IP Library Granted Patent US 11,651,075
Granted Patent B2
US 11,651,075 · App. 17/039,604 · Granted May 16, 2023

Extensible attack monitoring by a storage system

Inventor: Ronald Karr (Palo Alto, CA)
Assignee: Pure Storage, Inc.
G06F21/564G06F11/3034G06F21/57G06F21/6218H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,651,075
App. No.
17/039,604
Filed
Sep 30, 2020
Granted
May 16, 2023
Kind
B2
Art Unit
2499
USPC
726/23
Abstract

An illustrative method includes a storage system receiving attribute data representative of one or more attributes of a known attack against data maintained by a target system other than the storage system, updating an extensible attack monitoring process executed by the storage system with the attribute data, and monitoring, using the extensible attack monitoring process updated with the attribute data, storage operation requests of the storage system for one or more attributes that match the one or more attributes of the known attack.

Claims (45)

1. A method comprising:

receiving, by a storage system from a remote system communicatively coupled to the storage system and a plurality of storage systems other than the storage system by way of a network, attribute data representative of one or more attributes of a known attack that operated against data stored by a target system other than the storage system, the attribute data generated based on an analysis of storage operation requests with respect to the plurality of storage systems other than the storage system;

updating, by the storage system, an extensible attack monitoring process executed by the storage system with the attribute data;

monitoring, by the storage system using the extensible attack monitoring process updated with the attribute data, storage operation requests with respect to the storage system for one or more attributes that match the one or more attributes of the known attack;

maintaining, by the storage system, historical attribute data representative of one or more attributes of the storage operation requests with respect to the storage system over time that precedes an attack against the data stored by the storage system that was not detected during the monitoring, the historical attribute data comprising data representing one or more of: an identifier of a specific storage operation, a timing of the specific storage operation, a pattern of occurrence of the specific storage operation, or an analysis of data corrupted by the attack; and

transmitting, by the storage system to a remote system and based on a recognition of an occurrence of the attack that was not detected during the monitoring, the historical attribute data for analysis by the remote system.

2. The method of claim 1 , further comprising:

detecting, by the storage system during the monitoring, the one or more attributes of the storage operation requests that match the one or more attributes of the known attack; and

determining, by the storage system based on the detecting of the one or more attributes of the storage operation requests that match the one or more attributes of the known attack, that data stored by the storage system is possibly being targeted by an attack.

3. The method of claim 2 , further comprising performing, by the storage system in response to the determining that the storage system is possibly being targeted by the attack, a remedial action.

4. The method of claim 3 , wherein the performing of the remedial action comprises one or more of generating a recovery dataset for the data stored by the storage system, throttling one or more of the storage operation requests, providing a notification, or preventing one or more of the storage operation requests from being performed.

5. The method of claim 2 , further comprising allowing, by the storage system based on the determining that the data stored by the storage system is possibly being targeted by the attack, the remote system to analyze the storage operation requests with respect to the storage system.

6. The method of claim 5 , wherein the allowing comprises transmitting attribute data representative of the one or more of the attributes of the storage operation requests of the storage system to the remote system.

7. The method of claim 5 , further comprising:

receiving, by the storage system, confirmation from the remote system indicating that the remote system has determined, based on the analysis of the storage operation requests of the storage system, that the data stored by the storage system is being targeted by the attack; and

performing, by the storage system in response to the receiving of the confirmation, an additional remedial action.

8. The method of claim 1 , wherein the receiving of the attribute data comprises receiving the attribute data from a remote system by way of a network.

9. The method of claim 8 , wherein the remote system is in communication with a plurality of storage systems and configured to generate the attribute data based on an analysis of storage operation requests with respect to the plurality of storage systems.

10. The method of claim 1 , wherein the receiving of the attribute data comprises receiving the attribute data directly from the target system by way of a network.

11. The method of claim 1 , wherein the updating of the extensible attack monitoring process comprises dynamically updating the extensible attack monitoring process as the extensible attack monitoring process is being executed by the storage system.

