Skip to main content

Learn about ONTAP Autonomous Ransomware Protection

Contributors netapp-dbagwell netapp-ahibbard netapp-aaron-holt netapp-lenida netapp-aherbin netapp-forry netapp-adlove pixelchrome netapp-thomi netapp-barbe

Autonomous Ransomware Protection is built directly into ONTAP to perform workload analysis in NAS and SAN environments, proactively detecting and warning about abnormal activity that might indicate a ransomware attack. It operates in real-time, processing data as it is written to or read from storage, and responds automatically to protect data.

Beginning with ONTAP 9.16.1, Autonomous Ransomware Protection uses a pre-trained machine-learning model (ARP/AI) that provides immediate active protection with no learning period required. It supports both NAS (ONTAP 9.16.1 and later) and SAN (ONTAP 9.17.1 and later) volumes. For ONTAP 9.10.1 through 9.15.1, the original Autonomous Ransomware Protection (ARP) model supports NAS environments and requires a learning period before active detection begins.

Current documentation for your ONTAP version

ARP/AI is the current default model for ONTAP 9.16.1 and later. The original ARP model applies to ONTAP 9.10.1 through 9.15.1. Select the documentation for your ONTAP version:

  • ARP/AI (ONTAP 9.16.1 and later): Machine-learning model with immediate active protection, SAN support, and automatic security updates.

  • ARP (ONTAP 9.10.1 to 9.15.1): NAS-focused with a learning period before active protection begins. Also applies to FlexGroup volumes on ONTAP 9.16.1 and 9.17.1.

Note The original ARP model received no new functional improvements after ONTAP 9.14.1. If you are running ONTAP 9.16.1 or later on FlexVol volumes, use the ARP/AI documentation. FlexGroup volumes use the original ARP model through ONTAP 9.17.1 and are supported by ARP/AI beginning with ONTAP 9.18.1.

Licenses for Autonomous Ransomware Protection

Autonomous Ransomware Protection support is included with the ONTAP One license. If you do not have the ONTAP One license, other licenses are available for Autonomous Ransomware Protection usage that differ depending on your version of ONTAP.

ONTAP releases License

ONTAP 9.11.1 and later

Anti_ransomware

ONTAP 9.10.1

MT_EK_MGMT (Multi-Tenant Key Management)

  • If you are upgrading from ONTAP 9.10.1 to ONTAP 9.11.1 or later and Autonomous Ransomware Protection is already configured on your system, you do not need to install the new Anti-ransomware license. For new Autonomous Ransomware Protection configurations, the new license is required.

  • If you are reverting from ONTAP 9.11.1 or later to ONTAP 9.10.1, and you have enabled Autonomous Ransomware Protection with the Anti_ransomware license, you will see a warning message and might need to reconfigure. Learn about reverting Autonomous Ransomware Protection.

ONTAP ransomware protection strategy

Effective ransomware protection requires many layers of protection working together.

While ONTAP includes features like FPolicy, snapshots, SnapLock, and Active IQ Digital Advisor (also known as Digital Advisor) to help protect from ransomware, Autonomous Ransomware Protection provides an additional layer of defense.

To learn more about other features in the NetApp portfolio that safeguard against ransomware, see:

Autonomous Ransomware Protection with AI (ARP/AI) and legacy ARP feature comparison

Model ARP ARP/AI

ONTAP versions

ONTAP 9.10.1 to 9.15.1

ONTAP 9.16.1 and later

Detection method

Analyzes file activity, data entropy, and file extension types

AI/machine learning model trained on large forensic datasets; analyzes entropy and file behavior

Learning period

Requires 30-day learning mode for NAS FlexVol volumes (auto-switch available in ONTAP 9.13.1 and later)

No learning period; active immediately upon enablement

Volume type support

  • FlexVol: ONTAP 9.10.1 to 9.15.1

  • FlexGroup: ONTAP 9.13.1 to 9.17.1

  • SAN: Not supported

  • FlexVol: ONTAP 9.16.1 and later

  • FlexGroup: ONTAP 9.18.1 and later

  • SAN: ONTAP 9.17.1 and later (with evaluation period)

Snapshot creation

Triggered by high entropy, new file extensions, or file operation surges

Created on attack confirmation (ONTAP 9.16.1). Beginning with ONTAP 9.17.1, snapshots also created at fixed 4-hour intervals.

Snapshot retention

Retained until admin clears suspect activity

12-hour default; extended based on attack confirmation (24 hours for false positive, 7 days for confirmed positive)

Updates

Static detection logic (updated with ONTAP upgrades only)

Automatic security updates independent of ONTAP releases

Deployment

Manual enablement per volume or SVM-level default setting

Manual enablement per volume or SVM-level default setting; default enablement on all new volumes at cluster level for supported systems in ONTAP 9.18.1 and later

Evaluation period

Not applicable

Required for SAN volumes (2-4 weeks) to establish baseline encryption thresholds. Also required for NAS FlexVol volumes with ONTAP-detected hypervisor virtual disks beginning with ONTAP 9.17.1.

Multi-admin verification

Beginning with ONTAP 9.13.1, it's recommended that you enable multi-admin verification (MAV) so that two or more authenticated user admins are required for Autonomous Ransomware Protection configuration. For more information, see Enable multi-admin verification.

Related information