IP Library Granted Patent US 11,663,332
Granted Patent B2
US 11,663,332 · App. 17/150,344 · Granted May 30, 2023

Tracking a virus footprint in data copies

Inventors: Shiv S. Kumar (Pune, IN); Jai P. Gahlot (Pune, IN); Avadut Mungre (North Goa, IN)
Assignee: EMC IP HOLDING COMPANY LLC
G06F21/565G06F11/1464G06F21/561G06F21/568G06F2201/84G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,663,332
App. No.
17/150,344
Granted
May 30, 2023
Kind
B2
Abstract

Techniques are provided for tracking a virus footprint in data copies. Data copies can be made in a variety of ways, like with snapshots, backups, replications, and simple copies. As copies of files that have not been scanned since they were last modified are made, these copies can be kept track of, and associated with the original file. When the original file is later scanned and found to be clean or infected, this information can be propagated through the copies.

Claims (69)

1. A system, comprising:

a processor; and

a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations, comprising:

determining that a first file is infected with a virus;

in response to the determining,

taking a defined action to reduce an effect of the virus in the first file, and

identifying a data protection location in first metadata that is stored in a first extended attribute of a first inode for the first file, wherein the first metadata identifies first data protection locations of the first file that were made subsequent to a last clean virus scan of the first file, wherein the first data protection locations comprise the data protection location, wherein the data protection location comprises a snapshot of multiple files, and wherein the first inode comprises a data structure in a file system that describes a file system object; and

in response to the identifying, storing an indication that a copy of the first file that is stored as part of the data protection location is infected in second metadata for the data protection location that is stored in a second extended attribute of a second inode of the data protection location.

2. The system of claim 1 , wherein the operations further comprise:

in response to determining that a second file is not infected with any virus, clearing third metadata for the second file that identifies second data protection locations of the second file.

3. The system of claim 1 , wherein the indication is a first indication, and wherein the operations further comprise:

moving a data protection of a second file to a second data protection location;

determining that the second file has been modified subsequent to a time that the second file most recently has been scanned for any virus; and

storing a second indication of the second data protection location in third metadata of the second file that identifies second data protection locations with an unscanned copy of the second file.

4. The system of claim 1 , wherein the indication is a first indication wherein the data protection location is a first data protection location, and wherein the operations further comprise:

receiving a request to modify a second file;

determining that a most recent previous modification of the second file occurred after a time that the second file was last scanned for any virus;

identifying a second data protection location in third metadata for the second file that identifies data protection locations of the second file;

storing a second indication that the first file is unscanned in fourth metadata of the second data protection location; and

modifying the second file.

5. The system of claim 1 , wherein the operations further comprise:

receiving a request for a full restoration from the data protection location; and

in response to determining that the second metadata indicates that the data protection location lacks an infected file, performing the full restoration from the data protection location.

6. The system of claim 1 , wherein the operations further comprise:

receiving a request to for a full restoration from the data protection location; and

in response to determining that the second metadata indicates that at least one file of the data protection location is infected, determining not to perform the full restoration from the data protection location.

7. The system of claim 6 , wherein the operations further comprise:

in response to performing the determining that the second metadata indicates that the at least one file of the data protection location is infected, deleting the data protection location.

8. The system of claim 6 , wherein the operations further comprise:

in response to performing the determining that the second metadata indicates that the at least one file of the data protection location is infected, sending a notification to a user account associated with the data protection location.

9. A method, comprising:

in response to creating a data protection location for a first file, storing, by a system comprising a processor, an identifier of the data protection location in first metadata for the first file that identifies data protection locations of the first file;

determining, by the system, that the first file is infected with a virus;

in response to the determining, identifying, by the system, the data protection location from the first metadata for the first file; and

in response to the identifying, storing, by the system, an indication that the first file is infected in second metadata of the data protection location, wherein the data protection location comprises a data protection of multiple files, and wherein the indication identifies the first file within the data protection location.

10. The method of claim 9 , further comprising:

receiving, by the system a request for partial restoration from the data protection location; and

in response to determining that the second metadata indicates that the data protection location lacks an infected file, performing, by the system, the partial restoration from the data protection location.

11. The method of claim 9 , further comprising:

receiving, by the system, a request for partial restoration from the data protection location; and

in response to determining that the second metadata indicates that at least one file of the data protection location is infected, determining, by the system, not to perform the partial restoration from the data protection location, while preserving the data protection location in storage.

12. The method of claim 9 , wherein the data protection location comprises a backup system, and wherein performing the storing of the indication that the first file is infected in the second metadata of the data protection location comprises:

sending, by the system, a request to the backup system via a communications network to store the indication that the first file is infected in the second metadata.

13. The method of claim 9 , wherein the first file is stored on a first replication server and the data protection location is a second replication server, and further comprising:

in response to switching, by the system, from the first replication server to the second replication server as a live replication server, determining a copy of the first file on the second replication server has an infection based on the indication that the first file is infected in the second metadata; and

taking, by the system, a defined action to reduce the infection of the copy of the first file on the second replication server.

14. The method of claim 9 , further comprising:

in response to performing the determining that the first file is infected with the virus, quarantining, deleting, or repairing, by the system, the first file.

15. A non-transitory computer-readable medium comprising instructions that, in response to execution, cause a system comprising a processor to perform operations, comprising:

determining that a first file is infected with a virus;

in response to the determining, identifying a data protection location from first metadata the first file, wherein the first metadata identifies data protection locations of the first file; and

in response to the identifying, storing an indication that the first file is infected in second metadata of the data protection location, wherein the data protection location comprises a data protection of multiple files, and wherein the indication identifies the first file within the data protection location.

16. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:

receiving a request to copy a second file as a third file;

determining that a most recent previous modification of the second file occurred after a time that the second file was last scanned for the virus; and

storing an identifier of the third file in third metadata for the second file that identifies unscanned copies of the second file.

17. The non-transitory computer-readable medium of claim 16 , wherein the operations further comprise:

determining that the second file is infected with an infection;

taking a defined action to reduce the infection in the second file; and

based on the identifier of the third file existing in the third metadata for the second file, taking the defined action to reduce the infection in the third file.

18. The non-transitory computer-readable medium of claim 17 , wherein the operations further comprise:

determining that fourth metadata for the third file identifies that a copy of the third file has been made as a fourth file, and that the fourth file is unscanned; and

based on the fourth metadata, taking the defined action to reduce the infection in the fourth file.

19. The non-transitory computer-readable medium of claim 16 , wherein the operations further comprise:

in response to determining that the second file is uninfected, storing a first indication that the second file is uninfected;

based on the identifier of the third file being determined to be represented in the third metadata for the second file, storing a second indication that the third file is uninfected; and

removing the identifier of the third file the third metadata.

20. The non-transitory computer-readable medium of claim 16 , wherein the operations further comprise:

in response to modifying the second file, removing the identifier of the third file in the third metadata.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2021
From: KUMAR, SHIV S.; GAHLOT, JAI P.; MUNGRE, AVADUT
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 054934/0452 →
Continuity (1)
Related Publication 20220229905A1 · Jul 21, 2022
Cited By (1)
US 12,639,435