IP Library Granted Patent US 12,393,492
Granted Patent B2
US 12,393,492 · App. 17/900,661 · Granted Aug 19, 2025

Fortified backup of anomaly detection

Inventors: Jonathan Bell (Wake Forest, NC); Jonathon Mayor (Austin, TX); Nagapramod Mandagere (Los Altos, CA)
Assignee: Cohesity, Inc.
G06F11/1464G06F11/1451G06F11/328G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,393,492
App. No.
17/900,661
Granted
Aug 19, 2025
Kind
B2
Abstract

An indication to perform a backup of data stored in a persistent storage associated with a source system is received. In response to the indication to perform the backup, current execution information at least in part maintained in a volatile memory is captured. The captured current execution information is caused to be stored with backup data from the backup of the data stored in the persistent storage.

Claims (40)

1. A method comprising:

receiving an indication to perform a first backup of data stored in a persistent storage associated with a source system, wherein the source system is running one or more objects and the data comprises object data associated with the one or more objects;

based on the indication to perform the first backup, capturing first current execution information associated with the source system, wherein the first current execution information is indicative of a first execution state of the source system;

causing the captured first current execution information to be stored with first backup data from the first backup of the data stored in the persistent storage;

capturing second current execution information associated with the source system, wherein the second current execution information is indicative of a second execution state of the source system, and wherein the first current execution information and the second current execution information each includes one or more of computer process tables, a list of one or more current running computer processes, a list of one or more scheduled computer processes, or a log of one or more recently executed computer processes;

analyzing the captured first current execution information and the captured second current execution information to determine one or more indications of an exploitation associated with the source system; and

based on the one or more indications of an exploitation associated with the source system, modifying a backup workflow.

2. The method of claim 1 , wherein the first current execution information and the second current execution information each further includes one or more of one or more connections and their corresponding status or network status information.

3. The method of claim 1 , wherein the first current execution information is obtained from a computer process table stored in a volatile memory of the source system.

4. The method of claim 1 , wherein the first current execution information is captured at one or more points in time associated with the first backup of data stored in the persistent storage associated with the source system.

5. The method of claim 4 , wherein the one or more points in time associated with the first backup of data stored in the persistent storage associated with the source system include a point in time after the indication has been received.

6. The method of claim 4 , wherein the one or more points in time associated with the first backup of data stored in the persistent storage associated with the source system include a point in time after initiation of the first backup of data stored in the persistent storage associated with the source system.

7. The method of claim 6 , wherein the one or more points in time associated with the first backup of data stored in the persistent storage associated with the source system include one or more additional points in time after initiation of the first backup of data stored in the persistent storage associated with the source system.

8. The method of claim 4 , wherein the one or more points in time associated with the first backup of data stored in the persistent storage associated with the source system include a point in time after completion of the first backup of data stored in the persistent storage associated with the source system.

9. The method of claim 1 , further comprising initiating the first backup of the data stored in the persistent storage associated with the source system.

10. The method of claim 1 , wherein the second current execution information is associated with at least one of a subsequent full backup or one or more subsequent incremental backups.

11. The method of claim 1 , wherein analyzing the captured first current execution information and the captured second current execution information to determine the one or more indications of the exploitation associated with the source system includes inputting the captured second current execution information to a machine learning model.

12. The method of claim 11 , wherein analyzing the captured first current execution information and the captured second current execution information to determine the one or more indications of the exploitation associated with the source system includes comparing a score outputted by the machine learning model to an exploitation threshold score.

13. The method of claim 12 , wherein analyzing the captured first current execution information and the captured second current execution information to determine the one or more indications of the exploitation associated with the source system includes providing a notification based on a determination that the score outputted by the machine learning model indicates that the source system has been exploited.

14. The method of claim 12 , wherein analyzing the captured first current execution information and the captured second current execution information to determine the one or more indications of the exploitation associated with the source system includes canceling one or more scheduled processes based on a determination that the score outputted by the machine learning model indicates that the source system has been exploited.

15. The method of claim 12 , wherein analyzing the captured first current execution information and the captured second current execution information to determine the one or more indications of the exploitation associated with the source system includes altering a backup workflow for a second backup of data stored in the persistent storage associated with the source system based on a determination that the score outputted by the machine learning model indicates that the source system has been exploited.

