DETECTING RANSOMWARE IN MONITORED DATA
An information management system includes one or more client computing devices in communication with a storage manager and a secondary storage computing device. The storage manager manages the primary data of the one or more client computing devices and the secondary storage computing device manages secondary copies of the primary data of the one or more client computing devices. Each client computing device may be configured with a ransomware protection monitoring application that monitors for changes in their primary data. The ransomware protection monitoring application may input the changes detected in the primary data into a machine-learning classifier, where the classifier generates an output indicative of whether a client computing device has been affected by malware and/or ransomware. Using a virtual machine host, a virtual machine copy of an affected client computing device may be instantiated using a secondary copy of primary data of the affected client computing device.
1 . A method for protecting file system data of a client computing device being managed by a storage manager, the method comprising:
training an anomaly detection model based on file system data obtained from one or more backup operations;
monitoring file system data of a client computing device being managed by a storage manager, wherein the client computing device is in communication with a secondary storage computing device for storing a secondary copy of data of the client computing device;
determining that there are one or more changes to the file system data of the client computing device;
providing the one or more changes of the file system data to the anomaly detection model to determine whether there is an anomaly in the file system data;
determining that there is an anomaly in the file system data based on the anomaly detection model; and,
generating a notification to a user that there is an anomaly in the file system data based on the determination that there is an anomaly in the file system data.
2 . The method of claim 1 , further comprising transmitting the notification to the user and providing a graphical user interface for viewing the determined anomaly in response to a selection of the generated notification.
3 . The method of claim 1 , wherein the graphical user interface displays:
an activity summary of the file system data based on the determined anomaly;
a type of the determined anomaly in the activity summary; and,
a detected time when the determined anomaly was detected.
4 . The method of claim 1 , further comprising:
displaying at least one file system directory based on the determined anomaly in the file system data;
displaying at least one option to restore a prior version of the at least one file system directory stored as a secondary copy managed by the secondary storage computing device;
receiving an input of the at least one option to restore to the prior version; and,
restoring the prior version of the at least one file system directory to the client computing device.
5 . The method of claim 1 , further comprising:
displaying an identifier representing the client computing device in the graphical user interface based on the determined anomaly in the file system data with at least one option to create a virtual machine copy of the client computing device;
receiving an input of the at least one option to create the virtual machine copy of the client computing device; and,
creating the virtual machine copy of the client computing device.
6 . The method of claim 1 , further comprising:
determining a backup copy of the client computing device to use in creating a virtual machine copy of the client computing device, wherein:
the backup copy is stored as a secondary copy managed by the secondary storage computing device,
the determined backup copy originated from the client computing device prior to the detected anomaly in the file system data, and,
creating the virtual machine copy of the client computing device comprises creating the virtual machine copy from the determined backup copy.
7 . The method of claim 1 , further comprising displaying a geographic location of the client computing device having the detected anomaly in the file system data on a geographic map displayed by the graphical user interface.
8 . A system for protecting file system data of a client computing device, the system comprising:
one or more non-transitory, computer-readable mediums having computer-executable instructions stored thereon; and,
one or more processors that, having executed the computer-executable instructions, configures the system to perform a plurality of operations comprising:
training an anomaly detection model based on file system data obtained from one or more backup operations;
monitoring file system data of a client computing device being managed by a storage manager, wherein the client computing device is in communication with a secondary storage computing device for storing a secondary copy of data of the client computing device;
determining that there are one or more changes to the file system data of the client computing device;
providing the one or more changes of the file system data to the anomaly detection model to determine whether there is an anomaly in the file system data;
determining that there is an anomaly in the file system data based on the anomaly detection model; and,
generating a notification to a user that there is an anomaly in the file system data based on the determination that there is an anomaly in the file system data.
9 . The system of claim 8 , wherein the plurality of operations further includes transmitting the notification to the user and providing a graphical user interface for viewing the determined anomaly in response to a selection of the generated notification.
