IP Library Granted Patent US 12,476,992
Granted Patent B2
US 12,476,992 · App. 18/516,505 · Granted Nov 18, 2025

Scalable automated training framework

Inventors: Oscar Annen (San Jose, CA); Sumeet Bharatbhai Varma (Sunnyvale, CA); Guilherme Vale Ferreira Menezes (San Jose, CA); Stephen Chu (San Francisco, CA); Mohit Gupta (Palo Alto, CA)
Assignee: Rubrik, Inc.
H04L63/1425G06F9/45558G06F16/953G06F18/214G06F21/566G06F21/577G06N20/00H04L63/1416H04L63/1433G06F2009/4557G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,476,992
App. No.
18/516,505
Filed
Nov 21, 2023
Granted
Nov 18, 2025
Kind
B2
Art Unit
2407
USPC
726/23
Abstract

Techniques for implementing a scalable automated training framework for anomaly and ransomware detection are disclosed. In some embodiments, a computer system performs operations comprising: instantiating a plurality of virtual machines, each one of the virtual machines being loaded with a corresponding file system; simulating user actions and ransomware on the virtual machines, the simulating of user actions and ransomware on the virtual machines causing changes to the corresponding file systems of the virtual machines; for each one of the plurality of virtual machines, generating a corresponding metadata file based on one or more corresponding snapshots of the virtual machine, the one or more corresponding snapshots indicating the changes to the corresponding file system of the virtual machine; and training a ransomware detection model using a machine learning algorithm and training data, the training data being based on the corresponding metadata files of the virtual machines.

Claims (57)

1 . A method, comprising:

executing, by a computer system that comprises one or more memories and one or more processors and is configured for performance of data backups and malware detection, a computer program that simulates a plurality of user actions on a plurality of virtual machines in the presence of simulated malware, wherein the plurality of virtual machines are associated with corresponding file systems, and wherein simulating the plurality of user actions causes a plurality of changes to the corresponding file systems associated with the plurality of virtual machines;

storing, by the computer system, training data in a metadata store of the computer system, wherein:

the training data is based at least in part on simulating the plurality of user actions on the plurality of virtual machines in the presence of the simulated malware, and

the training data comprises the plurality of changes to the corresponding file systems of the plurality of virtual machines; and

training a machine learning model for malware detection based at least in part on the training data.

2 . The method of claim 1 , wherein training the machine learning model for the malware detection comprises:

training the machine learning model for detection of a first type of malware from among a plurality of candidate malware types based at least in part on a subset of training data from among the training data, wherein the subset of training data is associated with the first type of malware.

3 . The method of claim 1 , further comprising:

obtaining, after executing the computer program that simulates the plurality of user actions on the plurality of virtual machines, a plurality of snapshots of the plurality of virtual machines, wherein the plurality of snapshots indicate the plurality of changes to the corresponding file systems associated with the plurality of virtual machines, and wherein the training data is based at least in part on the plurality of snapshots.

4 . The method of claim 3 , further comprising:

obtaining, for a virtual machine of the plurality of virtual machines, a first snapshot at a first point in time, the first snapshot comprising a first set of changes to a corresponding file system of the virtual machine at the first point in time;

obtaining, for the virtual machine, a second snapshot at a second point in time, the second snapshot comprising a second set of changes to the corresponding file system of the virtual machine at the second point in time; and

comparing the second set of changes included in the second snapshot with the first set of changes included in the first snapshot, wherein generating the training data is based at least in part on the comparing.

5 . The method of claim 1 , wherein executing the computer program to simulate the plurality of user actions comprises:

simulating manipulation, selection, or both of one or more elements of a user interface associated with the plurality of virtual machines.

6 . The method of claim 1 , wherein executing the computer program to simulate the plurality of user actions comprises:

simulating navigation of one or more resources of an operating system of a virtual machine of the plurality of virtual machines.

7 . The method of claim 1 , wherein executing the computer program to simulate the plurality of user actions comprises:

simulating navigation of the Internet via a web browser.

8 . The method of claim 1 , further comprising:

detecting, based at least in part on the machine learning model trained using the training data, whether malware is preset on the plurality of virtual machines.

9 . The method of claim 1 , further comprising:

detecting, based at least in part on the machine learning model trained using the training data, whether malware is preset on a computing device that is different than the plurality of virtual machines.

10 . The method of claim 1 , further comprising:

generating, based at least in part on simulating the plurality of user actions, a plurality of metadata files for the plurality of virtual machines, wherein the plurality of metadata files comprise the training data for the malware detection.

11 . The method of claim 1 , wherein the simulated malware comprises simulated ransomware on the plurality of virtual machines.

12 . The method of claim 1 , wherein the training data is associated with training the machine learning model that comprises a deep neural network, a logistic regression, or both.

