NetApp Autonomous Ransomware Protection (ARP) integrates with Commvault to automate the response to ransomware events detected by NetApp ONTAP. When ONTAP identifies possible ransomware activity, Commvault validates the event, protects the affected data by starting backup jobs, identifies suspect files in backup data, and creates an approval workflow before updating the event status in NetApp ONTAP.
The integration helps you preserve backup copies, identify potentially compromised files, and restore data without including files that are marked as threats.
Key features
The integration provides the following capabilities:
-
Detect ransomware events from NetApp ONTAP.
-
Protect affected NetApp volumes by starting backup jobs automatically.
-
Validate suspect files against the Commvault index.
-
Mark matching files as threats.
-
Create approval actions in Command Center for security administrators.
-
Update the ARP event in NetApp ONTAP based on the approval decision.
-
Restore backup data without restoring threat-marked files.
How it works
Commvault detects NetApp ARP events by using one of the following methods:
-
Webhook-based response: NetApp ONTAP sends ARP events directly to Commvault.
-
Polling-based response: Commvault polls configured NetApp ONTAP clusters for ARP events by using the ONTAP EMS API.
After Commvault detects an event, it performs the same automated response workflow regardless of the detection method.
Automated response workflow
When Commvault detects a NetApp ARP event, it:
-
Validates the ARP attack state, attack probability, and suspect file data.
-
Determines whether the event has already been processed.
-
Maps the affected NetApp volumes to the corresponding Commvault subclients.
-
Starts backup jobs for the mapped subclients.
-
Validates suspect files against the Commvault index and marks matching files as threats.
-
Creates an approval action in Command Center.
-
Clears the ARP event in NetApp ONTAP based on the approval decision.
-
Sends summary email notifications.
An administrator reviews each approval action in Command Center. If the event is approved, Commvault clears the ARP event in NetApp ONTAP as a true positive. If the event is denied, Commvault clears the event as a false positive.
Monitor and restore data
After Commvault processes an ARP event, you can:
-
View NetApp ARP events as partner signals in Threat Scan.
-
Review files that were marked as threats.
-
Restore backup data without restoring files that are marked as threats.