IP Library Granted Patent US 10,754,731
Granted Patent B1
US 10,754,731 · App. 16/452,326 · Granted Aug 25, 2020

Compliance audit logging based backup

Inventors: Adaikkappan Arumugam (Fremont, CA); Raghavendra Chowdary Maddipatla (Sunnyvale, CA); Prashant Pogde (Sunnyvale, CA)
Assignee: Cohesity, Inc.
G06F11/1451G06F11/1461G06F16/128G06F2201/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,754,731
App. No.
16/452,326
Granted
Aug 25, 2020
Kind
B1
Abstract

A compliance audit log of a data storage is obtained. The compliance audit log is analyzed to identify one or more files associated with a mounted storage volume that have changed since a previous backup snapshot of the mounted storage volume associated with the data storage. An incremental backup snapshot of the mounted storage volume is caused to be performed based on a result of the analysis of the compliance audit log.

Claims (40)

1. A method, comprising:

obtaining a compliance audit log of a data storage, wherein the compliance audit log stores a plurality of entries associated with a plurality of mounted storage volumes, wherein the plurality of entries include one or more modification entries associated with the plurality of mounted stored volumes and one or more non-modification entries associated with the plurality of mounted storage volumes;

analyzing the compliance audit log to identify one or more files associated with a mounted storage volume that have changed since a previous backup snapshot of the mounted storage volume associated with the data storage, wherein analyzing the compliance audit log includes:

identifying one or more entries associated with the mounted storage volume from the plurality of entries associated with the plurality of mounted storage volumes;

identifying, from the one or more identified entries associated with the mounted storage volume, one or more modification entries associated with the mounted storage volume;

determining whether the one or more identified modification entries occurred within a threshold time of or after a previous backup of the mounted storage volume; and

determining that the one or more identified modification entries include one or more entries that occurred within the threshold time before the previous backup of the mounted storage volume and one or more entries that occurred after the previous backup of the mounted storage volume; and

causing an incremental backup snapshot of the mounted storage volume to be performed based on the one or more entries that occurred within the threshold time before the previous backup of the mounted storage volume and the one or more entries that occurred after the previous backup of the mounted storage volume.

2. The method of claim 1 , wherein at least one of the one or more modification entries is associated with a file system write operation.

3. The method of claim 1 , wherein the data storage is a network-attached storage.

4. The method of claim 1 , wherein the data storage is associated with a plurality of mounted storage volumes, wherein the mounted storage volume is one of the plurality of mounted storage volumes.

5. The method of claim 1 , wherein analyzing the compliance audit log to identify one or more files associated with a mounted storage volume that have changed since a previous backup snapshot of the mounted storage volume associated with the data storage further comprises determining that the one or more identified modification entries are associated with a file system modification operation.

6. The method of claim 5 , wherein analyzing the compliance audit log to identify one or more files associated with a mounted storage volume that have changed since a previous backup snapshot of the mounted storage volume associated with the data storage further comprises determining that the one or more identified modification entries are associated with a file system modification operation that is a write operation.

7. The method of claim 6 , wherein analyzing the compliance audit log to identify one or more files associated with a mounted storage volume that have changed since a previous backup snapshot of the mounted storage volume associated with the data storage further comprises determining that a file associated with one of the identified entries is not already on a list of one or more files to be included in the incremental backup snapshot.

8. The method of claim 7 , wherein analyzing the compliance audit log to identify one or more files associated with a mounted storage volume that have changed since a previous backup snapshot of the mounted storage volume associated with the data storage further comprises including the file associated with the one of the identified entries on the list of one or more files to be included in the incremental backup snapshot.

9. The method of claim 8 , wherein analyzing the compliance audit log to identify one or more files associated with a mounted storage volume that have changed since a previous backup snapshot of the mounted storage volume associated with the data storage further comprises verifying that the file included on the list of one or more files to be included in an incremental backup snapshot has changed since the previous backup snapshot.

