IP Library › Granted Patent US 12,596,792
Granted Patent B2
US 12,596,792 · App. 17/700,958 · Granted Apr 7, 2026

Data encryption detection

Inventors: Alex Veprinsky (San Jose, CA); Charles F. Clark (Roseville, CA); John Blumenthal (San Jose, CA); Ayman Abouelwafa (Roseville, CA)
Assignee: Hewlett Packard Enterprise Development LP
G06F21/552G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,792
App. No.
17/700,958
Granted
Apr 7, 2026
Kind
B2
Abstract

In some examples, a system applies an inline detection of a write of data in a storage, the inline detection to detect potential data encryption of the data. In response to an indication of the potential data encryption, the system creates a first object that represents a first version of the data, and applies a further analysis to determine whether the potential data encryption constitutes unauthorized data encryption, the further analysis based on the first object and a second object that represents a second version of the data that is prior to the first version of the data.

Claims (46)

1 . A non-transitory machine-readable storage medium comprising instructions that upon execution cause a system to:

apply an inline detection of a write of replicated data to a journal that logs writes in a storage system, the inline detection to detect potential data encryption of the replicated data, wherein the replicated data is a copy of data of a write request;

in response to an indication of the potential data encryption, create a first object that represents a first version of the data of the write request; and

apply a further analysis to determine whether the potential data encryption constitutes unauthorized data encryption, the further analysis comprising:

calculating a first relative entropy representing a first divergence between the first object and a second object that represents a second version of the data of the write request, the second version created prior to the first version, wherein the first divergence represents a statistical distance between a probability distribution created for the first object and a probability distribution created for the second object;

determining a write input/output (I/O) pattern from write metadata for the writes, the write I/O pattern comprising one or more of a spatial I/O pattern based on locations of the writes in storage volumes, or a temporal pattern based on timestamps of the writes;

calculating a second relative entropy representing a second divergence between the determined write I/O pattern and a baseline write I/O pattern, wherein the second divergence represents a statistical distance between a probability distribution created for the determined write I/O pattern and a probability distribution created for the baseline write I/O pattern; and

indicate that the potential data encryption constitutes the unauthorized data encryption responsive to the first relative entropy exceeding a first threshold and the second relative entropy exceeding a second threshold; and

initiate a remediation action to counter the unauthorized data encryption.

2 . The non-transitory machine-readable storage medium of claim 1 , wherein the creating of the first object comprises creating a first snapshot, and the second object comprises a second snapshot created prior to the first snapshot.

3 . The non-transitory machine-readable storage medium of claim 1 , wherein the write of the replicated data to the journal is over a data path that is separate from a data path for the writes between one or more requesters and the storage system.

4 . The non-transitory machine-readable storage medium of claim 3 , wherein the journal comprises the replicated data including a data checkpoint at a first timepoint and further replicated data including a data checkpoint at a second timepoint.

5 . The non-transitory machine-readable storage medium of claim 1 , wherein the inline detection is based on a calculation of an absolute entropy in the replicated data.

6 . The non-transitory machine-readable storage medium of claim 1 , wherein the first object and the second object are in the journal.

7 . The non-transitory machine-readable storage medium of claim 1 , wherein the probability distribution created for the first object comprises probabilities of occurrence of respective values in the first object, and the probability distribution created for the second object comprises probabilities of occurrence of respective values in the second object.

8 . The non-transitory machine-readable storage medium of claim 1 , wherein the further analysis is further based on a calculation of hashes of the first object and the second object.

9 . The non-transitory machine-readable storage medium of claim 1 , wherein the further analysis is further based on machine learning that produces an indication of the unauthorized data encryption based on the first object and the second object.

10 . The non-transitory machine-readable storage medium of claim 1 , wherein the write metadata is contained in the journal, and the write metadata comprises addresses of locations in the storage volumes to which the writes are targeted, and the timestamps of the writes.

11 . The non-transitory machine-readable storage medium of claim 10 , wherein the baseline write I/O pattern is derived from historical write operations.

12 . The non-transitory machine-readable storage medium of claim 1 , wherein the further analysis further comprises applying machine learning to the determined write I/O pattern to determine whether the potential data encryption constitutes the unauthorized data encryption.

13 . The non-transitory machine-readable storage medium of claim 1 , wherein the remediation action is selected from among shutting down the storage system or disabling network communication with the storage system.

