IP Library › Granted Patent US 12,393,494
Granted Patent B2
US 12,393,494 · App. 18/475,331 · Granted Aug 19, 2025

Determining risks in data backups

Inventors: Louie A. Dickens (Vernon, AZ); Tara Astigarraga (Fairport, NY); Maunik Patel (Tucson, AZ); Robert Efrain Jenkins (Leander, TX)
Assignee: International Business Machines Corporation
G06F11/1464H04L63/08H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,393,494
App. No.
18/475,331
Granted
Aug 19, 2025
Kind
B2
Abstract

Embodiments of the present invention provide computer-implemented methods, computer program product, and computer systems. One or more processors, in response to receiving a request to execute a backup operation, determine that backup software targeted to perform the request includes a signature associated with training data. The one or more processors, in response to determining that the backup software targeted to perform the received request has a signature in the associated training data, executing one or more actions, wherein the one or more actions comprise one or more processors to authenticate a user and an internet protocol (IP) address originating the request. The one or more processors calculate a risk, associated with the user, based on employee information associated with the user.

Claims (47)

1. A computer-implemented method comprising:

in response to receiving a request to execute a backup operation, determining that backup software targeted to perform the request includes a signature associated with training data; and

in response to determining that the backup software targeted to perform the received request has a signature in the associated training data, executing one or more actions, wherein the one or more actions comprise:

authenticating a user and an internet protocol (IP) address originating the request; and

calculating a risk, associated with the user, based on employee information associated with the user.

2. The computer-implemented method of claim 1 , further comprising:

in response to the risk associated with the user meeting requirements for low risk, authorizing the request to execute the backup operation.

3. The computer-implemented method of claim 1 , wherein the one or more actions further comprise:

verifying that the backup operation does not violate legal policies; and

verifying that the backup operation does not violate cybersecurity policies.

4. The computer-implemented method of claim 1 , wherein the signature is located in one or more of locations comprising previous backups and publicly available databases.

5. The computer-implemented method of claim 1 , wherein the employee information comprises employee user identity, employee name, employee function, previous predetermined time employee read/write access, corporate directory, and employee information.

6. The computer-implemented method of claim 1 , wherein IP information associated with the IP address comprises internal IP structure information, internal IP low level details, employee IP specific information, and well-known corporate backup/restore IP address.

7. The computer-implemented method of claim 1 , further comprising:

in response to determining that backup software targeted to perform the received request does not a signature in the associated training data, identifying known differences between a known datafile and data captured as the signature of the backup software.

8. A computer program product comprising:

one or more computer readable storage media and program instructions stored on the one or more computer readable storage media, the program instructions comprising:

program instructions to, in response to receiving a request to execute a backup operation, determining that backup software targeted to perform the request includes a signature associated with training data; and

program instructions to, in response to determining that the backup software targeted to perform the received request has a signature in the associated training data, executing one or more actions, wherein the one or more actions comprise:

program instructions to authenticate a user and an internet protocol (IP) address originating the request; and

program instructions to calculate a risk, associated with the user, based on employee information associated with the user.

9. The computer program product of claim 8 , wherein the program instructions stored on the one or more computer readable storage media further comprise:

program instructions to, in response to the risk associated with the user meeting requirements for low risk, authorize the request to execute the backup operation.

10. The computer program product of claim 8 , wherein the one or more actions further comprise:

program instructions to verify that the backup operation does not violate legal policies; and

program instructions to verify that the backup operation does not violate cybersecurity policies.

11. The computer program product of claim 8 , wherein the signature is located in one or more of locations comprising previous backups and publicly available databases.

12. The computer program product of claim 8 , wherein the employee information comprises employee user identity, employee name, employee function, previous predetermined time employee read/write access, corporate directory, and employee information.

13. The computer program product of claim 8 , wherein IP information associated with the IP address comprises internal IP structure information, internal IP low level details, employee IP specific information, and well-known corporate backup/restore IP address.

14. The computer program product of claim 8 , wherein the program instructions stored on the one or more computer readable storage media further comprise:

program instructions to, in response to determining that backup software targeted to perform the received request does not a signature in the associated training data, identify known differences between a known datafile and data captured as the signature of the backup software.

15. A computer system comprising:

one or more computer processors;

one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media for execution by at least one of the one or more computer processors, the program instructions comprising:

program instructions to, in response to receiving a request to execute a backup operation, determining that the backup software targeted to perform the request includes a signature associated with training data; and

program instructions to, in response to determining that backup software targeted to perform the received request has a signature in the associated training data, executing one or more actions, wherein the one or more actions comprise:

program instructions to authenticate a user and an internet protocol (IP) address originating the request; and

program instructions to calculate a risk, associated with the user, based on employee information associated with the user.

