IP Library Patent Application 19362067
Patent Application
App. No. 19/362,067

SUPPORTING NON-SNAPPABLE DATA SOURCES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/362,067
Abstract

Methods, systems, and devices for data management are described. One or more requests to apply data observation to one or more data sources may be received via an interface. Whether snapshots are supported for the one or more data sources may be determined. A first, snapshot-supported data source may be stored at a first data storage as a snapshot and a representation of the second, snapshot-unsupported data source may be stored at a second data storage. First data may be extracted from the snapshot and second data may be extracted from the representation of the second data source such that a first data observation procedure may be applied to the first data and a second data observation procedure may be applied to the second data. Results of the data observation procedures may be reported via an interface.

Claims (77)

1 . A method, comprising:

receiving, at an interface of a data management system that supports taking snapshots, one or more requests to apply one or more data observation procedures to a first data source;

determining, by the data management system, in response to the one or more requests, that snapshots are unsupported for the first data source;

initiating, by the data management system, based at least in part on snapshots being unsupported for the first data source, a procedure for storing a representation of the first data source at a data storage having data versioning capabilities;

extracting, by the data management system, data from the representation of the first data source stored at the data storage;

performing, by the data management system, a data observation procedure of the one or more data observation procedures for the data extracted from the representation of the first data source; and

reporting, via the interface, a first result of the data observation procedure.

2 . The method of claim 1 , further comprising:

receiving, at the interface, a second request to apply a second data observation procedure to a second data source that comprises sensitive information, wherein the data observation procedure is configured to identify the sensitive information in the second data source;

determining, in response to the second request, that snapshots are unsupported for the second data source;

extracting, based at least in part on the second data source comprising the sensitive information, second data from the second data source in a data stream; and

performing a third data observation procedure for the data stream.

3 . The method of claim 1 , wherein the data observation procedure is a procedure for identifying threats in the data, and wherein performing the data observation procedure further comprises:

extracting a plurality of versions of the data from the data storage;

analyzing, after extracting the plurality of versions of the data, the plurality of versions of the data relative to one another; and

determining, based at least in part on the analyzing, whether one or more anomalies, one or more malware signatures, or both, are identified for the data.

4 . The method of claim 1 , further comprising:

storing, a plurality of representations of the first data source, in the data storage, the plurality of representations corresponding to a plurality of versions of the first data source.

5 . The method of claim 4 , wherein the plurality of versions of the first data source comprise one or more full versions and one or more incremental versions.

6 . The method of claim 1 , further comprising:

receiving, after storing the representation of the first data source at the data storage, a request to restore the first data source to a point-in-time; and

initiating, in response to the request to restore the first data source, a procedure for restoring the first data source to the point-in-time using one or more representations of the first data source stored at the data storage.

7 . The method of claim 1 , further comprising:

storing file-system data, metadata, or both, of the first data source at the data storage, wherein the data extracted from the representation of the first data source comprises the file-system data, the metadata or both.

8 . The method of claim 1 , further comprising:

receiving, at the interface, a request to process a second data source for which snapshots are supported, the request prohibiting snapshots from being taken for the second data source, prohibiting second data of the second data source from being stored, or both;

extracting, based at least in part on the request prohibiting the second data from being stored, the second data from the second data source in a data stream without storing the second data in the data storage; and

performing a second data observation procedure for the data stream.

9 . An apparatus, comprising:

one or more memories storing processor-executable code; and

one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to:

receive, at an interface of a data management system that supports taking snapshots, one or more requests to apply one or more data observation procedures to a first data source;

determine, by the data management system, in response to the one or more requests, that snapshots are unsupported for the first data source;

initiate, by the data management system, based at least in part on snapshots being unsupported for the first data source, a procedure for storing a representation of the first data source at a data storage having data versioning capabilities;

extract, by the data management system, data from the representation of the first data source stored at the data storage;

perform, by the data management system, a data observation procedure of the one or more data observation procedures for the data extracted from the representation of the first data source; and

report, via the interface, a first result of the data observation procedure.

