IP Library › Granted Patent US 12,645,794
Granted Patent B2
US 12,645,794 · App. 18/128,442 · Granted Jun 2, 2026

Method, electronic device, and computer program product for snapshot classification

Inventors: Weibing Zhang (Beijing, CN); Victor Lei Gao (Beijing, CN); Hao Fang (Beijing, CN); Donglei Wang (Beijing, CN); Zhe He (Beijing, CN)
Assignee: Dell Products L.P.
G06F21/564G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,645,794
App. No.
18/128,442
Granted
Jun 2, 2026
Kind
B2
Abstract

Techniques for snapshot classification involve generating a plurality of snapshots of a storage system at multiple times; clustering the plurality of snapshots into a first group of snapshots and a second group of snapshots based on data features of the plurality of snapshots; and determining a clean snapshot among the plurality of snapshots based on a comparison between the generation time of the first group of snapshots and the generation time of the second group of snapshots. Accordingly, a clean snapshot and a damaged snapshot can be automatically and quickly distinguished, thereby improving the efficiency of finding a clean snapshot and helping a user recover data quickly.

Claims (82)

1 . A method for snapshot classification, comprising:

generating a plurality of snapshots of a storage system at multiple times;

clustering the plurality of snapshots into a first group of snapshots having multiple snapshots and a second group of snapshots having multiple snapshots based on data features of the plurality of snapshots; and

determining a clean snapshot among the plurality of snapshots based on a comparison between the generation time of the first group of snapshots and the generation time of the second group of snapshots; wherein determining the clean snapshot includes:

based on the average generation time of the first group of snapshots being earlier than the average generation time of the second group of snapshots, determining that the first group of snapshots are clean snapshots and the second group of snapshots are damaged snapshots; or

based on a median value of the generation time of the first group of snapshots being earlier than a median value of the generation time of the second group of snapshots, determining that the first group of snapshots are clean snapshots and the second group of snapshots are damaged snapshots; and

selecting the clean snapshot from the first group of snapshots; and

recovering the storage system to a storage state corresponding to the clean snapshot by performing a rollback operation that restores previous data access provided by the storage system.

2 . The method according to claim 1 , further comprising:

acquiring a plurality of data patterns; and

determining the data features of the snapshots based on the snapshots and the plurality of data patterns.

3 . The method according to claim 2 , wherein the data patterns are binary bytes of a predetermined length.

4 . The method according to claim 2 , wherein the plurality of data patterns comprise a first data pattern, a count value of the first data pattern of a first snapshot in the first group of snapshots is greater than a count value of the first data pattern of a second snapshot in the second group of snapshots, the first snapshot is a clean snapshot, and the second snapshot is a damaged snapshot.

5 . The method according to claim 2 , wherein determining the data features of the snapshots based on the snapshots and the plurality of data patterns comprises:

in response to generation of the snapshots, counting the number of each data pattern in the plurality of data patterns in the snapshots; and

determining the data features of the snapshots according to the counts of the plurality of data patterns of the snapshots obtained by the counting.

6 . The method according to claim 1 , further comprising:

taking a snapshot with the latest generation time in the first group of snapshots as a target snapshot,

the storage system being recovered to a state corresponding to the target snapshot.

7 . The method according to claim 1 , wherein the clean snapshots are snapshots of the storage system that have not been subjected to a malware attack, and the damaged snapshots are snapshots of the storage system that have been subjected to a malware attack.

8 . The method according to claim 7 , further comprising:

performing the classification on the plurality of snapshots in response to detecting the malware attack.

9 . The method according to claim 1 , wherein clustering the plurality of snapshots into a first group of snapshots and a second group of snapshots based on data features of the plurality of snapshots comprises:

randomly selecting feature values of data features of two of the snapshots as a first centroid of a first cluster and a second centroid of a second cluster;

performing a cyclic process until a preset condition is met, the cyclic process comprising:

calculating distances between feature values of data features of other snapshots and the first centroid and the second centroid;

for each data feature in the data features of the other snapshots, selecting a cluster corresponding to the centroid with a small distance for clustering;

calculating an average value of feature values of various data features in the first cluster obtained by clustering and an average value of feature values of various data features in the second cluster obtained by clustering; and

updating the first centroid to the average value of feature values of various data features in the first cluster obtained by clustering, and updating the second centroid to the average value of feature values of various data features in the second cluster obtained by clustering;

wherein the preset condition is that the first centroid is the same as the average value of feature values of various data features in the first cluster, and the second centroid is the same as the average value of feature values of various data features in the second cluster; and

taking the snapshots corresponding to the data features in the first cluster that meet the preset condition as the first group of snapshots, and taking the snapshots corresponding to the data features in the second cluster that meet the preset condition as the second group of snapshots.

