Ransomware detection and data pruning management
Abstract
This application relates to ransomware detection and data pruning management. Ransomware typically involves an I/O heavy process of encrypting data files and/or deleting or renaming the original files. Thus, ransomware attacks may be detected by analyzing the I/O activity in a given file system. In some embodiments, a software module running on a client machine manages copying, archiving, migrating, and/or replicating of primary data and restoring and/or pruning secondary data (e.g., backup copies of the primary data). When a potential ransomware attack is detected, the software module is immediately stopped so that the software module does not prune any data that may need to be restored. Upon receiving user input that indicates that the client machine is not under a ransomware attack, the software module is allowed to resume its operations, including pruning of the secondary data.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method for detecting file activity anomalies, the method comprising:
causing a copy of primary data associated with a client computing device to be stored in one or more secondary storage devices as part of secondary data associated with the client computing device; removing, at a first time, at least some of the secondary data stored in the one or more secondary storage devices according to a secondary data retention policy associated with the client computing device; detecting, at a second time subsequent to the first time, a file activity anomaly based at least on one or more file system operations performed on the client computing device satisfying one or more threshold conditions associated with the client computing device; in response to detecting the file activity anomaly, disabling removal of the secondary data associated with the client computing device from the one or more secondary storage devices according to the secondary data retention policy; and outputting a notification indicating at least the file activity anomaly.
2 . The computer-implemented method of claim 1 , further comprising:
monitoring file system operations performed on the client computing device over a specific time period preceding the second time; determining a baseline count of file system operations performed on the client computing device over the specific time period; and determining, based at least on the baseline count, at least one threshold condition of the one or more threshold conditions.
3 . The computer-implemented method of claim 2 , wherein the baseline count is an average number of file system operations performed on the client computing device for each sub-period of a plurality of sub-periods within the specific time period.
4 . The computer-implemented method of claim 2 , further comprising determining the at least one threshold condition at least by multiplying the baseline count with a predetermined percentage value, wherein the predetermined percentage value is greater than 100 percent.
5 . The computer-implemented method of claim 2 , further comprising periodically determining whether a current count of file system operations satisfies the one or more threshold conditions for each of a plurality of time periods subsequent to the specific time period and each having a same length as the specific time period.
6 . The computer-implemented method of claim 1 , wherein the one or more file system operations comprise at least one of write operations, create operations, rename operations, or delete operations.
7 . The computer-implemented method of claim 1 , wherein the secondary data retention policy specifies a retention period after which the secondary data is to be removed from the one or more secondary storage devices.
8 . The computer-implemented method of claim 1 , further comprising disabling, in response to detecting the file activity anomaly, backup of the primary data from the client computing device to the one or more secondary storage devices.
9 . The computer-implemented method of claim 1 , further comprising:
determining an indication of an input by a user of the client computing device for clearing the file activity anomaly; and in response to determining the indication of the input, re-enabling removal of the secondary data associated with the client computing device from the one or more secondary storage devices according to the secondary data retention policy.
10 . The computer-implemented method of claim 1 , further comprising:
determining an indication of an input by a user of the client computing device for clearing the file activity anomaly; and in response to determining the indication of the input, updating the one or more threshold conditions such that, subsequent to updating the one or more threshold conditions, a file activity anomaly is not detected for at least a specific type of file system operations.
11 . A system for detecting file activity anomalies, the system comprising:
a client computing device comprising computer hardware and configured to perform one or more file system operations within a file system residing on the client computing device; and one or more secondary storage devices comprising computer hardware and configured to store secondary data associated with the client computing device, wherein the secondary data is a copy of primary data stored on one or more primary storage devices associated with the client computing device, wherein the client computing device configured to:
remove, at a first time, at least some of the secondary data stored in the one or more secondary storage devices according to a secondary data retention policy associated with the client computing device;
detect, at a second time subsequent to the first time, a file activity anomaly based at least on the one or more file system operations satisfying one or more threshold conditions associated with the client computing device;
in response to detecting the file activity anomaly, disable removal of the secondary data associated with the client computing device from the one or more secondary storage devices according to the secondary data retention policy; and
output a notification indicating at least the file activity anomaly.
12 . The system of claim 11 , wherein the client computing device is further configured to:
monitor file system operations performed on the client computing device over a second time period preceding the first time period; determine a baseline count of file system operations performed on the client computing device over the second time period; and determine, based at least on the baseline count, the threshold value for disabling the one or more data protection operations.
13 . The system of claim 12 , wherein the baseline count is an average number of file system operations performed on the client computing device for each sub-period of a plurality of sub-periods within the second time period.
14 . The system of claim 12 , wherein the client computing device is further configured to determine the threshold value by multiplying the baseline count with a predetermined percentage value, wherein the predetermined percentage value is greater than 100 percent.
15 . The system of claim 11 , wherein the set of file system operations comprises at least one of write operations, create operations, rename operations, or delete operations.
16 . The system of claim 11 , wherein the client computing device is further configured to periodically determine whether a current count of file system operations exceeds the threshold value for each of a plurality of time periods subsequent to the first time period and each having a same length as the first time period.
17 . The system of claim 11 , wherein the client computing device is further configured to disable a data aging operation such that the secondary data associated with the client computing device is preserved.
18 . The system of claim 11 , wherein the client computing device is further configured to disable a backup operation associated with the client computing device such that an additional backup copy associated with the client computing device is not created on the one or more secondary storage devices.
19 . The system of claim 11 , wherein the client computing device is further configured to:
determine an indication of an input by a user of the client computing device for clearing the file activity anomaly; and in response to determining the indication of the input, re-enable the one or more data protection operations.
20 . The system of claim 11 , wherein the client computing device is further configured to:
determine an indication of an input by a user of the client computing device for clearing the file activity anomaly; and in response to determining the indication of the input, update one or more rules for disabling the one or more data protection operations such that, subsequent to updating the one or more rules, a file activity anomaly is not detected for at least a specific type of file system operations despite being associated with a count exceeding the threshold value.Join the waitlist — get patent alerts
Track US2019108341A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.