Invention Grant
- Patent Title: Efficient detection of ransomware attacks within a backup storage environment
-
Application No.: US16876274Application Date: 2020-05-18
-
Publication No.: US11238157B2Publication Date: 2022-02-01
- Inventor: Yossef Saad , Itay Glick
- Applicant: EMC IP Holding Company LLC
- Applicant Address: US MA Hopkinton
- Assignee: EMC IP Holding Company LLC
- Current Assignee: EMC IP Holding Company LLC
- Current Assignee Address: US MA Hopkinton
- Agency: Dergosits & Noah LLP
- Agent Todd A. Noah
- Main IPC: G06F21/56
- IPC: G06F21/56

Abstract:
Described is a system that efficiently detects ransomware attacks within a storage environment. The system may perform a specialized validation by comparing a sampling of backup data obtained from a storage environment with a sampling of data maintained by a specialized validation database. Accordingly, if there is a discrepancy between the samples, the system may issue an alert indicating the original backup data may be encrypted as part of a ransomware attack. The system may utilize the specialized sampling as a validation technique in addition, or as an alternative, to relying on data fingerprints for validation. For example, malicious code may be configured to cause the storage environment to provide fingerprints prior to an unauthorized encryption as an attempt to deceive certain validation processes. Accordingly, to counteract such attempts, the system may rely on the sampling of data, instead of relying solely on a fingerprint comparison.
Public/Granted literature
- US20210357504A1 EFFICIENT DETECTION OF RANSOMWARE ATTACKS WITHIN A BACKUP STORAGE ENVIRONMENT Public/Granted day:2021-11-18
Information query