Continuous Data Management for Ransomware Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data management systems face challenges in providing rapid data recovery and ransomware detection, with snapshot-based backup solutions offering poor recovery point objectives (RPOs) and existing ransomware detection methods being ineffective, particularly in real-time scenarios.

Innovation Solution

A disaster recovery system that employs continuous data management (CDM) to monitor compute infrastructure, intercept and replicate virtual disk I/O streams, and form recoverable snapshot-log chains for near-real-time data replication and recovery, enabling RPOs of seconds and rapid ransomware detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If snapshot-based backup is used, then data recovery capability is provided, but recovery point objective (RPO) is poor (tens of minutes to several hours)

Engineering Contradiction:
Improvedata recovery capabilityVSAvoidrecovery point objective
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements continuous data protection by continuously monitoring and replicating data changes to the backup site, eliminating the interruptions and delays inherent in periodic snapshots. This ensures that data is always being backed up without stopping, achieving near-real-time recovery capability.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary actions by continuously preparing backup copies of data changes before actual ransomware attacks occur. The backup infrastructure is pre-configured and continuously updated, so when an attack happens, recovery can immediately begin from the most recent backup point.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If frequent snapshots are taken to improve RPO, then recovery time is reduced, but system performance is impacted and user experience deteriorates

Engineering Contradiction:
Improverecovery point objectiveVSAvoidsystem performance
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

Instead of periodic snapshots that interrupt the system, the patent uses continuous background monitoring and replication of data changes. This continuous action happens transparently without requiring system freezes or interruptions, maintaining both fast recovery capability and system performance.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The backup process is segmented into continuous change detection, data replication, and backup storage operations that run independently in the background. This segmentation allows backup operations to proceed continuously without blocking or impacting the main system operations.

Inventive Principle:
Principle #1Segmentation

3Difficulty of detecting and measuring

If signature-based ransomware detection is used, then detection capability is provided, but detection accuracy is ineffective as ransomware uses different signatures

Engineering Contradiction:
Improveransomware detection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSMeasurement precision

Solution Approach 1:

The system continuously monitors data changes and compares them against established patterns of legitimate operations. When changes deviate from normal behavior patterns, the system triggers alerts and isolation procedures, providing feedback-based detection that adapts to various ransomware variants without relying on fixed signatures.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary layer of continuous monitoring and analysis between the ransomware and the detection system. This intermediary continuously observes data changes, file access patterns, and system behavior, analyzing them for signs of malicious activity without direct confrontation with the ransomware itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Difficulty of detecting and measuring

If behavioral analysis-based ransomware detection is used, then detection capability is improved, but computational resources are taxed

Engineering Contradiction:
Improveransomware detection capabilityVSAvoidcomputational resources
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

Instead of analyzing all system behavior globally, the patent applies focused monitoring at specific critical points where data changes occur. The system monitors only the data access patterns, file modification times, and storage operations that are most indicative of ransomware activity, concentrating computational resources where they are most effective.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial behavioral analysis by monitoring only the most relevant data change patterns rather than attempting complete system analysis. This selective monitoring approach provides sufficient detection capability while significantly reducing the computational burden compared to comprehensive behavioral analysis.

Inventive Principle:
Principle #16Partial or excessive action

5Difficulty of detecting and measuring

If status-based detection systems are used to look for system changes, then detection is provided, but real-time operation is not achieved and rapid notification cannot be provided

Engineering Contradiction:
Improvesystem change detectionVSAvoidreal-time response time
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of time

Solution Approach 1:

The system continuously monitors data changes and backup status in real-time, maintaining constant observation without interruption. This continuous monitoring enables immediate detection and response to ransomware activities, eliminating the delays inherent in periodic status checks.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The backup system is pre-configured with continuous monitoring capabilities that are ready to detect and report ransomware activities immediately upon occurrence. The infrastructure is prepared in advance with monitoring agents and analysis frameworks that can rapidly identify and notify about malicious events without delay.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12019748B2Application migration for cloud data management and ransomware recovery
Publication Date: 2024.06.25 RUBRIK INC
  • US12019748B2 patent drawing
  • US12019748B2 patent drawing
  • US12019748B2 patent drawing

AI summary

Examples relate generally to systems and methods for orchestrating a recovery in the event of a ransomware attack on a compute infrastructure. More specifically, some examples include techniques for application migration in cloud data management, ransomware recovery, and mitigation of lost data.