10 . The method according to claim 1 , wherein selecting the clean snapshot from the first group of snapshots includes:

locating a snapshot of the first group of snapshots with a latest generation time.

11 . An electronic device for snapshot classification, comprising:

a processor; and

a memory coupled to the processor and having instructions stored therein, wherein the instructions, when executed by the processor, cause the electronic device to perform operations comprising:

generating a plurality of snapshots of a storage system at multiple times;

clustering the plurality of snapshots into a first group of snapshots having multiple snapshots and a second group of snapshots having multiple snapshots based on data features of the plurality of snapshots; and

determining a clean snapshot among the plurality of snapshots based on a comparison between the generation time of the first group of snapshots and the generation time of the second group of snapshots; wherein determining the clean snapshot includes:

based on the average generation time of the first group of snapshots being earlier than the average generation time of the second group of snapshots, determining that the first group of snapshots are clean snapshots and the second group of snapshots are damaged snapshots; or

based on a median value of the generation time of the first group of snapshots being earlier than a median value of the generation time of the second group of snapshots, determining that the first group of snapshots are clean snapshots and the second group of snapshots are damaged snapshots; and

selecting the clean snapshot from the first group of snapshots; and

recovering the storage system to a storage state corresponding to the clean snapshot by performing a rollback operation that restores previous data access provided by the storage system.

12 . The electronic device according to claim 11 , wherein the operations further comprise:

acquiring a plurality of data patterns; and

determining the data features of the snapshots based on the snapshots and the plurality of data patterns.

13 . The electronic device according to claim 12 , wherein the data patterns are binary bytes of a predetermined length.

14 . The electronic device according to claim 12 , wherein the plurality of data patterns comprise a first data pattern, a count value of the first data pattern of a first snapshot in the first group of snapshots is greater than a count value of the first data pattern of a second snapshot in the second group of snapshots, the first snapshot is a clean snapshot, and the second snapshot is a damaged snapshot.

15 . The electronic device according to claim 12 , wherein determining the data features of the snapshots based on the snapshots and the plurality of data patterns comprises:

in response to generation of the snapshots, counting the number of each data pattern in the plurality of data patterns in the snapshots; and

determining the data features of the snapshots according to the counts of the plurality of data patterns of the snapshots obtained by the counting.

16 . The electronic device according to claim 11 , wherein the operations further comprise:

taking a snapshot with the latest generation time in the first group of snapshots as a target snapshot,

the storage system being recovered to a state corresponding to the target snapshot.

17 . The electronic device according to claim 11 , wherein the clean snapshots are snapshots of the storage system that have not been subjected to a malware attack, and the damaged snapshots are snapshots of the storage system that have been subjected to a malware attack.

18 . The electronic device according to claim 11 , wherein clustering the plurality of snapshots into a first group of snapshots and a second group of snapshots based on data features of the plurality of snapshots comprises:

randomly selecting feature values of data features of two of the snapshots as a first centroid of a first cluster and a second centroid of a second cluster;

performing a cyclic process until a preset condition is met, the cyclic process comprising:

calculating distances between feature values of data features of other snapshots and the first centroid and the second centroid;

for each data feature in the data features of the other snapshots, selecting a cluster corresponding to the centroid with a small distance for clustering;

calculating an average value of feature values of various data features in the first cluster obtained by clustering and an average value of feature values of various data features in the second cluster obtained by clustering; and

updating the first centroid to the average value of feature values of various data features in the first cluster obtained by clustering, and updating the second centroid to the average value of feature values of various data features in the second cluster obtained by clustering;

wherein the preset condition is that the first centroid is the same as the average value of feature values of various data features in the first cluster, and the second centroid is the same as the average value of feature values of various data features in the second cluster; and

taking the snapshots corresponding to the data features in the first cluster that meet the preset condition as the first group of snapshots, and taking the snapshots corresponding to the data features in the second cluster that meet the preset condition as the second group of snapshots.

