IP Library Granted Patent US 12,235,954
Granted Patent B2
US 12,235,954 · App. 18/438,922 · Granted Feb 25, 2025

Ransomware detection using multiple security threat detection processes

Inventors: Andrew Kutner (Quincy, IL); Ronald Karr (Palo Alto, CA); Andrew Miller (Greenville, SC); Patrick D. Lee (Los Altos, CA); David Huskisson (Minneapolis, MN); Brian Carpenter (Frisco, TX); Cynthia Dote (San Jose, CA)
Assignee: Pure Storage, Inc.
G06F21/554G06F3/0619G06F3/0647G06F3/0673G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,235,954
App. No.
18/438,922
Granted
Feb 25, 2025
Kind
B2
Abstract

A method includes a data protection system determining, based on a first security threat detection process, that a storage system is possibly being targeted by a security threat; performing, based on the determining that the storage system is possibly being targeted by the security threat, a first remedial action with respect to the storage system, the first remedial action comprising generating a snapshot of data stored by the storage system; confirming, based on a second security threat detection process, whether the storage system is possibly being targeted by the security threat; and performing, based on the confirming whether the storage system is possibly being targeted by the security threat, a second remedial action with respect to the storage system, the second remedial action comprising specifying a retention duration with respect to the snapshot.

Claims (37)

1. A method comprising:

determining, by a data protection system based on a first security threat detection process, that a storage system is possibly being targeted by a security threat;

performing, by the data protection system based on the determining that the storage system is possibly being targeted by the security threat, a first remedial action with respect to the storage system, the first remedial action comprising generating a snapshot of data stored by the storage system to restore the data to an uncorrupted state when confirmed that the data is corrupted;

confirming, by the data protection system based on a second security threat detection process, whether the storage system is possibly being targeted by the security threat;

continuing, by the data protection system when the confirming comprises determining that the storage system is not being targeted by the security threat, to perform the first security threat detection process; and

performing, by the data protection system when the confirming comprises determining that the storage system is being targeted by the security threat, a second remedial action with respect to the storage system, the second remedial action comprising locking down the snapshot that will be used to restore the data to the uncorrupted state.

2. The method of claim 1 , wherein the first remedial action further comprises one or more of providing a notification, preventing a second snapshot from being deleted or modified, or modifying a data protection parameter set for a third snapshot.

3. The method of claim 1 , further comprising determining, by the data protection system subsequent to the performing the second remedial action, that the storage system is no longer being targeted by the security threat.

4. The method of claim 3 , further comprising directing, by the data protection system based on the determining that the storage system is no longer being targeted by the security threat, the storage system to revert back to performing the first security threat detection process.

5. The method of claim 1 , wherein the second security threat detection process is performed in response to the determining that the storage system is possibly being targeted by the security threat.

6. The method of claim 1 , wherein the second security threat detection process is performed in parallel with the first security threat detection process.

7. The method of claim 1 , wherein the data protection system is implemented by a controller within the storage system.

8. The method of claim 1 , wherein the data protection system is implemented by a computing system communicatively coupled to the storage system by way of a network.

9. The method of claim 1 , wherein the determining that the storage system is possibly being targeted by the security threat comprises determining that a ransomware attack is possibly operating against the storage system.

10. A system comprising:

a memory storing instructions; and

one or more processors communicatively coupled to the memory and configured to execute the instructions to perform a process comprising:

determining, based on a first security threat detection process, that a storage system is possibly being targeted by a security threat;

performing, based on the determining that the storage system is possibly being targeted by the security threat, a first remedial action with respect to the storage system, the first remedial action comprising generating a snapshot of data stored by the storage system to restore the data to an uncorrupted state when confirmed that the data is corrupted;

confirming, based on a second security threat detection process, whether the storage system is possibly being targeted by the security threat;

continuing, when the confirming comprises determining that the storage system is not being targeted by the security threat, to perform the first security threat detection process; and

performing, when the confirming comprises determining that the storage system is being targeted by the security threat, a second remedial action with respect to the storage system, the second remedial action comprising locking down the snapshot that will be used to restore the data to the uncorrupted state.