16. The computer system of claim 15 , wherein the program instructions stored on the one or more computer readable storage media further comprise:

program instructions to, in response to the risk associated with the user meeting requirements for low risk, authorize the request to execute the backup operation.

17. The computer system of claim 15 , wherein the one or more actions further comprise:

program instructions to verify that the backup operation does not violate legal policies; and

program instructions to verify that the backup operation does not violate cybersecurity policies.

18. The computer system of claim 15 , wherein the signature is located in one or more of locations comprising previous backups and publicly available databases.

19. The computer system of claim 15 , wherein the employee information comprises employee user identity, employee name, employee function, previous predetermined time employee read/write access, corporate directory, and employee information.

20. The computer system of claim 15 , wherein IP information associated with the IP address comprises internal IP structure information, internal IP low level details, employee IP specific information, and well-known corporate backup/restore IP address.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2023
From: DICKENS, LOUIE A.; ASTIGARRAGA, TARA; PATEL, MAUNIK; JENKINS, ROBERT EFRAIN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 065041/0230 →
Continuity (1)
Related Publication 20250103441A1 · Mar 27, 2025
References Cited (19)
US 10423782B2 · Muttik · 2019 [cited by applicant]
US 10810088B1 · Gu · 2020 [cited by applicant]
US 10887339B1 · Sokolov · 2021 [cited by applicant]
US 11244047B2 · Muttik · 2022 [cited by applicant]
US 20180173874A1 · Muttik · 2018 [cited by applicant]
US 20200034532A1 · Muttik · 2020 [cited by applicant]
US 20240111633A1 · Yadav · 2024 [cited by examiner]
US 20240320207A1 · Palm · 2024 [cited by examiner]
US 20240403170A1 · Av · 2024 [cited by examiner]
Anonymous, “Cloud Toolchain and DevOps Optimization”, An IP.com Prior Art Database Technical Disclosure, Authors et al.: Disclosed Anonymously, IP.com No. IPCOM000266229D, IP.com Electronic Publication Date: Jun. 24, 20… [cited by applicant]
Anonymous, “Enhanced Data Security within Backup Systems”, An IP.com Prior Art Database Technical Disclosure, Authors et al.: Disclosed Anonymously, IP.com No. IPCOM000250429D, IP.com Electronic Publication Date: Jul. 1… [cited by applicant]
Anonymous, “Hybrid Cloud With Security and Compliance”, Opus Interactive, provided by inventors on Aug. 31, 2023, 8 pages. [cited by applicant]
Anonymous, “IBM Targets Ransomware, Other Cyberattacks with Next-Generation Flash Storage Offerings”, IBM, Feb. 8, 2022, <https://newsroom.IBM.com/2022-02-08-IBM-Targets-Ransomware,-Other-Cyberattacks-with-Next-Generati… [cited by applicant]
Anonymous, “Immutable Backups Are Crucial To Enterprise Hybrid Cloud Security”, Veritas, White Paper, May 2023, 5 pages. [cited by applicant]
Anonymous, “System and Method for Automated Cloud Backup Distribution”, An IP.com Prior Art Database Technical Disclosure, Authors et al.: Disclosed Anonymously, IP.com No. IPCOM000250428D, IP.com Electronic Publication… [cited by applicant]
Anonymous, “System and Method of Validating Changes for Database in Multi-Cloud Environment”, An IP.com Prior Art Database Technical Disclosure, Authors et al.: Disclosed Anonymously, IP.com No. IPCOM000259425D, IP.com … [cited by applicant]
Anonymous, “System and Method to Strategize Cloud Object Migrations”, An IP.com Prior Art Database Technical Disclosure, Authors et al.: Disclosed Anonymously, IP.com No. IPCOM000271804D, IP.com Electronic Publication D… [cited by applicant]
Chandramouli et al., “Security Guidelines for Storage Infrastructure”, NIST Special Publication 800-209, Oct. 2020, <https://doi.org/10.6028/NIST.SP.800-209>, 79 pages. [cited by applicant]
Kim et al., “Security of Data on NVMe over Fabrics, The Armored Truck Way”, SNIA NSF, Live Webcast May 12, 2021, <https://www.snia.org/educational-library/security-data-nvme-over-fabrics-armored-truck-way-2021>, 34 page… [cited by applicant]