IP Library Granted Patent US 11,841,953
Granted Patent B2
US 11,841,953 · App. 17/573,483 · Granted Dec 12, 2023

Scanning a backup for vulnerabilities

Inventors: Nagapramod Mandagere (Mountain View, CA); Karandeep Singh Chawla (Santa Clara, CA); Virupaksha Kanjilal (Baltimore, MD); Nilesh Pathak (Sunnyvale, CA)
Assignee: Cohesity, Inc.
G06F21/577G06F11/1446G06F2201/84G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,841,953
App. No.
17/573,483
Granted
Dec 12, 2023
Kind
B2
Abstract

A plurality of scanned backup snapshots are generated. A backup snapshot among a plurality of backup snapshots is selected. At least a portion of the selected backup snapshot is restored in a temporary environment to create a restored instance of at least the portion of the selected backup snapshot. A vulnerability scan of the restored instance of at least the portion of the selected backup snapshot is performed. One or more vulnerabilities of the scanned portion of the selected backup snapshot are tracked. A request associated with identifying a scanned backup snapshot to restore from the plurality of scanned backup snapshots is received. In response to the request, at least a predetermined identification of the one or more vulnerabilities of the selected backup snapshot is provided.

Claims (38)

1. A method, comprising:

assigning a corresponding scanning score to each of a plurality of backup snapshots stored by a storage system;

in response to a determination that a scanning score associated with a particular backup snapshot of the plurality of backup snapshots is greater than or equal to a scanning score threshold, scanning the particular backup snapshot including by:

restoring in a temporary environment at least a portion of the particular backup snapshot to create a restored instance of at least the portion of the particular backup snapshot; and

performing a vulnerability scan of the restored instance of at least the portion of the particular backup snapshot;

determining a recovery time to restore at least the portion of the particular backup snapshot to a restore system, wherein the determined recovery time to restore at least the portion of the particular backup to the restore system includes a first amount of time for providing data corresponding to at least the portion of the particular backup snapshot from the storage system to the restore system and a second amount of time for applying one or more remedies to the provided data corresponding to at least the portion of the particular backup snapshot; and

tracking one or more corresponding vulnerabilities of at least the portion of the particular backup snapshot.

2. The method of claim 1 , wherein the scanning score is based on at least one of a snapshot distance between the particular backup snapshot and a latest backup snapshot, a snapshot distance between the particular backup snapshot and a previous scan, a snapshot distance between the particular backup snapshot and a previous scan that included one or more critical vulnerabilities, and/or an amount of change associated with the particular backup snapshot.

3. The method of claim 1 , wherein scanning the particular backup snapshot further includes discovering the one or more corresponding vulnerabilities of at least the portion of the particular backup snapshot.

4. The method of claim 1 , wherein scanning the particular backup snapshot further includes assigning a corresponding vulnerability score to each of the one or more corresponding vulnerabilities of at least the portion of the particular backup snapshot.

5. The method of claim 1 , further comprising ranking a plurality of scanned backup snapshots based on the one or more corresponding vulnerabilities associated with each of the plurality of scanned backup snapshots.

6. The method of claim 1 , further comprising receiving a request to identify a scanned backup snapshot to restore to a restore environment.

7. The method of claim 6 , further comprising providing at least a predetermined identification of the one or more corresponding vulnerabilities of at least the portion of the particular backup snapshot.

8. The method of claim 1 , wherein determining the recovery time to restore at least the portion of the particular backup snapshot to a restore system comprises filtering the one or more corresponding vulnerabilities based on a security posture of a restore environment.

9. The method of claim 8 , wherein determining the recovery time to restore at least the portion of the particular backup snapshot comprises generating an ordering of one or more remedies to apply to the one or more filtered vulnerabilities.

10. The method of claim 9 , wherein determining the recovery time to restore at least the portion of the particular backup snapshot to the restore system comprises determining a roll forward time to provide data of the at least the portion of the particular backup snapshot.

11. The method of claim 9 , wherein the recovery time to restore at least the portion of the particular backup snapshot to the restore system is determined based on the determined roll forward time to provide data of at least the portion of the particular backup snapshot and the second amount of time to apply the one or more ordered remedies.

12. The method of claim 1 , further comprising receiving a request to restore a first portion of the plurality of backup snapshots.

13. The method of claim 12 , further comprising providing data associated with the first portion of the plurality of backup snapshots.

14. The method of claim 1 , wherein the at least the portion of the particular backup snapshot includes some of the data associated with the particular backup snapshot.

15. The method of claim 1 , wherein the at least the portion of the particular backup snapshot includes all of the data associated with the particular backup snapshot.

16. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

assigning a corresponding scanning score to each of a plurality of backup snapshots stored by a storage system;

in response to a determination that a scanning score associated with a particular backup snapshot of the plurality of backup snapshots is greater than or equal to a scanning score threshold, scanning the particular backup snapshot including by:

restoring in a temporary environment at least a portion of the particular backup snapshot to create a restored instance of at least the portion of the particular backup snapshot; and

performing a vulnerability scan of the restored instance of at least the portion of the particular backup snapshot;

determining a recovery time to restore at least the portion of the particular backup snapshot to a restore system, wherein the determined recovery time to restore at least the portion of the particular backup to the restore system includes a first amount of time for providing data corresponding to at least the portion of the particular backup snapshot from the storage system to the restore system and a second amount of time for applying one or more remedies to the provided data corresponding to at least the portion of the particular backup snapshot; and

tracking one or more corresponding vulnerabilities of at least the portion of the particular backup snapshot.

17. The computer program product of claim 16 , scanning the particular backup snapshot further includes discovering the one or more corresponding vulnerabilities of at least the portion of the particular backup snapshot.

18. A system, comprising:

a processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions which when executed cause the processor to:

assign a corresponding scanning score to each of a plurality of backup snapshots stored by a storage system;

in response to a determination that a scanning score associated with a particular backup snapshot of the plurality of backup snapshots is greater than or equal to a scanning score threshold, scan the particular backup snapshot including by:

restoring in a temporary environment at least a portion of the particular backup snapshot to create a restored instance of at least the portion of the particular backup snapshot; and,

performing a vulnerability scan of the restored instance of at least the portion of the particular backup snapshot;

determine a recovery time to restore at least the portion of the particular backup snapshot to a restore system, wherein the determined recovery time to restore at least the portion of the particular backup to the restore system includes a first amount of time for providing data associated with at least the portion of the particular backup snapshot from the storage system to the restore system and a second amount of time for applying one or more remedies to the provided data corresponding to at least the portion of the particular backup snapshot; and

track one or more corresponding vulnerabilities of at least the portion of the particular backup snapshot.

Assignments (4)
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 10, 2024
From: FIRST-CITIZENS BANK & TRUST COMPANY (AS SUCCESSOR TO SILICON VALLEY BANK)
To: COHESITY, INC.
Reel/Frame 069584/0498 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
SECURITY INTEREST Recorded Sep 23, 2022
From: COHESITY, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 061509/0818 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2022
From: MANDAGERE, NAGAPRAMOD; CHAWLA, KARANDEEP SINGH; KANJILAL, VIRUPAKSHA; PATHAK, NILESH
To: COHESITY, INC.
Reel/Frame 058942/0865 →
Continuity (2)
Continuation 16660521 · Oct 22, 2019
Related Publication 20220156384A1 · May 19, 2022
Cited By (1)
US 12,711,239