IP Library Granted Patent US 12,067,118
Granted Patent B2
US 12,067,118 · App. 17/463,088 · Granted Aug 20, 2024

Detection of writing to a non-header portion of a file as an indicator of a possible ransomware attack against a storage system

Inventor: Ronald Karr (Palo Alto, CA)
Assignee: Pure Storage, Inc.
G06F21/568G06F11/1435G06F11/1464G06F11/1469G06F21/554G06F21/78G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,067,118
App. No.
17/463,088
Filed
Aug 31, 2021
Granted
Aug 20, 2024
Kind
B2
Art Unit
2499
USPC
726/23
Abstract

An illustrative method includes detecting a request to perform an overwrite operation with respect to a non-header portion of a file stored by a storage system and determining, based on the detecting the request, that data stored by the storage system is possibly being targeted by a security threat.

Claims (46)

1. A method comprising:

detecting, by a data protection system, a request to perform an overwrite operation with respect to a non-header portion of a file stored by a storage system, the non-header portion including bits representative of content represented by the file, the file further including a header that includes bits representative of metadata or other types of data that describe or otherwise provide information about the non-header portion;

determining, by the data protection system based on the detecting the request, that data stored by the storage system is possibly being targeted by a security threat;

determining, by the data protection system, whether an attribute of the file is associated with files that are typically written in place; and

when the data protection system determines that the attribute of the file is associated with files that are typically written in place, determining that the request is not associated with the security threat and continuing to monitor for additional requests to perform overwrite operations.

2. The method of claim 1 , wherein the attribute of the file comprises one or more of a type of the file, a size of the file, a filename pattern of the file, an age of the file, or a source of the file.

3. The method of claim 1 , further comprising:

detecting, by the data protection system based on the request, an anomaly associated with a host that provides the request;

wherein the determining that the data stored by the storage system is possibly being targeted by the security threat is further based on the detecting of the anomaly associated with the host.

4. The method of claim 1 , further comprising:

determining, by the data protection system, that the file is of a particular type for which overwrite operations have not been previously detected by the storage system;

wherein the determining that the data stored by the storage system is possibly being targeted by the security threat is further based on the determining that the file is of the particular type.

5. The method of claim 1 , further comprising performing, by the data protection system based on the determining that the data stored by the storage system is possibly being targeted by the security threat, a remedial action with respect to the data stored by the storage system.

6. The method of claim 5 , wherein the performing the remedial action comprises directing the storage system to generate a recovery dataset for the data stored by the storage system.

7. The method of claim 5 , wherein the performing the remedial action comprises directing the storage system to back up the file before performing the request.

8. The method of claim 5 , wherein the performing the remedial action comprises preventing the storage system from performing the request.

9. The method of claim 5 , wherein the performing the remedial action comprises quarantining the file.

10. The method of claim 5 , wherein the performing the remedial action comprises providing an alert.

11. The method of claim 5 , wherein the performing the remedial action comprises quarantining requests provided by a source of the request.

12. The method of claim 1 , wherein one or more of the detecting or the determining is performed using a machine learning model.

13. A system comprising:

a memory storing instructions; and

a processor communicatively coupled to the memory and configured to execute the instructions to:

detect a request to perform an overwrite operation with respect to a non-header portion of a file stored by a storage system, the non-header portion including bits representative of content represented by the file, the file further including a header that includes bits representative of metadata or other types of data that describe or otherwise provide information about the non-header portion;

determine, based on the detecting the request, that data stored by the storage system is possibly being targeted by a security threat;

determine whether an attribute of the file is associated with files that are typically written in place; and

when the processor determines that the attribute of the file is associated with files that are typically written in place, determine that the request is not associated with the security threat and continue to monitor for additional requests to perform overwrite operations.

14. The system of claim 13 , wherein the attribute of the file comprises one or more of a type of the file, a size of the file, a filename pattern of the file, an age of the file, or a source of the file.

15. The system of claim 13 , wherein:

the processor is further configured to execute the instructions to detect, based on the request, an anomaly associated with a host that provides the request; and

the determining that the data stored by the storage system is possibly being targeted by the security threat is further based on the detecting of the anomaly associated with the host.

16. The system of claim 13 , wherein:

the processor is further configured to execute the instructions to determine that the file is of a particular type for which overwrite operations have not been previously detected by the storage system; and

the determining that the data stored by the storage system is possibly being targeted by the security threat is further based on the determining that the file is of the particular type.

17. The system of claim 13 , wherein the processor is further configured to execute the instructions to perform, based on the determining that the data stored by the storage system is possibly being targeted by the security threat, a remedial action with respect to the data stored by the storage system.

18. A non-transitory computer-readable medium storing instructions that, when executed, direct a processor of a computing device to:

detect a request to perform an overwrite operation with respect to a non-header portion of a file stored by a storage system, the non-header portion including bits representative of content represented by the file, the file further including a header that includes bits representative of metadata or other types of data that describe or otherwise provide information about the non-header portion;

determine, based on the detecting the request, that data stored by the storage system is possibly being targeted by a security threat;

determine whether an attribute of the file is associated with files that are typically written in place; and

when the processor determines that the attribute of the file is associated with files that are typically written in place, determine that the request is not associated with the security threat and continue to monitor for additional requests to perform overwrite operations.

19. The method of claim 1 , wherein:

the determining whether the attribute of the file comprises determining that the attribute of the file is not associated with files that are typically written in place; and

the determining that the data stored by the storage system is possibly being targeted by the security threat is further based on the determining that the attribute of the file is not associated with files that are typically written in place.

20. The system of claim 13 , wherein:

the determining whether the attribute of the file comprises determining that the attribute of the file is not associated with files that are typically written in place; and

the determining that the data stored by the storage system is possibly being targeted by the security threat is further based on the determining that the attribute of the file is not associated with files that are typically written in place.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2021
From: KARR, RONALD
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 057346/0008 →
Continuity (4)
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16711060 · Dec 11, 2019
Provisional Application 62939518 · Nov 22, 2019
Related Publication 20210397711A1 · Dec 23, 2021