IP Library Granted Patent US 12,462,039
Granted Patent B2
US 12,462,039 · App. 18/193,229 · Granted Nov 4, 2025

System and method for evaluating active backups using penetration testing

Inventors: Candid Wuest (Bassersdorf, CH); Philipp Gysel (Bern, CH); Serg Bell (Singapore, SG); Stanislav Protasov (Singapore, SG)
Assignee: Acronis International GmbH
G06F21/577G06F21/53G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,462,039
App. No.
18/193,229
Granted
Nov 4, 2025
Kind
B2
Abstract

Systems and methods for verifying a production system automatically by testing a mirror copy of the production system on a testing computer. The system includes a mirror update transporter to deliver a mirror update from the production system to the mirror system, a mounting module to apply the mirror update to the mirror system, a testing computer on which the mirror system is running, a testing module to automatically execute a set of tests on the mirror system, and a communication module to communicate the results of the tests.

Claims (67)

1 . A method for evaluating a production system by testing a live mirror image of the production system on a testing computer, the method comprising:

creating a live mirror system as a copy of the production system on a testing computer;

obtaining a mirror update comprising one or more changes to the production system since the generation of a previous mirror update;

replicating a set of files or other data units associated with the mirror update on the testing computer to apply to the live mirror system;

running a set of automatic dynamic tests on the testing computer to evaluate the live mirror system;

generating a list of results of execution of each of the tests on the testing computer, wherein the list of results is indicative of at least one vulnerability or defect; and

saving the list of results to a computer memory or communicating it to a user, wherein at least one of:

obtaining the mirror update is stopped before the running the set of dynamic automatic tests on the live mirror system on the testing computer starts,

replicating the set of files is stopped before the running the set of dynamic automatic tests on the live mirror system on the testing computer starts, or

applying the set of files to the live mirror system is stopped before the running the set of dynamic automatic tests on the live mirror system on the testing computer starts.

2 . The method of claim 1 , wherein the production system is at least one of a virtual machine, a container, a scripting engine, or a web server.

3 . The method of claim 1 , wherein obtaining the mirror update comprises using a file synchronization system with a shadow copy method to detect changes to the files on the production system.

4 . The method of claim 1 , wherein obtaining a mirror update comprises using database mirroring or a replication functionality on the production system.

5 . The method of claim 1 , wherein obtaining a mirror update is performed by an external system.

6 . The method of claim 1 , wherein the live mirror system is created when the production system is live.

7 . The method of claim 1 , wherein at least one of:

obtaining the mirror update continues while the running the set of dynamic automatic tests on the testing computer executes,

replicating the set of files continues while the running the set of dynamic automatic tests on the testing computer executes, or

applying the set of files to the live mirror system continues while the running the set of dynamic automatic tests on the testing computer executes.

8 . The method of claim 1 , wherein at least one of:

obtaining the mirror update resumes after the running the test of dynamic automatic tests on the live mirror system on the testing computer has finished,

replicating the set of files resumes after the running the test of dynamic automatic tests on the live mirror system on the testing computer has finished, or

applying the set of files to the live mirror system resumes after the running the test of dynamic automatic tests on the live mirror system on the testing computer has finished.

9 . The method of claim 1 , further comprising:

creating a full backup of the production system or an incremental backup of the production system; and

applying the full backup or the incremental backup to the live mirror system on the testing computer.

10 . The method of claim 1 , further comprising delivering the list of results to a user by at least one of:

sending an electronic communication;

displaying on a display unit of user's computer;

printing in a print media; or

publishing in electronic media.

11 . The method of claim 1 , wherein the running the set of dynamic automatic tests is implemented by an automated dynamic testing system having a local testing agent installed onto the testing system before dynamic automatic testing is performed.

12 . The method of claim 1 further comprising:

comparing a current list of results with a list of results corresponding to one or more previous backups of the production system;

identifying at least one differentiating factor indicative of a vulnerability; and

communicating the at least one differentiating factor to a user.

13 . The method of claim 1 further comprising:

tracking at least one emerging new threat or vulnerability as detected by threat intelligence; and

revising the set of dynamic automatic tests for testing the live mirror system on the testing computer.