14 . A system comprising:

a hardware processor; and

a non-transitory storage medium storing instructions executable on the hardware processor to:

apply, using an inline detector, an inline detection of replicated data in a data path to a journal that logs writes to a storage, the inline detection to detect potential data encryption, wherein the replicated data is a copy of data of a write request;

send, from the inline detector to an object analyzer, an indication of the potential data encryption; and

in response to the indication of the potential data encryption, apply, using the object analyzer, a further analysis to determine whether the potential data encryption constitutes unauthorized data encryption, the further analysis comprising:

calculating a first relative entropy representing a first divergence between a first object and a second object, the first object representing a first version of the data of the write request created after occurrence of the potential data encryption, and the second object representing a second version of the data of the write request, the second version created prior to the occurrence of the potential data encryption, wherein the first divergence represents a statistical distance between a probability distribution created for the first object and a probability distribution created for the second object,

determining a write input/output (I/O) pattern from write metadata for the writes, the write I/O pattern comprising one or more of a spatial I/O pattern based on locations of the writes in storage volumes, or a temporal pattern based on timestamps of the writes,

calculating a second relative entropy representing a second divergence between the determined write I/O pattern and a baseline write I/O pattern, wherein the second divergence represents a statistical distance between a probability distribution created for the determined write I/O pattern and a probability distribution created for the baseline write I/O pattern, and

indicating that the potential data encryption constitutes the unauthorized data encryption responsive to the first relative entropy exceeding a first threshold and the second relative entropy exceeding a second threshold; and

initiate a remediation action to counter the unauthorized data encryption.

15 . The system of claim 14 , wherein the write metadata is contained in the journal, and the write metadata comprises addresses of locations in the storage volumes to which the writes are targeted, and the timestamps of the writes.

16 . The system of claim 14 , wherein the further analysis by the object analyzer further comprises applying machine learning to the determined write I/O pattern to determine whether the potential data encryption constitutes the unauthorized data encryption.

17 . The system of claim 14 , wherein the inline detector is to calculate a measure of absolute entropy of the replicated data to detect the potential data encryption, and wherein the probability distribution created for the first object comprises probabilities of occurrence of respective values in the first object, and the probability distribution created for the second object comprises probabilities of occurrence of respective values in the second object.

18 . A method executed by a system comprising a hardware processor, the method comprising:

applying, using an inline detector, an inline detection of replicated data in a first data path to a journal that logs writes to a storage, the inline detection to detect potential data encryption, wherein the replicated data is a copy of data of a write request being written over a separate second data path to the storage;

sending, from the inline detector to an object analyzer, an indication of the potential data encryption; and

based on the indication of the potential data encryption, applying, using the object analyzer, a further analysis to determine whether the potential data encryption constitutes unauthorized data encryption, the further analysis comprising:

calculating a first relative entropy representing a first divergence between a first object and a second object, the first object representing a first version of the data of the write request created after occurrence of the potential data encryption, and the second object representing a second version of the data of the write request, the second version created prior to the occurrence of the potential data encryption, wherein the first divergence represents a statistical distance between a probability distribution created for the first object and a probability distribution created for the second object,

determining a write input/output (I/O) pattern from write metadata for the writes, the write I/O pattern comprising one or more of a spatial I/O pattern based on locations of the writes in storage volumes, or a temporal pattern based on timestamps of the writes,

calculating a second relative entropy representing a second divergence between the determined write I/O pattern and a baseline write I/O pattern, wherein the second divergence represents a statistical distance between a probability distribution created for the determined write I/O pattern and a probability distribution created for the baseline write I/O pattern, and

indicating that the potential data encryption constitutes the unauthorized data encryption responsive to the first relative entropy exceeding a first threshold and the second relative entropy exceeding a second threshold; and

initiating a remediation action to counter the unauthorized data encryption.

19 . The method of claim 18 , wherein the further analysis further comprises applying machine learning to the determined write I/O pattern to determine whether the potential data encryption constitutes the unauthorized data encryption.

