US2023078476A1PendingUtilityA1

Methods and systems for ransomware protection

Assignee: ZOHO CORPORATION PRIVATE LTDPriority: Sep 16, 2021Filed: Jul 13, 2022Published: Mar 16, 2023
Est. expirySep 16, 2041(~15.1 yrs left)· nominal 20-yr term from priority
G06F 21/565G06F 21/57G06F 21/554G06F 2221/033G06F 21/566G06F 21/602
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Described are methods and systems for detecting a ransomware process acting on files organized in folders of a file system. A subfolder path is identified for each file acted upon by a suspect process and the paths are combined into a number of unique paths for the suspect process. If the number of unique paths exceeds a threshold, the suspect process is categorized as malware. The methods and systems also include a hook and a filter to prevent shadow-copy deletions that would otherwise interfere with file recovery.

Claims

exact text as granted — not AI-modified
1 . A method for detecting ransomware from a process acting on files organized in folders of a file system, each of the files specified by a file path, the method comprising:
 for each of the files acted upon by the process, identifying a subfolder path in the file path of each of the file;   combining the subfolder paths into a number of unique process paths; and   comparing the number of unique process paths to a folder threshold.   
     
     
         2 . The method of  claim 1 , further comprising issuing a ransomware-warning responsive to the comparing if the number of unique process paths exceeds the folder threshold. 
     
     
         3 . The method of  claim 1 , wherein each of the folders has a folder-creation time, and wherein identifying the subfolder path for each of the files comprises comparing the folder-creation times of the folders specified in the subfolder path. 
     
     
         4 . The method of  claim 3 , wherein identifying the subfolder path for each of the files further comprises comparing a difference between the folder-creation times with a time threshold. 
     
     
         5 . The method of  claim 1 , further comprising checking whether the files are encrypted. 
     
     
         6 . The method of  claim 5 , wherein the checking comprises applying a machine-learning algorithm to the files. 
     
     
         7 . The method of  claim 5 , further comprising issuing a ransomware-warning responsive to the comparing if the number of unique process paths exceeds the folder threshold and at least some of the files are encrypted. 
     
     
         8 . A computer system for detecting ransomware from a process acting on files organized in folders of a file system, each of the files specified by a file path, the system comprising:
 an event detection engine to detect events that threaten the files; and   a response engine that responds to each of the detected events, the response engine, for each of the files threatened by one of the detected events:   identifying a subfolder path in the file path of each of the file;   combining the subfolder paths into a number of unique process paths; and   comparing the number of unique process paths to a folder threshold.   
     
     
         9 . The computer system of  claim 8 , the response engine further issuing a ransomware-warning responsive to the comparing if the number of unique process paths exceeds the folder threshold. 
     
     
         10 . The computer system of  claim 8 , wherein each of the folders has a folder-creation time, and wherein identifying the subfolder path for each of the files comprises comparing the folder-creation times of the folders specified in the subfolder path. 
     
     
         11 . The computer system of  claim 10 , wherein identifying the subfolder path for each of the files further comprises comparing a difference between the folder-creation times with a time threshold. 
     
     
         12 . The computer system of  claim 8 , the response engine further checking whether the files are encrypted. 
     
     
         13 . The computer system of  claim 12 , wherein the checking comprises applying a machine-learning algorithm to the files. 
     
     
         14 . The computer system of  claim 13 , the response engine further issuing a ransomware-warning responsive to the comparing if the number of unique process paths exceeds the folder threshold and at least some of the files are encrypted. 
     
     
         15 - 17 . (canceled) 
     
     
         18 . A ransomware-protection system instantiated on a computer system including a processor and memory to execute a shadow-copy process that invokes a system call to an operating-system kernel to write a shadow copy of a file in the memory to secondary storage, the shadow-copy process including a hook to intercept a request to alter the shadow copy of the file in the secondary storage. 
     
     
         19 . The ransomware-protection system of  claim 18 , the operating-system kernel including a filter to intercept a second request to alter the shadow copy of the file in the secondary storage. 
     
     
         20 . The ransomware-protection system of  claim 19 , wherein the second request comprises a request packet. 
     
     
         21 . The ransomware-protection system of  claim 18 , wherein the request to alter the shadow copy comprises at least one of a delete request and an overwrite request. 
     
     
         22 . The ransomware-protection system of  claim 18 , wherein the hook declines the request to alter the shadow copy of the file. 
     
     
         23 . The ransomware-protection system of  claim 22 , wherein the hook informs the shadow-copy process that the request to alter the shadow copy of the file was declined. 
     
     
         24 . The ransomware-protection system of  claim 18 , wherein the hook informs the shadow-copy process that the request to alter the shadow copy of the file will be declined. 
     
     
         25 - 29 . (canceled)

Join the waitlist — get patent alerts

Track US2023078476A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.