メインコンテンツへスキップ

System Managerのダッシュボードにx個のボリュームのアクティビティが異常であると表示されるが、ボリュームのセキュリティタブに[疑わしいファイルタイプを表示]ボタンが表示されない

Views:
8
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
CORE
Last Updated:

環境

問題

  • System Managerの[Events]セクションで、x個のボリュームに異常なアクティビティがあるというアラートが生成されました。
  • [View [Storage]>[Volumes]>[Security] >[Anti-Ransomware]にがないSuspected File Types]ボタン 
  • 新しいファイル拡張子のみに基づくARW攻撃検出。

::> security anti-ransomware volume attack-detection-parameters show -vserver svm1 -volume vol1
                       Vserver Name : svm1
                        Volume Name : vol1
       Is Detection Based on High Entropy Data Rate? : true
  Is Detection Based on Never Seen before File Extension? : true
 Never Seen before File Extensions Count Notify Threshold : 20
    Never Seen before File Extensions Duration in Hour : 24

  • ARW攻撃は、脅威が低いボリュームで報告されます。

::> security anti-ransomware volume show -vserver svm1 -volume vol1

  Vserver Name: svm1
   Volume Name: vol1
   State: enabled
Dry Run Start Time: -
Attack Probability: low
  Attack Timeline: 4/5/2025 12:06:48
 Number of Attacks: 1

  • ワークロード動作の出力にサージが観測されず、Newly Observed File Extensions にエントリが見つかりません。

::> security anti-ransomware volume workload-behavior show -vserver svm1 -volume vol1
                     Vserver: svm1
                      Volume: vol1
             File Extensions Observed: log,...
        Number of File Extensions Observed: 433

 Historical Statistics
        High Entropy Data Write Percentage: 57
  High Entropy Data Write Peak Rate (KB/Minute): 298340
        File Create Peak Rate (per Minute): 9
        File Delete Peak Rate (per Minute): 5
        File Rename Peak Rate (per Minute): 3

 Surge Observed
                 Surge Timeline: -
        High Entropy Data Write Percentage: -
  High Entropy Data Write Peak Rate (KB/Minute): -
        File Create Peak Rate (per Minute): -
        File Delete Peak Rate (per Minute): -
        File Rename Peak Rate (per Minute): -
         Newly Observed File Extensions: -
    Number of Newly Observed File Extensions: -

 

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.

 

  • この記事は役に立ちましたか?