IP Library Granted Patent US 12,153,670
Granted Patent B2
US 12,153,670 · App. 17/541,870 · Granted Nov 26, 2024

Host-driven threat detection-based protection of storage elements within a storage system

Inventors: Michael Anthony Richardson (Kansas City, MO); Ronald Karr (Palo Alto, CA)
Assignee: Pure Storage, Inc.
G06F21/554G06F21/78
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,153,670
App. No.
17/541,870
Filed
Dec 3, 2021
Granted
Nov 26, 2024
Kind
B2
Art Unit
2499
USPC
726/23
Abstract

An illustrative method includes a data protection controller receiving, from a security threat monitoring application communicatively coupled to the data protection controller by way of a network, event data triggered by a detection by the security threat monitoring application of a security threat against a host attached to a storage element of a storage system remote from the host; and performing, based on the event data, a data protection operation with respect to the storage element.

Claims (39)

1. A method comprising:

receiving, by a data protection controller from a security threat monitoring application communicatively coupled to the data protection controller by way of a network, event data triggered by a detection by the security threat monitoring application of a security threat against a host attached to a storage element of a storage system remote from the host;

authenticating, by the data protection controller, the event data using an authentication protocol;

analyzing, by the data protection controller, the event data, the analyzing including determining a threat classification associated with the event data, the threat classification representing a grouping of common event triggers based on severity and potential threat;

identifying, by the data protection controller based on the analyzing, a data protection policy; and

performing, by the data protection controller based on the event data and the data protection policy, a data protection operation with respect to the storage element, the data protection operation comprising:

disconnecting the host from the storage element, and

directing the storage system to generate a recovery dataset for the storage element.

2. The method of claim 1 , wherein the security threat monitoring application is executed by the host.

3. The method of claim 1 , wherein the security threat monitoring application is executed by a remote monitoring system communicatively coupled to the host and the storage system by way of one or more networks.

4. The method of claim 1 , wherein the data protection controller is included in the storage system.

5. The method of claim 1 , wherein the data protection controller is included in a computing system remote from both the storage system and the host.

6. The method of claim 1 , wherein the receiving the data event comprises receiving an application programming interface (API) call initiated by the security threat monitoring application.

7. The method of claim 1 , wherein the performing the data protection operation further comprises directing the storage system to generate:

one or more recovery datasets for one or more storage elements associated with one or more hosts included in a same network domain as the host.

8. The method of claim 7 , further comprising preventing at least one of the recovery dataset or the one or more recovery datasets from being deleted or modified without permission provided by one or more authorized users.

9. The method of claim 1 , wherein the performing the data protection operation further comprises putting the storage element into a safe mode in which one or more verification operations are required to perform one or more operations with respect to the storage element.

10. The method of claim 1 , further comprising abstaining, by the data protection controller, from performing the data protection operation with respect to one or more storage elements not associated with the host and included in the storage system.

11. The method of claim 1 , wherein the performing the data protection operation further comprises providing an alert.

12. The method of claim 1 , wherein the storage element comprises a volume.

13. The method of claim 1 , wherein one or more of the receiving or the performing is performed using a machine learning model.

14. A system comprising:

a memory storing instructions; and

one or more processors communicatively coupled to the memory and configured to execute the instructions to perform a process comprising:

receiving, from a security threat monitoring application, event data triggered by a detection by the security threat monitoring application of a security threat against a host attached to a storage element of a storage system remote from the host;

authenticating the event data using an authentication protocol;

analyzing the event data, the analyzing including determining a threat classification associated with the event data, the threat classification representing a grouping of common event triggers based on severity and potential threat;

identifying, based on the analyzing, a data protection policy; and

performing, based on the event data and the data protection policy, a data protection operation with respect to the storage element, the data protection operation comprising:

disconnecting the host from the storage element, and

directing the storage system to generate a recovery dataset for the storage element.

15. A non-transitory computer-readable medium storing instructions that, when executed, direct a processor of a computing device to perform a process comprising:

receiving, from a security threat monitoring application, event data triggered by a detection by the security threat monitoring application of a security threat against a host attached to a storage element of a storage system remote from the host;

authenticating the event data using an authentication protocol;

analyzing the event data, the analyzing including determining a threat classification associated with the event data, the threat classification representing a grouping of common event triggers based on severity and potential threat;

identifying, based on the analyzing, a data protection policy; and

performing, based on the event data and the data protection policy, a data protection operation with respect to the storage element, the data protection operation comprising:

disconnecting the host from the storage element, and

directing the storage system to generate a recovery dataset for the storage element.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2021
From: RICHARDSON, MICHAEL ANTHONY; KARR, RONALD
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 058283/0627 →
Continuity (4)
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16711060 · Dec 11, 2019
Provisional Application 62939518 · Nov 22, 2019
Related Publication 20220092180A1 · Mar 24, 2022
Cited By (1)
US 12,556,555