IP Library Granted Patent US 11,977,636
Granted Patent B2
US 11,977,636 · App. 17/474,907 · Granted May 7, 2024

Storage transaction log

Inventor: Tomohiro Kawaguchi (Santa Clara, CA)
Assignee: HITACHI, LTD.
G06F21/568G06F3/0611G06F3/0619G06F3/064G06F3/0659G06F3/0673G06F21/554G06F21/78
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,977,636
App. No.
17/474,907
Granted
May 7, 2024
Kind
B2
Abstract

Example implementations described herein provide systems and methods for detecting damage to data by malware and involve generating log information at a storage device based on a write input/output (I/O) provided to the storage device by one or more servers, the log information comprising time information for storing the write I/O to the storage device, logical block information for the write I/O, and a compression ratio associated with storing the write I/O to the storage device; and, for a request by a management server to provide the log information for a specified time range for the storage device, returning, from the storage device, the logical block information and the compression ratio associated with the time information within the specified time range.

Claims (24)

1. A method for detecting damage to data by malware, the method comprising:

generating log information at a storage device based on a write input/output (I/O) provided to the storage device by one or more servers, the log information comprising time information for storing the write I/O to the storage device, logical block information for the write I/O, and a compression ratio associated with storing the write I/O to the storage device; and

for a request by a management server to provide the log information for a specified time range for the storage device, returning, from the storage device, the logical block information and the compression ratio associated with the time information within the specified time range.

2. The method of claim 1 , wherein the management server executes malware detection software to detect malware from the returned logical block information and compression ratio.

3. The method of claim 1 , wherein the management server sends the request to the storage device cyclically based on a schedule provided by a user.

4. The method of claim 1 , wherein the time information is a marker inserted periodically into the log information.

5. The method of claim 1 , wherein the time information is from metadata associated with the logical block information.

6. A system for detecting damage to data by malware, the system comprising:

a storage device configured to generate log information at a storage device based on a write input/output (I/O) provided to the storage device by one or more servers, the log information comprising time information for storing the write I/O to the storage device, logical block information for the write I/O, and a compression ratio associated with storing the write I/O to the storage device; and

a management server configured to request the storage device provide the log information for a specified time range,

the storage device is further configured to, for the request by the management server, provide the log information, return the logical block information and the compression ratio associated with the time information within the specified time range.

7. The system of claim 6 , wherein the management server executes malware detection software to detect malware from the returned logical block information and compression ratio.

8. The system of claim 6 , wherein the management server sends the request to the storage device cyclically based on a schedule provided by a user.

9. The system of claim 6 , wherein the time information is a marker inserted periodically into the log information.

10. The system of claim 6 , wherein the time information is from metadata associated with the logical block information.

11. A storage device for detecting damage to data by malware, the storage device comprising:

one or more memory configured to store instructions; and

one or more processors configured to execute the instructions stored in the memory to:

generate log information at the storage device based on a write input/output (I/O) provided to the storage device by one or more servers, the log information comprising time information for storing the write I/O to the storage device, logical block information for the write I/O, and a compression ratio associated with storing the write I/O to the storage device; and

for a request received from a management server to provide the log information for a specified time range, return, to the management server, the logical block information and the compression ratio associated with the time information within the specified time range.

12. The storage device of claim 11 , wherein the management server executes malware detection software to detect malware from the returned logical block information and compression ratio.

13. The storage device of claim 11 , wherein the management server sends the request to the storage device cyclically based on a schedule provided by a user.

14. The storage device of claim 11 , wherein the time information is a marker inserted periodically into the log information.

15. The storage device of claim 11 , wherein the time information is from metadata associated with the logical block information.

Assignments (2)
DE-MERGER EFFECTIVE APRIL 1, 2024 Recorded Oct 1, 2024
From: HITACHI, LTD.
To: HITACHI VANTARA, LTD.
Reel/Frame 069083/0345 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2021
From: KAWAGUCHI, TOMOHIRO
To: HITACHI, LTD.
Reel/Frame 057480/0397 →
Continuity (1)
Related Publication 20230079432A1 · Mar 16, 2023