IP Library Granted Patent US 11,030,314
Granted Patent B2
US 11,030,314 · App. 16/050,167 · Granted Jun 8, 2021

Storage system with snapshot-based detection and remediation of ransomware attacks

Inventors: Anton Kucherov (Dudley, MA); David Meiri (Somerville, MA)
Assignee: EMC IP Holding Company LLC
G06F21/566G06F3/0622G06F3/0637G06F3/0683G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,030,314
App. No.
16/050,167
Granted
Jun 8, 2021
Kind
B2
Abstract

A storage system in one embodiment comprises a plurality of storage devices and a storage controller. The storage controller is configured to generate a plurality of snapshots of a storage volume of the storage system at respective different points in time, to monitor a differential between a given one of the snapshots and the storage volume, and to generate an alert indicative of at least a potential ransomware attack on the storage system based at least in part on the monitored differential satisfying one or more specified conditions. The one or more specified conditions illustratively comprise a specified minimum amount of change in the storage volume relative to the given snapshot of the storage volume. Compressibility of the storage volume is also taken into account in generating the alert in some embodiments. The storage controller illustratively initiates restoration of the storage volume utilizing a selected snapshot responsive to confirmation of an actual attack.

Claims (48)

1. An apparatus comprising:

a storage system comprising a plurality of storage devices and a storage controller;

the storage controller being configured:

to generate a plurality of snapshots of a storage volume of the storage system at respective different points in time;

to monitor a differential between a given one of the snapshots and a current version of the storage volume; and

to generate an alert indicative of at least a potential ransomware attack on the storage system based at least in part on the monitored differential satisfying one or more specified conditions, the potential ransomware attack comprising a suspected ransomware attack not yet confirmed as an actual ransomware attack;

wherein generating an alert indicative of at least a potential ransomware attack on the storage system based at least in part on the monitored differential satisfying one or more specified conditions comprises:

determining that the monitored differential satisfies the one or more specified conditions;

determining compressibility of at least a portion of the storage volume; and

generating the alert responsive to the monitored differential satisfying the one or more specified conditions and the compressibility of the storage volume being below a specified level of compressibility, the specified level of compressibility being based at least in part on a minimum compressibility achievable for said at least a portion of the storage volume;

wherein determining compressibility of at least a portion of the storage volume comprises collecting compressibility statistics for the storage volume as data is written to the storage volume; and

wherein the storage controller comprises at least one processing device comprising a processor coupled to a memory.

2. The apparatus of claim 1 wherein the storage volume comprises at least one logical storage volume comprising at least a portion of a physical storage space of one or more of the storage devices.

3. The apparatus of claim 1 wherein at least a subset of the snapshots comprise respective point-in-time replicas of the storage volume generated at respective different points in time.

4. The apparatus of claim 1 wherein only two most recently generated snapshots for the storage volume are retained in the storage system.

5. The apparatus of claim 1 wherein the one or more specified conditions comprise a specified minimum amount of change in the storage volume relative to the given snapshot of the storage volume.

6. The apparatus of claim 5 wherein the specified minimum amount of change in the storage volume is specified in terms of a minimum number of storage units of the storage volume that have changed since generation of the given snapshot.

7. The apparatus of claim 5 wherein the specified minimum amount of change in the storage volume is specified in terms of a minimum percentage of the storage volume that has changed since generation of the given snapshot.

8. The apparatus of claim 1 wherein generating an alert indicative of at least a potential ransomware attack on the storage system based at least in part on the monitored differential satisfying one or more specified conditions comprises generating an alert of a potential ransomware attack and initiating one or more attack remediation operations responsive to confirmation of the potential ransomware attack as an actual ransomware attack.

9. The apparatus of claim 1 wherein the storage controller is configured to control deletion of one or more of the snapshots from the storage system based at least in part on the generated alert.

10. The apparatus of claim 1 wherein the storage controller is configured to determine that the generated alert is a false positive and to delete one or more of the snapshots from the storage system based at least in part on the false positive determination.