14 . A system for evaluating a production system by testing a live mirror image of the production system, the system comprising:

a testing computer configured to run a live copy of the production system as a live mirror system;

a mirror update transporter configured to obtain a mirror update comprising changes to the live production system that occurred since a previous mirror update, and to deliver the mirror update to the testing computer to create a near real-time copy of the production system on the live mirror system;

a mounting module configured to apply the mirror update to the live mirror system;

a testing module configured to:

run a set of dynamic automatic tests against the live mirror system on the testing computer to evaluate the production system for at least one vulnerability or defect,

and generate a list of results of execution of the set of tests on the testing computer, wherein the list of results is indicative of the at least one vulnerability or defect,

save the list of results in computer memory or communicate it to a user,

wherein at least one of:

obtaining the mirror update is stopped before the running the set of dynamic automatic tests on the live mirror system on the testing computer starts,

replicating a set of files associated with the live mirror update is stopped before the running the set of dynamic automatic tests on the live mirror system on the testing computer starts, or

applying mirror update to the live mirror system is stopped before the running the set of dynamic automatic tests on the live mirror system on the testing computer starts.

15 . The system of claim 14 , further comprising:

a mirror update backup generator configured to generate the mirror update.

16 . The system of claim 14 , wherein the production system is at least one of a virtual machine, a virtual environment, a container, a scripting engine, or a web server.

17 . The system of claim 14 , further comprising:

a communication module to deliver the list of results to a user by:

sending an electronic communication;

displaying on a display unit of a user's computer;

printing in a print media; or

publishing in electronic media.

18 . The system of claim 14 , wherein the testing module is further configured to collect the list of results from each iteration of the testing against the live mirror system and store the list of results from each iteration of the testing for analysis.

19 . The system of claim 14 , further comprising:

a communication module configured to:

compare a current list of results with a list of results corresponding to one or more previous backups of the production system;

identify at least one differentiating factor indicative of a vulnerability; and

communicate the at least one differentiating factor to a user.

20 . The method of claim 1 , wherein replicating a set of files or other data units associated with the mirror update comprises enumerating one or more newly created files or currently-running processes since a last evaluation.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENTS LISTED BY DELETING PATENT APPLICATION NO. 18388907 FROM SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 66797 FRAME 766. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Nov 13, 2024
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 069594/0136 →
SECURITY INTEREST Recorded Mar 14, 2024
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 066797/0766 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2023
From: WUEST, CANDID; GYSEL, PHILIPP; BELL, SERG; PROTASOV, STANISLAV
To: ACRONIS INTERNATIONAL GMBH
Reel/Frame 063176/0557 →
Continuity (1)
Related Publication 20240330477A1 · Oct 3, 2024
References Cited (15)
US 9921769B2 · Aron et al. · 2018 [cited by applicant]
US 10042711B1 · Chopra et al. · 2018 [cited by applicant]
US 11057419B2 · Murphy · 2021 [cited by examiner]
US 11106632B2 · Bangalore · 2021 [cited by examiner]
US 11106792B2 · Kostyushko et al. · 2021 [cited by applicant]
US 11250136B2 · Mandagere et al. · 2022 [cited by applicant]
US 11513878B2 · Kulaga et al. · 2022 [cited by applicant]
US 20210397726A1 · Kulaga et al. · 2021 [cited by applicant]
US 20230063529A1 · Canfield · 2023 [cited by applicant]
US 20230289443A1 · Sinha · 2023 [cited by examiner]
US 20240111857A1 · Luniya · 2024 [cited by examiner]
CN 109460331B · 2021 [cited by applicant]
CN 115495360A · 2022 [cited by applicant]
Wundsam et al., IEEE 210, “Network Troubleshooting with Mirror VNets”, pp. 283-287 (Year: 2010). [cited by examiner]
Antimalware Scans of Backups: Creating More Security Without Harming Performance or Usability (Acronis Blog), https://www.acronis.com/en-sg/blog/posts/antimalware-backup-archive-scanning/, Sep. 28, 2020. [cited by applicant]