US2023078476A1PendingUtilityA1
Methods and systems for ransomware protection
Assignee: ZOHO CORPORATION PRIVATE LTDPriority: Sep 16, 2021Filed: Jul 13, 2022Published: Mar 16, 2023
Est. expirySep 16, 2041(~15.1 yrs left)· nominal 20-yr term from priority
G06F 21/565G06F 21/57G06F 21/554G06F 2221/033G06F 21/566G06F 21/602
63
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Described are methods and systems for detecting a ransomware process acting on files organized in folders of a file system. A subfolder path is identified for each file acted upon by a suspect process and the paths are combined into a number of unique paths for the suspect process. If the number of unique paths exceeds a threshold, the suspect process is categorized as malware. The methods and systems also include a hook and a filter to prevent shadow-copy deletions that would otherwise interfere with file recovery.
Claims
exact text as granted — not AI-modified1 . A method for detecting ransomware from a process acting on files organized in folders of a file system, each of the files specified by a file path, the method comprising:
for each of the files acted upon by the process, identifying a subfolder path in the file path of each of the file; combining the subfolder paths into a number of unique process paths; and comparing the number of unique process paths to a folder threshold.
2 . The method of claim 1 , further comprising issuing a ransomware-warning responsive to the comparing if the number of unique process paths exceeds the folder threshold.
3 . The method of claim 1 , wherein each of the folders has a folder-creation time, and wherein identifying the subfolder path for each of the files comprises comparing the folder-creation times of the folders specified in the subfolder path.
4 . The method of claim 3 , wherein identifying the subfolder path for each of the files further comprises comparing a difference between the folder-creation times with a time threshold.
5 . The method of claim 1 , further comprising checking whether the files are encrypted.
6 . The method of claim 5 , wherein the checking comprises applying a machine-learning algorithm to the files.
7 . The method of claim 5 , further comprising issuing a ransomware-warning responsive to the comparing if the number of unique process paths exceeds the folder threshold and at least some of the files are encrypted.
8 . A computer system for detecting ransomware from a process acting on files organized in folders of a file system, each of the files specified by a file path, the system comprising:
an event detection engine to detect events that threaten the files; and a response engine that responds to each of the detected events, the response engine, for each of the files threatened by one of the detected events: identifying a subfolder path in the file path of each of the file; combining the subfolder paths into a number of unique process paths; and comparing the number of unique process paths to a folder threshold.
9 . The computer system of claim 8 , the response engine further issuing a ransomware-warning responsive to the comparing if the number of unique process paths exceeds the folder threshold.
10 . The computer system of claim 8 , wherein each of the folders has a folder-creation time, and wherein identifying the subfolder path for each of the files comprises comparing the folder-creation times of the folders specified in the subfolder path.
11 . The computer system of claim 10 , wherein identifying the subfolder path for each of the files further comprises comparing a difference between the folder-creation times with a time threshold.
12 . The computer system of claim 8 , the response engine further checking whether the files are encrypted.
13 . The computer system of claim 12 , wherein the checking comprises applying a machine-learning algorithm to the files.
14 . The computer system of claim 13 , the response engine further issuing a ransomware-warning responsive to the comparing if the number of unique process paths exceeds the folder threshold and at least some of the files are encrypted.
15 - 17 . (canceled)
18 . A ransomware-protection system instantiated on a computer system including a processor and memory to execute a shadow-copy process that invokes a system call to an operating-system kernel to write a shadow copy of a file in the memory to secondary storage, the shadow-copy process including a hook to intercept a request to alter the shadow copy of the file in the secondary storage.
19 . The ransomware-protection system of claim 18 , the operating-system kernel including a filter to intercept a second request to alter the shadow copy of the file in the secondary storage.
20 . The ransomware-protection system of claim 19 , wherein the second request comprises a request packet.
21 . The ransomware-protection system of claim 18 , wherein the request to alter the shadow copy comprises at least one of a delete request and an overwrite request.
22 . The ransomware-protection system of claim 18 , wherein the hook declines the request to alter the shadow copy of the file.
23 . The ransomware-protection system of claim 22 , wherein the hook informs the shadow-copy process that the request to alter the shadow copy of the file was declined.
24 . The ransomware-protection system of claim 18 , wherein the hook informs the shadow-copy process that the request to alter the shadow copy of the file will be declined.
25 - 29 . (canceled)Join the waitlist — get patent alerts
Track US2023078476A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.