IP Library Granted Patent US 12,386,959
Granted Patent B2
US 12,386,959 · App. 17/980,645 · Granted Aug 12, 2025

Indicating infected snapshots in a snapshot chain

Inventors: Adam Gee (San Francisco, CA); Surendar Chandra (Sunnyvale, CA); Gregory Robert Johnston (Mountain View, CA); Ishaan Sang (Mountain View, CA)
Assignee: Rubrik, Inc.
G06F21/565G06F11/1435G06F11/1469G06F16/156G06F21/53G06F21/56G06F21/568G06F2201/84G06F2221/032G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,386,959
App. No.
17/980,645
Filed
Nov 4, 2022
Granted
Aug 12, 2025
Kind
B2
Examiner
NAJI, YOUNES
Art Unit
2445
USPC
726/23
Abstract

Subject matter related to data management is discussed. A most recent snapshot in a snapshot chain that is not infected by malware may be identified based on mounting snapshots in the snapshot chain and determining whether the snapshots are infected. A graphical user interface showing individual snapshots in the snapshot change and indicating whether the snapshot is infected with malware may be displayed. The graphical user interface may provide a recover function for non-infected snapshots and may not enable the recover function for infected snapshots. A command to recover a non-infected snapshot in the snapshot chain may be received. Based on receiving the command, the non-infected snapshot may be recovered.

Claims (49)

1. A method, comprising:

identifying, in respective snapshot chains for respective computing objects of a plurality of computing objects, a most recent, non-infected snapshot, wherein the identifying comprises mounting snapshots in the respective snapshot chains and determining whether the mounted snapshots are infected by malware, and wherein a first computing object of the plurality of computing objects is a first virtual machine, a first file system, a first database, or a first network attached storage system, and a second computing object of the plurality of computing objects is a second virtual machine, a second file system, a second database, or a second network attached storage system;

displaying a graphical user interface showing:

at least a portion of the respective snapshot chains, wherein the respective snapshot chains are represented as one or more individual snapshots, and wherein a representation of an individual snapshot indicates whether the individual snapshot is infected with malware, and

across the respective snapshot chains, a cut line delineating infected snapshots from non-infected snapshots, wherein snapshots above the cut line are restricted from being recovered;

receiving a command to recover, for the respective computing objects, non-infected data; and

recovering, in response to the command, for the respective computing objects, a non-infected snapshot from the respective snapshot chains in accordance with the cut line.

2. The method of claim 1 , wherein the identifying comprises:

mounting the snapshots in the respective snapshot chains in reverse chronological order.

3. The method of claim 2 , wherein the mounting and the determining is repeated until at least one non-infected snapshot in the respective snapshot chains is identified.

4. The method of claim 2 , wherein the mounting and the determining is repeated past at least one non-infected snapshot in the respective snapshot chains being identified.

5. The method of claim 1 , further comprising:

repeating the identifying for all computing objects in a system.

6. The method of claim 1 , wherein the determining comprises:

applying YARA rules and hash matching to a mounted snapshot.

7. The method of claim 1 , wherein mounting the snapshots comprises mounting the snapshots in a sandboxed virtual machine.

8. The method of claim 1 , further comprising:

hydrating data in a mounted snapshot before the determining.

9. An apparatus, comprising:

a processor; and

a memory storing instructions that, when executed by the processor, cause the apparatus to:

identify, in respective snapshot chains for respective computing objects of a plurality of computing objects, a most recent, non-infected snapshot, wherein the identifying comprises mounting snapshots in the respective snapshot chains and determining whether the mounted snapshots are infected by malware, and wherein a first computing object of the plurality of computing objects is a first virtual machine, a first file system, a first database, or a first network attached storage system, and a second computing object of the plurality of computing objects is a second virtual machine, a second file system, a second database, or a second network attached storage system;

display a graphical user interface showing:

at least a portion of the respective snapshot chains, wherein the respective snapshot chains are represented as one or more individual snapshots, and wherein a representation of an individual snapshot indicates whether the individual snapshot is infected with malware, and

across the respective snapshot chains, a cut line delineating infected snapshots from non-infected snapshots, wherein snapshots above the cut line are restricted from being recovered;

receive a command to recover, for the respective computing objects, non-infected data; and

recover, in response to the command, for the respective computing objects, a non-infected snapshot from the respective snapshot chains in accordance with the cut line.

10. The apparatus of claim 9 , wherein, to identify the most recent snapshot, the instructions are further executable by the processor to cause the apparatus to:

mount the snapshots in the respective snapshot chains in reverse chronological order.

11. The apparatus of claim 10 , wherein the instructions are further executable by the processor to cause the apparatus to:

repeat the mounting and the determining until at least one non-infected snapshot in the respective snapshot chains is identified.

12. The apparatus of claim 10 , wherein the instructions are further executable by the processor to cause the apparatus to:

repeat the mounting and the determining past at least one non-infected snapshot in the respective snapshot chains being identified.

13. The apparatus of claim 9 , wherein the instructions are further executable by the processor to cause the apparatus to:

repeat the identifying for all computing objects in a system.