20 . The method of claim 18 , wherein the write metadata is contained in the journal, and the write metadata comprises addresses of locations in the storage volumes to which the writes are targeted, and the timestamps of the writes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2022
From: ALEX VEPRINSKY; CLARK, CHARLES F.; BLUMENTHAL, JOHN; ABOUELWAFA, AYMAN
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 059340/0744 →
Continuity (1)
Related Publication 20230306108A1 · Sep 28, 2023
References Cited (56)
US 8332687B1 · Natanzon · 2012 [cited by examiner]
US 8688620B2 · Viswanathan · 2014 [cited by examiner]
US 8832037B2 · Boldo et al. · 2014 [cited by applicant]
US 9251009B2 · Ben-Or et al. · 2016 [cited by applicant]
US 9256498B1 · Leibowitz et al. · 2016 [cited by applicant]
US 9268648B1 · Barash et al. · 2016 [cited by applicant]
US 9317686B1 · Ye et al. · 2016 [cited by applicant]
US 9710294B2 · Kedem et al. · 2017 [cited by applicant]
US 9817729B2 · Kedem et al. · 2017 [cited by applicant]
US 9892005B2 · Kedem et al. · 2018 [cited by applicant]
US 10009360B1 · Todd et al. · 2018 [cited by applicant]
US 10229269B1 · Patton · 2019 [cited by examiner]
US 10303877B2 · Roguine et al. · 2019 [cited by applicant]
US 10346258B2 · Sella et al. · 2019 [cited by applicant]
US 10621346B1 · Singh · 2020 [cited by examiner]
US 10735448B2 · Kesin · 2020 [cited by examiner]
US 11055411B2 · Strogov · 2021 [cited by examiner]
US 11144638B1 · Golden · 2021 [cited by examiner]
US 11256529B2 · Kedem et al. · 2022 [cited by applicant]
US 11349855B1 · Amit · 2022 [cited by examiner]
US 11520907B1 · Borowiec · 2022 [cited by examiner]
US 11921589B2 · Shemer · 2024 [cited by examiner]
US 20120023489A1 · Motta · 2012 [cited by examiner]
US 20170083540A1 · Mamluk et al. · 2017 [cited by applicant]
US 20170223031A1 · Gu et al. · 2017 [cited by applicant]
US 20170366563A1 · Volfman et al. · 2017 [cited by applicant]
US 20180034835A1 · Iwanir et al. · 2018 [cited by applicant]
US 20180248896A1 · Challita et al. · 2018 [cited by applicant]
US 20190005235A1 · Klonowski · 2019 [cited by examiner]
US 20190108340A1 · Bedhapudi · 2019 [cited by examiner]
US 20190130097A1 · Berler et al. · 2019 [cited by examiner]
US 20200250522A1 · Meiri · 2020 [cited by examiner]
US 20200319979A1 · Kulaga · 2020 [cited by examiner]
US 20200342104A1 · Palisse et al. · 2020 [cited by applicant]
US 20210044604A1 · Annen · 2021 [cited by examiner]
US 20210103490A1 · LeCrone · 2021 [cited by examiner]
US 20210203690A1 · Nunes · 2021 [cited by examiner]
US 20210240828A1 · Gaurav · 2021 [cited by examiner]
US 20210334374A1 · Vasudeva · 2021 [cited by examiner]
US 20210336968A1 · Bender · 2021 [cited by examiner]
US 20210409425A1 · Varshney · 2021 [cited by examiner]
US 20220222041A1 · Zhang · 2022 [cited by examiner]
US 20230229675A1 · Hautyunyan · 2023 [cited by examiner]
US 20230273999A1 · Nazari · 2023 [cited by examiner]
WO 2021016270A1 · 2021 [cited by applicant]
Tang, F., Ma, B., Li, J., Zhang, F., Su, J., & Ma, J. (2020). RansomSpector: An introspection-based approach to detect crypto ransomware. Computers & Security, 97, 101997 (Year: 2020). [cited by examiner]
Cosma Shalizi, “Shannon Entropy and Kullback-Leibler Divergence”, Advanced Probability II, Chapter 28, 2006, (course lecture notes), 8 pages, <https://www.stat.cmu.edu/˜cshalizi/754/2006/notes/lecture-28.pdf>. [cited by applicant]
Kharraz et al., “Unveil: A Large-Scale, Automated Approach to Detecting Ransomware”, 25th {USENIX} Security Symposium ({USENIX} Security 16), 2016, 16 pages, <https://www.ftc.gov/es/system/files/documents/public_comment… [cited by applicant]
Rubrik, “Accelerate Ransomware Recovery”, available online at <https://www.rubrik.com/solutions/ransomware-recovery>, Aug. 23, 2021, 15 pages. [cited by applicant]
Rubrik, “Recover Faster From Ransomware”, available online at <available online at <https://web.archive.org/web/20210604201541/https://www.rubrik.com/products/polaris-overview/polaris-radar>, Jun. 4, 2021, 8 pages. [cited by applicant]
SDMagazine, “Ransomware Protection Market worth 17.36 Billion USD by 2021”, available online at <<https://sd-magazine.com/securite-numerique-cybersecurite/ransomware-protection-market-worth-17-36-billion-usd-by-2021>, F… [cited by applicant]
Stonefly, “StoneFly Ransomware Protection Solutions,”, available online at <https://www.rubrik.com/solutions/ransomware-recovery>, Aug. 23, 2021, 8 pages. [cited by applicant]
Wu et al., “Local Shannon entropy measure with statistical tests for image randomness”, Information Sciences 222, 2013, 20 pages. [cited by applicant]
Tang et al., “RansomSpector: An introspection-based approach to detect crypto ransomware”, 2020, Computers & Security, vol. 97, 2020, pp. 1-14. [cited by applicant]
Anomaly Detection, “Proactively Detect and Investigate Ransomware”, available online at <http://web.archive.org/web/20250613124532/https://www.rubrik.com/products/anomaly-detection>, Jun. 13, 2025, 5 pages. [cited by applicant]
Sam Curry, “Report: Ransomware Attacks and the True Cost to Business”, Jun. 16, 2021, available online at <http://web.archive.org/web/20220415192852/https://www.cybereason.com/blog/research/report-ransomware-attacks-and… [cited by applicant]