Method and apparatus of investigating a ransomware attack on a network device during runtime

EP4740360A1Pending Publication Date: 2026-05-13HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2024-02-15
Publication Date
2026-05-13

Smart Images

  • Figure EP2024053879_21082025_PF_FP_ABST
    Figure EP2024053879_21082025_PF_FP_ABST
Patent Text Reader

Abstract

A method investigating a ransomware attack on a network device (126) during runtime is provided. The method includes detecting the ransomware attack on the network device (126). The method includes determining one or more investigating properties of the detected ransomware attack. The method includes generating one or more bait files and one or more processes. Each of the one or more bait files and each of the one or more processes corresponds to the one or more investigating properties, and the method includes inspecting the ransomware attack during the runtime using the one or more bait files and the one or more processes to mitigate the ransomware attack.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHOD AND APPARATUS OF INVESTIGATING A RANSOMWARE ATTACK ON A NETWORK DEVICE

[0002] DURING RUNTIME

[0003] TECHNICAL FIELD

[0004] The disclosure generally relates to inspecting a ransomware attack, and more particularly, the disclosure relates to a method and an apparatus for investigating a ransomware attack on a network device during runtime.

[0005] BACKGROUND

[0006] In recent years, ransomware attacks have become prominent cyber-attacks. There are various existing techniques utilized for detecting and mitigating the ransomware attacks. The existing techniques are used to protect important data from corruption or encryption. For example, if an existing defense system detects an unknown ransomware running on a network device, different detection techniques are utilized by the existing defense system to halt the unknown ransomware. The existing defense system requires an investigation to completely mitigate or recover an impact of the unknown ransomware on the network device. This investigation is used to extract properties of the unknown ransomware. The investigation is done by a Security Operation Center, SOC professionals experienced in investigating and mitigating cyber-attacks. The investigation may be automatic or manual.

[0007] The investigation requires executing the unknown ransomware in a sandbox. Once the sandbox is configured to run the unknown ransomware, playbooks featuring various execution and configuration scenarios are used to execute the unknown ransomware allowing the SOC professionals to comprehend and map or extract the properties of the unknown ransomware. The SOC professionals conduct a network scan using a Security Information and Event Management, SIEM tool. The network scan is conducted to identify any network devices that may have been infected or affected by the unknown ransomware, facilitating its recovery and termination. The SOC professionals halt the unknown ransomware if any network devices are affected by the unknown ransomware. During the investigation, the unknown ransomware, even if identified and terminated or quarantined, may persist in causing damages and spreading, thereby affecting the network device and inflicting unrecoverable impacts. This is because, without a complete understanding of all properties of the unknown ransomware, it is challenging for SOC professionals to determine whether the unknown ransomware has been completely halted and mitigated. Moreover, the properties of the unknown ransomware are vast. Interpreting the vast number of properties of the unknown ransomware for SOC professionals is difficult. For example, the properties of the unknown ransomware may be encryption technique, speed, attacked file properties that are changed, traversal of the attack, and ransomware notes.

[0008] An existing system protects a database against a ransomware attack. The existing system includes (i) a database backup handler that is configured to selectively store a backup database associated with the database in a storage device, (ii) a ransomware detector that is configured to monitor changes within the database and identify changes in the database resulting from a ransomware attack, and (iii) a ransomware remediator configured to restore data in the database to a point before the ransomware attack based upon the backup database in the storage device. The existing system might not recover recent changes in the database if there are changes to the data between intervals of backup and the ransomware attack.

[0009] Another existing monitoring system monitors a ransomware attack. This monitoring system includes a monitoring module that monitors files within the system for specific patterns of file access. If a number of patterns of file access exceeds a first threshold, an investigation module is activated. The investigation module records actions carried out by processes in modifying the files. This monitoring system further includes a reaction module that intervenes by temporarily halting a set of processes on the system when the number of patterns of file access exceeds a second threshold. This monitoring system further includes a reaction module that identifies processes associated with a suspected ransomware attack based on logging performed by the investigation module and resumes legitimate processes. This monitoring system might not accurately identify the processes associated with a suspected ransomware attack as utilizing the logging of the investigation module may be inaccurate. Moreover, this monitoring system does not mitigate the suspected ransomware attack associated with the identified processes.

[0010] Another existing system orchestrates a large-scale and high-interaction honeypot network. This system sends traffic detected at a sensor to a smart proxy for a honeypot farm. The traffic is a forwarded attack that is sent using a tunneling protocol. The high-interaction honeypot network includes container images, each representing different types of vulnerable services. This system selects a matching type of vulnerable service from the container images of the different types of vulnerable services based on a profile of the forwarded attack traffic. Subsequently, the forwarded attack is directed to an instance of the identified vulnerable service. This system executes a security agent associated with the instance of the matching type of vulnerable service to identify a threat by monitoring behaviors and detecting anomalies or post-exploitation activities. This existing system only focuses on network attacks that affect files rather than ransomware attacks.

