IP Library Patent Application 19285964
Patent Application
App. No. 19/285,964

User Behavior Modeling for Detecting and Containing Malicious Activity in a Storage System

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/285,964
Filed
Jul 30, 2025
Art Unit
OPAP
USPC
713/189
Abstract

An illustrative method includes monitoring operations performed with respect to a storage system by an entity using an identity associated with a particular role, the particular role providing the entity with a set of permissions associated with the storage system; determining, based on the monitoring, that one or more operations of the operations deviate from an expected activity profile associated with the role by more than a threshold; and performing, based on the determining that the one or more operations deviate from the expected activity by more than the threshold, a remedial action with respect to the entity.

Claims (41)

1 . A method comprising:

monitoring, by a data protection system, operations performed with respect to a storage system by an entity using an identity associated with a particular role, the particular role providing the entity with a set of permissions associated with the storage system;

determining, by the data protection system based on the monitoring, that one or more operations of the operations deviate from an expected activity profile associated with the role by more than a threshold; and

performing, by the data protection system based on the determining that the one or more operations deviate from the expected activity by more than the threshold, a remedial action with respect to the entity.

2 . The method of claim 1 , wherein the monitoring the operations is performed using a dedicated monitoring service executed by one or more processors within the storage system.

3 . The method of claim 1 , wherein the monitoring the operations is performed using a dedicated monitoring service executed by a cloud-based monitoring system.

4 . The method of claim 1 , wherein the monitoring the operations comprises one or more of:

detecting a volume creation rate associated with the entity;

detecting one or more operations performed by the entity with respect to one or more volumes within the storage system;

detecting one or more volume activity metrics associated with the one or more volumes;

detecting a mount target entropy metric associated with the operations;

detecting one or more replication peer set changes performed by the entity;

detecting a snapshot generation frequency associated with the entity; or

detecting one or more operations performed by the entity with respect to data stored within the storage system;

accessing one or more audit logs associated with the entity; or

accessing data representative of one or more network activity patterns associated with the entity.

5 . The method of claim 1 , wherein the expected activity profile is based on historical activity performed with respect to the storage system by entities associated with the particular role.

6 . The method of claim 5 , wherein:

the historical activity is performed during a rolling lookback period with respect to a current time associated with the monitoring.

7 . The method of claim 6 , wherein the rolling lookback period comprises a plurality of days.

8 . The method of claim 1 , further comprising generating the expected activity profile.

9 . The method of claim 1 , wherein the expected activity profile is based on historical activity performed with respect to one or more storage systems separate from the storage system by entities associated with the particular role.

10 . The method of claim 1 , further comprising updating the threshold based on the determining that the operations deviate from the expected activity profile.

11 . The method of claim 1 , wherein the performing the remedial action comprises providing a notification.

12 . The method of claim 1 , wherein the performing the remedial action comprises throttling the operations performed with respect to the storage system by the entity.

13 . The method of claim 1 , wherein the performing the remedial action comprises modifying the set of permissions.

14 . The method of claim 1 , wherein the performing the remedial action comprises directing the storage system to generate a snapshot of data stored within the storage system.

15 . The method of claim 1 , wherein the performing the remedial action comprises directing the storage system to modify a data protection parameter set for snapshot of data stored within the storage system.

16 . The method of claim 1 , wherein the performing the remedial action comprises triggering a multi-factor authentication requirement for the entity to perform one or more operations with respect to the storage system.

17 . The method of claim 1 , wherein the performing the remedial action comprises preventing one or more configuration settings associated with the storage system from being modified until approval is provided by one or more authorized entities.

18 . The method of claim 1 , wherein the storage system comprises a fleet of storage devices.

19 . A system comprising:

a memory storing instructions; and

one or more processors communicatively coupled to the memory and configured to execute the instructions to perform a process comprising:

monitoring operations performed with respect to a storage system by an entity using an identity associated with a particular role, the particular role providing the entity with a set of permissions associated with the storage system;

determining, based on the monitoring, that one or more operations of the operations deviate from an expected activity profile associated with the role by more than a threshold; and

performing, based on the determining that the one or more operations deviate from the expected activity by more than the threshold, a remedial action with respect to the entity.

20 . A computer program product comprising instructions that, when executed, cause a computing device to perform a process comprising:

monitoring operations performed with respect to a storage system by an entity using an identity associated with a particular role, the particular role providing the entity with a set of permissions associated with the storage system;

determining, based on the monitoring, that one or more operations of the operations deviate from an expected activity profile associated with the role by more than a threshold; and

performing, based on the determining that the one or more operations deviate from the expected activity by more than the threshold, a remedial action with respect to the entity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2025
From: GOTTIPARTHY, ROHIT; KERR, GLEN
To: PURE STORAGE, INC.
Reel/Frame 071884/0413 →