News: 1649766488

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Backup frustration brought this CTO to forefront of ransomware protection

(2022/04/12)


Interview As CTO of The New York Times two decades ago, Andres Rodriguez became frustrated with the time-consuming and unreliable process of backing up massive amounts of data that was only tested when it failed.

That experience led him in 2008 to launch Nasuni, building what has become a cloud-native global file platform that does away with traditional backups and instead constantly creates new versions of files that are not shipped to a backup system but instead are kept on the cloud-based platform. In addition, everything is managed – both in the cloud and on-premises – via the platform.

Enterprises save money by not having to build extensive backup environments and they can better protect their data, said Rodriguez, who also is now Nasuni's CTO. As an added bonus, the platform also gives organizations more tools to protect against the ongoing threat of ransomware.

[1]

It's not something company officials thought about while building Nasuni's portfolio over the past decade, but it was nice realization.

[2]

[3]

"My entire focus was, 'We can get rid of back up because backup is unreliable and the backup windows take too long,'" he told The Register .

"What I did not foresee was the dramatic chink in the armor of data protection that ransomware was going to throw into the whole backup model. The reason ransomware works is because when you quietly encrypt lots and lots of files and file servers and you do that for long enough that your snapshots are no longer current, your snapshots are no longer holding the healthy parts of your files when you have to go to backup."

[4]

Ransomware groups rely on that, Rodriguez said. Their strategy is predicated on the long time and high costs it takes for a targeted enterprise to copy the data back into the file servers, regardless of what that backup technology is. Once a ransomware attack occurs, data – often terabytes worth of data – needs to be copied and sent from a healthy backup system to unhealthy one in what is rapidly becoming a highly distributed environment.

Attackers also now are targeting backups to increase the odds that organizations will have to pay the ransom.

[5]FIN7 crime-gang pen tester headed to US prison for five years

[6]Borat RAT: Multiple threat of ransomware, DDoS and spyware

[7]'Precursor malware' infection may be sign you're about to get ransomware, says startup

[8]Unit 42: Ransomware demands we're aware of averaged $2.2m last year

"Now you can get both problems: you get the file servers taking a long time to rebuild and you get the many distributed file servers saturating the pipe of the backup media server," he said.

"That pretty much adds up to a kill shot for backup when it comes to unstructured data or files. There's no way to make backup better or faster so that this is no longer a problem. You have to not have to back up the data. The only way not to have to back up the data and still be protected is you have to version the data within the file system."

The threat of ransomware promises to continue to rise as many threat groups shift away from simply deploying their own ransomware code and instead build it and then lease it to others, lowering the barrier to entry for hackers and accelerating the use of ransomware as a weapon. Cybersecurity firm Sophos [9]said [PDF] that in 2020 and 2021, 79 percent of all rapid response calls to incidents involved ransomware.

[10]

Combating ransomware is not just about preventing it, Rodriguez said. Eventually an attack will be successful. What's increasingly important is how quickly a company can recover.

Cybersecurity firms and industry analysts will argue that backing up data can [11]help an organization recover in the case of an attack, but Rodriguez said it's too slow and too costly. Four weeks of downtime for a Fortune 500 company can mean millions, or billions, of dollars in lost revenues and expenses to restore operations, Nick Burling, veep of product management at Nasuni, told The Register . The price can be higher if the company has to pay the ransom.

Burling said he likes to talk about the end of ransomware being in sight, but "it's not because you magically figured out how to prevent attacks. The attack is going to happen. As good as your endpoint protection might be and all of the different tools … the way you make ransomware go away is if you stop customers from ever having to pay it. That's the key thing. No Nasuni customer has ever paid a ransom when using our platform."

The foundation of the platform is the highly scalable UniFS file system that is housed inside Amazon Web Services, Microsoft Azure and Google Cloud. Data protection has always been a function of Nasuni's technology, but in recent years ransomware has become a focus. The vendor's Continuous File Versioning snapshot technology ensures that changes to files wherever they're located are deduplicated compressed and stored as immutable, reads-only objects in cloud storage.

With this, organizations always have the last unaffected version of every file. If a ransomware attack hits, the enterprise can quickly revert back to the latest version from before the attack and restore all the files within minutes, no matter when the attack occurred or the damage it did. Platform users can decide how often to create snapshots of the files.

There also is an auditing system in place that enables enterprises to restore only those files affected by the ransomware attack.

Most recently, the Boston-based company in September introduced a new cloud service called Global File Acceleration that makes hybrid cloud file synchronization up to five times faster by running near real-time analysis to ensure that often-used data is located closer to the company's edge systems for faster retrieval.

"At the end of the day, the file system is the place of record," Rodriguez said. "The difference between a file system that's being backed up and relies on that backup for recovery and a file system that is fully reliant on versioning for that recovery is orders of magnitude in the time that it takes to bring the healthy version of the file system back to the line. That's the game changer."

