IP Library Granted Patent US 12,050,689
Granted Patent B2
US 12,050,689 · App. 17/409,135 · Granted Jul 30, 2024

Host anomaly-based generation of snapshots

Inventors: Paul R Massiglia (Colorado Springs, CO); Ronald Karr (Palo Alto, CA); John Colgrove (Los Altos, CA)
Assignee: Pure Storage, Inc.
G06F21/568G06F3/0619G06F3/0659G06F3/067G06F21/554G06F21/78
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,050,689
App. No.
17/409,135
Filed
Aug 23, 2021
Granted
Jul 30, 2024
Kind
B2
Art Unit
2499
USPC
726/23
Abstract

An illustrative method includes a data protection system detecting a request provided by a host to perform an operation with respect to a storage system, detecting, based on the request, an anomaly associated with the host, and directing, based on the detecting the anomaly associated with the host, the storage system to generate a recovery dataset for data maintained by the storage system.

Claims (42)

1. A method comprising:

detecting, by a data protection system, a request provided by a host to perform an operation with respect to a storage system, wherein the request is for the host to attach to a volume of the storage system;

detecting, by the data protection system based on the request, an anomaly associated with the host, the detecting the anomaly comprising determining that an additional host is already attached to the volume at a time of the request;

directing, by the data protection system based on the detecting the anomaly associated with the host, the storage system to generate a recovery dataset for data maintained by the storage system; and

using, by the data protection system, the recovery dataset to perform a data recovery process with respect to the data maintained by the storage system.

2. The method of claim 1 , wherein the detecting the anomaly associated with the host further comprises determining that the host has not historically provided requests of a similar type as the request.

3. The method of claim 1 , wherein the detecting the anomaly associated with the host further comprises determining that the host is associated with an Internet protocol (IP) address that has not been previously used to perform an operation with respect to the storage system.

4. The method of claim 1 , wherein the detecting the anomaly associated with the host further comprises determining that the host has not previously provided requests to perform one or more operations with respect to the storage system.

5. The method of claim 1 , wherein the detecting the anomaly associated with the host further comprises determining that a round-trip time from an Internet protocol (IP) address associated with the request exceeds a predetermined threshold.

6. The method of claim 1 , further comprising:

the recovery dataset is initially classified as a provisional recovery dataset that has a first set of criteria that has to be met for the recovery dataset to be deleted; and

the method further comprises:

determining, by the data protection system, that the anomaly is indicative of a possible security threat against the data maintained by the storage system; and

reclassifying, by the data protection system that the anomaly is indicative of the security threat, the recovery dataset as a protected recovery dataset, the protected recovery dataset having a second set of criteria that has to be met for the recovery dataset to be deleted, the second set of criteria more stringent than the first set of criteria.

7. The method of claim 1 , wherein the directing the storage system to generate the recovery dataset comprises directing the storage system to generate the recovery dataset prior to performing the operation.

8. A system comprising:

a memory storing instructions; and

a processor communicatively coupled to the memory and configured to execute the instructions to:

detect a request provided by a host to perform an operation with respect to a storage system, wherein the request is for the host to attach to a volume of the storage system;

detect, based on the request, an anomaly associated with the host, the detecting the anomaly comprising determining that an additional host is already attached to the volume at a time of the request; and

direct, based on the detecting the anomaly associated with the host, the storage system to generate a recovery dataset for data maintained by the storage system; and

use the recovery dataset to perform a data recovery process with respect to the data maintained by the storage system.

9. The system of claim 8 , wherein the detecting the anomaly associated with the host further comprises determining that the host has not historically provided requests of a similar type as the request.

10. The system of claim 8 , wherein the detecting the anomaly associated with the host further comprises determining that the host is associated with an Internet protocol (IP) address that has not been previously used to perform an operation with respect to the storage system.

11. The system of claim 8 , wherein the detecting the anomaly associated with the host further comprises determining that the host has not previously provided requests to perform one or more operations with respect to the storage system.

12. The system of claim 8 , wherein the detecting the anomaly associated with the host further comprises determining that a round-trip time from an Internet protocol (IP) address associated with the request exceeds a predetermined threshold.

13. The system of claim 8 , wherein:

the recovery dataset is initially classified as a provisional recovery dataset that has a first set of criteria that has to be met for the recovery dataset to be deleted; and

the processor is further configured to execute the instructions to:

determine that the anomaly is indicative of a possible security threat against the data maintained by the storage system; and

reclassify, based on the determining that the anomaly is indicative of the security threat, the recovery dataset as a protected recovery dataset, the protected recovery dataset having a second set of criteria that has to be met for the recovery dataset to be deleted, the second set of criteria more stringent than the first set of criteria.

14. The system of claim 8 , wherein the processor is further configured to execute the instructions to use the recovery dataset to perform a data recovery process with respect to the data maintained by the storage system.

15. A non-transitory computer-readable medium storing instructions that, when executed, direct a processor of a computing device to:

detect a request provided by a host to perform an operation with respect to a storage system, wherein the request is for the host to attach to a volume of the storage system;

detect, based on the request, an anomaly associated with the host, the detecting the anomaly comprising determining that an additional host is already attached to the volume at a time of the request;

direct, based on the detecting the anomaly associated with the host, the storage system to generate a recovery dataset for data maintained by the storage system; and

use the recovery dataset to perform a data recovery process with respect to the data maintained by the storage system.

16. The non-transitory computer-readable medium of claim 15 , wherein the detecting the anomaly associated with the host further comprises determining that the host has not historically provided requests of a similar type as the request.

17. The non-transitory computer-readable medium of claim 15 , wherein the detecting the anomaly associated with the host further comprises determining that the host is associated with an Internet protocol (IP) address that has not been previously used to perform an operation with respect to the storage system.

18. The non-transitory computer-readable medium of claim 15 , wherein the detecting the anomaly associated with the host further comprises determining that the host has not previously provided requests to perform one or more operations with respect to the storage system.

19. The non-transitory computer-readable medium of claim 15 , wherein the detecting the anomaly associated with the host further comprises determining that a round-trip time from an Internet protocol (IP) address associated with the request exceeds a predetermined threshold.

20. The non-transitory computer-readable medium of claim 15 , wherein the directing the storage system to generate the recovery dataset comprises directing the storage system to generate the recovery dataset prior to performing the operation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2021
From: MASSIGLIA, PAUL R; KARR, RONALD; COLGROVE, JOHN
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 057260/0313 →
Continuity (4)
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16711060 · Dec 11, 2019
Provisional Application 62939518 · Nov 22, 2019
Related Publication 20210382995A1 · Dec 9, 2021