IP Library Granted Patent US 12,282,551
Granted Patent B2
US 12,282,551 · App. 17/308,113 · Granted Apr 22, 2025

Detection of anomalous backup files using known anomalous file fingerprints

Inventors: Tomer Shachar (Omer, IL); Maxim Balin (Gan-Yavne, IL); Yevgeni Gehtman (Modi'in, IL)
Assignee: EMC IP Holding Company LLC
G06F21/562G06F11/1451G06F16/11G06F21/568G06F2201/80G06F2201/82G06F2221/033G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,282,551
App. No.
17/308,113
Granted
Apr 22, 2025
Kind
B2
Abstract

Techniques are provided for detection of anomalous backup files using known anomalous file fingerprints (or other file-dependent values such as hash values, signatures and/or digest values). One method comprises obtaining first file-dependent values corresponding to respective known anomalous files; obtaining a second file-dependent value for a stored backup file; comparing the second file-dependent value to the first file-dependent values; and performing an automated remedial action in response to a result of the comparing. The second file-dependent value for the stored backup file may be determined by a backup server in response to a source file corresponding to the stored backup file being backed up by the backup server, and may be stored as part of metadata associated with the stored backup file.

Claims (35)

1. A method, comprising:

obtaining a plurality of first file-dependent values corresponding to respective known anomalous files;

obtaining at least one second file-dependent value for at least one stored backup file, wherein the at least one second file-dependent value is computed by a backup server in response to a source file corresponding to the at least one stored backup file being backed up by the backup server, wherein the at least one second file-dependent value is based at least in part on a content of the at least one stored backup file, and wherein the at least one second file-dependent value is distinct from the at least one stored backup file;

comparing the at least one second file-dependent value to the plurality of first file- dependent values; and

performing one or more automated remedial actions in response to a result of the comparing;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The method of claim 1 , wherein one or more of the plurality of first file-dependent values and the at least one second file-dependent value comprises one or more of a hash value, a signature, a digest value and a fingerprint of a corresponding file.

3. The method of claim 1 , wherein the plurality of first file-dependent values is obtained from a third-party computer security provider.

4. The method of claim 1 , wherein the comparing the at least one second file-dependent value to the plurality of first file-dependent values comprises scanning a plurality of the at least one second file-dependent values to identify an anomalous backup file.

5. The method of claim 1 , wherein the at least one second file-dependent value for the at least one stored backup file is stored as part of metadata associated with the at least one stored backup file in connection with a backup of a source file corresponding to the at least one stored backup file.

6. The method of claim 1 , wherein the one or more automated remedial actions comprise one or more of: generating an anomalous file alert notification, suspending a backup of at least one file, suspending a restore operation with respect to the at least one stored backup file and deleting the at least one stored backup file from a backup storage device.

7. The method of claim 1 , wherein the first file-dependent value corresponding to a given known anomalous file is obtained, by the backup server, subsequent to a backup of a source file corresponding to the at least one stored backup file.

8. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured to implement the following steps:

obtaining a plurality of first file-dependent values corresponding to respective known anomalous files;

obtaining at least one second file-dependent value for at least one stored backup file, wherein the at least one second file-dependent value is computed by a backup server in response to a source file corresponding to the at least one stored backup file being backed up by the backup server, wherein the at least one second file-dependent value is based at least in part on a content of the at least one stored backup file, and wherein the at least one second file-dependent value is distinct from the at least one stored backup file;

comparing the at least one second file-dependent value to the plurality of first file-dependent values; and

performing one or more automated remedial actions in response to a result of the comparing.

9. The apparatus of claim 8 , wherein one or more of the plurality of first file-dependent values and the at least one second file-dependent value comprises one or more of a hash value, a signature, a digest value and a fingerprint of a corresponding file.

10. The apparatus of claim 8 , wherein the at least one second file-dependent value for the at least one stored backup file is stored as part of metadata associated with the at least one stored backup file in connection with a backup of a source file corresponding to the at least one stored backup file.

11. The apparatus of claim 8 , wherein the one or more automated remedial actions comprise one or more of: generating an anomalous file alert notification, suspending a backup of at least one file, suspending a restore operation with respect to the at least one stored backup file and deleting the at least one stored backup file from a backup storage device.

12. The apparatus of claim 8 , wherein the first file-dependent value corresponding to a given known anomalous file is obtained, by the backup server, subsequent to a backup of a source file corresponding to the at least one stored backup file.

13. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:

obtaining a plurality of first file-dependent values corresponding to respective known anomalous files;

obtaining at least one second file-dependent value for at least one stored backup file, wherein the at least one second file-dependent value is computed by a backup server in response to a source file corresponding to the at least one stored backup file being backed up by the backup server, wherein the at least one second file-dependent value is based at least in part on a content of the at least one stored backup file, and wherein the at least one second file-dependent value is distinct from the at least one stored backup file;

comparing the at least one second file-dependent value to the plurality of first file-dependent values; and

performing one or more automated remedial actions in response to a result of the comparing.

14. The non-transitory processor-readable storage medium of claim 13 , wherein one or more of the plurality of first file-dependent values and the at least one second file-dependent value comprises one or more of a hash value, a signature, a digest value and a fingerprint of a corresponding file.

15. The non-transitory processor-readable storage medium of claim 13 , wherein the at least one second file-dependent value for the at least one stored backup file is stored as part of metadata associated with the at least one stored backup file in connection with a backup of a source file corresponding to the at least one stored backup file.

16. The non-transitory processor-readable storage medium of claim 13 , wherein the one or more automated remedial actions comprise one or more of: generating an anomalous file alert notification, suspending a backup of at least one file, suspending a restore operation with respect to the at least one stored backup file and deleting the at least one stored backup file from a backup storage device.

17. The non-transitory processor-readable storage medium of claim 13 , wherein the first file-dependent value corresponding to a given known anomalous file is obtained, by the backup server, subsequent to a backup of a source file corresponding to the at least one stored backup file.

18. The method of claim 1 , wherein the comparing is performed in response to an occurrence of a trigger event comprising a request to restore the at least one stored backup file.

19. The apparatus of claim 8 , wherein the comparing is performed in response to an occurrence of a trigger event comprising a request to restore the at least one stored backup file.

20. The non-transitory processor-readable storage medium of claim 13 , wherein the comparing is performed in response to an occurrence of a trigger event comprising a request to restore the at least one stored backup file.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2021
From: SHACHAR, TOMER; BALIN, MAXIM; GEHTMAN, YEVGENI
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 056137/0806 →
Continuity (1)
Related Publication 20220358215A1 · Nov 10, 2022
References Cited (11)
US 8099605B1 · Billsrom · 2012 [cited by examiner]
US 8667591B1 · Claudatos · 2014 [cited by examiner]
US 10970395B1 · Bansal · 2021 [cited by examiner]
US 11520907B1 · Borowiec · 2022 [cited by examiner]
US 20150067860A1 · Levow · 2015 [cited by examiner]
US 20170177867A1 · Crofton · 2017 [cited by examiner]
US 20170308420A1 · Korotaev · 2017 [cited by examiner]
US 20180359272A1 · Mizrachi · 2018 [cited by examiner]
https://www.carbonite.com/blog/article/2020/06/antivirus-and-backup-why-you-need-both, downloaded on Apr. 21, 2021. [cited by applicant]
https://www.microtechboise.com/our-services/antivirus-and-backups/, downloaded on Apr. 21, 2021. [cited by applicant]
https://www.handybackup.net/antivirus.shtml, downloaded on Apr. 21, 2021. [cited by applicant]