The response has been good. The company has about 600 customers and last month announced another investment round that [12]netted $60 million , bringing to $148 million that Nasuni has raised over the past five years and [13]$247 million total , according to Crunchbase. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YlWiNXF@twKUNUEri2UT1wAAAEI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YlWiNXF@twKUNUEri2UT1wAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YlWiNXF@twKUNUEri2UT1wAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YlWiNXF@twKUNUEri2UT1wAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/04/07/fin7_pen_tester/

[6] https://www.theregister.com/2022/04/04/borat-rat-ransomware-ddos/

[7] https://www.theregister.com/2022/03/26/lumu-ransomware-precursor-malware/

[8] https://www.theregister.com/2022/03/25/ransomware_unit_42_report/

[9] https://assets.sophos.com/X24WTUEQ/at/b739xqx5jg5w9w7p2bpzxg/sophos-2022-threat-report.pdf

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YlWiNXF@twKUNUEri2UT1wAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2022/04/07/security_driving_down_ransomware_payments/

[12] https://blocksandfiles.com/2022/03/24/nasuni-funding/

[13] https://www.crunchbase.com/organization/nasuni/company_financials

[14] https://whitepapers.theregister.com/



ZFS?

Paul Smith

Is that not just a propitiatory version of ZFS?

Anonymous Coward

I am old enough to have used the old DEC systems that always versioned files when altered. I wish Windows had that as an option. That would not provide the resiliance of read-only remote duplication, but it does save time for recovering from a whole host of issues, which is why things like Sharepoint have a shitty versioning system in the file history.

Doctor Syntax

"the time-consuming and unreliable process of backing up massive amounts of data that was only tested when it failed....a cloud-native global file platform that does away with traditional backups and instead constantly creates new versions of files that are not shipped to a backup system but instead are kept on the cloud-based platform. In addition, everything is managed – both in the cloud and on-premises – via the platform."

If I were in the market for something like this I'd walk away at this point.

As CTO wasn't it his job to test the backup restore process? If he did he'd have made it more reliable and probably less time consuming. And maybe the description under-sells - it probably does - it but if I read it right there's a single platform containing all versions. Lose that platform and...

Anonymous Coward

Let's see: The old files are still held on the nebulous "cloud platform". If they are on the same media then they are equally vulnerable to attack or or loss; If they are on separate media then welcome to "overly complicated backups by another name".

The whole point of off-site backup is that you have a recovery point even if the whole datacenter is destroyed.

Yes, I remember file versioning (I too an an old VAX/VMS alumni), but it wasn't always as useful as you wanted, wasn't always appropriate and burned through space.

Greybearded old scrote

Space is cheap, data is precious.

to version the data within the file system

VoiceOfTruth

You mean like snapshots?

I recovered some systems a few years ago that held a lot of data on NetApps. Average users did not have direct access to the systems, only via mounts from Windows machines. One day, somebody got infected with some malware/ransomware and files started being encrypted. By the time it was noticed a day or so had passed.

"Can you get our files back?", was the question. "I can the whole file system back to how it was yesterday, pre-infection. And for many files I can put them back based on the hourly snapshots", was my reply. "Good enough"...

ZFS can do the same, as Paul Smith writes above.

Yeah

Greybearded old scrote

Snapshots are great, but you still need more than one copy. Otherwise what do you do when your disk array/server/data centre go boom?

Anyone know if the [1]Interplanetary Filing System is any good? Looks interesting.

[1] https://ipfs.io/

Re: Yeah

VoiceOfTruth

In our case the NetApps were replicated to another site. Not quite real time, about 5 minutes behind the 'live' system.

Any particular reason this wasn't tagged as an advertisement?

DrG

See title.

Re: Any particular reason this wasn't tagged as an advertisement?

MiguelC

It is tagged as an interview with the company's CTO, what did you expect?

Humorix Holiday Gift Idea #5

AbsoluteZero(tm) Cryogenic Refrigerator
$29,999.95 for economy model at Cryo-Me-A-River, Inc.

The pundits have been hyping new technology allowing your home appliances to
have Internet access. Most people aren't too keen with the thought of their
refrigerator sharing an IP address with their can opener.

But with the new AbsoluteZero(tm) Refrigerator, that might change. This is not
a fridge for your food -- it's a fridge for your overclocked, overheating CPU.
You stick your computer inside, bolt the door shut, turn the temperature down
to 5 degrees Kelvin, and you've got the perfect environment for accelerating
your CPU to 1 Terahertz or more.

This cryogenic cooling system may not actually reach absolute zero, but it
comes mighty close. Unfortunately, the AbsoluteZero(tm) is the size of a small
house, consumes a constant stream of liquid nitrogen, and requires it's own
nuclear reactor (not included). But that's a small price to pay for the
ability to play Quake 3 at 100,000 frames per second.