IP Library Granted Patent US 11,449,607
Granted Patent B2
US 11,449,607 · App. 16/534,486 · Granted Sep 20, 2022

Anomaly and ransomware detection

Inventors: Oscar Annen (San Jose, CA); Di Wu (Newark, CA); Ajay Saini (Mountain View, CA)
Assignee: Rubrik, Inc.
G06F21/565G06F21/561G06N20/00G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,449,607
App. No.
16/534,486
Granted
Sep 20, 2022
Kind
B2
Abstract

Some examples relate generally to computer architecture software for information security and, in some more particular aspects, to machine learning based on changes in snapshot metadata for anomaly and ransomware detection in a file system.

Claims (32)

1. A filesystem metadata augmentation technique (FMAT) system, comprising:

a memory; and

one or more processors configured to perform training data augmentation operations including, at least:

generating or accessing a first file sampled from a first seed dataset associated with a negative target class, and sampling a first number of lines according to a first probability distribution from the first file, wherein the first file comprises a change between two consecutive snapshots of the first seed dataset;

generating or accessing a second file sampled from a second seed dataset associated with a positive target class, and sampling a second number of lines according to a second probability distribution from the second file, wherein the second file comprises a change between two consecutive snapshots of the second seed dataset;

creating a third file comprising the lines sampled from the first file and the second file; and

repeating to create a new file for every file in the first seed dataset to generate or augment training data for one or more machine-learning models.

2. The FMAT system of claim 1 , wherein the first seed dataset comprises data points not corresponding to a ransomware attack.

3. The FMAT system of claim 1 , wherein the second seed dataset comprises data points corresponding to a ransomware attack.

4. The FMAT system of claim 1 , wherein the training data augmentation operations are performed by a backup system without impacting production operations in a production system served by the backup system.

5. The FMAT system of claim 1 , wherein at least some of the training data augmentation operations are offloaded by the FMAT system to a cloud-based computing platform.

6. The FMAT system of claim 1 , wherein the one or more machine-learning models includes an anomaly model or an encryption model or both.

7. A computer-implemented method, by a filesystem metadata augmentation technique (FMAT) system, the FMAT system including one or more processors configured to training data augmentation operations including, at least:

generating or accessing a first file sampled from a first seed dataset associated with a negative target class, and sampling a first number of lines according to a first probability distribution from the first file, wherein the first file comprises a change between two consecutive snapshots of the first seed dataset;

generating or accessing a second file sampled from a second seed dataset associated with a positive target class, and sampling a second number of lines according to a second probability distribution from the second file, wherein the second file comprises a change between two consecutive snapshots of the second seed dataset;

creating a third file comprising the lines sampled from the first file and the second file; and

repeating to create a new file for every file in the first seed dataset to generate or augment training data for one or more machine-learning models.

8. The method of claim 7 , wherein the first seed dataset comprises data points not corresponding to a ransomware attack.

9. The method of claim 7 , wherein the second seed dataset comprises data points corresponding to a ransomware attack.

10. The method of claim 7 , wherein the training data augmentation operations are performed by a backup system without impacting production operations in a production system served by the backup system.

11. The method of claim 7 , wherein at least some of the training data augmentation operations are offloaded by the FMAT system to a cloud-based computing platform.

12. The method of claim 7 , wherein the one or more machine-learning models includes an anomaly model or an encryption model or both.

13. A non-transitory, machine-readable medium storing instructions which, when read by a machine, cause the machine to perform operations comprising, at least:

generating or accessing a first file sampled from a first seed dataset associated with a negative target class, and sampling a first number of lines according to a first probability distribution from the first file, wherein the first file comprises a change between two consecutive snapshots of the first seed dataset;

generating or accessing a second file sampled from a second seed dataset associated with a positive target class, and sampling a second number of lines according to a second probability distribution from the second file, wherein the second file comprises a change between two consecutive snapshots of the second seed dataset;

creating a third file comprising the lines sampled from the first file and the second file; and

repeating to create a new file for every file in the first seed dataset to generate or augment training data for one or more machine-learning models.

14. The medium of claim 13 , wherein the first seed dataset comprises data points not corresponding to a ransomware attack.

15. The medium of claim 13 , wherein the second seed dataset comprises data points corresponding to a ransomware attack.

16. The medium of claim 13 , wherein the training data augmentation operations are performed by a backup system without impacting production operations in a production system served by the backup system.

17. The medium of claim 13 , wherein at least some of the training data augmentation operations are offloaded to a cloud-based computing platform.

18. The medium of claim 13 , wherein the one or more machine-learning models includes an anomaly model or an encryption model or both.

Assignments (3)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 60333/0323 Recorded Jun 13, 2025
From: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
To: RUBRIK, INC.
Reel/Frame 071565/0602 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 10, 2022
From: RUBRIK, INC.
To: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
Reel/Frame 060333/0323 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2020
From: ANNEN, OSCAR; WU, DI; SAINI, AJAY
To: RUBRIK, INC.
Reel/Frame 051949/0963 →
Cited By (5)
US 12,250,235 US 12,476,992 US 12,495,053 US 12,579,266 US 12,647,440