Detection of writing to a non-header portion of a file as an indicator of a possible ransomware attack against a storage system
An illustrative method includes detecting a request to perform an overwrite operation with respect to a non-header portion of a file stored by a storage system and determining, based on the detecting the request, that data stored by the storage system is possibly being targeted by a security threat.
1. A method comprising:
detecting, by a data protection system, a request to perform an overwrite operation with respect to a non-header portion of a file stored by a storage system, the non-header portion including bits representative of content represented by the file, the file further including a header that includes bits representative of metadata or other types of data that describe or otherwise provide information about the non-header portion;
determining, by the data protection system based on the detecting the request, that data stored by the storage system is possibly being targeted by a security threat;
determining, by the data protection system, whether an attribute of the file is associated with files that are typically written in place; and
when the data protection system determines that the attribute of the file is associated with files that are typically written in place, determining that the request is not associated with the security threat and continuing to monitor for additional requests to perform overwrite operations.
2. The method of claim 1 , wherein the attribute of the file comprises one or more of a type of the file, a size of the file, a filename pattern of the file, an age of the file, or a source of the file.
3. The method of claim 1 , further comprising:
detecting, by the data protection system based on the request, an anomaly associated with a host that provides the request;
wherein the determining that the data stored by the storage system is possibly being targeted by the security threat is further based on the detecting of the anomaly associated with the host.
4. The method of claim 1 , further comprising:
determining, by the data protection system, that the file is of a particular type for which overwrite operations have not been previously detected by the storage system;
wherein the determining that the data stored by the storage system is possibly being targeted by the security threat is further based on the determining that the file is of the particular type.
5. The method of claim 1 , further comprising performing, by the data protection system based on the determining that the data stored by the storage system is possibly being targeted by the security threat, a remedial action with respect to the data stored by the storage system.
6. The method of claim 5 , wherein the performing the remedial action comprises directing the storage system to generate a recovery dataset for the data stored by the storage system.
7. The method of claim 5 , wherein the performing the remedial action comprises directing the storage system to back up the file before performing the request.
8. The method of claim 5 , wherein the performing the remedial action comprises preventing the storage system from performing the request.
9. The method of claim 5 , wherein the performing the remedial action comprises quarantining the file.
10. The method of claim 5 , wherein the performing the remedial action comprises providing an alert.
11. The method of claim 5 , wherein the performing the remedial action comprises quarantining requests provided by a source of the request.
12. The method of claim 1 , wherein one or more of the detecting or the determining is performed using a machine learning model.
13. A system comprising:
a memory storing instructions; and
a processor communicatively coupled to the memory and configured to execute the instructions to:
detect a request to perform an overwrite operation with respect to a non-header portion of a file stored by a storage system, the non-header portion including bits representative of content represented by the file, the file further including a header that includes bits representative of metadata or other types of data that describe or otherwise provide information about the non-header portion;
determine, based on the detecting the request, that data stored by the storage system is possibly being targeted by a security threat;
determine whether an attribute of the file is associated with files that are typically written in place; and
when the processor determines that the attribute of the file is associated with files that are typically written in place, determine that the request is not associated with the security threat and continue to monitor for additional requests to perform overwrite operations.
14. The system of claim 13 , wherein the attribute of the file comprises one or more of a type of the file, a size of the file, a filename pattern of the file, an age of the file, or a source of the file.
15. The system of claim 13 , wherein:
the processor is further configured to execute the instructions to detect, based on the request, an anomaly associated with a host that provides the request; and
the determining that the data stored by the storage system is possibly being targeted by the security threat is further based on the detecting of the anomaly associated with the host.
16. The system of claim 13 , wherein:
the processor is further configured to execute the instructions to determine that the file is of a particular type for which overwrite operations have not been previously detected by the storage system; and
the determining that the data stored by the storage system is possibly being targeted by the security threat is further based on the determining that the file is of the particular type.
17. The system of claim 13 , wherein the processor is further configured to execute the instructions to perform, based on the determining that the data stored by the storage system is possibly being targeted by the security threat, a remedial action with respect to the data stored by the storage system.
18. A non-transitory computer-readable medium storing instructions that, when executed, direct a processor of a computing device to:
detect a request to perform an overwrite operation with respect to a non-header portion of a file stored by a storage system, the non-header portion including bits representative of content represented by the file, the file further including a header that includes bits representative of metadata or other types of data that describe or otherwise provide information about the non-header portion;
determine, based on the detecting the request, that data stored by the storage system is possibly being targeted by a security threat;
determine whether an attribute of the file is associated with files that are typically written in place; and
when the processor determines that the attribute of the file is associated with files that are typically written in place, determine that the request is not associated with the security threat and continue to monitor for additional requests to perform overwrite operations.
19. The method of claim 1 , wherein:
the determining whether the attribute of the file comprises determining that the attribute of the file is not associated with files that are typically written in place; and
the determining that the data stored by the storage system is possibly being targeted by the security threat is further based on the determining that the attribute of the file is not associated with files that are typically written in place.
20. The system of claim 13 , wherein:
the determining whether the attribute of the file comprises determining that the attribute of the file is not associated with files that are typically written in place; and
the determining that the data stored by the storage system is possibly being targeted by the security threat is further based on the determining that the attribute of the file is not associated with files that are typically written in place.