IP Library › Granted Patent US 12,518,007
Granted Patent B2
US 12,518,007 · App. 17/681,144 · Granted Jan 6, 2026

Hybrid data scan pipeline reducing response latency and increasing attack scanning accuracy

Inventors: Huamin Chen (Westboro, MA); Yuval Lifshitz (Ra'anana, IL)
Assignee: Red Hat, Inc.
G06F21/561G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,518,007
App. No.
17/681,144
Granted
Jan 6, 2026
Kind
B2
Abstract

Methods, systems, and computer program products provide a hybrid data scan pipeline or detector that reduces (as compared to conventional storage operations) response latency and increases scanning accuracy of encryption attacks such as ransomware attacks. For example, a frontend of a storage platform receiving an incoming data object may scan a portion of the data object for a change of an entropy level. The portion scanned may be insignificant relative to the overall size of the data object. As such, the operations of the frontend would place an insignificant delay to the overall storage processing. Other portions of the data object will be processed at a backend of the storage platform. For example, subsequent to receiving the data object, a change of entropy level of the other portions is scanned for detecting ransomware attacks.

Claims (46)

1 . A method comprising:

receiving, at a frontend of a storage platform, an incoming object having a first segment and a second segment different from the first segment, the second segment including a number of parallel segments processed by two or more object storage daemons (OSDs);

scanning inline, by a processing device of the frontend of the storage platform, the first segment of the incoming object for a change of an entropy level of the first segment, wherein the scanning inline does not scan the second segment of the incoming object;

scanning offline, subsequent to the receiving and by a backend of the storage platform, the second segment of the incoming object for a change of an entropy level of the second segment, the backend being more computationally powerful than the frontend, wherein the scanning offline of the second segment comprises scanning, by the backend of the storage platform, the second segment of the incoming object during processing of the incoming object for storage at the backend of the storage platform; and

determining an encryption of the incoming object when the change of the entropy level of the first segment or the second segment exceeds a threshold value based on the scanning inline of the first segment and the scanning offline of the second segment.

2 . The method of claim 1 , wherein the change of the entropy level of the first segment and the change of the entropy level of the second segment indicates an encryption by a ransomware to the incoming object.

3 . The method of claim 1 , further comprising:

generating a warning upon detecting the change of the entropy level of the first segment exceeding the threshold value indicating a ransomware encryption; and

generating a metadata record of the scanning offline of the second segment, regardless whether the change of the entropy level of the second segment exceeds the threshold value.

4 . The method of claim 3 , further comprising:

responsive to detecting that the change of the entropy level of the second segment exceeds the threshold value, providing the generated metadata record to an external policy engine for verification of the ransomware encryption.

5 . The method of claim 1 , wherein the first segment comprises an initial subset of the incoming object.

6 . The method of claim 1 , wherein:

the storage platform implements object storage on a distributed computer cluster and provides integrated interfaces for at least one of: object-level, block-level, or file-level storage;

the frontend comprises a presentation layer or protocol of a reliable, autonomous, distributed object store (RADOS) gateway (RGW); and

the backend comprises a data access layer or storage of the two or more OSDs.

7 . A non-transitory computer-readable storage medium having instructions stored thereon that, when executed by a processing device, cause the processing device to:

receive, at a frontend of a storage platform, an incoming object having a first segment and a second segment different from the first segment, the second segment including a number of parallel segments processed by two or more object storage daemons (OSDs);

scan inline, by the processing device of the frontend of the storage platform, the first segment of the incoming object for a change of an entropy level of the first segment, wherein the scanning inline does not scan the second segment of the incoming object;

scan offline, subsequent to the receiving and by a backend of the storage platform, the second segment of the incoming object for a change of an entropy level of the second segment, the backend being more computationally powerful than the frontend and configured to scan the second segment of the incoming object during processing of the incoming object for storage at the backend of the storage platform; and

determine an encryption of the incoming object when the change of the entropy level of the first segment or the second segment exceeds a threshold value based on the scanning inline of the first segment and the scanning offline of the second segment.

8 . The non-transitory computer-readable storage medium of claim 7 , wherein the change of the entropy level of the first segment and the change of the entropy level of the second segment indicates an encryption by a ransomware to the incoming object.

9 . The non-transitory computer-readable storage medium of claim 7 , further comprises instructions stored thereon to cause the processing device to:

generate a warning upon detecting the change of the entropy level of the first segment exceeding the threshold value indicating a ransomware encryption; and

generate a metadata record of the scanning offline of the second segment, regardless whether the change of the entropy level of the second segment exceeds the threshold value.

10 . The non-transitory computer-readable storage medium of claim 9 , further comprises instructions stored thereon to cause the processing device to:

responsive to detecting that the change of the entropy level of the second segment exceeds the threshold value, provide the generated metadata record to an external policy engine for verification of the ransomware encryption.