12. The method of claim 1 , wherein the attribute data comprises data representative of a pattern associated with the known attack, a compressibility of data being written to the target system, or a format of data being written to the target system.

13. The method of claim 1 , wherein the monitoring for the one or more attributes of the storage operation requests that match the one or more attributes of the known attack comprises determining that the one or more attributes of the storage operation requests satisfy a similarity threshold with respect to the one or more attributes of the known attack.

14. The method of claim 1 , wherein the known attack comprises an encryption attack against the data stored by the target storage system.

15. A method comprising:

receiving, by a storage system from a remote system communicatively coupled to the storage system and a plurality of storage systems other than the storage system by way of a network, attribute data representative of one or more attributes of a known attack against data stored by a system other than the storage system, the attribute data generated based on an analysis of storage operation requests with respect to the plurality of storage systems other than the storage system;

using, by the storage system, the attribute data to detect one or more attributes of storage operation requests with respect to the storage system that match the one or more attributes of the known attack;

determining, by the storage system based on the detecting that the one or more attributes of the storage operation requests match the one or more attributes of the known attack, that data stored by the storage system is possibly being targeted by an attack;

maintaining, by the storage system, historical attribute data representative of one or more attributes of the storage operation requests with respect to the storage system over time that precedes an attack against the data stored by the storage system that was not detected during the determining, the historical attribute data comprising data representing one or more of: an identifier of a specific storage operation, a timing of the specific storage operation, a pattern of occurrence of the specific storage operation, or an analysis of data corrupted by the attack; and

transmitting, by the storage system to a remote system and based on a recognition of an occurrence of the attack that was not detected during the monitoring, the historical attribute data for analysis by the remote system.

16. The method of claim 15 , wherein the using the attribute data comprises updating, by the storage system, an extensible attack monitoring process executed by the storage system with the attribute data.

17. A system comprising:

a memory storing instructions;

a processor communicatively coupled to the memory and configured to execute the instructions to:

receive, from a remote system communicatively coupled to the system and a plurality of storage systems other than the system by way of a network, attribute data representative of one or more attributes of a known attack against data stored by a target system other than the storage system, the attribute data generated based on an analysis of storage operation requests with respect to the plurality of storage systems other than the system;

update an extensible attack monitoring process executed by the storage system with the attribute data;

monitor, using the extensible attack monitoring process updated with the attribute data, input/output (I/O) traffic of the storage system for one or more attributes that match the one or more attributes of the known attack;

maintain historical attribute data representative of one or more attributes of the I/O traffic over time that precedes an attack against the data stored by the storage system that was not detected during the monitoring, the historical attribute data comprising data representing one or more of: an identifier of a specific storage operation, a timing of the specific storage operation, a pattern of occurrence of the specific storage operation, or an analysis of data corrupted by the attack; and

transmit, to a remote system and based on a recognition of an occurrence of the attack that was not detected during the monitoring, the historical attribute data for analysis by the remote system.

18. The system of claim 17 , wherein the processor is further configured to execute the instructions to:

detect, during the monitoring, the one or more attributes of the storage operation requests that match the one or more attributes of the known attack; and

determine, by the storage system based on the detecting of the one or more attributes of the storage operation requests that match the one or more attributes of the known attack, that data stored by the storage system is possibly being targeted by an attack.

19. The system of claim 18 , wherein the processor is further configured to execute the instructions to perform, in response to the determining that the storage system is possibly being targeted by the attack, a remedial action.

20. The method of claim 1 , further comprising:

receiving, by the storage system from the remote system, updated attribute data generated based on the historical attribute data; and

updating, by the storage system based on the updated attribute data, the extensible attack monitoring process.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2020
From: KARR, RONALD
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 053939/0299 →
Continuity (4)
Continuation In Part 16711060 · Dec 11, 2019
Provisional Application 62939518 · Nov 22, 2019
Provisional Application 62985229 · Mar 4, 2020
Related Publication 20210216630A1 · Jul 15, 2021
Cited By (2)
US 12,556,388 US 12,561,193