IP Library › Granted Patent US 12,386,953
Granted Patent B2
US 12,386,953 · App. 17/957,329 · Granted Aug 12, 2025

Using backup meta-data and analytics for detecting cyber-attacks

Inventors: Sunil Yadav (Bangalore, IN); Shelesh Chopra (Bangalore, IN)
Assignee: Dell Products L.P.
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,386,953
App. No.
17/957,329
Granted
Aug 12, 2025
Kind
B2
Abstract

Embodiments of the invention relate to generating backups of assets. More specifically, in one or more embodiments of the invention, the meta-data generated during the backups is leveraged for detecting cyber-attacks by leveraging backup meta-data, to reduce the amount of data that needs to be scanned by a cyber-security module to detect a cyber-attack, such as a ransomware attack. This allows any attacks to be detected earlier and reduce processing by leveraging the periodic backups that are performed as part of data protection, to detect when an attack has or is occurring. By making these determinations, a quick identification of possible ransomware attacks may be made and other methods of mitigating the attack may be deployed when the method of mitigating the attack might still be useful to mitigate potential damage to a user's data.

Claims (52)

1. A method for performing a backup, the method comprising:

initiating, by a user, an initial backup of a production host;

storing a vault copy of the initial backup's meta-data in a vault in a cyber-security module, wherein the vault is a virtualized storage for safely securing the initial backup's meta-data and wherein the vault is not connected to any internal or external networks except when receiving the vault copy or subsequent vault copies from the production host;

periodically performing a subsequent backup of the production host, wherein the subsequent backup of the production host is performed in response to a backup policy or a request of the user;

sending the subsequent backup's meta-data to the cyber-security module, wherein the cyber-security module compares the subsequent backup's meta-data to the vault copy of the initial backup's meta-data to determine where changes have occurred in the production host;

sending to the cyber-security module, first portions of backup data that correspond to the determined changes in the production host shown in the subsequent backup's meta-data;

analyzing, by the cyber-security module, the first portions of the backup data to determine when the first portions of the backup data are corrupted due to a cyber-attack;

notifying the user when the first portions of the backup data are corrupted due to the cyber-attack;

after notifying the user when the first portions are corrupted:

sending to the cyber-security module, a second portion of the backup data that does not correspond to the determined changes in the production host shown in the subsequent backup's meta-data; and

analyzing, by the cyber-security module, the second portion of the backup data that does not correspond to the determined changes in the production host to determine when any third portion of the second portion is corrupted due to the cyber-attack, wherein the user is notified when it is determined that any third portion of the second portion is corrupted due to the cyber-attack.

2. The method of claim 1 , wherein the second portion of the backup data that does not correspond to the determined changes in the production host comprises of less than all of the first portions of the backup data that do not correspond to the determined changes in the production host.

3. The method of claim 2 , wherein the second portion of the backup data that does not correspond to the determined changes in the production hostis selected randomly from all the first portions of the backup data that do not correspond to the determined changes in the production host.

4. The method of claim 2 , wherein the second portion of the backup data that does not correspond to the determined changes in the production host is a predetermined percentage of all of the first portions of the backup data that do not correspond to the determined changes in the production host.

5. The method of claim 4 , wherein the predetermined percentage is determined by the user when the backup is configured.

6. The method of claim 5 , wherein if the cyber-security module detects that the second portion of the backup data that does not correspond to the determined changes in the production host includes corruption, the predetermined percentage is increased by a predetermined amount.

7. A non-transitory computer readable medium comprising computer readable program code, which when executed by a computer processor enables the computer processor to perform a method for performing a backup, the method comprising:

initiating, by a user, an initial backup of a production host;

storing a vault copy of the initial backup's meta-data in a cyber-security module's vault, wherein the vault is a virtualized storage for safely securing the initial backup's meta-data and wherein the vault is not connected to any internal or external networks except when receiving the vault copy or subsequent vault copies from the production host;

periodically performing a subsequent backup of the production host, wherein the subsequent backup of the production host is performed in response to a backup policy or a request of the user;

sending the subsequent backup's meta-data to a cyber-security module, wherein the cyber-security module compares the subsequent backup's meta-data to the vault copy of the initial backup's meta-data to determine where changes have occurred in the production host;

sending, to the cyber-security module, first portions of backup data that correspond to the determined changes in the production host shown in the subsequent backup's meta-data;

analyzing, by the cyber-security module, the first portions of the backup data to determine when the first portions of the backup data are corrupted due to a cyber-attack;

notifying the user when the first portions of the backup data are corrupted due to the cyber-attack;

after notifying the user when the first portions are corrupted:

sending to the cyber-security module, a second portion of the backup data that does not correspond to the determined changes in the production host shown in the subsequent backup's meta-data; and

analyzing by the cyber-security module, the second portion of the backup data that does not correspond to the determined changes in the production host to determine when any third portion of the second portion is corrupted due to the cyber-attack, wherein the user is notified when it is determined that any third portion of the second portion is corrupted due to the cyber-attack.