11 . The non-transitory computer-readable storage medium of claim 7 , wherein the first segment comprises an initial subset of the incoming object.

12 . The non-transitory computer-readable storage medium of claim 7 , wherein:

the storage platform implements object storage on a distributed computer cluster and provides integrated interfaces for at least one of: object-level, block-level, or file-level storage;

the frontend comprises a presentation layer or protocol of a reliable, autonomous, distributed object store (RADOS) gateway (RGW); and

the backend comprises a data access layer or storage of the two or more OSDs.

13 . A system comprising:

a memory; and

a processing device coupled to the memory, to:

receive, at a frontend of a storage platform, an incoming object having a first segment and a second segment different from the first segment, the second segment including a number of parallel segments processed by two or more object storage daemons (OSDs);

scan inline, by the processing device of the frontend, the first segment of the incoming object for a change of an entropy level of the first segment, wherein the scanning inline does not scan the second segment of the incoming object;

scan offline, subsequent to the receiving and by a backend of the storage platform, the second segment of the incoming object for a change of an entropy level of the second segment, the backend being more computationally powerful than the frontend, wherein the scanning offline of the second segment comprises scanning, by the backend of the storage platform, the second segment of the incoming object during processing of the incoming object for storage at the backend of the storage platform; and

determine an encryption of the incoming object when the change of the entropy level of the first segment or the second segment exceeds a threshold value based on the scanning inline of the first segment and the scanning offline of the second segment.

14 . The system of claim 13 , wherein the change of the entropy level of the first segment and the change of the entropy level of the second segment indicates an encryption by a ransomware to the incoming object.

15 . The system of claim 13 , the processing device and the memory further to:

generate a warning upon detecting the change of the entropy level of the first segment exceeding the threshold value indicating a ransomware encryption; and

generate a metadata record of the scanning offline of the second segment, regardless whether the change of the entropy level of the second segment exceeds the threshold value.

16 . The system of claim 15 , the processing device and the memory further to:

responsive to detecting that the change of the entropy level of the second segment exceeds the threshold value, provide the generated metadata record to an external policy engine for verification of the ransomware encryption.

17 . The system of claim 13 , wherein the first segment comprises an initial subset of the incoming object.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2022
From: CHEN, HUAMIN; LIFSHITZ, YUVAL
To: RED HAT, INC.
Reel/Frame 059105/0763 →
Continuity (1)
Related Publication 20230273995A1 · Aug 31, 2023
References Cited (23)
US 8973135B2 · Francis et al. · 2015 [cited by applicant]
US 9575828B2 · Agarwal et al. · 2017 [cited by applicant]
US 9609015B2 · Natarajan et al. · 2017 [cited by applicant]
US 11178172B2 · Hittel et al. · 2021 [cited by applicant]
US 20060026154A1 · Altinel · 2006 [cited by examiner]
US 20110099635A1 · Silberman · 2011 [cited by examiner]
US 20160292419A1 · Langton · 2016 [cited by examiner]
US 20170004306A1 · Zhang · 2017 [cited by examiner]
US 20170024276A1 · Kanno · 2017 [cited by examiner]
US 20180007069A1 · Hunt et al. · 2018 [cited by applicant]
US 20180048658A1 · Hittel · 2018 [cited by examiner]
US 20180212987A1 · Tamir · 2018 [cited by examiner]
US 20190034295A1 · Bourgeois · 2019 [cited by examiner]
US 20190129888A1 · Bowman · 2019 [cited by examiner]
US 20190319987A1 · Levy · 2019 [cited by examiner]
US 20200304539A1 · Chen · 2020 [cited by examiner]
US 20200351277A1 · Dhanabalan · 2020 [cited by examiner]
US 20210021611A1 · Hewlett, II et al. · 2021 [cited by applicant]
US 20230247048A1 · Samosseiko · 2023 [cited by examiner]
US 20230308460A1 · Thomas · 2023 [cited by examiner]
Netskope, “Configure Threat Protection for a Real-time Protection Policy,” https://docs.netskope.com/en/configure-threat protection-for-a-real-time-protection-policy.html, Oct. 7, 2021, 2 pages. [cited by applicant]
Google Cloud, “Automating Malware Scanning for Documents Uploaded to Cloud Storage,” Cloud Architecture Center, https://cloud.google.com/architecture/automating-malware-scanning-for-documents-uploaded-to-cloud-storage, … [cited by applicant]
Davies, Simon R., et al., “Differential Area Analysis for Ransomware Attack Detection within Mixed File Dataset,” School of Computing, Edinburgh Napier University, Edinburgh, UK, Jun. 28, 2021, 13 pages. [cited by applicant]