DETECTING MALICIOUS SOFTWARE AND RECOVERING A STORAGE SYSTEM
A storage system sends information on input/output patterns and data blocks written to a cloud-based service for detection of suspected ransomware activity. Analysis of the I/O patterns and data may be performed by the storage system, the cloud-based service, or both. The cloud-based service can instruct the storage system to create or maintain snapshots that allow the storage system continue operation and allow the storage system to roll back for recovery after a ransomware attack is confirmed.
1 . A process for operating a storage system including a plurality of servers containing a plurality of service processing units (SPUs), the process comprising:
the SPUs receiving a series of storage service requests from client;
the SPUs performing storage operations to fulfill the storage service requests;
the SPUs reporting information on the storage operations to a cloud-based service; and
the cloud-based service analyzing the information to detect an indicator of malware activity.
2 . The process of claim 1 , further comprising, in response to detecting malware the indicator of malware activity, the cloud-based service instruction the SPUs to maintain snapshots of data in a state before the indicator occurred.
3 . The process of claim 1 , further comprising:
training a model using past information on the storage operations; and
the cloud-based service detecting the indicator of malware activity based on a difference between the model and the information reported by the SPUs.
4 . The process of claim 1 , further comprising the SPUs analyzing blocks of data written by performance of the storage operations, the information reported to the cloud-based service indicating results from the SPUs analyzing the blocks of data.
5 . A storage system comprising:
one or more storage nodes, each storage node including:
a server;
a storage device; and
a storage processing unit connected to the storage device, the storage processing unit operating the storage device to physically store data of one or more virtual volumes and to provide storage services to clients using the data of the virtual volumes; and
a cloud-based infrastructure in communication with the storage processing units in the storage nodes, the cloud-based infrastructure being configured to analyze information that the storage processing units provide about the virtual volumes and based on the analysis, to direct the storage processing units to maintain snapshots that permit recovery of data after a ransomware attack.
6 . The system of claim 5 , wherein the information that the storage processing units provides indicate patterns of storage operations targeting the virtual volumes.
7 . The system of claim 5 , wherein the information that the storage processing units provides includes tests results from analysis of data blocks written to the virtual volumes by the storage processing units.
8 . The system of claim 7 , wherein the test results indicate one or more of compressibility, entropy, and encryption of data.
9 . The system of claim 7 , wherein the information represents a histogram of the test results.
10 . The system of claim 5 , wherein cloud-based infrastructure analysis of the information includes detecting an anomaly by comparing the information to a model that results a machine learning process that trained using past information.