- Patent Title: Ransomware detection in a continuous data protection environment
-
Application No.: US15275768Application Date: 2016-09-26
-
Publication No.: US10409986B1Publication Date: 2019-09-10
- Inventor: Assaf Natanzon , Sorin Faibish , Philip Derbeko
- Applicant: EMC IP Holding Company LLC
- Applicant Address: US MA Hopkinton
- Assignee: EMC IP HOLDING COMPANY LLC
- Current Assignee: EMC IP HOLDING COMPANY LLC
- Current Assignee Address: US MA Hopkinton
- Agency: Daly, Crowley Mofford & Durkee, LLP
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F12/14 ; G06F21/56

Abstract:
A computer program product, system, and method for generating coded fragments comprises intercepting, at a splitter, a write request from a host to storage, the write request comprising write data; sending the write request to a data protection appliance (DPA); calculating a probability of ransomware within the host; if the probability of ransomware is less than or equal to a first threshold, sending an acknowledgement (ACK) to the splitter; if the probability of ransomware is greater than a first threshold value and less than or equal to a second threshold value, creating a bookmark and sending an ACK to the splitter; and if the probability of ransomware is greater than the second threshold value, sending a delayed ACK to the splitter.
Information query