13 . An apparatus configured for performance of data backups and malware detection, comprising:

one or more memories storing processor-executable code; and

one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to:

execute, by the apparatus, a computer program that simulates a plurality of user actions on a plurality of virtual machines in the presence of simulated malware, wherein the plurality of virtual machines are associated with corresponding file systems, and wherein simulating the plurality of user actions causes a plurality of changes to the corresponding file systems associated with the plurality of virtual machines;

store, by the apparatus, training data in a metadata store of the apparatus, wherein:

the training data is based at least in part on simulating the plurality of user actions on the plurality of virtual machines in the presence of the simulated malware, and

the training data comprises the plurality of changes to the corresponding file systems of the plurality of virtual machines; and

train a machine learning model for malware detection based at least in part on the training data.

14 . The apparatus of claim 13 , wherein, to train the machine learning model, the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:

train the machine learning model for detection of a first type of malware from among a plurality of candidate malware types based at least in part on a subset of training data from among the training data, wherein the subset of training data is associated with the first type of malware.

15 . The apparatus of claim 13 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:

obtain, after executing the computer program that simulates the plurality of user actions on the plurality of virtual machines, a plurality of snapshots of the plurality of virtual machines, wherein the plurality of snapshots indicate the plurality of changes to the corresponding file systems associated with the plurality of virtual machines, and wherein the training data is based at least in part on the plurality of snapshots.

16 . The apparatus of claim 15 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:

obtain, for a virtual machine of the plurality of virtual machines, a first snapshot at a first point in time, the first snapshot comprising a first set of changes to a corresponding file system of the virtual machine at the first point in time;

obtain, for the virtual machine, a second snapshot at a second point in time, the second snapshot comprising a second set of changes to the corresponding file system of the virtual machine at the second point in time; and

compare the second set of changes included in the second snapshot with the first set of changes included in the first snapshot, wherein generating

the training data is based at least in part on the comparing.

17 . The apparatus of claim 13 , wherein, to execute the computer program to simulate the plurality of user actions, the one or more processors are individually or collectively operable to execute the code to cause the apparatus to:

simulate manipulation, selection, or both of one or more elements of a user interface associated with the plurality of virtual machines.

18 . The apparatus of claim 13 , wherein, to execute the computer program to simulate the plurality of user actions, the one or more processors are individually or collectively operable to execute the code to cause the apparatus to:

simulate navigation of one or more resources of an operating system of a virtual machine of the plurality of virtual machines.

19 . A non-transitory computer-readable medium storing code, the code comprising instructions executable by one or more processors to:

execute, by a computer system that comprises one or more memories and one or more processors and is configured for performance of data backups and malware detection, a computer program that simulates a plurality of user actions on a plurality of virtual machines in the presence of simulated malware, wherein the plurality of virtual machines are associated with corresponding file systems, and wherein simulating the plurality of user actions causes a plurality of changes to the corresponding file systems associated with the plurality of virtual machines;

store, by the computer system, training data in a metadata store of the computer system, wherein:

the training data is based at least in part on simulating the plurality of user actions on the plurality of virtual machines in the presence of the simulated malware, and

the training data comprises the plurality of changes to the corresponding file systems of the plurality of virtual machines; and

train a machine learning model for malware detection based at least in part on the generated training data.

20 . The non-transitory computer-readable medium of claim 19 , wherein, to train the machine learning model, the instructions are executable by the one or more processors to:

