IP Library Granted Patent US 10,409,986
Granted Patent B1
US 10,409,986 · App. 15/275,768 · Granted Sep 10, 2019

Ransomware detection in a continuous data protection environment

Inventors: Assaf Natanzon (Tel Aviv, IL); Sorin Faibish (Newton, MA); Philip Derbeko (Modi'in, IL)
Assignee: EMC IP HOLDING COMPANY LLC
G06F21/554G06F12/1408G06F21/56G06F2212/1052G06F2212/402
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,409,986
App. No.
15/275,768
Granted
Sep 10, 2019
Kind
B1
Abstract

A computer program product, system, and method for generating coded fragments comprises intercepting, at a splitter, a write request from a host to storage, the write request comprising write data; sending the write request to a data protection appliance (DPA); calculating a probability of ransomware within the host; if the probability of ransomware is less than or equal to a first threshold, sending an acknowledgement (ACK) to the splitter; if the probability of ransomware is greater than a first threshold value and less than or equal to a second threshold value, creating a bookmark and sending an ACK to the splitter; and if the probability of ransomware is greater than the second threshold value, sending a delayed ACK to the splitter.

Claims (40)

1. A method for use in a storage system comprising:

intercepting a write request from a host to the storage system, the write request comprising write data;

adding the write data to a list of recent write data and determining a probability that the write data is actually encrypted by calculating an entropy over the list of recent write data;

calculating a probability of ransomware within the host based upon the probability that the write data is actually encrypted;

if the probability of ransomware is less than or equal to a first threshold, sending an acknowledgement (ACK) without delay from the storage system to the host;

if the probability of ransomware is greater than a first threshold value and less than or equal to a second threshold value, creating a bookmark that is associated with a point in time corresponding to the data, storing the bookmark in the storage system, and sending an ACK without delay from the storage system to the host; and

if the probability of ransomware is greater than the second threshold value, sending a delayed ACK from the storage system to the host.

2. The method of claim 1 wherein intercepting the write request from a host to storage comprises intercepting the write request at a splitter, the method further comprising:

sending the write request from the splitter to a data protection appliance (DPA), wherein sending an acknowledgement (ACK) comprises sending an acknowledgement (ACK) from the DPA to the splitter.

3. The method of claim 2 further comprising:

sending the write request to the storage after the splitter receives an ACK from the DPA.

4. The method of claim 1 further comprising:

if the probability of ransomware is greater than the second threshold value, notifying a user of suspected ransomware.

5. The method of claim 1 wherein determining a probability that the write data is actually encrypted comprises calculating an entropy of the write data.

6. The method of claim 1 wherein determining the probability that the write data is expected to be encrypted comprises determining a percentage of the storage that is encrypted.

7. The method of claim 1 wherein the write request further comprises an offset within the storage, wherein determining the probability that the write data is expected to be encrypted comprises determining whether encrypted data was previously written to the offset within the storage.

8. The method of claim 1 wherein determining the probability that the write data is expected to be encrypted comprises determining one or more applications running on the host.

9. A system comprising:

one or more processors;

a volatile memory; and

a non-volatile memory storing computer program code that when executed on the processor causes execution across the one or more processors of a process operable to perform the operations of:

intercepting a write request from a host to a storage system, the write request comprising write data;

adding the write data to a list of recent write data and determining a probability that the write data is actually encrypted by calculating an entropy over the list of recent write data;

calculating a probability of ransomware within the host based upon the probability that the write data is actually encrypted;

if the probability of ransomware is less than or equal to a first threshold, sending to an acknowledgement (ACK) to the host;

if the probability of ransomware is greater than a first threshold value and less than or equal to a second threshold value, creating a bookmark that is associated with a point in time corresponding to the data, storing the bookmark in the storage system, and sending an ACK to the host; and

if the probability of ransomware is greater than the second threshold value, sending a delayed ACK to the host.

10. The system of claim 9 wherein the computer program code causes execution of a process further operable to perform the operations of:

if the probability of ransomware is greater than the second threshold value, notifying a user of suspected ransomware.

11. The system of claim 9 wherein determining a probability that the write data is actually encrypted comprises calculating an entropy of the write data.

12. The system of claim 9 wherein determining the probability that the write data is expected to be encrypted comprises determining a percentage of the storage that is encrypted.

13. The system of claim 9 wherein the write request further comprises an offset within the storage, wherein determining the probability that the write data is expected to be encrypted comprises determining whether encrypted data was previously written to the offset within the storage.

14. The system of claim 9 wherein determining the probability that the write data is expected to be encrypted comprises determining one or more applications running on the host.

15. A computer program product tangibly embodied in a non-transitory computer-readable medium, the computer-readable medium storing program instructions that are executable to:

intercept a write request from a host to a storage system, the write request comprising write data;

add the write data to a list of recent write data and determining a probability that the write data is actually encrypted by calculating an entropy over the list of recent write data;

calculate a probability of ransomware within the host based upon the probability that the write data is actually encrypted;

if the probability of ransomware is less than or equal to a first threshold, send an acknowledgement (ACK) to the host;

if the probability of ransomware is greater than a first threshold value and less than or equal to a second threshold value, create a bookmark that is associated with a point in time corresponding to the data, storing the bookmark in the storage system, and sending an ACK to the host; and

if the probability of ransomware is greater than the second threshold value, send a delayed ACK to the host.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (051302/0528) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.); SECUREWORKS CORP.
Reel/Frame 060438/0593 →
RELEASE OF SECURITY INTEREST AT REEL 051449 FRAME 0728 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
Reel/Frame 058002/0010 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Dec 31, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 051449/0728 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 16, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 051302/0528 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2016
From: NATANZON, ASSAF; FAIBISH, SORIN; DERBEKO, PHILIP
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 039995/0264 →
Cited By (10)
US 12,204,657 US 12,235,954 US 12,248,566 US 12,411,962 US 12,423,411 US 12,518,010 US 12,554,397 US 12,554,844 US 12,561,428 US 12,675,373