14. The apparatus of claim 9 , wherein, to determine whether the snapshots are infected by the malware, the instructions are further executable by the processor to cause the apparatus to:

apply YARA rules and hash matching to a mounted snapshot.

15. The apparatus of claim 9 , wherein, to mount the snapshots, the instructions are further executable by the processor to cause the apparatus to mount the snapshots in a sandboxed virtual machine.

16. The apparatus of claim 9 , wherein the instructions are further executable by the processor to cause the apparatus to:

hydrate data in a mounted snapshot before the determining.

17. The apparatus of claim 9 , wherein the instructions to display the graphical user interface are further executable by the processor to cause the apparatus to:

display an indication of whether a snapshot is encrypted by malware as determined by a measure of entropy of the snapshot.

18. A non-transitory, computer-readable medium storing code comprising instructions executable by a processor of a device to cause the device to:

identify, in respective snapshot chains for respective computing objects of a plurality of computing objects, a most recent, non-infected snapshot, wherein the identifying comprises mounting snapshots in the respective snapshot chains and determining whether the mounted snapshots are infected by malware, and wherein a first computing object of the plurality of computing objects is a first virtual machine, a first file system, a first database, or a first network attached storage system, and a second computing object of the plurality of computing objects is a second virtual machine, a second file system, a second database, or a second network attached storage system;

display a graphical user interface showing:

at least a portion of the respective snapshot chains, wherein the respective snapshot chains are represented as one or more individual snapshots, and wherein a representation of an individual snapshot indicates whether the individual snapshot is infected with malware, and

across the respective snapshot chains, a cut line delineating infected snapshots from non-infected snapshots, wherein snapshots above the cut line are restricted from being recovered;

receive a command to recover, for the respective computing objects, non-infected data; and

recover, in response to the command, for the respective computing objects, a non-infected snapshot from the respective snapshot chains in accordance with the cut line.

Assignments (3)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 64659/0236 Recorded Jun 13, 2025
From: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
To: RUBRIK, INC.
Reel/Frame 071566/0187 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 21, 2023
From: RUBRIK, INC.
To: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
Reel/Frame 064659/0236 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2023
From: GEE, ADAM; CHANDRA, SURENDAR; JOHNSTON, GREGORY ROBERT; SANG, ISHAAN
To: RUBRIK, INC.
Reel/Frame 062267/0776 →
Continuity (4)
Provisional Application 63421536 · Nov 1, 2022
Provisional Application 63319953 · Mar 15, 2022
Provisional Application 63276822 · Nov 8, 2021
Related Publication 20230144069A1 · May 11, 2023
References Cited (25)
US 8495037B1 · Westenberg · 2013 [cited by examiner]
US 9218252B1 · Revur et al. · 2015 [cited by applicant]
US 10650146B1 · Gaurav et al. · 2020 [cited by applicant]
US 10887339B1 · Sokolov et al. · 2021 [cited by applicant]
US 11681591B2 · Kulaga et al. · 2023 [cited by applicant]
US 20070245105A1 · Suzuki et al. · 2007 [cited by applicant]
US 20110197279A1 · Ueoka · 2011 [cited by applicant]
US 20190235973A1 · Brewer et al. · 2019 [cited by applicant]
US 20190354443A1 · Haustein et al. · 2019 [cited by applicant]
US 20200159624A1 · Malkov et al. · 2020 [cited by applicant]
US 20200201998A1 · Jung · 2020 [cited by examiner]
US 20200226256A1 · Gaurav · 2020 [cited by examiner]
US 20200319979A1 · Kulaga · 2020 [cited by examiner]
US 20210044604A1 · Annen et al. · 2021 [cited by applicant]
US 20210240828A1 · Gaurav et al. · 2021 [cited by applicant]
US 20220100378A1 · Borate · 2022 [cited by examiner]
US 20220245250A1 · Warwick · 2022 [cited by examiner]
US 20220345473A1 · Kare et al. · 2022 [cited by applicant]
ISA/EP, Int'l App. No. PCT/US2022/079400, Partial International Search Report and Provisional Opinion dated Mar. 7, 2023, 6 pages. [cited by applicant]
ISA/EP, Int'l App. No. PCT/US2022/079400, Search Report and Written Opinion dated Mar. 7, 2023, 9 pages. [cited by applicant]
U.S. Appl. No. 17/980,652, filed Nov. 4, 2022, Pending, Recovering Infected Snapshots in a Snapshot Chain. [cited by applicant]
U.S. Appl. No. 17/980,676, filed Nov. 4, 2022, Pending, Quarantining Information in Backup Locations. [cited by applicant]
U.S. Appl. No. 17/980,752, filed Nov. 4, 2022, Pending, Recovering Quarantined Information From Backup Locations. [cited by applicant]
U.S. Appl. No. 17/980,930, filed Nov. 4, 2022, Pending, Bulk Snapshot Recovery. [cited by applicant]
PCT/US22/79400, filed Nov. 7, 2022, Pending, Snapshot-Based Malware Management. [cited by applicant]