11. The apparatus of claim 1 wherein the storage controller is further configured to generate a message containing the generated alert and to deliver the message over a network to a storage administrator device.

12. The apparatus of claim 1 wherein the storage controller is further configured to initiate restoration of the storage volume utilizing a selected one of the snapshots generated prior to the given snapshot based at least in part on the generated alert.

13. A method comprising:

generating a plurality of snapshots of a storage volume of a storage system at respective different points in time;

monitoring a differential between a given one of the snapshots and a current version of the storage volume; and

generating an alert indicative of at least a potential ransomware attack on the storage system based at least in part on the monitored differential satisfying one or more specified conditions, the potential ransomware attack comprising a suspected ransomware attack not yet confirmed as an actual ransomware attack;

wherein generating an alert indicative of at least a potential ransomware attack on the storage system based at least in part on the monitored differential satisfying one or more specified conditions comprises:

determining that the monitored differential satisfies the one or more specified conditions;

determining compressibility of at least a portion of the storage volume; and

generating the alert responsive to the monitored differential satisfying the one or more specified conditions and the compressibility of the storage volume being below a specified level of compressibility, the specified level of compressibility being based at least in part on a minimum compressibility achievable for said at least a portion of the storage volume;

wherein determining compressibility of at least a portion of the storage volume comprises collecting compressibility statistics for the storage volume as data is written to the storage volume; and

wherein the method is implemented by at least one processing device comprising a processor coupled to a memory.

14. The method of claim 13 wherein the one or more specified conditions comprise a specified minimum amount of change in the storage volume relative to the given snapshot of the storage volume.

15. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes said at least one processing device:

to generate a plurality of snapshots of a storage volume of a storage system at respective different points in time;

to monitor a differential between a given one of the snapshots and a current version of the storage volume; and

to generate an alert indicative of at least a potential ransomware attack on the storage system based at least in part on the monitored differential satisfying one or more specified conditions, the potential ransomware attack comprising a suspected ransomware attack not yet confirmed as an actual ransomware attack;

wherein generating an alert indicative of at least a potential ransomware attack on the storage system based at least in part on the monitored differential satisfying one or more specified conditions comprises:

determining that the monitored differential satisfies the one or more specified conditions;

determining compressibility of at least a portion of the storage volume; and

generating the alert responsive to the monitored differential satisfying the one or more specified conditions and the compressibility of the storage volume being below a specified level of compressibility, the specified level of compressibility being based at least in part on a minimum compressibility achievable for said at least a portion of the storage volume; and

wherein determining compressibility of at least a portion of the storage volume comprises collecting compressibility statistics for the storage volume as data is written to the storage volume.

16. The computer program product of claim 15 wherein the one or more specified conditions comprise a specified minimum amount of change in the storage volume relative to the given snapshot of the storage volume.

17. The computer program product of claim 16 wherein the specified minimum amount of change in the storage volume is specified in terms of a minimum number of storage units of the storage volume that have changed since generation of the given snapshot.

18. The computer program product of claim 16 wherein the specified minimum amount of change in the storage volume is specified in terms of a minimum percentage of the storage volume that has changed since generation of the given snapshot.

19. The computer program product of claim 15 wherein generating an alert indicative of at least a potential ransomware attack on the storage system based at least in part on the monitored differential satisfying one or more specified conditions comprises generating an alert of a potential ransomware attack and initiating one or more attack remediation operations responsive to confirmation of the potential ransomware attack as an actual ransomware attack.

20. The computer program product of claim 15 wherein the program code when executed by said at least one processing device further causes said at least one processing device to determine that the generated alert is a false positive and to delete one or more of the snapshots from the storage system based at least in part on the false positive determination.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (047648/0422) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060160/0862 →
RELEASE OF SECURITY INTEREST AT REEL 047648 FRAME 0346 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0510 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 047648/0422 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047648/0346 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2018
From: KUCHEROV, ANTON; MEIRI, DAVID
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 046842/0528 →
Cited By (1)
US 12,651,063