11. The system of claim 10 , wherein the first remedial action further comprises one or more of providing a notification, preventing a second snapshot from being deleted or modified, or modifying a data protection parameter set for a third snapshot.

12. The system of claim 10 , wherein the process further comprises determining, subsequent to the performing the second remedial action, that the storage system is no longer being targeted by the security threat.

13. The system of claim 12 , wherein the process further comprises directing, based on the determining that the storage system is no longer being targeted by the security threat, the storage system to revert back to performing the first security threat detection process.

14. The system of claim 10 , wherein the second security threat detection process is performed in response to the determining that the storage system is possibly being targeted by the security threat.

15. The system of claim 10 , wherein the second security threat detection process is performed in parallel with the first security threat detection process.

16. The system of claim 10 , wherein the determining that the storage system is possibly being targeted by the security threat comprises determining that a ransomware attack is possibly operating against the storage system.

17. A non-transitory computer-readable medium storing instructions that, when executed, direct a processor of a computing device to perform a process comprising:

determining, based on a first security threat detection process, that a storage system is possibly being targeted by a security threat;

performing, based on the determining that the storage system is possibly being targeted by the security threat, a first remedial action with respect to the storage system, the first remedial action comprising generating a snapshot of data stored by the storage system to restore the data to an uncorrupted state when confirmed that the data is corrupted;

confirming, based on a second security threat detection process, whether the storage system is possibly being targeted by the security threat; and

continuing, when the confirming comprises determining that the storage system is not being targeted by the security threat, to perform the first security threat detection process; and

performing, when the confirming comprises determining that the storage system is being targeted by the security threat, a second remedial action with respect to the storage system, the second remedial action comprising locking down the snapshot that will be used to restore the data to the uncorrupted state.

18. The non-transitory computer-readable medium of claim 17 , wherein the first remedial action further comprises one or more of providing a notification, preventing a second snapshot from being deleted or modified, or modifying a data protection parameter set for a third snapshot.

19. The non-transitory computer-readable medium of claim 17 , wherein the process further comprises determining, subsequent to the performing the second remedial action, that the storage system is no longer being targeted by the security threat.

