Network accessible file server
US-10558622-B2 · Feb 11, 2020 · US
US12301619B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-12301619-B2 |
| Application number | US-202418602687-A |
| Country | US |
| Kind code | B2 |
| Filing date | Mar 12, 2024 |
| Priority date | Dec 22, 2021 |
| Publication date | May 13, 2025 |
| Grant date | May 13, 2025 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A cloud-native global file system, in which one or more filers are associated with a volume of a versioned files system in a private, public or hybrid cloud object store, is augmented to include a rapid ransomware recovery service. Upon detecting a ransomware attack associated with one or more files or directories of the volume, read and write access to the volume is restricted. A recovery filer is then activated or designated in the cloud. A restore operation is then initiated at the recovery filter. Following completion of the restore operation, a new clean (healthy) snapshot of the volume is then created using the recovery filer For any filer other than the recovery filer, a determination is made whether the filer has completed a merge operation with respect to the new clean snapshot. If so, read and write access to the volume is re-enabled from that filer.
Opening claim text (preview).
Having described the subject matter herein, what we claim is as follows: 1. An apparatus to configure and manage storage for an enterprise, comprising: one or more hardware processors; computer memory associated with each hardware processor to hold computer software executed by the hardware processor, wherein the computer software comprises: first computer software configured to receive input data to provision and manage a scalable file system across storage resources associated with at least one cloud-based storage provider, wherein the input data defines a volume, and one or more attributes associated with the volume, wherein the volume is a logical construct representing a point of indirection separating the scalable file system from the storage resources; second computer software configured as a filer to represent, to the enterprise, a local file system whose inode structure and data are stored as a version in the storage resources in a write-once, read-many manner; third computer software configured to detect a ransomware attack; and fourth computer software configured to respond to detection of the ransomware attack to restrict access to the volume, activate or designate an instance of a recovery filer, initiate a restore operation at the recovery filer, create a new clean snapshot of the volume using the recovery filer upon completion of the restore operation, and re-enable access to the volume. 2. The apparatus as described in claim 1 , wherein the restore operation reverses damage to one of: a file in the volume, a directory in the volume, and the entire volume. 3. The apparatus as described in claim 1 , wherein the ransomware attack is detected using machine learning. 4. The apparatus as described in claim 1 , wherein recovery from the ransomware attack is carried out with respect to the volume and not any other volume in the scalable file system. 5. The apparatus as described in claim 1 , wherein recovery from the ransomware attack occurs over a time period measured in minutes with respect to a point-in-time when the ransomware attack is detected.
Backup restoration techniques · CPC title
Event detection, e.g. attack signature detection · CPC title
Using snapshots, i.e. a logical point-in-time copy of the data · CPC title
for networked environments · CPC title
Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.