10. The method of claim 9 , wherein verifying that the file has changed since the previous backup snapshot comprises inspecting metadata associated with the file.

11. The method of claim 10 , wherein the metadata associated with the file includes a modification timestamp.

12. The method of claim 9 , wherein the data associated with the verified file is included in the incremental backup snapshot.

13. The method of claim 1 , wherein the incremental backup snapshot includes a portion of an identified file that was not previously backed up.

14. The method of claim 1 , wherein the incremental backup snapshot includes an entire portion of an identified file.

15. The method of claim 1 , wherein data associated with the incremental backup snapshot is provided to a storage system, wherein the storage system is configured to deduplicate the data included in the incremental backup snapshot.

16. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

obtaining a compliance audit log of a data storage, wherein the compliance audit log stores a plurality of entries associated with a plurality of mounted storage volumes, wherein the plurality of entries include one or more modification entries associated with the plurality of mounted stored volumes and one or more non-modification entries associated with the plurality of mounted storage volumes;

analyzing the compliance audit log in identifying any files associated with a mounted storage volume that have changed since a previous backup snapshot of the mounted storage volume associated with the data storage, wherein analyzing the compliance audit log includes:

identifying one or more entries associated with the mounted storage volume from the plurality of entries associated with the plurality of mounted storage volumes;

identifying, from the one or more identified entries associated with the mounted storage volume, one or more modification entries associated with the mounted storage volume;

determining whether the one or more identified modification entries occurred within a threshold time of or after a previous backup of the mounted storage volume; and

determining that the one or more identified modification entries include one or more entries that occurred within the threshold time before the previous backup of the mounted storage volume and one or more entries that occurred after the previous backup of the mounted storage volume; and

causing an incremental backup snapshot of the mounted storage volume to be performed based on the one or more entries that occurred within the threshold time before the previous backup of the mounted storage volume and the one or more entries that occurred after the previous backup of the mounted storage volume.

17. A system, comprising:

a processor configured to:

obtain a compliance audit log of a data storage, wherein the compliance audit log stores a plurality of entries associated with a plurality of mounted storage volumes, wherein the plurality of entries include one or more modification entries associated with the plurality of mounted stored volumes and one or more non-modification entries associated with the plurality of mounted storage volumes;

analyze the compliance audit log to identify one or more files associated with a mounted storage volume that have changed since a previous backup snapshot of the mounted storage volume associated with of the data storage, wherein to analyze the compliance audit log, the processor is configured to:

identify one or more entries associated with the mounted storage volume from the plurality of entries associated with the plurality of mounted storage volumes;

identify, from the one or more identified entries associated with the mounted storage volume, one or more modification entries associated with the mounted storage volume;

determine whether the one or more identified modification entries occurred within a threshold time of or after a previous backup of the mounted storage volume; and

determine that the one or more identified modification entries include one or more entries that occurred within the threshold time before the previous backup of the mounted storage volume and one or more entries that occurred after the previous backup of the mounted storage volume; and

cause an incremental backup snapshot of the mounted storage volume to be performed based on the one or more entries that occurred within the threshold time before the previous backup of the mounted storage volume and the one or more entries that occurred after the previous backup of the mounted storage volume; and

a memory coupled to the processor and configured to provide the processor with instructions.

Assignments (4)
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 10, 2024
From: FIRST-CITIZENS BANK & TRUST COMPANY (AS SUCCESSOR TO SILICON VALLEY BANK)
To: COHESITY, INC.
Reel/Frame 069584/0498 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
SECURITY INTEREST Recorded Sep 23, 2022
From: COHESITY, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 061509/0818 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2019
From: ARUMUGAM, ADAIKKAPPAN; MADDIPATLA, RAGHAVENDRA CHOWDARY; POGDE, PRASHANT
To: COHESITY, INC.
Reel/Frame 050031/0437 →
Cited By (3)
US 12,326,834 US 12,511,278 US 12,711,100