IP Library Granted Patent US 12,495,053
Granted Patent B2
US 12,495,053 · App. 18/061,344 · Granted Dec 9, 2025

Anomaly and ransomware detection

Inventors: Oscar Annen (San Jose, CA); Di Wu (Newark, CA); Ajay Saini (Mountain View, CA)
Assignee: Rubrik, Inc.
H04L63/1425G06F11/1464G06N20/00H04L63/1466G06F2201/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,495,053
App. No.
18/061,344
Granted
Dec 9, 2025
Kind
B2
Abstract

Some examples relate generally to computer architecture software for information security and, in some more particular aspects, to machine learning based on changes in snapshot metadata for anomaly and ransomware detection in a file system.

Claims (44)

1 . A system, comprising:

a storage device configured to store one or more snapshots of a primary machine; and

one or more processors in communication with the storage device and a production system, the one or more processors configured to perform one or more anomaly and ransomware detection operations comprising:

taking a first snapshot and a second snapshot of the primary machine;

identifying one or more changes in snapshot-based metadata based on the first snapshot and the second snapshot;

training, in accordance with a two-stage machine learning analysis, a first machine-learning model that compares the one or more changes in the snapshot-based metadata occurring over a time duration to a threshold quantity of changes indicative of an anomalous event and a second machine-learning model different from the first machine-learning model that performs an entropy scan of the one or more changes in the snapshot-based metadata to identify whether respective entropies associated with the one or more changes in the snapshot-based metadata comprise a ransomware encryption event, wherein the training of the first machine-learning model and the second machine-learning model is further based on training data derived from the one or more changes in the snapshot-based metadata;

detecting an anomaly from a new snapshot of the primary machine using the first machine-learning model at a first stage of the two-stage machine learning analysis; and

passing, in response to detecting the anomaly, the new snapshot of the primary machine through the second machine-learning model to detect whether the detected anomaly is a ransomware encryption anomaly at a second stage of the two-stage machine learning analysis.

2 . The system of claim 1 , wherein the storage device is a backup storage device and the one or more changes in the snapshot-based metadata are sourced from a backup system that includes the backup storage device.

3 . The system of claim 1 , wherein the one or more anomaly and ransomware detection operations are performed without impacting the production system.

4 . The system of claim 1 , wherein training the first machine-learning model further comprises:

analyzing the one or more changes in the snapshot-based metadata over the time duration, wherein the one or more changes comprise a threshold number of file creations, a threshold number of file deletions, a threshold number of file modifications, or any combination thereof.

5 . The system of claim 1 , wherein the first machine-learning model and the second machine-learning model comprise an anomaly model, an encryption model, or both.

6 . The system of claim 1 , wherein training the second machine-learning model comprises:

performing the entropy scan of the one or more changes in the snapshot-based metadata to identify

whether an event comprises the ransomware encryption event based at least in part on the respective entropies.

7 . A method at an anomaly and ransomware detection system, the anomaly and ransomware detection system including one or more processors in communication with a storage device and a production system, the one or more processors configured to perform one or more anomaly and ransomware detection operations comprising:

taking a first snapshot and a second snapshot of a primary machine;

identifying one or more changes in snapshot-based metadata based on the first snapshot and the second snapshot;

training, in accordance with a two-stage machine learning analysis, a first machine-learning model that compares the one or more changes in the snapshot-based metadata occurring over a time duration to a threshold quantity of changes indicative of an anomalous event and a second machine-learning model different from the first machine-learning model that performs an entropy scan of the one or more changes in the snapshot-based metadata to identify whether respective entropies associated with the one or more changes in the snapshot-based metadata comprise a ransomware encryption event, wherein the training of the first machine-learning model and the second machine-learning model is further based on training data derived from the one or more changes in the snapshot-based metadata;

detecting an anomaly from a new snapshot of the primary machine using the first machine-learning model at a first stage of the two-stage machine learning analysis; and

passing, in response to detecting the anomaly, the new snapshot of the primary machine through the second machine-learning model to detect whether the detected anomaly is a ransomware encryption anomaly at a second stage of the two-stage machine learning analysis.

8 . The method of claim 7 , wherein the storage device is a backup storage device and the one or more changes in the snapshot-based metadata are sourced from a backup system that includes the backup storage device.

9 . The method of claim 7 , wherein the one or more anomaly and ransomware detection operations are performed without impacting the production system.

10 . The method of claim 7 , wherein training the first machine-learning model further comprises:

analyzing the one or more changes in the snapshot-based metadata over the time duration, wherein the one or more changes comprise a threshold number of file creations, a threshold number of file deletions, a threshold number of file modifications, or any combination thereof.

11 . The method of claim 7 , wherein the first machine-learning model and the second machine-learning model comprise an anomaly model, an encryption model, or both.