16. Non-transitory computer-readable media comprising computer instructions that, when executed by one or more processors, cause the one or more processors to:

receive an indication to perform a first backup of data stored in a persistent storage associated with a source system, wherein the source system is configured to run one or more objects and the data comprises object data associated with the one or more objects;

based on the indication to perform the first backup, capture first current execution information associated with the source system, wherein the first current execution information is indicative of a first execution state of the source system;

cause the captured first current execution information to be stored with first backup data from the first backup of the data stored in the persistent storage;

capture second current execution information associated with the source system, wherein the second current execution information is indicative of a second execution state of the source system, and wherein the first current execution information and the second current execution information each includes one or more of computer process tables, a list of one or more current running computer processes, a list of one or more scheduled computer processes, or a log of one or more recently executed computer processes;

analyze the captured first current execution information and the captured second current execution information to determine one or more indications of an exploitation associated with the source system; and

based on the one or more indications of an exploitation associated with the source system, modify a backup workflow.

17. The non-transitory computer-readable media of claim 16 , wherein the first current execution information and the second current execution information each includes one or more of one or more connections and their corresponding status or network status information.

18. The non-transitory computer-readable media of claim 16 , wherein the first current execution information is obtained from a computer process table stored in a volatile memory of the source system.

19. The non-transitory computer-readable media of claim 16 , wherein the first current execution information is captured at one or more points in time associated with the first backup of data stored in the persistent storage associated with the source system.

20. A system, comprising:

memory storing instructions; and

a processor configured to execute the instructions to:

receive an indication to perform a first backup of data stored in a persistent storage associated with a source system, wherein the source system is configured to run one or more objects and the data comprises object data associated with the one or more objects;

based on the indication to perform the first backup, capture first current execution information associated with the source system, wherein the first current execution information is indicative of a first execution state of the source system;

cause the captured first current execution information to be stored with first backup data from the first backup of the data stored in the persistent storage;

capture second current execution information associated with the source system, wherein the second current execution information is indicative of a second execution state of the source system, and wherein the first current execution information and the second current execution information each includes one or more of computer process tables, a list of one or more current running computer processes, a list of one or more scheduled computer processes, or a log of one or more recently executed computer processes;

analyze the captured first current execution information and the captured second current execution information to determine one or more indications of an exploitation associated with the source system; and

based on the one or more indications of an exploitation associated with the source system, modify a backup workflow.

Assignments (4)
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 10, 2024
From: FIRST-CITIZENS BANK & TRUST COMPANY (AS SUCCESSOR TO SILICON VALLEY BANK)
To: COHESITY, INC.
Reel/Frame 069584/0498 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2023
From: BELL, JONATHAN; MAYOR, JONATHON; MANDAGERE, NAGAPRAMOD
To: COHESITY, INC.
Reel/Frame 063290/0872 →
SECURITY INTEREST Recorded Sep 23, 2022
From: COHESITY, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 061509/0818 →
Continuity (1)
Related Publication 20240070034A1 · Feb 29, 2024
References Cited (21)
US 8447923B2 · Suryanarayanan · 2013 [cited by examiner]
US 9306969B2 · Dagon et al. · 2016 [cited by applicant]
US 9785365B1 · Shallal · 2017 [cited by examiner]
US 10254996B1 · Jain · 2019 [cited by examiner]
US 10289845B2 · Charters et al. · 2019 [cited by applicant]
US 11349855B1 · Amit · 2022 [cited by examiner]
US 20200159624A1 · Malkov · 2020 [cited by examiner]
US 20210044603A1 · Annen · 2021 [cited by examiner]
US 20210044604A1 · Annen · 2021 [cited by examiner]
US 20210232685A1 · Kraemer · 2021 [cited by examiner]
US 20220083657A1 · Karr · 2022 [cited by examiner]
US 20220245245A1 · Annen · 2022 [cited by examiner]
US 20220292196A1 · Bhagi · 2022 [cited by examiner]
US 20220374519A1 · Botelho · 2022 [cited by examiner]
US 20230289265A1 · Trachy · 2023 [cited by examiner]
KR19990004788A How to check the backup data written to memory, 1997, South Korea (Year: 1997). [cited by examiner]
CYNET, “4 Malware Detection Techniques and Their Use in EPP and EDR”, Jul. 9, 2022, 8 pp., URL: https://www.cynet.com/malware/4-malware-detection-techniques-and-their-use-in-epp-and-edr/. [cited by applicant]
Extended Search Report from counterpart European Application No. 23194288.9 dated Nov. 6, 2023, 10 pp. [cited by applicant]
Response to Extended Search Report dated Nov. 6, 2023, from counterpart European Application No. 23194288.9 filed Sep. 5, 2024, 16 pp. [cited by applicant]
Communication pursuant to Article 94(3) EPC from counterpart European Application No. 23194288.9 dated Dec. 2, 2024, 7 pp. [cited by applicant]
Notice of Intent to Grant and Text Intended to Grant from counterpart European Application No. 23194288.9 dated Apr. 16, 2025, 49 pp. [cited by applicant]