IP Library Granted Patent US 11,657,155
Granted Patent B2
US 11,657,155 · App. 17/342,203 · Granted May 23, 2023

Snapshot delta metric based determination of a possible ransomware attack against data maintained by a storage system

Inventors: Daniel Pendlebury (Thomson, AU); Ronald Karr (Palo Alto, CA)
Assignee: Pure Storage, Inc
G06F21/566G06F11/1469G06F21/554G06F21/64G06F2201/84G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,657,155
App. No.
17/342,203
Filed
Jun 8, 2021
Granted
May 23, 2023
Kind
B2
Art Unit
2499
USPC
726/23
Abstract

An illustrative method includes a data protection system determining a delta metric between a first recovery dataset generated by a storage system at a first time and a second recovery dataset generated by the storage system at a second time subsequent to the first time and determining, based on the delta metric, whether data maintained by the storage system is possibly being targeted by a security threat.

Claims (23)

1. A method comprising:

determining, by a data protection system, a delta metric between a first recovery dataset generated by a storage system at a first time and a second recovery dataset generated by the storage system at a second time subsequent to the first time;

determining, by the data protection system based on the delta metric, whether data maintained by the storage system is possibly being targeted by a security threat, wherein the determining whether the data maintained by the storage system is possibly being targeted by the security threat comprises determining that the data maintained by the storage system is possibly being targeted by the security threat if the delta metric is greater than a threshold, the threshold set to be a certain number of standard deviations above a historical average size difference between recovery datasets generated by the storage system prior to the first time; and

performing, by the data protection system based on the determining that the storage system is possibly being targeted by the security threat, a remedial action with respect to the storage system, the remedial action comprising at least one of preventing one or more recovery datasets from being deleted until one or more conditions are fulfilled or using one or more recovery datasets to restore the data maintained by the storage system to a state that corresponds to a point in time that precedes a point in time at which the data protection system determines that the data maintained by the storage system is possibly being targeted by the security threat.

2. The method of claim 1 , wherein the one or more recovery datasets are generated by the storage system prior to the first time.

3. The method of claim 1 , wherein the performing the remedial action comprises providing a notification.

4. The method of claim 1 , wherein the threshold is further set to be a certain amount above a maximum delta between recovery datasets generated during a predetermined time period prior to the first time.

5. The method of claim 1 , wherein the determining whether the data maintained by the storage system is possibly being targeted by the security threat comprises determining that the data maintained by the storage system is not being targeted by the security threat if the delta metric is less than a threshold.

6. The method of claim 1 , wherein the delta metric comprises a size difference between the first and second recovery datasets.

7. The method of claim 1 , wherein the delta metric comprises a compressibility difference between the first and second recovery datasets.

8. The method of claim 1 , wherein the data protection system is implemented by a controller within the storage system.

9. The method of claim 1 , wherein the data protection system is implemented by a computing system communicatively coupled to the storage system by way of a network.

10. The method of claim 1 , wherein the security threat comprises a ransomware attack.

11. A system comprising:

a memory storing instructions; and

a processor communicatively coupled to the memory and configured to execute the instructions to:

determine a delta metric between a first recovery dataset generated by a storage system at a first time and a second recovery dataset generated by the storage system at a second time subsequent to the first time;

determine, based on the delta metric, whether data maintained by the storage system is possibly being targeted by a security threat, wherein the determining whether the data maintained by the storage system is possibly being targeted by the security threat comprises determining that the data maintained by the storage system is possibly being targeted by the security threat if the delta metric is greater than a threshold, the threshold set to be a certain number of standard deviations above a historical average size difference between recovery datasets generated by the storage system prior to the first time;

perform, based on the determining that the storage system is possibly being targeted by the security threat, a remedial action with respect to the storage system, the remedial action comprising at least one of preventing one or more recovery datasets from being deleted until one or more conditions are fulfilled or using one or more recovery datasets to restore the data maintained by the storage system to a state that corresponds to a point in time that precedes a point in time at which the system determines that the data maintained by the storage system is possibly being targeted by the security threat.

12. A non-transitory computer-readable medium storing instructions that, when executed, direct a processor of a computing device to:

determine a delta metric between a first recovery dataset generated by a storage system at a first time and a second recovery dataset generated by the storage system at a second time subsequent to the first time;

determine, based on the delta metric, whether data maintained by the storage system is possibly being targeted by a security threat, wherein the determining whether the data maintained by the storage system is possibly being targeted by the security threat comprises determining that the data maintained by the storage system is possibly being targeted by the security threat if the delta metric is greater than a threshold, the threshold set to be a certain number of standard deviations above a historical average size difference between recovery datasets generated by the storage system prior to the first time;

perform, based on the determining that the storage system is possibly being targeted by the security threat, a remedial action with respect to the storage system, the remedial action comprising at least one of preventing one or more recovery datasets from being deleted until one or more conditions are fulfilled or using one or more recovery datasets to restore the data maintained by the storage system to a state that corresponds to a point in time that precedes a point in time at which the processor determines that the data maintained by the storage system is possibly being targeted by the security threat.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2021
From: PENDLEBURY, DANIEL; KARR, RONALD
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 056472/0714 →
Continuity (4)
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16711060 · Dec 11, 2019
Provisional Application 62939518 · Nov 22, 2019
Related Publication 20210303687A1 · Sep 30, 2021
Cited By (2)
US 12,306,941 US 12,701,127