IP Library › Granted Patent US 10,819,738
Granted Patent B2
US 10,819,738 · App. 16/138,034 · Granted Oct 27, 2020

Detecting and protecting against ransomware

Inventor: Yossef Saad (Gannei Tikva, IL)
Assignee: EMC IP Holding Company, LLC
H04L63/145G06F3/061G06F3/065G06F3/067G06F3/0641G06F11/3034G06F21/554G06F21/56H03M7/3086G06F2201/81
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,819,738
App. No.
16/138,034
Granted
Oct 27, 2020
Kind
B2
Abstract

In a system that replicates data writes by a server to form a local copy for a local production site with local storage and a remote copy for a remote recovery site having remote storage, ransomware is detected by a decrease of more than a predetermined threshold in either or both of compression ratio or deduplication ratio in a length of data selected by a sliding time window. Upon detecting ransomware, data writes to said remote storage are stopped to minimize corruption of the remote data.

Claims (30)

1. A method of detecting ransomware in a computer storage system having a server, a local production site having local storage, and a remote recovery site having remote storage, comprising:

replicating data of a data write from the server to form a local copy of said data for said local storage and to form a remote copy of said data for said remote storage;

inputting selected data of one of said copies to a process to transform said selected data into processed output data;

determining a value of a process ratio comprising a ratio of said selected data input to said process divided by said processed output data;

comparing said determined value of said process ratio with a previous process ratio value for data of said one copy to detect a change in said determined value of process ratio; and

upon detecting said change in said value of said determined process ratio exceeding a predetermined threshold, identifying said change to be due to ransomware encryption of said data from the server.

2. The method of claim 1 , wherein said processing comprises compressing said selected data, and said process ratio comprises a compression ratio representing an amount of compression of said selected data.

3. The method of claim 2 , wherein said identifying comprises identifying said ransomware encryption upon detecting a decrease in said compression ratio that exceeds said predetermined threshold.

4. The method of claim 1 , wherein said processing comprise deduplication of said selected data to remove redundant data, and said process ratio comprises a deduplication ratio of said selected data.

5. The method of claim 4 , wherein said identifying comprises identifying said ransomware encryption upon detecting a decrease in said deduplication ratio that exceeds said predetermined threshold.

6. The method of claim 1 , wherein said processing is applied to data of said remote copy prior to storage in said remote storage.

7. The method of claim 1 further comprising stopping writing of data to said remote storage upon detecting ransomware encryption.

8. The method of claim 1 further comprising stopping writing of data to said local storage upon detecting ransomware encryption.

9. The method of claim 1 , wherein said selected data comprises a predetermined length of data selected by a sliding time window having a predetermined time length, and wherein the method further comprises incrementing said sliding window to select additional data, and repeating said method.

10. The method of claim 9 , wherein said selected data comprises N blocks of data corresponding to said predetermined time length of said sliding window, and wherein said incrementing said sliding window comprises incrementing to select one of all new data or a mixture of new data and previously processed data.

11. A non-transitory storage medium storing executable instructions for controlling a processor to perform a method of detecting ransomware in a computer storage system having a server, a local production site having local storage, and a remote recovery site having remote storage, comprising:

replicating data of a data write from the server to form a local copy of said data for said local storage and to form a remote copy of said data for said remote storage;

inputting selected data of one of said copies to a process to transform said selected data into processed output data;

determining a value of a process ratio comprising a ratio of said selected data input to said process divided by said processed output data;

comparing said determined value of said process ratio with a previous process ratio value for data of said one copy to detect a change in said determined value of process ratio; and

upon detecting said change in said value of said determined process ratio exceeding a predetermined threshold, identifying said change to be due to ransomware encryption of said data from the server.

12. The non-transitory storage medium of claim 11 , wherein said processing comprises compressing said selected data, and said process ratio comprises a compression ratio representing an amount of compression of said selected data.

13. The non-transitory storage medium of claim 12 , wherein said identifying comprises identifying said ransomware encryption upon detecting a decrease in said compression ratio that exceeds said predetermined threshold.

14. The non-transitory storage medium of claim 11 , wherein said processing comprise deduplication of said selected data to remove redundant data, and said process ratio comprises a deduplication ratio of said selected data.

15. The non-transitory storage medium of claim 14 , wherein said identifying comprises identifying said ransomware encryption upon detecting a decrease in said deduplication ratio that exceeds said predetermined threshold.

16. The non-transitory storage medium of claim 11 , wherein said processing is applied to data of said remote copy prior to storage in said remote storage.

17. The non-transitory storage medium of claim 11 further comprising stopping writing of data to said remote storage upon detecting ransomware encryption.

18. The non-transitory storage medium claim 11 further comprising stopping writing of data to said local storage upon detecting ransomware encryption.

19. The non-transitory storage medium claim 11 , wherein said selected data comprises a predetermined length of data selected by a sliding time window having a predetermined time length, and wherein the method further comprises incrementing said sliding window to select additional data, and repeating said method.

20. The non-transitory storage medium of claim 19 , wherein said selected data comprises N blocks of data corresponding to said predetermined time length of said sliding window, and wherein said incrementing said sliding window comprises incrementing to select one of all new data or a mixture of new data and previously processed data.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2018
From: SAAD, YOSSEF
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 046939/0268 →
Continuity (1)
Related Publication 20200099699A1 · Mar 26, 2020
Cited By (2)
US 12,306,941 US 12,554,849