the non-volatile memory of the computing system, the path comprising the one or more first locations, the method further comprising:

initiating, by the agent, the data protection operation, wherein data stored at the path in the non-volatile memory of the computing system is excluded from the long-term information obtained by the data management system.

10 . The method of claim 1 , wherein the information stored in the volatile memory of the computing system is received in a first file, the network traffic associated with the computing system is received in a second file, and the information stored in the non-volatile memory of the computing system is received in a third file.

11 . The method of claim 1 , further comprising:

analyzing the short-term information for an indication of malicious activity.

12 . The method of claim 11 , wherein analyzing the short-term information for the malicious activity comprises:

analyzing the information stored in the volatile memory of the computing system for one or more processes that are associated with a malware infection,

analyzing the network traffic associated with the computing system for one or more network requests that are associated with a denial of service attack, or

any combination thereof.

13 . The method of claim 11 , wherein the data management system is configured to protect a computing environment comprising a plurality of computing systems that includes the computing system, and wherein analyzing the short-term information for the malicious activity comprises:

comparing the network traffic associated with the computing system with network traffic of one or more other computing systems of the plurality of computing systems; and

identifying, based at least in part on the comparing, coordinated network activity that indicates the malicious activity is distributed across the computing environment.

14 . The method of claim 11 , wherein the data management system is configured to protect a computing environment comprising a plurality of computing systems that includes the computing system, and wherein analyzing the short-term information for the malicious activity comprises:

identifying, based at least in part on the network traffic associated with the computing system, one or more ports of the computing system being probed, attacked, or both, by an external actor; and

generating an alert that the one or more ports of the computing system are being probed, attacked, or both.

15 . The method of claim 11 , wherein the data management system is configured to protect a computing environment comprising a plurality of computing systems that includes the computing system, and wherein analyzing the short-term information for the malicious activity comprises:

identifying, based at least in part on the network traffic associated with the computing system, that multiple computing systems of the plurality of computing systems are being probed, attacked, or both, by an external actor; and

generating an alert that the computing environment is being probed, attacked, or both.

16 . The method of claim 1 , wherein a forthcoming initiation of the data protection operation is identified based at least in part on a schedule for executing the data protection operation, an occurrence of an event for triggering the data protection operation, or both.

17 . The method of claim 1 , wherein the long-term information comprises system files, user files, metadata for system files, metadata for user files, filesystem information, or any combination thereof.

18 . An apparatus, comprising:

one or more processors; and

one or more memories coupled with the one or more processors, the one or more memories storing instructions executable by the one or more processors to cause the apparatus to:

identify, by a data management system, that a data protection operation for a computing system has been initiated or is to be initiated, the computing system comprising volatile memory and non-volatile memory, wherein the data protection operation corresponds to backing up data stored at the computing system;

obtain, by the data management system, short-term information of the computing system based at least in part on identifying that the data protection operation has been initiated or is to be initiated, wherein the short-term information comprises information stored in the volatile memory of the computing system, network traffic associated with the computing system, or any combination thereof, and wherein a copy of the short-term information is stored to one or more first locations in the non-volatile memory of the computing system, the one or more first locations excluded from the data protection operation;

obtain, by the data management system and as part of the data protection operation, long-term information of the computing system based at least in part on the data protection operation being initiated, wherein the long-term information comprises information stored in one or more second locations of the non-volatile memory of the computing system, the one or more second locations of the non-volatile memory being different from the one or more first locations comprising the copy of the short-term information; and

store, by the data management system, the short-term information and the long-term information obtained from the computing system.

19 . The apparatus of claim 18 , wherein the computing system comprises a physical machine, wherein an agent of the data management system is configured to run on the computing system, and wherein the instructions are further executable by the one or more processors to cause the apparatus to:

introduce, by the agent, based at least in part on identifying that the data protection operation has been initiated or is to be initiated, a kernel into an operating system of the computing system, wherein the kernel is configured to access the volatile memory of the computing system and copy the information stored in the volatile memory of the computing system to a path in the non-volatile memory of the computing system, the path comprising the one or more first locations.

20 . A non-transitory, computer-readable medium storing code comprising instructions executable by one or more processors to:

identify, by a data management system, that a data protection operation for a computing system has been initiated or is to be initiated, the computing system comprising volatile memory and non-volatile memory, wherein the data protection operation corresponds to backing up data stored at the computing system;

obtain, by the data management system, short-term information of the computing system based at least in part on identifying that the data protection operation has been initiated or is to be initiated, wherein the short-term information comprises information stored in the volatile memory of the computing system, network traffic associated with the computing system, or any combination thereof, and wherein a copy of the short-term information is stored to one or more first locations in the non-volatile memory of the computing system, the one or more first locations excluded from the data protection operation;

obtain, by the data management system and as part of the data protection operation, long-term information of the computing system based at least in part on the data protection operation being initiated, wherein the long-term information comprises information stored in one or more second locations of the non-volatile memory of the computing system, the one or more second locations of the non-volatile memory being different from the one or more first locations comprising the copy of the short-term information; and

store, by the data management system, the short-term information and the long-term information obtained from the computing system.