10 . The system of claim 8 , wherein the graphical user interface displays:
an activity summary of the file system data based on the determined anomaly;
a type of the determined anomaly in the activity summary; and,
a detected time when the determined anomaly was detected.
11 . The system of claim 8 , wherein the plurality of operations further includes:
displaying at least one file system directory based on the determined anomaly in the file system data;
displaying at least one option to restore a prior version of the at least one file system directory stored as a secondary copy managed by the secondary storage computing device;
receiving an input of the at least one option to restore to the prior version; and,
restoring the prior version of the at least one file system directory to the client computing device.
12 . The system of claim 8 , wherein the plurality of operations further includes:
displaying an identifier representing the client computing device in the graphical user interface based on the determined anomaly in the file system data with at least one option to create a virtual machine copy of the client computing device;
receiving an input of the at least one option to create the virtual machine copy of the client computing device; and,
creating the virtual machine copy of the client computing device.
13 . The system of claim 8 , wherein the plurality of operations further includes:
determining a backup copy of the client computing device to use in creating a virtual machine copy of the client computing device, wherein:
the backup copy is stored as a secondary copy managed by the secondary storage computing device,
the determined backup copy originated from the client computing device prior to the detected anomaly in the file system data, and
creating the virtual machine copy of the client computing device comprises creating the virtual machine copy from the determined backup copy.
14 . The system of claim 8 , wherein the plurality of operations further includes displaying a geographic location of the client computing device having the detected anomaly in the file system data on a geographic map displayed by the graphical user interface.
15 . A non-transitory, computer-readable medium having computer-executable instructions stored that, when executed by one or more processors, configures a system to perform a plurality of operations that comprises:
training an anomaly detection model based on file system data obtained from one or more backup operations;
monitoring file system data of a client computing device being managed by a storage manager, wherein the client computing device is in communication with a secondary storage computing device for storing a secondary copy of data of the client computing device;
determining that there are one or more changes to the file system data of the client computing device;
providing the one or more changes of the file system data to the anomaly detection model to determine whether there is an anomaly in the file system data;
determining that there is an anomaly in the file system data based on the anomaly detection model; and,
generating a notification to a user that there is an anomaly in the file system data based on the determination that there is an anomaly in the file system data.
16 . The non-transitory, computer-readable medium of claim 15 , wherein the plurality of operations further comprises transmitting the notification to the user and providing a graphical user interface for viewing the determined anomaly in response to a selection of the generated notification.
17 . The non-transitory, computer-readable medium of claim 15 , wherein the graphical user interface displays:
an activity summary of the file system data based on the determined anomaly;
a type of the determined anomaly in the activity summary; and,
a detected time when the determined anomaly was detected.
18 . The non-transitory, computer-readable medium of claim 15 , wherein the plurality of operations further comprises:
displaying at least one file system directory based on the determined anomaly in the file system data;
displaying at least one option to restore a prior version of the at least one file system directory stored as a secondary copy managed by the secondary storage computing device; and,
receiving an input of the at least one option to restore to the prior version, and restoring the prior version of the at least one file system directory to the client computing device.
19 . The non-transitory, computer-readable medium of claim 15 , wherein the plurality of operations further comprises:
displaying an identifier representing the client computing device in the graphical user interface based on the determined anomaly in the file system data with at least one option to create a virtual machine copy of the client computing device;
receiving an input of the at least one option to create the virtual machine copy of the client computing device; and,
creating the virtual machine copy of the client computing device.
20 . The non-transitory, computer-readable medium of claim 15 , wherein the plurality of operations further comprises:
determining a backup copy of the client computing device to use in creating a virtual machine copy of the client computing device, wherein:
the backup copy is stored as a secondary copy managed by the secondary storage computing device,
the determined backup copy originated from the client computing device prior to the detected anomaly in the file system data, and
creating the virtual machine copy of the client computing device comprises creating the virtual machine copy from the determined backup copy.