[0011] A cloud service-based system exists for identifying ransomware attacks on client devices. The cloud service-based system monitors changes made to files stored on the cloud service by the client device. The cloud service-based system assesses whether these changes to the files exhibit characteristics of malicious activity associated with ransomware. Upon detecting the malicious activity in the changes to the files, the cloud service-based system performs a countermeasure to halt synchronization of the files between the client devices, other client devices, and the cloud service. This propagates the files from the client device facing a ransomware attack. The cloud service-based system does not focus on ransomware detection and remediation in the cloud service. The cloud service-based system may not respond effectively to emerging ransomware attacks, putting security of the files in the cloud service at risk.

[0012] Another existing system identifies ransomware and malicious programs. In this system, a hardware processor generates a file honeypot within a directory in a filesystem. The file honeypot is included on a file list representing contents of the directory. This system checks whether a process is listed in a list of trusted processes, based on factors such as certificate, fingerprint, name, and process identifier upon receiving a directory enumeration request from a process executing within an operating system environment. If the process is not found in the list of trusted processes, the filesystem provides a file list, including the file honeypot, to the process in response to the directory enumeration request. If the process is identified as trusted, the file list provided to the process excludes the file honeypot. Simultaneously, the filesystem filter driver in this system intercepts a file modification request for the file honeypot from the process. Upon interception, if the file honeypot is included in the file list and the process is not identified as trusted, this system identifies the process as suspicious. This system only focuses on the implementation of bait files.

[0013] An anti-malware system for analyzing the behavior of an executing or running process to identify ransomware. The antimalware system identifies an untrusted process that requests to enumerate a directory of user files. It directs the untrusted process to initially operate on a decoy file that mimics a structure of the user files. If the behavior of the untrusted process for the decoy file indicates ransomware, the process may be terminated without any loss of the user files. The decoy file may be deployed in a way that is undetectable to the user. This anti-malware system only focuses on the implementation of bait files.

[0014] Another existing system detects and neutralizes malware at runtime on a computing device to prevent any encrypted user files from the malware. For example, a malicious process detector may generate decoy files in a directory. The decoy files may include attributes. The attributes cause the decoy files to reside at the beginning and / or end of a file list. In this process, a malicious process targets the decoy files in the directory to encrypt the decoy files before other files. The detector in this system monitors operations on the decoy files to determine whether a malicious process is active on a computing device of a user. The detector initiates protective measures to neutralize the malicious process upon identifying an active malicious process in the decoy files. This system only focuses on the implementation of bait files, especially the decoy files. A stackable file system architecture is used to mitigate data theft risks for file integrity protection in a stackable file. The stackable filesystem architecture groups processes into a ranked file system i.e., security domains or layers. The stackable filesystem architecture utilizes a theory algorithm to determine a root domain for running an application. The root domain provides a single view of the stackable filesystem. Each security domain creates multiple levels of stacking to protect the stack filesystem and to monitor file accesses in the stack filesystem. This stackable file system architecture only focuses on the implementation of bait files (i.e., allowing access to stackable files based on different security domains), especially the decoy files.

[0015] Another existing system identifies malware through file encryption detection. In this system, a monitoring module is integrated into multiple active processes running on a computer system through a kernel mode driver. The monitoring module identifies an execution of a directory traversal operation (i.e., process of navigating through a directory) in a directory of the computer system by a first process among the multiple active processes. The directory traversal operation includes a number of wildcard characters. When the number of wildcard characters-based directory traversal operations performed by a first process exceeds a predetermined threshold, the monitoring module deploys a decoy file within the directory and notifies the kernel mode driver. The kernel mode driver monitors and identifies any attempts by the first process to tamper with the decoy file by intercepting and evaluating file system operations. Upon detecting any such attempt, the first process is confirmed as a malware process and is subsequently terminated. This system monitors the behavior of processes involved in directory traversal, (i.e.,) only detects instances where directory traversal operations include the number of wildcard characters. This system only focuses on the implementation of bait files.

[0016] Another existing system detects a Lesox virus in network security. This system obtains directory information from a preset directory, monitors if a suspicious process traverses a root directory in real-time, in the event of such traversal, generates a decoy directory under a target root directory based on the directory information from the preset directory, and generates virtual decoy files of various document types within the decoy directory. This system redirects a path of the virtual bait file to match a bait file under the preset directory to determine whether the suspicious process is the Lesox virus when the Lesox virus interacts with the virtual bait file in the bait directory. This determination is based on an operation result of the virtual bait file, which has been redirected to the bait file in the preset directory by the suspicious process. This system only focuses on deployment of the bait files throughout the preset directory. Moreover, this system requires lots of memory for deploying the bait files.

