IP Library Granted Patent US 12,373,560
Granted Patent B2
US 12,373,560 · App. 17/994,495 · Granted Jul 29, 2025

System and method for machine learning-based detection of ransomware attacks on a storage system

Inventors: Shaul Dar (Petach Tikva, IL); Ramakanth Kanagovi (Bengaluru, IN); Guhesh Swaminathan (Tamil Nadu, IN); Rajan Kumar (Nawada, IN)
Assignee: Dell Products L.P.
G06F21/568G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,560
App. No.
17/994,495
Granted
Jul 29, 2025
Kind
B2
Abstract

A method, computer program product, and computing system for processing a plurality of input/output (IO) requests associated with a plurality of storage objects of a storage system. A plurality of IO features are generated using the plurality of IO requests. The plurality of IO features are processed using a machine learning model. A ransomware attack on the storage system may be monitored for in real-time based upon, at least in part, the processing of the plurality of IO features using the machine learning model.

Claims (54)

1. A computer-implemented method, executed on a computing device, comprising:

processing a plurality of input/output (IO) requests associated with a plurality of storage objects of a storage system;

generating a plurality of IO features using the plurality of IO requests, wherein each IO request of the plurality of IO requests has a plurality of IO features associated with the IO request;

processing the plurality of IO features using a machine learning model;

monitoring for a ransomware attack on the storage system in real-time based upon, at least in part, the processing of the plurality of IO features using the machine learning model; and

in response to monitoring a ransomware attack, performing a remedial action on the storage system, wherein the remedial action includes suspending one or more IO requests on the storage object.

2. The computer-implemented method of claim 1 , wherein the plurality of storage objects include at least one of a block storage object and a file storage object.

3. The computer-implemented method of claim 1 , wherein the plurality of IO features include one or more of:

a number of IO requests per second (IOPS);

a total number of read IO requests;

a total number of write IO requests;

a percentage of sequential read IO requests; and

a percentage of sequential write IO requests.

4. The computer-implemented method of claim 1 , wherein generating the plurality of IO features using the plurality of IO requests includes:

aggregating the plurality of IO requests periodically; and

generating the plurality of IO features using the aggregated plurality of IO requests.

5. The computer-implemented method of claim 1 , further comprising:

training the machine learning model by processing a plurality of IO requests associated with one or more known ransomware attacks.

6. The computer-implemented method of claim 5 , wherein monitoring for a ransomware attack on the storage system in real-time includes identifying a known ransomware attack based upon, at least in part, the processing of the plurality of IO features using the machine learning model.

7. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

processing a plurality of input/output (IO) requests associated with a plurality of storage objects of a storage system;

generating a plurality of IO features using the plurality of IO requests, wherein each IO request of the plurality of IO requests has a plurality of IO features associated with the IO request;

processing the plurality of IO features using a machine learning model;

monitoring for a ransomware attack on the storage system in real-time based upon, at least in part, the processing of the plurality of IO features using the machine learning model; and

in response to monitoring a ransomware attack, performing a remedial action on the storage system, wherein the remedial action includes suspending one or more IO requests on the storage object.

8. The computer program product of claim 7 , wherein the plurality of storage objects include at least one of a block storage object and a file storage object.

9. The computer program product of claim 7 , wherein the plurality of IO features include one or more of:

a number of IO requests per second (IOPS);

a total number of read IO requests;

a total number of write IO requests;

a percentage of sequential read IO requests; and

a percentage of sequential write IO requests.

10. The computer program product of claim 7 , wherein generating the plurality of IO features using the plurality of IO requests includes:

aggregating the plurality of IO requests periodically; and

generating the plurality of IO features using the aggregated plurality of IO requests.

11. The computer program product of claim 7 , wherein the operations further comprise:

training the machine learning model by processing a plurality of IO requests associated with one or more known ransomware attacks.

12. The computer program product of claim 11 , wherein monitoring for a ransomware attack on the storage system in real-time includes identifying a known ransomware attack based upon, at least in part, the processing of the plurality of IO features using the machine learning model.

13. A computing system comprising:

a memory; and

a processor configured to process a plurality of input/output (IO) requests associated with a plurality of storage objects of a storage system, wherein the processor is further configured to generate a plurality of IO features using the plurality of IO requests, wherein each IO request of the plurality of IO requests has a plurality of IO features associated with the IO request, wherein the processor is further configured to process the plurality of IO features using a machine learning model, wherein the processor is further configured to monitor for a ransomware attack on the storage system in real-time based upon, at least in part, the processing of the plurality of IO features using the machine learning model, and wherein the processor is further configured to, in response to monitoring a ransomware attack, perform a remedial action on the storage system, wherein the remedial action includes suspending one or more IO requests on the storage object.

14. The computing system of claim 13 , wherein the plurality of storage objects include at least one of a block storage object and a file storage object.

15. The computing system of claim 13 , wherein the plurality of IO features include one or more of:

a number of IO requests per second (IOPS);

a total number of read IO requests;

a total number of write IO requests;

a percentage of sequential read IO requests; and

a percentage of sequential write IO requests.

16. The computing system of claim 13 , wherein generating the plurality of IO features using the plurality of IO requests includes:

aggregating the plurality of IO requests periodically; and

generating the plurality of IO features using the aggregated plurality of IO requests.

17. The computing system of claim 13 , wherein the processor is further configured to:

training the machine learning model by processing a plurality of IO requests associated with one or more known ransomware attacks.

18. The computing system of claim 17 , wherein monitoring for a ransomware attack on the storage system in real-time includes identifying a known ransomware attack based upon, at least in part, the processing of the plurality of IO features using the machine learning model.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME: DELL PRODUCTS L.P. PREVIOUSLY RECORDED AT REEL: 061886 FRAME: 0837. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 18, 2023
From: DAR, SHAUL; KANAGOVI, RAMAKANTH; SWAMINATHAN, GUHESH; KUMAR, RAJAN
To: DELL PRODUCTS L.P.
Reel/Frame 062416/0940 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2022
From: DAR, SHAUL; KANAGOVI, RAMAKANTH; SWAMINATHAN, GUHESH; KUMAR, RAJAN
To: DELL PRODUCTS LLP
Reel/Frame 061886/0837 →
Continuity (1)
Related Publication 20240176882A1 · May 30, 2024
References Cited (9)
US 10970395B1 · Bansal · 2021 [cited by examiner]
US 11010474B2 · Hu · 2021 [cited by examiner]
US 20200250522A1 · Meiri · 2020 [cited by examiner]
US 20220083657A1 · Karr · 2022 [cited by examiner]
US 20220092180A1 · Richardson · 2022 [cited by examiner]
US 20220291986A1 · Klein · 2022 [cited by examiner]
US 20220374519A1 · Botelho · 2022 [cited by examiner]
Yang CY, Sahita R. Towards a Resilient Machine Learning Classifier—a Case Study of Ransomware Detection. arXiv preprint arXiv: 2003.06428. Mar. 13, 2020. (Year: 2020). [cited by examiner]
Ayub MA, Continella A, Siraj A. An i/o request packet (irp) driven effective ransomware detection scheme using artificial neural network. In2020 IEEE 21st International Conference on Information Reuse and Integration fo… [cited by examiner]