8. The non-transitory computer readable medium of claim 7 , wherein the second portion of the backup data that does not correspond to the determined changes in the production host comprises of less than all of the first portions of the backup data of the backup that do not correspond to the determined changes in the production host.

9. The non-transitory computer readable medium of claim 8 , wherein the second portion of the backup data that does not correspond to the determined changes in the production host is selected randomly from all the first portions of the backup data that do not correspond to the determined changes in the production host.

10. The non-transitory computer readable medium of claim 8 , wherein the second portion of the backup data that does not correspond to the determined changes in the production host is a predetermined percentage of all of the first portions of the backup data that do not correspond to the determined changes in the production host.

11. The non-transitory computer readable medium of claim 10 , wherein the predetermined percentage is determined by the user when the backup is configured.

12. The non-transitory computer readable medium of claim 11 , wherein if the cyber-security module detects that the second portion of the backup data that does not correspond to the determined changes in the production host includes corruption, the predetermined percentage is increased by a predetermined amount.

13. A system comprising:

a cyber-security module;

a production host; and

a backup agent comprising:

a processor; and

a memory comprising instructions, which when executed by the processor, perform a method for performing a backup, the method comprising:

initiating, by a user of the system, an initial backup of the production host;

storing a vault copy of the initial backup's meta-data in a cyber-security module's vault, wherein the vault is a virtualized storage for safely securing the initial backup's meta-data and wherein the vault is not connected to any internal or external networks except when receiving the vault copy or subsequent vault copies from the production host;

periodically performing a subsequent backup of the production host, wherein the subsequent backup of the production host is performed in response to a backup policy or a request of the user;

sending the subsequent backup's meta-data to the cyber-security module, wherein the cyber-security module compares the subsequent backup's meta-data to the vault copy of the initial backup's meta-data to determine where changes have occurred in the production host;

sending to the cyber-security module, first portions of backup data that correspond to the determined changes in the production host shown in the subsequent backup's meta-data;

analyzing, by the cyber-security module, the first portions of the backup data to determine when the first portions of the backup data are corrupted due to a cyber-attack; and

notifying the user when the first portions of the backup data are corrupted due to the cyber-attack;

after notifying the user when the first portions are corrupted:

sending to the cyber-security module, a second portion of the backup data that does not correspond to the determined changes in the production host shown in the subsequent backup's meta-data; and

analyzing by the cyber-security module, the second portion of the backup data that does not correspond to the determined changes in the production host to determine when any third portion of the second portion is corrupted due to the cyber-attack, wherein the user is notified when it is determined that any third portion of the second portion is corrupted-due to the cyber-attack.

14. The system of claim 13 , wherein the second portion of the backup data that does not correspond to the determined changes in the production host comprises of less than all of the first portions of the backup data that do not correspond to the determined changes in the production host.

15. The system of claim 14 , wherein the second portion of the backup data that does not correspond to the determined changes in the production hostis selected randomly from all the first portions of the backup data that do not correspond to the determined changes in the production host.

16. The system of claim 14 , wherein the second portion of the backup data that does not correspond to the determined changes in the production host is a predetermined percentage of all of the first portions of the backup data that do not correspond to the determined changes in the production host.

17. The system of claim 16 , wherein the predetermined percentage is determined by the user when the backup is configured.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2022
From: YADAV, SUNIL; CHOPRA, SHELESH
To: DELL PRODUCTS L.P.
Reel/Frame 061272/0029 →
Continuity (1)
Related Publication 20240111861A1 · Apr 4, 2024
References Cited (6)
US 7774315B1 · Galker · 2010 [cited by examiner]
US 20150293896A1 · Runkis · 2015 [cited by examiner]
US 20170177867A1 · Crofton · 2017 [cited by examiner]
US 20200241962A1 · Dain · 2020 [cited by examiner]
US 20220237084A1 · Bhagi · 2022 [cited by examiner]
US 20230239321A1 · Doshi · 2023 [cited by examiner]