Learn about ONTAP Autonomous Ransomware Protection
Autonomous Ransomware Protection is built directly into ONTAP to perform workload analysis in NAS and SAN environments, proactively detecting and warning about abnormal activity that might indicate a ransomware attack. It operates in real-time, processing data as it is written to or read from storage, and responds automatically to protect data.
Beginning with ONTAP 9.16.1, Autonomous Ransomware Protection uses a pre-trained machine-learning model (ARP/AI) that provides immediate active protection with no learning period required. It supports both NAS (ONTAP 9.16.1 and later) and SAN (ONTAP 9.17.1 and later) volumes. For ONTAP 9.10.1 through 9.15.1, the original Autonomous Ransomware Protection (ARP) model supports NAS environments and requires a learning period before active detection begins.
Current documentation for your ONTAP version
ARP/AI is the current default model for ONTAP 9.16.1 and later. The original ARP model applies to ONTAP 9.10.1 through 9.15.1. Select the documentation for your ONTAP version:
-
ARP/AI (ONTAP 9.16.1 and later): Machine-learning model with immediate active protection, SAN support, and automatic security updates.
-
ARP (ONTAP 9.10.1 to 9.15.1): NAS-focused with a learning period before active protection begins. Also applies to FlexGroup volumes on ONTAP 9.16.1 and 9.17.1.
|
|
The original ARP model received no new functional improvements after ONTAP 9.14.1. If you are running ONTAP 9.16.1 or later on FlexVol volumes, use the ARP/AI documentation. FlexGroup volumes use the original ARP model through ONTAP 9.17.1 and are supported by ARP/AI beginning with ONTAP 9.18.1. |
Licenses for Autonomous Ransomware Protection
Autonomous Ransomware Protection support is included with the ONTAP One license. If you do not have the ONTAP One license, other licenses are available for Autonomous Ransomware Protection usage that differ depending on your version of ONTAP.
| ONTAP releases | License |
|---|---|
ONTAP 9.11.1 and later |
|
ONTAP 9.10.1 |
|
-
If you are upgrading from ONTAP 9.10.1 to ONTAP 9.11.1 or later and Autonomous Ransomware Protection is already configured on your system, you do not need to install the new
Anti-ransomwarelicense. For new Autonomous Ransomware Protection configurations, the new license is required. -
If you are reverting from ONTAP 9.11.1 or later to ONTAP 9.10.1, and you have enabled Autonomous Ransomware Protection with the
Anti_ransomwarelicense, you will see a warning message and might need to reconfigure. Learn about reverting Autonomous Ransomware Protection.
ONTAP ransomware protection strategy
Effective ransomware protection requires many layers of protection working together.
While ONTAP includes features like FPolicy, snapshots, SnapLock, and Active IQ Digital Advisor (also known as Digital Advisor) to help protect from ransomware, Autonomous Ransomware Protection provides an additional layer of defense.
To learn more about other features in the NetApp portfolio that safeguard against ransomware, see:
Autonomous Ransomware Protection with AI (ARP/AI) and legacy ARP feature comparison
| Model | ARP | ARP/AI |
|---|---|---|
ONTAP versions |
ONTAP 9.10.1 to 9.15.1 |
ONTAP 9.16.1 and later |
Detection method |
Analyzes file activity, data entropy, and file extension types |
AI/machine learning model trained on large forensic datasets; analyzes entropy and file behavior |
Learning period |
Requires 30-day learning mode for NAS FlexVol volumes (auto-switch available in ONTAP 9.13.1 and later) |
No learning period; active immediately upon enablement |
Volume type support |
|
|
Snapshot creation |
Triggered by high entropy, new file extensions, or file operation surges |
Created on attack confirmation (ONTAP 9.16.1). Beginning with ONTAP 9.17.1, snapshots also created at fixed 4-hour intervals. |
Snapshot retention |
Retained until admin clears suspect activity |
12-hour default; extended based on attack confirmation (24 hours for false positive, 7 days for confirmed positive) |
Updates |
Static detection logic (updated with ONTAP upgrades only) |
Automatic security updates independent of ONTAP releases |
Deployment |
Manual enablement per volume or SVM-level default setting |
Manual enablement per volume or SVM-level default setting; default enablement on all new volumes at cluster level for supported systems in ONTAP 9.18.1 and later |
Evaluation period |
Not applicable |
Required for SAN volumes (2-4 weeks) to establish baseline encryption thresholds. Also required for NAS FlexVol volumes with ONTAP-detected hypervisor virtual disks beginning with ONTAP 9.17.1. |
Multi-admin verification
Beginning with ONTAP 9.13.1, it's recommended that you enable multi-admin verification (MAV) so that two or more authenticated user admins are required for Autonomous Ransomware Protection configuration. For more information, see Enable multi-admin verification.