20. The non-transitory computer-readable medium of claim 19 , wherein the process further comprises directing, based on the determining that the storage system is no longer being targeted by the security threat, the storage system to revert back to performing the first security threat detection process.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2024
From: KUTNER, ANDREW; KARR, RONALD; MILLER, ANDREW; LEE, PATRICK D.; HUSKISSON, DAVID; CARPENTER, BRIAN; DOTE, CYNTHIA
To: PURE STORAGE, INC.
Reel/Frame 066440/0885 →
Continuity (6)
Continuation 18141545 · May 1, 2023
Continuation 16917030 · Jun 30, 2020
Continuation In Part 16711060 · Dec 11, 2019
Provisional Application 62985229 · Mar 4, 2020
Provisional Application 62939518 · Nov 22, 2019
Related Publication 20240184886A1 · Jun 6, 2024
References Cited (75)
US 7149858B1 · Kiselev · 2006 [cited by examiner]
US 8132260B1 · Mayer · 2012 [cited by examiner]
US 8468604B2 · Claudatos · 2013 [cited by examiner]
US 9338181B1 · Burns · 2016 [cited by examiner]
US 9350750B1 · Aval · 2016 [cited by examiner]
US 9386009B1 · Marion · 2016 [cited by examiner]
US 9477693B1 · Bachu · 2016 [cited by examiner]
US 9729572B1 · Adams · 2017 [cited by examiner]
US 9904587B1 · Potlapally · 2018 [cited by examiner]
US 9916849B1 · Mader · 2018 [cited by examiner]
US 9923910B2 · Di Pietro · 2018 [cited by examiner]
US 9930061B2 · Zandani · 2018 [cited by examiner]
US 9954884B2 · Hassell · 2018 [cited by examiner]
US 10042697B2 · Ahad · 2018 [cited by examiner]
US 10078473B2 · Ahmed · 2018 [cited by examiner]
US 10102356B1 · Sahin · 2018 [cited by examiner]
US 10120887B1 · Patel · 2018 [cited by examiner]
US 10122740B1 · Finkelshtein · 2018 [cited by examiner]
US 10122752B1 · Soman · 2018 [cited by examiner]
US 10169601B2 · Arasan · 2019 [cited by examiner]
US 10409986B1 · Natanzon · 2019 [cited by examiner]
US 10503427B2 · Botes et al. · 2019 [cited by applicant]
US 10503897B1 · Striem-Amit · 2019 [cited by examiner]
US 10628586B1 · Jung · 2020 [cited by examiner]
US 10725965B1 · Rokicki · 2020 [cited by examiner]
US 10810088B1 · Gu · 2020 [cited by examiner]
US 10992581B2 · Kuang · 2021 [cited by examiner]
US 11036392B2 · Resch · 2021 [cited by examiner]
US 11212681B1 · Balaramn · 2021 [cited by examiner]
US 20020035683A1 · Kaashoek · 2002 [cited by examiner]
US 20020038436A1 · Suzuki · 2002 [cited by examiner]
US 20050193236A1 · Stager · 2005 [cited by examiner]
US 20080047013A1 · Claudatos · 2008 [cited by examiner]
US 20100005173A1 · Baskaran · 2010 [cited by examiner]
US 20100031361A1 · Shukla · 2010 [cited by examiner]
US 20110125716A1 · Drews · 2011 [cited by examiner]
US 20140289853A1 · Teddy · 2014 [cited by examiner]
US 20160164918A1 · Satish · 2016 [cited by examiner]
US 20160352518A1 · Ford · 2016 [cited by examiner]
US 20170054686A1 · Malkov · 2017 [cited by examiner]
US 20170063534A1 · Brown · 2017 [cited by examiner]
US 20170277596A1 · Kyathanahalli · 2017 [cited by examiner]
US 20170364681A1 · Roguine · 2017 [cited by examiner]
US 20170374083A1 · Cohen · 2017 [cited by examiner]
US 20180024893A1 · Sella · 2018 [cited by examiner]
US 20180032758A1 · Wang · 2018 [cited by examiner]
US 20180054454A1 · Astigarraga · 2018 [cited by examiner]
US 20180139053A1 · Kadam · 2018 [cited by examiner]
US 20180198765A1 · Maybee · 2018 [cited by examiner]
US 20180248896A1 · Challita · 2018 [cited by examiner]
US 20180278647A1 · Gabaev · 2018 [cited by examiner]
US 20190042744A1 · Rajasekharan · 2019 [cited by examiner]
US 20190081981A1 · Bansal · 2019 [cited by examiner]
US 20190108099A1 · Mazumdar · 2019 [cited by examiner]
US 20190188385A1 · Selvaraj · 2019 [cited by examiner]
US 20190245881A1 · Ward · 2019 [cited by examiner]
US 20190319980A1 · Levy · 2019 [cited by examiner]
US 20190319987A1 · Levy · 2019 [cited by examiner]
US 20190354443A1 · Haustein · 2019 [cited by examiner]
US 20200019470A1 · Wolfson · 2020 [cited by examiner]
US 20200134049A1 · Bassov · 2020 [cited by examiner]
US 20200233959A1 · Spurlock · 2020 [cited by examiner]
US 20200356686A1 · Vijayvargiya · 2020 [cited by examiner]
US 20200364128A1 · Vittal · 2020 [cited by examiner]
US 20200364429A1 · Yang · 2020 [cited by examiner]
US 20210042411A1 · Annen · 2021 [cited by examiner]
US 20210096957A1 · Rahman et al. · 2021 [cited by applicant]
US 20210117377A1 · Savir · 2021 [cited by examiner]
US 20210255938A1 · Baker · 2021 [cited by examiner]
US 20210374096A1 · Von Hein · 2021 [cited by examiner]
US 20220150241A1 · Nadiminti et al. · 2022 [cited by applicant]
US 20220229909A1 · Shachar · 2022 [cited by examiner]
US 20240184886A1 · Kutner · 2024 [cited by examiner]
US 20240356959A1 · Jeyakumar · 2024 [cited by examiner]
International Search Report and Written Opinion for International Application No. PCT/US2023/023859, mailed Sep. 20, 2023, 13 pages. [cited by applicant]
Cited By (1)
US 12,561,428