Multi-Cloud Failover for Ransomware Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for recovering from ransomware attacks often result in extended downtime for production sites due to the need for forensic investigation and cleansing, leading to significant business disruption and loss.
Innovation Solution
Implementing a temporary failover site, such as a public cloud site, to replicate production site assets and data, allowing continuous operation during site evaluation and quick resumption of normal operations upon site restoration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the production site is shut down for forensic investigation and cleansing, then the site can be securely restored, but production operations are stopped and business is lost
Solution Approach 1:
The patent creates a copy of the production site in a cloud environment. This copy includes replicated assets, data, and configurations that can be independently operated while the original site undergoes forensic investigation and cleansing. The copy allows business continuity without compromising the security clearance process of the original site.
Solution Approach 2:
The patent segments the production site into a primary site and a cloud-based failover site. This segmentation allows the primary site to be isolated for security purposes while the secondary site continues operations. The segmentation separates the forensic investigation process from business operations, enabling parallel processing of both activities.
2Reliability
If the production site is restored after forensic investigation, then normal operations can resume, but the restoration process takes several hours and business is disrupted
Solution Approach 1:
The patent performs preliminary actions by continuously replicating production site assets, data, and configurations to the cloud environment before any failure or forensic investigation occurs. This pre-positioned copy is ready for immediate activation, eliminating the need for lengthy restoration processes during critical recovery periods.
Solution Approach 2:
The patent maintains an ongoing copy of the production site in the cloud, including real-time synchronization of data differentials. When restoration is needed, this pre-existing copy can be activated immediately, reducing restoration time from hours to minutes while ensuring the site is fully functional and up-to-date.
3Productivity
If a failover site is created to continue operations, then production can continue during site evaluation, but the system complexity increases
Solution Approach 1:
The patent introduces a cloud-based intermediary platform that simplifies the failover process. The cloud environment acts as a mediator between the primary production site and the failover site, providing automated replication, synchronization, and activation capabilities. This intermediary layer reduces the operational complexity of managing failover without requiring complex on-premises infrastructure.
Solution Approach 2:
The patent designs the cloud-based failover site to serve multiple functions: it acts as a backup destination, a failover target, a forensic isolation environment, and a business continuity platform. This multi-functionality reduces the need for separate systems and simplifies the overall architecture by consolidating multiple purposes into a single versatile platform.
4Loss of time
If data is replicated to the failover site, then quick failback is possible, but the replication process requires additional resources and time
Solution Approach 1:
The patent performs preliminary replication of production site data to the cloud failover site continuously or near-real-time. This pre-positioned data is ready for immediate failback activation, eliminating the need for large-scale data transfer during critical recovery periods. The preliminary action ensures fast failback while distributing the replication workload over time rather than concentrating it during emergency moments.
Data Source
AI summary
One example method includes receiving, at a remote site from a production site, copies of production site assets, storing, at the remote site, the copies of the production site assets, using, at the remote site, the copies of the production site assets to restore a temporary production site, running the temporary production site at the remote site, and restoring, from the remote site to the production site, the copies of the production site assets.