[0017] Another existing system detects the Lesox virus within the field of information security. This system initiates a bait file at a target position on a computer. The targeted position is either the computer, a C disk of a root directory in the computer, or a user-defined location. The user-defined position is determined by a user based on the characteristics of different Lesox viruses. Subsequently, this system sends a path of the bait file to a kernel in the computer. This system controls the kernel to monitor any operational events directed at the bait file in the computer. If an operational event is detected, this system assesses whether the path of the bait file associated with the event matches the path of the bait file. If a match is identified, it indicates that the operational event is executed by the Lesox virus. This existing system only focuses on deployment of bait files within a file system of a computer.

[0018] Therefore, there arises a need to address the aforementioned technical problem / drawbacks of investigating a ransomware attack on a network device during runtime.

[0019] SUMMARY

[0020] It is an object of the disclosure to provide a method and an apparatus for investigating a ransomware attack on a network device during runtime while avoiding one or more disadvantages of prior art approaches. This object is achieved by the features of the independent claims. Further, implementation forms are apparent from the dependent claims, the description, and the figures.

[0021] According to a first aspect, there is a method of investigating a ransomware attack on a network device during runtime. The method includes detecting the ransomware attack on the network device. The method includes determining one or more investigating properties of the detected ransomware attack. The method includes generating one or more bait files and one or more processes. Each one of the one or more bait files and each one of the one or more processes corresponds to at least one of the one or more investigating properties. The method includes inspecting the ransomware attack during the runtime using the one or more bait files and the one or more processes, to mitigate the ransomware attack.

[0022] This method investigates an unknown ransomware on the network device within less time ensuring zero effect on data or files on the network device. This method extracts the properties of the unknown ransomware in run-time that ensures zero impact on actual files which enables faster recovery and active mitigation of the unknown ransomware attack. This method generates and utilizes the one or more bait files to delay the ransomware to inspect and mitigate the ransomware impact on the network device which prevents or decreases the chances for the ransomware to communicate with a command-and-control server, C&C for acknowledging the unknown ransomware attack. For example, when an encryption of the file is completed by the ransomware, the C&C instructs the ransomware to initiate the exfiltration phase. In view of the example, an adversary assumes the ransomware attack is ongoing. However, this method gathers and discloses detailed information about the adversary and the ransomware attack by delaying the ransomware running on the network device. This method eliminates the complexity of executing the ransomware on a sandbox as this method identifies an appropriate operating system. This method ensures that a file system can support the execution, reducing investigation runtime and subsequently minimizing detection time, even in the face of reduced system overload. This method can be implemented in different environments including edge devices, databases cloud infrastructures, servers, mobile, cloud platforms, and Internet of Things, loT.

[0023] Preferably, the method includes generating further bait files and using the generated further bait files to delay the ransomware attack during the inspection of the ransomware attack.

[0024] Preferably, the method includes generating further bait files and using the generated further bait files to delay the ransomware attack that occurs throughout the inspecting of the ransomware attack.

[0025] Preferably, the one or more investigating properties which correspond to the one or more bait files include file formats affected by the ransomware attack, whether the ransomware attack is targeted to specific file names, file sizes, or specific directories.

[0026] Preferably, the one or more investigation properties which correspond to the one or more processes include whether the ransomware attack is aware of a monitoring tool.

[0027] Preferably, the one or more investigation properties which correspond to the one or more processes include whether the ransomware attack is aware of the monitoring tool and can terminate the monitoring tool.

[0028] According to a second aspect, a computer program includes instructions for carrying out all the steps of the method when the computer program is executed on a computer system.

[0029] According to a third aspect, there is an apparatus for investigating a ransomware attack on a network device. The apparatus includes a detecting unit, a determining unit, a generating unit, and an inspecting unit. The detecting unit is configured to detect a ransomware attack on the network device. The determining unit is configured to determine one or more investigating properties of the detected ransomware attack. The generating unit is configured to generate one or more bait files and one or more processes, where each one of the one or more bait files and each one of the one or more processes corresponds to at least one of the one or more investigating properties. The inspecting unit is configured to inspect the ransomware attack during runtime using the one or more bait files and the one or more processes to mitigate the ransomware attack.

[0030] Therefore, in contradistinction to the existing solutions, a method and an apparatus of investigating an unknown ransomware attack on a network device during runtime by generating and utilizing the one or more bait files to delay the unknown ransomware. Thereby this method and the apparatus actively mitigate the unknown ransomware attack on a network device during runtime and within less time as well.

[0031] These and other aspects of the disclosure will be apparent from the implementations) described below.

