IP Library Granted Patent US 11,930,042
Granted Patent B2
US 11,930,042 · App. 18/136,092 · Granted Mar 12, 2024

Cloud-native global file system with rapid ransomware recovery

Inventors: Andres Rodriguez (Boston, MA); David M. Shaw (Newton, MA); John A. Capello (Cambridge, MA); Matthew J. Stech (Huntley, IL)
Assignee: Nasuni Corporation
H04L63/1466G06F11/1469H04L63/1416G06F2201/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,930,042
App. No.
18/136,092
Granted
Mar 12, 2024
Kind
B2
Abstract

A cloud-native global file system, in which one or more filers are associated with a volume of a versioned files system in a private, public or hybrid cloud object store, is augmented to include a rapid ransomware recovery service. Upon detecting a ransomware attack associated with one or more files or directories of the volume, read and write access to the volume is restricted. A recovery filer is then activated or designated in the cloud. A restore operation is then initiated at the recovery filter. Following completion of the restore operation, a new clean (healthy) snapshot of the volume is then created using the recovery filer For any filer other than the recovery filer, a determination is made whether the filer has completed a merge operation with respect to the new clean snapshot. If so, read and write access to the volume is re-enabled from that filer.

Claims (23)

1. A method of detecting and recovering from a ransomware attack in association with a cloud-based global file system wherein a filer is associated with a volume of a versioned file system in a private, public or hybrid cloud object store, comprising:

responsive to detecting a ransomware attack, restricting access to the volume, wherein the ransomware attack is detected by a filer- or cloud-based detector configured to score a set of markers that, when taken together, provide an indication of the ransomware attack, wherein at least one marker is associated with a given test associated with an occurrence indicative of a ransomware attack;

activating or designating a recovery filer;

initiating a restore operation at the recovery filer;

upon completion of the restore operation, creating a new clean snapshot of the volume using the recovery filer; and

thereafter, re-enabling access to the volume.

2. The method as described in claim 1 wherein each of the markers are distinct from one another.

3. The method as described in claim 1 wherein the individual test has an associated score.

4. The method as described in claim 1 further including receiving data that configures the individual test.

5. The method as described in claim 4 wherein the data performs one of: enabling the individual test, designating a score value, and designating an action to take when a score exceeds one or more configurable values.

6. The method as described in claim 1 further including selectively adjusting a score associated with the test upon a given occurrence or event.

7. The method as described in claim 1 wherein scores associated with the set of markers are aggregated and compared to one or more configurable thresholds to detect the ransomware attack.

8. The method as described in claim 1 wherein the detector implements a machine learning.

9. The method as described in claim 1 wherein the test is one of: tracking a number of new file creations in a given unit of time, tracking a number of complete file overwrites in a given unit of time, tracking a number of new file manifests appearing in a given push, tracking a number of file reads in a given unit of time, tracking a number of file reads for files that have not been read in a given time period, examining a characteristic of a filename, and searching for a ransom demand.

10. The method as described in claim 1 wherein the restore operation reverses damage to one of: a file in the volume, a directory in the volume, and the entire volume.

11. The method as described in claim 1 wherein recovery from the ransomware attack is carried out with respect to the volume and not any other volume in the cloud-based global file system.

12. A method of detecting and recovering from a ransomware attack in association with a cloud-based global file system wherein a filer is associated with a volume of a versioned file system in a private, public or hybrid cloud object store, comprising:

responsive to detecting a ransomware attack, restricting access to the volume;

activating or designating a recovery filer;

initiating a restore operation at the recovery filer;

upon completion of the restore operation, creating a new clean snapshot of the volume using the recovery filer; and

thereafter, re-enabling access to the volume;

wherein recovery from the ransomware attack occurs over a time period measured in minutes with respect to a point-in-time when the ransomware attack is detected.

Assignments (1)
PATENT SECURITY AGREEMENT Recorded Sep 12, 2024
From: NASUNI CORPORATION
To: AB PRIVATE CREDIT INVESTORS LLC, AS COLLATERAL AGENT
Reel/Frame 068947/0138 →
Continuity (3)
Continuation 17745581 · May 16, 2022
Continuation 17559561 · Dec 22, 2021
Related Publication 20230262090A1 · Aug 17, 2023