train the machine learning model for detection of a first type of malware from among a plurality of candidate malware types based at least in part on a subset of training data from among the training data, wherein the subset of training data is associated with the first type of malware.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2025
From: ANNEN, OSCAR; VARMA, SUMEET BHARATBHAI; MENEZES, GUILHERME VALE FERREIRA; CHU, STEPHEN; GUPTA, MOHIT
To: RUBRIK, INC.
Reel/Frame 070072/0037 →
Continuity (2)
Continuation 17162808 · Jan 29, 2021
Related Publication 20240089282A1 · Mar 14, 2024
References Cited (87)
US 7181768B1 · Ghosh et al. · 2007 [cited by applicant]
US 7765217B2 · Yamakawa et al. · 2010 [cited by applicant]
US 7802300B1 · Liu et al. · 2010 [cited by applicant]
US 7934103B2 · Kidron · 2011 [cited by applicant]
US 7941855B2 · Sung et al. · 2011 [cited by applicant]
US 7962956B1 · Liao et al. · 2011 [cited by applicant]
US 9116722B2 · Shenfield et al. · 2015 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9734337B1 · Patton et al. · 2017 [cited by applicant]
US 9779240B2 · Feroz et al. · 2017 [cited by applicant]
US 10032033B2 · Gu et al. · 2018 [cited by applicant]
US 10229269B1 · Patton et al. · 2019 [cited by applicant]
US 10572993B2 · Tanaka et al. · 2020 [cited by applicant]
US 10867040B2 · Gibbons et al. · 2020 [cited by applicant]
US 10929031B2 · Sapuntzakis et al. · 2021 [cited by applicant]
US 10992699B1 · Sites · 2021 [cited by examiner]
US 11086987B2 · Brown · 2021 [cited by applicant]
US 11120131B2 · Chen et al. · 2021 [cited by applicant]
US 11170104B1 · Stickle et al. · 2021 [cited by applicant]
US 11449607B2 · Annen et al. · 2022 [cited by applicant]
US 11522889B2 · Annen et al. · 2022 [cited by applicant]
US 11606379B1 · Pratt · 2023 [cited by examiner]
US 11657152B2 · Kraemer et al. · 2023 [cited by applicant]
US 11770391B1 · Bakthavatchalam · 2023 [cited by examiner]
US 20060074824A1 · Li · 2006 [cited by applicant]
US 20080127346A1 · Oh et al. · 2008 [cited by applicant]
US 20080209138A1 · Sheldon et al. · 2008 [cited by applicant]
US 20090055604A1 · Lemar et al. · 2009 [cited by applicant]
US 20100125911A1 · Bhaskaran · 2010 [cited by applicant]
US 20130305373A1 · Lim et al. · 2013 [cited by applicant]
US 20140013434A1 · Ranum et al. · 2014 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150264077A1 · Berger et al. · 2015 [cited by applicant]
US 20160012227A1 · Tuvell et al. · 2016 [cited by applicant]
US 20160239661A1 · Kawauchi · 2016 [cited by applicant]
US 20160292418A1 · Wojnowicz et al. · 2016 [cited by applicant]
US 20170053118A1 · Malkov et al. · 2017 [cited by applicant]
US 20170063906A1 · Muddu et al. · 2017 [cited by applicant]
US 20170103334A1 · Gusev et al. · 2017 [cited by applicant]
US 20170180394A1 · Crofton et al. · 2017 [cited by applicant]
US 20170195353A1 · Taylor · 2017 [cited by examiner]
US 20170214708A1 · Gukal et al. · 2017 [cited by applicant]
US 20170315979A1 · Boucher et al. · 2017 [cited by applicant]
US 20170339178A1 · Mahaffey et al. · 2017 [cited by applicant]
US 20180034835A1 · Iwanir et al. · 2018 [cited by applicant]
US 20180173874A1 · Muttik et al. · 2018 [cited by applicant]
US 20180211039A1 · Tamir et al. · 2018 [cited by applicant]
US 20180307839A1 · Bhave et al. · 2018 [cited by applicant]
US 20190042744A1 · Rajasekharan et al. · 2019 [cited by applicant]
US 20190163763A1 · Pandey et al. · 2019 [cited by applicant]
US 20190171966A1 · Rangasamy · 2019 [cited by applicant]
US 20190235973A1 · Brewer et al. · 2019 [cited by applicant]
US 20190236272A1 · Piatt · 2019 [cited by applicant]
US 20190286534A1 · O'Mahony et al. · 2019 [cited by applicant]
US 20190332766A1 · Guri et al. · 2019 [cited by applicant]
US 20190332769A1 · Fralick et al. · 2019 [cited by applicant]
US 20190347418A1 · Strogov et al. · 2019 [cited by applicant]
US 20190347578A1 · Bolding et al. · 2019 [cited by applicant]
US 20190354850A1 · Watson et al. · 2019 [cited by applicant]
US 20200004808A1 · Yao et al. · 2020 [cited by applicant]
US 20200004962A1 · Araujo et al. · 2020 [cited by applicant]
US 20200034537A1 · Chen et al. · 2020 [cited by applicant]
US 20200042703A1 · Herman et al. · 2020 [cited by applicant]
US 20200076812A1 · Spurlock et al. · 2020 [cited by applicant]
US 20200089886A1 · Oetken · 2020 [cited by applicant]
US 20200177612A1 · Kras et al. · 2020 [cited by applicant]
US 20200279043A1 · Thornton et al. · 2020 [cited by applicant]
US 20200311595A1 · Chen et al. · 2020 [cited by applicant]
US 20200342652A1 · Rowell · 2020 [cited by examiner]
US 20210034994A1 · Stocker et al. · 2021 [cited by applicant]
US 20210042411A1 · Annen et al. · 2021 [cited by applicant]
US 20210044603A1 · Annen et al. · 2021 [cited by applicant]
US 20210044604A1 · Annen et al. · 2021 [cited by applicant]
US 20210089957A1 · Ermans et al. · 2021 [cited by applicant]
US 20210374027A1 · Joglekar · 2021 [cited by examiner]
US 20220247766A1 · Annen et al. · 2022 [cited by applicant]
US 20220318203A1 · Kotwal et al. · 2022 [cited by applicant]
US 20230004749A1 · Jaganathan · 2023 [cited by examiner]
US 20230026368A1 · Silverstein · 2023 [cited by examiner]
US 20230105500A1 · Annen et al. · 2023 [cited by applicant]
US 20240430278A1 · Tyborowski · 2024 [cited by examiner]
CN 106845223A · 2017 [cited by applicant]
KR 101772439B1 · 2017 [cited by applicant]
KR 101828600B1 · 2018 [cited by applicant]
WO 2020028152A1 · 2020 [cited by applicant]
International Preliminary Report on Patentability received for PCT Patent Application No. PCT/US19/43563, mailed on Feb. 11, 2021, 8 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US19/43563, mailed on Oct. 29, 2019, 9 pages. [cited by applicant]