12 . The method of claim 7 , wherein training the second machine-learning model comprises:

performing the entropy scan of the one or more changes in the snapshot-based metadata to identify

whether an event comprises the ransomware encryption event based at least in part on the respective entropies.

13 . A non-transitory, machine-readable medium storing instructions which, when read by a machine, cause the machine to perform one or more anomaly and ransomware detection operations comprising:

taking a first snapshot and a second snapshot of a primary machine;

identifying one or more changes in snapshot-based metadata based on the first snapshot and the second snapshot;

training, in accordance with a two-stage machine learning analysis, a first machine-learning model that compares the one or more changes in the snapshot-based metadata occurring over a time duration to a threshold quantity of changes indicative of an anomalous event and a second machine-learning model different from the first machine-learning model that performs an entropy scan of the one or more changes in the snapshot-based metadata to identify whether respective entropies associated with the one or more changes in the snapshot-based metadata comprise a ransomware encryption event, wherein the training of the first machine-learning model and the second machine-learning model is further based on training data derived from the one or more changes in the snapshot-based metadata;

detecting an anomaly from a new snapshot of the primary machine using the first machine-learning model at a first stage of the two-stage machine learning analysis; and

passing, in response to detecting the anomaly, the new snapshot of the primary machine through the second machine-learning model to detect whether the detected anomaly is a ransomware encryption anomaly at a second stage of the two-stage machine learning analysis.

14 . The non-transitory, machine-readable medium of claim 13 , wherein the one or more changes in the snapshot-based metadata are sourced from a backup system that includes a backup storage device.

15 . The non-transitory, machine-readable medium of claim 13 , wherein the one or more anomaly and ransomware detection operations are performed without impacting a production system.

16 . The non-transitory, machine-readable medium of claim 13 , wherein training the first machine-learning model further comprises:

analyzing the one or more changes in the snapshot-based metadata over the time duration, wherein the one or more changes comprise a threshold number of file creations, a threshold number of file deletions, a threshold number of file modifications, or any combination thereof.

17 . The non-transitory, machine-readable medium of claim 13 , wherein the first machine-learning model and the second machine-learning model comprise an anomaly model, an encryption model, or both.

18 . The non-transitory, machine-readable medium of claim 13 , wherein training the second machine-learning model comprises:

performing the entropy scan of the one or more changes in the snapshot-based metadata to identify

whether an event comprises the ransomware encryption event based at least in part on the respective entropies.