19 . A computer program product having a non-transitory computer readable medium which stores a set of instructions for snapshot classification; the set of instructions, when carried out by computerized circuitry, causing the computerized circuitry to perform a method of:

generating a plurality of snapshots of a storage system at multiple times;

clustering the plurality of snapshots into a first group of snapshots having multiple snapshots and a second group of snapshots having multiple snapshots based on data features of the plurality of snapshots;

determining a clean snapshot among the plurality of snapshots based on a comparison between the generation time of the first group of snapshots and the generation time of the second group of snapshots; and

recovering the storage system to a storage state corresponding to the clean snapshot by performing a rollback operation that restores previous data access provided by the storage system;

wherein clustering the plurality of snapshots into a first group of snapshots and a second group of snapshots based on data features of the plurality of snapshots comprises:

randomly selecting feature values of data features of two of the snapshots as a first centroid of a first cluster and a second centroid of a second cluster;

performing a cyclic process until a preset condition is met, the cyclic process comprising:

calculating distances between feature values of data features of other snapshots and the first centroid and the second centroid;

for each data feature in the data features of the other snapshots, selecting a cluster corresponding to the centroid with a small distance for clustering;

calculating an average value of feature values of various data features in the first cluster obtained by clustering and an average value of feature values of various data features in the second cluster obtained by clustering; and

updating the first centroid to the average value of feature values of various data features in the first cluster obtained by clustering, and updating the second centroid to the average value of feature values of various data features in the second cluster obtained by clustering;

wherein the preset condition is that the first centroid is the same as the average value of feature values of various data features in the first cluster, and the second centroid is the same as the average value of feature values of various data features in the second cluster; and

taking the snapshots corresponding to the data features in the first cluster that meet the preset condition as the first group of snapshots, and taking the snapshots corresponding to the data features in the second cluster that meet the preset condition as the second group of snapshots.

20 . The computer program product according to claim 19 , wherein determining the clean snapshot includes:

based on the average generation time of the first group of snapshots being earlier than the average generation time of the second group of snapshots, determining that the first group of snapshots are clean snapshots and the second group of snapshots are damaged snapshots; or

based on a median value of the generation time of the first group of snapshots being earlier than a median value of the generation time of the second group of snapshots, determining that the first group of snapshots are clean snapshots and the second group of snapshots are damaged snapshots; and

selecting the clean snapshot from the first group of snapshots.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2023
From: ZHANG, WEIBING; GAO, VICTOR LEI; FANG, HAO; WANG, DONGLEI; HE, ZHE
To: DELL PRODUCTS L.P.
Reel/Frame 063614/0558 →
Priority Claims (1)
CN 202211132018.8 · Sep 16, 2022 · national
Continuity (1)
Related Publication 20240095358A1 · Mar 21, 2024
References Cited (30)
US 11055405B1 · Jin · 2021 [cited by examiner]
US 11275656B2 · Martin · 2022 [cited by examiner]
US 11770398B1 · Erlingsson et al. · 2023 [cited by applicant]
US 11792284B1 · Nanduri et al. · 2023 [cited by applicant]
US 11818156B1 · Parikh et al. · 2023 [cited by applicant]
US 20150149411A1 · Plisko · 2015 [cited by examiner]
US 20200137084A1 · Roy · 2020 [cited by examiner]
US 20220100378A1 · Borate · 2022 [cited by examiner]
US 20220156396A1 · Bednash et al. · 2022 [cited by applicant]
US 20220200869A1 · Erlingsson et al. · 2022 [cited by applicant]
US 20220215101A1 · Rioux et al. · 2022 [cited by applicant]
US 20220229805A1 · Chakeres et al. · 2022 [cited by applicant]
US 20220232024A1 · Kapoor et al. · 2022 [cited by applicant]
US 20220232025A1 · Kapoor et al. · 2022 [cited by applicant]
US 20220247769A1 · Erlingsson et al. · 2022 [cited by applicant]
US 20220294816A1 · Martin et al. · 2022 [cited by applicant]
US 20220311794A1 · Maya et al. · 2022 [cited by applicant]
US 20220329616A1 · O'Hearn et al. · 2022 [cited by applicant]
US 20220360600A1 · Reed et al. · 2022 [cited by applicant]
US 20220400130A1 · Kapoor et al. · 2022 [cited by applicant]
US 20230032686A1 · Williams et al. · 2023 [cited by applicant]
US 20230075355A1 · Twigg et al. · 2023 [cited by applicant]
US 20230095870A1 · Du et al. · 2023 [cited by applicant]
US 20230128602A1 · Park · 2023 [cited by examiner]
US 20230254330A1 · Kumar et al. · 2023 [cited by applicant]
US 20230275917A1 · Karmali et al. · 2023 [cited by applicant]
US 20230306108A1 · Veprinsky et al. · 2023 [cited by applicant]
US 20230319092A1 · Zeng et al. · 2023 [cited by applicant]
US 20230328086A1 · Kapoor et al. · 2023 [cited by applicant]
US 20250258918A1 · Sun · 2025 [cited by examiner]