IP Library Granted Patent US 11,522,889
Granted Patent B2
US 11,522,889 · App. 16/534,447 · Granted Dec 6, 2022

Anomaly and ransomware detection

Inventors: Oscar Annen (San Jose, CA); Di Wu (Newark, CA); Ajay Saini (Mountain View, CA)
Assignee: Rubrik, Inc.
H04L63/1425G06F11/1464G06N20/00H04L63/1466G06F2201/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,522,889
App. No.
16/534,447
Granted
Dec 6, 2022
Kind
B2
Abstract

Some examples relate generally to computer architecture software for information security and, in some more particular aspects, to machine learning based on changes in snapshot metadata for anomaly and ransomware detection in a file system.

Claims (32)

1. An anomaly and ransomware detection system, comprising:

a storage device configured to store one or more snapshots of a primary machine; and

one or more processors in communication with the storage device and a production system, the one or more processors configured to perform one or more anomaly and ransomware detection operations that are offloaded to a cloud-based software-as-a-service platform, the one or more anomaly and ransomware detection operations comprising:

taking a first snapshot and a second snapshot of the primary machine and storing the first snapshot and the second snapshot in the storage device;

identifying one or more changes in filesystem metadata based on the first snapshot and the second snapshot;

generating training data based on the one or more changes in the filesystem metadata;

training a first machine-learning model and a second machine-learning model using the training data, wherein the training of the first machine-learning model and the second machine-learning model is based on the training data being derived from snapshot-based metadata, and wherein the first machine-learning model is configured to detect anomalies and the second machine-learning model is configured to detect whether an anomaly is a ransomware encryption anomaly;

detecting the anomaly from a new snapshot of the primary machine using the first machine-learning model; and

passing, in response to detecting the anomaly, the new snapshot of the primary machine through the second machine-learning model to detect whether the detected anomaly is a ransomware encryption anomaly.

2. The anomaly and ransomware detection system of claim 1 , wherein the storage device is a backup storage device and the one or more changes in the filesystem metadata are sourced from a backup system that includes the backup storage device.

3. The anomaly and ransomware detection system of claim 1 , wherein the one or more anomaly and ransomware detection operations are performed without impacting the production system.

4. The anomaly and ransomware detection system of claim 1 , wherein the first machine-learning model and the second machine-learning model comprise an anomaly model, an encryption model, or both.

5. A computer-implemented method at an anomaly and ransomware detection system, the anomaly and ransomware detection system including one or more processors in communication with a storage device and a production system, the one or more processors configured to perform one or more anomaly and ransomware detection operations that are offloaded to a cloud-based software-as-a-service platform, the one or more anomaly and ransomware detection operations, comprising:

taking a first snapshot and a second snapshot of a primary machine and storing the first snapshot and the second snapshot in the storage device;

identifying one or more changes in filesystem metadata based on the first snapshot and the second snapshot;

generating training data based on the one or more changes in the filesystem metadata;

training a first machine-learning model and a second machine-learning model using the training data, wherein the training of the first machine-learning model and the second machine-learning model is based on the training data being derived from snapshot-based metadata, and wherein the first machine-learning model is configured to detect anomalies and the second machine-learning model is configured to detect whether an anomaly is a ransomware encryption anomaly;

detecting the anomaly from a new snapshot of the primary machine using the first machine-learning model; and

passing, in response to detecting the anomaly, the new snapshot of the primary machine through the second machine-learning model to detect whether the detected anomaly is a ransomware encryption anomaly.

6. The computer-implemented method of claim 5 , wherein the storage device is a backup storage device and the one or more changes in the filesystem metadata are sourced from a backup system that includes the backup storage device.

7. The computer-implemented method of claim 5 , wherein the one or more anomaly and ransomware detection operations are performed without impacting the production system.

8. The computer-implemented method of claim 5 , wherein the first machine-learning model and the second machine-learning model comprise an anomaly model, an encryption model, or both.

9. A non-transitory, machine-readable medium storing instructions which, when read by a machine, cause the machine to perform one or more anomaly and ransomware detection operations that are offloaded to a cloud-based software-as-a-service platform, the one or more anomaly and ransomware detection operations comprising:

taking a first snapshot and a second snapshot of a primary machine and storing the first snapshot and the second snapshot in a storage device;

identifying one or more changes in filesystem metadata based on the first snapshot and the second snapshot;

generating training data based on the one or more changes in the filesystem metadata;

training a first machine-learning model and a second machine-learning model using the training data, wherein the training of the first machine-learning model and the second machine-learning model is based on the training data being derived from snapshot-based metadata, and wherein the first machine-learning model is configured to detect anomalies and the second machine-learning model is configured to detect whether an anomaly is a ransomware encryption anomaly;

detecting the anomaly from a new snapshot of the primary machine using the first machine-learning model; and

passing, in response to detecting the anomaly, the new snapshot of the primary machine through the second machine-learning model to detect whether the detected anomaly is a ransomware encryption anomaly.

10. The non-transitory, machine-readable medium of claim 9 , wherein the storage device is a backup storage device and the one or more changes in the filesystem metadata are sourced from a backup system that includes the backup storage device.

11. The non-transitory, machine-readable medium of claim 9 , wherein the one or more anomaly and ransomware detection operations are performed without impacting a production system.

12. The non-transitory, machine-readable medium of claim 9 , wherein the first machine-learning model and the second machine-learning model comprise an anomaly model, an encryption model, or both.

Assignments (3)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 60333/0323 Recorded Jun 13, 2025
From: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
To: RUBRIK, INC.
Reel/Frame 071565/0602 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 10, 2022
From: RUBRIK, INC.
To: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
Reel/Frame 060333/0323 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2020
From: ANNEN, OSCAR; WU, DI; SAINI, AJAY
To: RUBRIK, INC.
Reel/Frame 051601/0218 →
Cited By (6)
US 12,250,235 US 12,476,992 US 12,495,053 US 12,518,008 US 12,579,266 US 12,647,440