IP Library Granted Patent US 12,050,683
Granted Patent B2
US 12,050,683 · App. 17/506,501 · Granted Jul 30, 2024

Selective control of a data synchronization setting of a storage system based on a possible ransomware attack against the storage system

Inventors: Arun Rokade (Fremont, CA); Ronald Karr (Palo Alto, CA)
Assignee: Pure Storage, Inc.
G06F21/554G06F21/52G06F21/566G06F21/568
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,050,683
App. No.
17/506,501
Filed
Oct 20, 2021
Granted
Jul 30, 2024
Kind
B2
Art Unit
2499
USPC
726/23
Abstract

An illustrative method includes determining, by a data protection system, that a dataset stored by a first storage system is possibly being targeted by a security threat while a data synchronization setting for the first storage system is enabled such that the dataset stored by the first storage system is synchronously replicated to a second storage system; and disabling, by the data protection system based on the determining that the dataset stored by the first storage system is possibly being targeted by the security threat, the data synchronization setting to prevent the dataset stored by the first storage system from being synchronously replicated to the second storage system.

Claims (46)

1. A method comprising:

determining, by a data protection system, that a dataset stored by a first storage system is possibly being targeted by a security threat while a data synchronization setting for the first storage system is enabled such that the dataset stored by the first storage system is synchronously replicated to a second storage system;

detecting, by the data protection system, a request to perform a write operation with respect to the first storage system while the data synchronization setting is enabled;

directing, by the data protection system, the first storage system to abstain from performing the write operation for a predetermined time period;

determining, by the data protection system prior to completion of the predetermined time period, that the request is associated with the security threat;

preventing, by the data protection system, the first storage system from performing the write operation; and

disabling, by the data protection system based on the determining that the dataset stored by the first storage system is possibly being targeted by the security threat, the data synchronization setting to prevent the dataset stored by the first storage system from being synchronously replicated to the second storage system.

2. The method of claim 1 , further comprising performing, by the data protection system based on the determining that the dataset stored by the first storage system is possibly being targeted by the security threat, one or more additional remedial actions with respect to the dataset stored by the first storage system.

3. The method of claim 2 , wherein the one or more additional remedial actions comprise one or more of:

directing the first storage system to generate a first recovery dataset for the dataset stored by the first storage system; or

directing the second storage system to generate a second recovery dataset for dataset stored by the second storage system.

4. The method of claim 3 , further comprising using one or more of the first recovery dataset or the second recovery dataset to perform a data recovery operation with respect to the dataset stored by the first storage system.

5. The method of claim 1 , further comprising using data stored by the second storage system to perform a data recovery operation with respect to the dataset stored by the first storage system.

6. The method of claim 1 , further comprising:

determining, by the data protection system, that the dataset stored by the first storage system is no longer possibly being targeted by the security threat; and

enabling, by the data protection system based on the determining that the dataset stored by the first storage system is no longer possibly being targeted by the security threat, the data synchronization setting.

7. The method of claim 1 , wherein the determining that the dataset stored by the first storage system is possibly being targeted by a security threat is performed using a machine learning model.

8. A system comprising:

a memory storing instructions; and

a processor communicatively coupled to the memory and configured to execute the instructions to:

determine that a dataset stored by a first storage system is possibly being targeted by a security threat while a data synchronization setting for the first storage system is enabled such that the dataset stored by the first storage system is synchronously replicated to a second storage system;

detect a request to perform a write operation with respect to the first storage system while the data synchronization setting is enabled;

direct the first storage system to abstain from performing the write operation for a predetermined time period;

determine, prior to completion of the predetermined time period, that the request is associated with the security threat;

prevent the first storage system from performing the write operation; and

disable, based on the determining that the dataset stored by the first storage system is possibly being targeted by the security threat, the data synchronization setting to prevent the dataset stored by the first storage system from being synchronously replicated to the second storage system.

9. The system of claim 8 , wherein the processor is further configured to execute the instructions to perform, based on the determining that the dataset stored by the first storage system is possibly being targeted by the security threat, one or more additional remedial actions with respect to the dataset stored by the first storage system.

10. The system of claim 9 , wherein the one or more additional remedial actions comprise one or more of:

directing the first storage system to generate a first recovery dataset for the dataset stored by the first storage system; or

directing the second storage system to generate a second recovery dataset for dataset stored by the second storage system.

11. The system of claim 10 , wherein the processor is further configured to execute the instructions to use one or more of the first recovery dataset or the second recovery dataset to perform a data recovery operation with respect to the dataset stored by the first storage system.

12. The system of claim 8 , wherein the processor is further configured to execute the instructions to use data stored by the second storage system to perform a data recovery operation with respect to the dataset stored by the first storage system.

13. The system of claim 8 , wherein the processor is further configured to execute the instructions to:

determine that the dataset stored by the first storage system is no longer possibly being targeted by the security threat; and

enable, based on the determining that the dataset stored by the first storage system is no longer possibly being targeted by the security threat, the data synchronization setting.

14. A non-transitory computer-readable medium storing instructions that, when executed, direct a processor of a computing device to:

determine that a dataset stored by a first storage system is possibly being targeted by a security threat while a data synchronization setting for the first storage system is enabled such that the dataset stored by the first storage system is synchronously replicated to a second storage system;

detect a request to perform a write operation with respect to the first storage system while the data synchronization setting is enabled;

direct the first storage system to abstain from performing the write operation for a predetermined time period;

determine, prior to completion of the predetermined time period, that the request is associated with the security threat;

prevent the first storage system from performing the write operation; and

disable, based on the determining that the dataset stored by the first storage system is possibly being targeted by the security threat, the data synchronization setting to prevent the dataset stored by the first storage system from being synchronously replicated to the second storage system.

15. The non-transitory computer-readable medium of claim 14 , wherein the instructions further direct the processor to perform, based on the determining that the dataset stored by the first storage system is possibly being targeted by the security threat, one or more additional remedial actions with respect to the dataset stored by the first storage system.

16. The non-transitory computer-readable medium of claim 15 , wherein the one or more additional remedial actions comprise one or more of:

directing the first storage system to generate a first recovery dataset for the dataset stored by the first storage system; or

directing the second storage system to generate a second recovery dataset for dataset stored by the second storage system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2021
From: ROKADE, ARUN; KARR, RONALD
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 057854/0928 →
Continuity (4)
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16711060 · Dec 11, 2019
Provisional Application 62939518 · Nov 22, 2019
Related Publication 20220050898A1 · Feb 17, 2022
Cited By (1)
US 12,645,637