Cloud-Native File System Ransomware Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current ransomware recovery methods are slow and inefficient due to limitations in backup restore technologies, which require time-consuming copy back operations and can be bottlenecked by the output bandwidth of backup media servers.
Innovation Solution
A cloud-native global file system is augmented with a rapid ransomware recovery service that restricts access to affected volumes, activates a recovery filer in the cloud, and initiates a restore operation using audit trails, eliminating the need for copy back operations and enabling rapid recovery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional backup restore technologies are used for ransomware recovery, then recovery capability is provided, but recovery time is slow and tedious
Solution Approach 1:
The system performs preliminary actions by continuously maintaining versioned snapshots of file system metadata and data in the cloud object store before ransomware attacks occur. When an attack is detected, these pre-stored versions are immediately available for restoration without requiring any copy-back operations, enabling rapid recovery from the state before the attack.
Solution Approach 2:
Instead of using traditional backup media servers that require slow copy-back operations, the invention uses cloud-based versioned copies of the entire file system state stored in object storage. These copies are already replicated in the cloud and can be restored instantly, eliminating the bandwidth bottleneck of traditional backup restoration.
2Reliability
If traditional backup media servers are used for restore operations, then data restoration is achieved, but the output bandwidth of backup media servers becomes a bottleneck
Solution Approach 1:
The invention replaces the mechanical copy-back process of traditional backup media servers with a cloud-based object storage system. Data is retrieved from the cloud object store directly to the affected filer, eliminating the intermediate backup media server bottleneck and enabling parallel, high-speed restoration across multiple filers simultaneously.
3Reliability
If multiple file servers are affected by ransomware attacks, then comprehensive coverage is achieved, but the number of affected servers increases the complexity and time of restoration
Solution Approach 1:
The cloud-based versioned file system serves multiple filers simultaneously, providing a universal restoration source for all affected servers. Any filer can restore from the same cloud object store, eliminating the need for separate backup servers for each filer and simplifying the management of multiple restoration operations.
Solution Approach 2:
The system pre-stores versioned snapshots of the entire file system in the cloud for all filers. When multiple filers are affected by ransomware, these pre-stored versions can be restored to all filers simultaneously and independently, reducing the overall restoration time and complexity compared to sequential restoration from a single backup server.
Data Source
AI summary
A cloud-native global file system, in which one or more filers are associated with a volume of a versioned files system in a private, public or hybrid cloud object store, is augmented to include a rapid ransomware recovery service. Upon detecting a ransomware attack associated with one or more files or directories of the volume, read and write access to the volume is restricted. A recovery filer is then activated or designated in the cloud. A restore operation is then initiated at the recovery filter. Following completion of the restore operation, a new clean (healthy) snapshot of the volume is then created using the recovery filer For any filer other than the recovery filer, a determination is made whether the filer has completed a merge operation with respect to the new clean snapshot. If so, read and write access to the volume is re-enabled from that filer.


