Snapshot delta metric based determination of a possible ransomware attack against data maintained by a storage system
An illustrative method includes a data protection system determining a delta metric between a first recovery dataset generated by a storage system at a first time and a second recovery dataset generated by the storage system at a second time subsequent to the first time and determining, based on the delta metric, whether data maintained by the storage system is possibly being targeted by a security threat.
1. A method comprising:
determining, by a data protection system, a delta metric between a first recovery dataset generated by a storage system at a first time and a second recovery dataset generated by the storage system at a second time subsequent to the first time;
determining, by the data protection system based on the delta metric, whether data maintained by the storage system is possibly being targeted by a security threat, wherein the determining whether the data maintained by the storage system is possibly being targeted by the security threat comprises determining that the data maintained by the storage system is possibly being targeted by the security threat if the delta metric is greater than a threshold, the threshold set to be a certain number of standard deviations above a historical average size difference between recovery datasets generated by the storage system prior to the first time; and
performing, by the data protection system based on the determining that the storage system is possibly being targeted by the security threat, a remedial action with respect to the storage system, the remedial action comprising at least one of preventing one or more recovery datasets from being deleted until one or more conditions are fulfilled or using one or more recovery datasets to restore the data maintained by the storage system to a state that corresponds to a point in time that precedes a point in time at which the data protection system determines that the data maintained by the storage system is possibly being targeted by the security threat.
2. The method of claim 1 , wherein the one or more recovery datasets are generated by the storage system prior to the first time.
3. The method of claim 1 , wherein the performing the remedial action comprises providing a notification.
4. The method of claim 1 , wherein the threshold is further set to be a certain amount above a maximum delta between recovery datasets generated during a predetermined time period prior to the first time.
5. The method of claim 1 , wherein the determining whether the data maintained by the storage system is possibly being targeted by the security threat comprises determining that the data maintained by the storage system is not being targeted by the security threat if the delta metric is less than a threshold.
6. The method of claim 1 , wherein the delta metric comprises a size difference between the first and second recovery datasets.
7. The method of claim 1 , wherein the delta metric comprises a compressibility difference between the first and second recovery datasets.
8. The method of claim 1 , wherein the data protection system is implemented by a controller within the storage system.
9. The method of claim 1 , wherein the data protection system is implemented by a computing system communicatively coupled to the storage system by way of a network.
10. The method of claim 1 , wherein the security threat comprises a ransomware attack.
11. A system comprising:
a memory storing instructions; and
a processor communicatively coupled to the memory and configured to execute the instructions to:
determine a delta metric between a first recovery dataset generated by a storage system at a first time and a second recovery dataset generated by the storage system at a second time subsequent to the first time;
determine, based on the delta metric, whether data maintained by the storage system is possibly being targeted by a security threat, wherein the determining whether the data maintained by the storage system is possibly being targeted by the security threat comprises determining that the data maintained by the storage system is possibly being targeted by the security threat if the delta metric is greater than a threshold, the threshold set to be a certain number of standard deviations above a historical average size difference between recovery datasets generated by the storage system prior to the first time;
perform, based on the determining that the storage system is possibly being targeted by the security threat, a remedial action with respect to the storage system, the remedial action comprising at least one of preventing one or more recovery datasets from being deleted until one or more conditions are fulfilled or using one or more recovery datasets to restore the data maintained by the storage system to a state that corresponds to a point in time that precedes a point in time at which the system determines that the data maintained by the storage system is possibly being targeted by the security threat.
12. A non-transitory computer-readable medium storing instructions that, when executed, direct a processor of a computing device to:
determine a delta metric between a first recovery dataset generated by a storage system at a first time and a second recovery dataset generated by the storage system at a second time subsequent to the first time;
determine, based on the delta metric, whether data maintained by the storage system is possibly being targeted by a security threat, wherein the determining whether the data maintained by the storage system is possibly being targeted by the security threat comprises determining that the data maintained by the storage system is possibly being targeted by the security threat if the delta metric is greater than a threshold, the threshold set to be a certain number of standard deviations above a historical average size difference between recovery datasets generated by the storage system prior to the first time;
perform, based on the determining that the storage system is possibly being targeted by the security threat, a remedial action with respect to the storage system, the remedial action comprising at least one of preventing one or more recovery datasets from being deleted until one or more conditions are fulfilled or using one or more recovery datasets to restore the data maintained by the storage system to a state that corresponds to a point in time that precedes a point in time at which the processor determines that the data maintained by the storage system is possibly being targeted by the security threat.