IP Library Patent Application 17074261
Patent Application
App. No. 17/074,261

Filesystem Property Based Determination of a Possible Ransomware Attack Against a Storage System

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/074,261
Abstract

An illustrative method includes a data protection system identifying a first attribute set associated with a first file stored in a storage system, determining that the first file is replaced in the storage system with a second file, identifying a second attribute set associated with the second file, and determining, based on the determining that the first file is replaced in the storage system with the second file and on one or more attributes in at least one of the first attribute set or the second attribute set, that data stored by the storage system is possibly being targeted by a security threat.

Claims (67)

1 . A method comprising:

identifying, by a data protection system, a first attribute set associated with a first file stored in a storage system;

determining, by the data protection system, that the first file is replaced in the storage system with a second file;

identifying, by the data protection system, a second attribute set associated with the second file; and

determining, by the data protection system based on the determining that the first file is replaced in the storage system with the second file and on one or more attributes in at least one of the first attribute set or the second attribute set, that data stored by the storage system is possibly being targeted by a security threat.

2 . The method of claim 1 , wherein the determining that the data stored by the storage system is possibly being targeted by the security threat includes:

determining that an attribute in the second attribute set associated with the second file satisfies an attribute threshold.

3 . The method of claim 1 , wherein the determining that the data stored by the storage system is possibly being targeted by the security threat includes:

determining a difference between a first attribute in the first attribute set associated with the first file and a second attribute in the second attribute set associated with the second file; and

determining that the difference between the first attribute and the second attribute satisfies a difference threshold.

4 . The method of claim 1 , wherein:

the one or more attributes in at least one of the first attribute set or the second attribute set includes one or more of a file size, a file format, a compressibility ratio, or a bit pattern of the first file or the second file.

5 . The method of claim 1 , wherein:

the determining that the first file is replaced with the second file includes determining that the second file is renamed from a temporary name of the second file to a name of the first file; and

the determining that the data stored by the storage system is possibly being targeted by the security threat is based on at least one of the temporary name of the second file or a difference between the temporary name of the second file and the name of the first file.

6 . The method of claim 1 , wherein:

the first attribute set associated with the first file includes a source of the first file;

the second attribute set associated with the second file includes a source of the second file; and

the determining that the data stored by the storage system is possibly being targeted by the security threat includes determining that the source of the second file is different from the source of the first file.

7 . The method of claim 1 , wherein:

the second attribute set associated with the second file includes a source of the second file; and

the determining that the data stored by the storage system is possibly being targeted by the security threat includes one or more of:

determining that the source of the second file is associated with an abnormal pattern; or

determining that the source of the second file has been previously associated with one or more security threats against the storage system.

8 . The method of claim 7 , wherein the determining that the source of the second file is associated with the abnormal pattern includes:

determining that the source of the second file is a source for more than a predetermined threshold number of file replacement requests with respect to the storage system during a predetermined time period.

9 . The method of claim 1 , further comprising:

performing, by the data protection system in response to determining that the data stored by the storage system is possibly being targeted by the security threat, a remedial action with respect to the storage system.

10 . The method of claim 9 , wherein the performing the remedial action with respect to the storage system includes:

directing the storage system to generate a recovery dataset for the data stored by the storage system.

11 . The method of claim 1 , wherein the determining that the first file is replaced with the second file includes:

determining that the first file is included in a first set of files deleted from a first location within the storage system after the first set of files has been stored at the first location for longer than a predetermined amount of time;

determining that the second file is included in a second set of files written to a second location within the storage system; and

determining that the second set of files is related to the first set of files.

12 . The method of claim 11 , wherein the determining that the second set of files is related to the first set of files includes:

determining that the second set of files has a total number of files that is within a predetermined amount of a total number of files included in the first set of files.

13 . The method of claim 11 , wherein the determining that the second set of files is related to the first set of files includes:

determining that the second set of files has an overall compressibility that is less than an overall compressibility of the first set of files.

14 . The method of claim 11 , wherein the determining that the second set of files is related to the first set of files includes:

determining that a read operation that reads the first set of files from the storage system is performed at a first time; and

determining that a write operation that writes the second set of files to the storage system is performed at a second time subsequent to the first time.

15 . A system comprising:

a memory storing instructions;

a processor communicatively coupled to the memory and configured to execute the instructions to:

identify a first attribute set associated with a first file stored in a storage system;

determine that the first file is replaced in the storage system with a second file;

identify a second attribute set associated with the second file; and

determine, based on the determining that the first file is replaced in the storage system with the second file and on one or more attributes in at least one of the first attribute set or the second attribute set, that data stored by the storage system is possibly being targeted by a security threat.

16 . The system of claim 15 , wherein the determining that the data stored by the storage system is possibly being targeted by the security threat includes:

determining that an attribute in the second attribute set associated with the second file satisfies an attribute threshold.

17 . The system of claim 15 , wherein the determining that the data stored by the storage system is possibly being targeted by the security threat includes:

determining a difference between a first attribute in the first attribute set associated with the first file and a second attribute in the second attribute set associated with the second file; and

determining that the difference between the first attribute and the second attribute satisfies a difference threshold.

18 . The system of claim 11 , wherein:

the first attribute set associated with the first file includes a source of the first file;

the second attribute set associated with the second file includes a source of the second file; and

the determining that the data stored by the storage system is possibly being targeted by the security threat includes determining that the source of the second file is different from the source of the first file.

19 . The system of claim 11 , wherein:

the second attribute set associated with the second file includes a source of the second file; and

the determining that the data stored by the storage system is possibly being targeted by the security threat includes one or more of:

determining that the source of the second file is associated with an abnormal pattern; or

determining that the source of the second file has been previously associated with one or more security threats against the storage system.

20 . A non-transitory computer-readable medium storing instructions that, when executed, direct a processor of a computing device to:

identify a first attribute set associated with a first file stored in a storage system;

determine that the first file is replaced in the storage system with a second file;

identify a second attribute set associated with the second file; and

determine, based on the determining that the first file is replaced in the storage system with the second file and on one or more attributes in at least one of the first attribute set or the second attribute set, that data stored by the storage system is possibly being targeted by a security threat.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2020
From: CHILD, ROY; LEE, ROBERT; JIBAJA, IVAN; KARR, RONALD
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 054099/0568 →