Assignments (3)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 64659/0236 Recorded Jun 13, 2025
From: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
To: RUBRIK, INC.
Reel/Frame 071566/0187 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 21, 2023
From: RUBRIK, INC.
To: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
Reel/Frame 064659/0236 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2022
From: ANNEN, OSCAR; WU, DI; SAINI, AJAY
To: RUBRIK, INC.
Reel/Frame 061961/0572 →
Continuity (2)
Continuation 16534447 · Aug 7, 2019
Related Publication 20230105500A1 · Apr 6, 2023
References Cited (88)
US 7181768B1 · Ghosh et al. · 2007 [cited by applicant]
US 7765217B2 · Yamakawa et al. · 2010 [cited by applicant]
US 7802300B1 · Liu et al. · 2010 [cited by applicant]
US 7934103B2 · Kidron · 2011 [cited by applicant]
US 7941855B2 · Sung et al. · 2011 [cited by applicant]
US 7962956B1 · Liao et al. · 2011 [cited by applicant]
US 9116722B2 · Shenfield et al. · 2015 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9734337B1 · Patton et al. · 2017 [cited by applicant]
US 9779240B2 · Feroz et al. · 2017 [cited by applicant]
US 10032033B2 · Gu et al. · 2018 [cited by applicant]
US 10229269B1 · Patton et al. · 2019 [cited by applicant]
US 10572993B2 · Tanaka et al. · 2020 [cited by applicant]
US 10867040B2 · Gibbons et al. · 2020 [cited by applicant]
US 10929031B2 · Sapuntzakis et al. · 2021 [cited by applicant]
US 10992699B1 · Sites et al. · 2021 [cited by applicant]
US 11086987B2 · Brown · 2021 [cited by applicant]
US 11120131B2 · Chen et al. · 2021 [cited by applicant]
US 11170104B1 · Stickle et al. · 2021 [cited by applicant]
US 11449607B2 · Annen et al. · 2022 [cited by applicant]
US 11522889B2 · Annen et al. · 2022 [cited by applicant]
US 11606379B1 · Pratt et al. · 2023 [cited by applicant]
US 11657152B2 · Kraemer et al. · 2023 [cited by applicant]
US 11770391B1 · Bakthavatchalam et al. · 2023 [cited by applicant]
US 20060074824A1 · Li · 2006 [cited by applicant]
US 20080127346A1 · Oh et al. · 2008 [cited by applicant]
US 20080209138A1 · Sheldon et al. · 2008 [cited by applicant]
US 20090055604A1 · Lemar et al. · 2009 [cited by applicant]
US 20100125911A1 · Bhaskaran · 2010 [cited by applicant]
US 20130305373A1 · Lim et al. · 2013 [cited by applicant]
US 20140013434A1 · Ranum et al. · 2014 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150264077A1 · Berger et al. · 2015 [cited by applicant]
US 20160012227A1 · Tuvell et al. · 2016 [cited by applicant]
US 20160239661A1 · Kawauchi · 2016 [cited by applicant]
US 20160292418A1 · Wojnowicz et al. · 2016 [cited by applicant]
US 20170053118A1 · Malkov et al. · 2017 [cited by applicant]
US 20170063906A1 · Muddu et al. · 2017 [cited by applicant]
US 20170103334A1 · Gusev et al. · 2017 [cited by applicant]
US 20170180394A1 · Crofton et al. · 2017 [cited by applicant]
US 20170195353A1 · Taylor et al. · 2017 [cited by applicant]
US 20170214708A1 · Gukal et al. · 2017 [cited by applicant]
US 20170315979A1 · Boucher et al. · 2017 [cited by applicant]
US 20170339178A1 · Mahaffey et al. · 2017 [cited by applicant]
US 20180034835A1 · Iwanir et al. · 2018 [cited by applicant]
US 20180173874A1 · Muttik et al. · 2018 [cited by applicant]
US 20180211039A1 · Tamir et al. · 2018 [cited by applicant]
US 20180307839A1 · Bhave et al. · 2018 [cited by applicant]
US 20190042744A1 · Rajasekharan et al. · 2019 [cited by applicant]
US 20190163763A1 · Pandey et al. · 2019 [cited by applicant]
US 20190171966A1 · Rangasamy · 2019 [cited by applicant]
US 20190235973A1 · Brewer · 2019 [cited by examiner]
US 20190236272A1 · Piatt · 2019 [cited by applicant]
US 20190286534A1 · O'Mahony et al. · 2019 [cited by applicant]
US 20190332766A1 · Guri et al. · 2019 [cited by applicant]
US 20190332769A1 · Fralick et al. · 2019 [cited by applicant]
US 20190347418A1 · Strogov · 2019 [cited by examiner]
US 20190347578A1 · Bolding et al. · 2019 [cited by applicant]
US 20190354850A1 · Watson et al. · 2019 [cited by applicant]
US 20200004808A1 · Yao et al. · 2020 [cited by applicant]
US 20200004962A1 · Araujo et al. · 2020 [cited by applicant]
US 20200034537A1 · Chen et al. · 2020 [cited by applicant]
US 20200042703A1 · Herman Saffar et al. · 2020 [cited by applicant]
US 20200076812A1 · Spurlock et al. · 2020 [cited by applicant]
US 20200089886A1 · Oetken · 2020 [cited by applicant]
US 20200177612A1 · Kras et al. · 2020 [cited by applicant]
US 20200279043A1 · Thornton et al. · 2020 [cited by applicant]
US 20200311595A1 · Chen et al. · 2020 [cited by applicant]
US 20200342652A1 · Rowell et al. · 2020 [cited by applicant]
US 20210034994A1 · Stocker et al. · 2021 [cited by applicant]
US 20210042411A1 · Annen et al. · 2021 [cited by applicant]
US 20210044603A1 · Annen et al. · 2021 [cited by applicant]
US 20210044604A1 · Annen et al. · 2021 [cited by applicant]
US 20210089957A1 · Ermans et al. · 2021 [cited by applicant]
US 20210374027A1 · Joglekar et al. · 2021 [cited by applicant]
US 20220247766A1 · Annen et al. · 2022 [cited by applicant]
US 20220318203A1 · Kotwal et al. · 2022 [cited by applicant]
US 20230004749A1 · Jaganathan et al. · 2023 [cited by applicant]
US 20230026368A1 · Silverstein · 2023 [cited by applicant]
US 20240430278A1 · Tyborowski et al. · 2024 [cited by applicant]
CN 106845223A · 2017 [cited by applicant]
KR 101772439B1 · 2017 [cited by applicant]
KR 101828600B1 · 2018 [cited by applicant]
WO 2020028152A1 · 2020 [cited by applicant]
U.S. Appl. No. 16/534,447, filed Aug. 7, 2019, Issued, U.S. Pat. No. 11,522,889 B2. [cited by applicant]
U.S. Appl. No. 16/534,479, filed Aug. 7, 2019, Pending. [cited by applicant]
U.S. Appl. No. 16/534,486, filed Aug. 7, 2019, Issued, U.S. Pat. No. 11,449,607 B2. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US19/43563, mailed on Oct. 29, 2019, 9 pages. [cited by applicant]
Cited By (1)
US 12,711,233