10 . The apparatus of claim 9 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:

receive, at the interface, a second request to apply a second data observation procedure to a second data source that comprises sensitive information, wherein the data observation procedure is configured to identify the sensitive information in the second data source;

determine, in response to the second request, that snapshots are unsupported for the second data source;

extract, based at least in part on the second data source comprising the sensitive information, second data from the second data source in a data stream; and

perform a third data observation procedure for the data stream.

11 . The apparatus of claim 9 , wherein, to perform the data observation procedure, the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:

extract a plurality of versions of the data from the data storage;

analyze, after extracting the plurality of versions of the data, the plurality of versions of the data relative to one another; and

determine, based at least in part on the analyzing, whether one or more anomalies, one or more malware signatures, or both, are identified for the data.

12 . The apparatus of claim 9 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:

store, a plurality of representations of the first data source, in the data storage, the plurality of representations corresponding to a plurality of versions of the first data source.

13 . The apparatus of claim 12 , wherein:

the plurality of versions of the first data source comprise one or more full versions and one or more incremental versions.

14 . The apparatus of claim 9 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:

receive, after storing the representation of the first data source at the data storage, a request to restore the first data source to a point-in-time; and

initiate, in response to the request to restore the first data source, a procedure for restoring the first data source to the point-in-time using one or more representations of the first data source stored at the data storage.

15 . The apparatus of claim 9 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:

store file-system data, metadata, or both, of the first data source at the data storage, wherein the data extracted from the representation of the first data source comprises the file-system data, the metadata or both.

16 . The apparatus of claim 9 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:

receive, at the interface, a request to process a second data source for which snapshots are supported, the request prohibiting snapshots from being taken for the second data source, prohibiting second data of the second data source from being stored, or both;

extract, based at least in part on the request prohibiting the second data from being stored, the second data from the second data source in a data stream without storing the second data in the data storage; and

perform a second data observation procedure for the data stream.

17 . A non-transitory computer-readable medium storing code, the code comprising instructions executable by one or more processors to:

receive, at an interface of a data management system that supports taking snapshots, one or more requests to apply one or more data observation procedures to a first data source;

determine, by the data management system, in response to the one or more requests, that snapshots are unsupported for the first data source;

initiate, by the data management system, based at least in part on snapshots being unsupported for the first data source, a procedure for storing a representation of the first data source at a data storage having data versioning capabilities;

extract, by the data management system, data from the representation of the first data source stored at the data storage;

perform, by the data management system, a data observation procedure of the one or more data observation procedures for the data extracted from the representation of the first data source; and

report, via the interface, a first result of the data observation procedure.

18 . The non-transitory computer-readable medium of claim 17 , wherein the instructions are further executable by the one or more processors to:

receive, at the interface, a second request to apply a second data observation procedure to a second data source that comprises sensitive information, wherein the data observation procedure is configured to identify the sensitive information in the second data source;

determine, in response to the second request, that snapshots are unsupported for the second data source;

extract, based at least in part on the second data source comprising the sensitive information, second data from the second data source in a data stream; and

perform a third data observation procedure for the data stream.

19 . The non-transitory computer-readable medium of claim 17 , wherein the instructions to perform the data observation procedure are further executable by the one or more processors to:

extract a plurality of versions of the data from the data storage;

analyze, after extracting the plurality of versions of the data, the plurality of versions of the data relative to one another; and

determine, based at least in part on the analyzing, whether one or more anomalies, one or more malware signatures, or both, are identified for the data.

20 . The non-transitory computer-readable medium of claim 17 , wherein the instructions are further executable by the one or more processors to:

store, a plurality of representations of the first data source, in the data storage, the plurality of representations corresponding to a plurality of versions of the first data source.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2025
From: CHINNI, MANJUNATH; KATURI, SAI KIRAN; BAWASKAR, SWAPNIL; DEVEGOWDA, MANJUNATHA; IRVIN, JAMES; NGUYEN, VAN HOANG THUY; JAIN, KAMNA
To: RUBRIK, INC.
Reel/Frame 073173/0701 →