IP Library Patent Application 16711060
Patent Application
App. No. 16/711,060

Mitigation of Malicious Operations with Respect to Storage Structures

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/711,060
Filed
Dec 11, 2019
Art Unit
2499
USPC
726/23
Abstract

An exemplary method includes a monitoring system detecting that a storage system receives a request to perform an operation that affects a capacity of a storage structure within the storage system, identifying an attribute of at least one of the request and the storage system, determining, based on the attribute, that the request is indicative of a malicious action, and performing, in response to the determining that the request is indicative of the malicious action, a remedial action with respect to the requested operation.

Claims (57)

1 . A method comprising:

detecting, by a monitoring system, that a storage system receives a request to perform an operation that affects a capacity of a storage structure within the storage system;

identifying, by the monitoring system, an attribute of at least one of the request and the storage system;

determining, by the monitoring system and based on the attribute, that the request is indicative of a malicious action; and

performing, by the monitoring system in response to the determining that the request is indicative of the malicious action, a remedial action with respect to the requested operation.

2 . The method of claim 1 , wherein:

the identifying of the attribute comprises determining that the request is included in a plurality of requests of a similar type received by the storage system during a time period; and

the determining that the request is indicative of the malicious action comprises determining that the plurality of requests exceeds a threshold.

3 . The method of claim 1 , wherein:

the identifying of the attribute comprises determining that the request is included in a plurality of requests received by the storage system during a time period, the requests being for a number of storage structures within the storage system; and

the determining that the request is indicative of the malicious action comprises determining that the number of storage structures compared to a total number of storage structures within the storage system exceeds a predetermined ratio.

4 . The method of claim 1 , wherein:

the identifying of the attribute comprises determining a source of the request; and

the determining that the request is indicative of the malicious action comprises determining that the source is a malicious source.

5 . The method of claim 1 , wherein:

the identifying of the attribute comprises determining that the request comprises a write request; and

the determining that the request is indicative of the malicious action comprises determining that the write request comprises an attempt to overwrite compressible data in the storage structure with incompressible data.

6 . The method of claim 1 , wherein:

the identifying of the attribute comprises determining that the storage system receives a request to change an operation time delay associated with storage structures within the storage system; and

the determining that the request is indicative of the malicious action comprises determining that the request to change the operation time delay is received by the storage system within a predetermined amount of time of the request.

7 . The method of claim 1 , wherein:

the identifying of the attribute comprises detecting an abnormal pattern of interaction with the storage system during a time period; and

the determining that the request is indicative of the malicious action comprises determining that the request is received by the storage system during the time period.

8 . The method of claim 7 , wherein the detecting of the abnormal pattern of interaction with the storage system comprises determining that operations performed with respect to the storage system during the time period differ by more than a threshold amount from historical operations performed with respect to the storage system.

9 . The method of claim 1 , wherein:

the identifying of the attribute comprises determining an age of other storage structures within the storage system; and

the determining that the request is indicative of the malicious action comprises determining that the age is older than a predetermined age.

10 . The method of claim 1 , wherein:

the identifying of the attribute comprises determining an amount of undisturbed capacity of the storage system, the undisturbed capacity not affected by a plurality of requests that includes the request; and

the determining that the request is indicative of the malicious action comprises determining that the undisturbed capacity is less than a threshold.

11 . The method of claim 1 , wherein:

the identifying of the attribute comprises determining that the storage structure is flagged as being a ransomware recovery structure; and

the determining that the request is indicative of the malicious action comprises determining that the request is for a particular storage structure that is flagged as being the ransomware recovery structure.

12 . The method of claim 11 , wherein the performing of the remedial action comprises requiring data from multiple sources for the operation to be performed.

13 . The method of claim 1 , wherein the performing of the remedial action comprises providing a notification indicating that the request is indicative of the malicious action.

14 . The method of claim 1 , wherein the performing of the remedial action comprises directing the storage system to abstain from actually performing the operation for a predetermined time period subsequent to the storage system receiving the request.

15 . The method of claim 14 , further comprising directing, by the monitoring system, the storage system to encrypt data in the storage structure so that the data is encrypted during the predetermined time period.

16 . The method of claim 1 , wherein the performing of the remedial action comprises directing the storage system to abstain from actually performing the operation until a garbage collection process is to be performed with respect to the storage structure.

17 . The method of claim 1 , wherein the performing of the remedial action comprises at least one of blocking the request, throttling a performance of the operation, and disabling the storage system.

18 . The method of claim 1 , wherein the detecting that the storage system receives the request comprises:

receiving, by way of a network, phone-home logs from the storage system; and

extracting data representative of the request from the phone-home logs.

19 . A system comprising:

a memory storing instructions;

a processor communicatively coupled to the memory and configured to execute the instructions to:

detect that a storage system receives a request to perform an operation that affects a capacity of a storage structure within the storage system;

identify an attribute of at least one of the request and the storage system;

determine, based on the attribute, that the request is indicative of a malicious action; and

perform, in response to the determining that the request is indicative of the malicious action, a remedial action with respect to the requested operation.

20 . A storage system comprising:

a plurality of storage elements configured to maintain data in a plurality of storage structures;

a memory storing instructions;

a processor communicatively coupled to the memory and to the plurality of storage elements, the processor configured to execute the instructions to

receive a request to perform an operation that affects a capacity of a storage structure included in the plurality of storage structures;

identify an attribute of at least one of the request and the plurality of storage structures;

determine, based on the attribute, that the request is indicative of a malicious action; and

perform, in response to the determining that the request is indicative of the malicious action, a remedial action with respect to the requested operation.

Assignments (3)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2019
From: GRUNWALD, DAVID A.; FAY, MATTHEW PAUL; KARR, RONALD; HUSKISSON, DAVID; KUTNER, ANDREW
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 051252/0225 →