[0032] BRIEF DESCRIPTION OF DRAWINGS

[0033] Implementations of the disclosure will now be described, by way of example only, with reference to the accompanying drawings, in which:

[0034] FIG. 1 illustrates a block diagram of an apparatus for investigating a ransomware attack on a network device during runtime in accordance with an implementation of the disclosure;

[0035] FIGS. 2A-2D are flow diagrams that illustrate a method of detecting an unknown ransomware running on a network device using one or more decoy files and investigating the unknown ransomware present in the one or more decoy files using one or more bait files in accordance with an implementation of the disclosure; and

[0036] FIG. 3 is an illustration of a computer system (e.g., an apparatus, a network device, an edge device) in which the various architectures and functionalities of the various previous implementations may be implemented.

[0037] DETAILED DESCRIPTION OF THE DRAWINGS

[0038] Implementations of the disclosure provide a method and an apparatus for investigating a ransomware attack on a network device during runtime.

[0039] To make solutions of the disclosure more comprehensible for a person skilled in the art, the following implementations of the disclosure are described with reference to the accompanying drawings.

[0040] Terms such as “a first”, “a second”, “a third”, and “a fourth” (if any) in the summary, claims, and foregoing accompanying drawings of the disclosure are used to distinguish between similar objects and are not necessarily used to describe a specific sequence or order. It should be understood that the terms so used are interchangeable under appropriate circumstances, so that the implementations of the disclosure described herein are, for example, capable of being implemented in sequences other than the sequences illustrated or described herein. Furthermore, the terms “include” and “have” and any variations thereof, are intended to cover a non-exclusive inclusion. For example, a process, a method, a system, a product, or a device that includes a series of steps or units, is not necessarily limited to expressly listed steps or units but may include other steps or units that are not expressly listed or that are inherent to such process, method, product, or device.

[0041] Definitions:

[0042] Detection Process: Detection Process is an act of detecting ransomware based on prior knowledge such as properties of the ransomware and using different behavior analysis techniques. Mitigation: Mitigation is an act of recovery from the moment ransomware was detected till the moment the system gets back to its state before the attack started.

[0043] Investigation: Investigation is a process of collecting properties of a malware attack. The properties are varied and include all data behavior and structural properties of the malware from the moment the attack was initiated until the moment the malware stopped or finished the attack. The most high-level overview includes all MITRE attack tactics in a very low-level and detailed manner. Since we focus on ransomware malware attacks, the properties are much more specific and they focus mostly on the MITRE tactic impact properties, but also other tactics such as Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control and Exfiltration. Some examples of properties that are related to the impact properties of ransomware include the encryption method, the file extension changes, or the ransomware note. Some examples of other properties that are related to other tactics include tactic for Property, a lateral movement for directory traversal method, defense evasion for antivirus, AV process killing, or credential cracking for attacking password- protected files. The investigation result is the full property list of the ransomware, divided according to the MITRE tactics.

[0044] FIG. 1 illustrates a block diagram of an apparatus 100 for investigating a ransomware attack on a network device 126 during runtime in accordance with an implementation of the disclosure. The apparatus 100 may include one or more units and one or more sub modules. The one or more units include a process monitoring unit 102, a detecting unit 104, an inspecting unit 108, and a mitigating unit 124. The apparatus 100 is communicatively connected to the network device 126. Optionally, the network device 126 can be an edge device. The detecting unit 104 includes one or more detector sub-modules 106A-N. The apparatus 100 is in Endpoint Detection and Response, EDR, and / or security systems.

[0045] The process monitoring unit 102 is configured to monitor actions of one or more processes running on the network device 126. The actions of the one or more processes may be an authorized process or an unauthorized process. The unauthorized process means an untrusted process or a whitelisted process. The detecting unit 104 is configured to detect a request that is sent by the unauthorized process to the network device 126. The request includes attempting to access actual files in the network device 126. The one or more detector sub-modules 106A-N in the detecting unit 104 activate one or more decoy files in the network device 126 while the request is received from the unauthorized process. Optionally, the detecting unit 104 includes detection sensors that activate the one or more decoy files in the network device 126. The one or more decoy files are fake files or duplicate files of the actual files.

[0046] The detecting unit 104 identifies a malware attack associated with the request using the one or more decoy files. The identified malware attack may be ransomware. The one or more decoy files divert and mislead the ransomware if the request done by the ransomware, i.e., the one or more decoy files divert the ransomware away from the actual files in the network device 126. The one or more decoy files may be generated to replicate characteristics of the actual files, where the malware attack or the ransomware accesses the one or more decoy files instead of the actual files in the network device 126, i.e., the malware attack or the ransomware accesses the duplicate files instead of the actual files in the network device 126 when the unauthorized processes request to access the actual files in the network device 126. The detecting unit 104 identifies whether the malware attack is being accessed or present in the one or more decoy files.

[0047] The inspecting unit 108 includes a determining unit 110, a generating unit 114, and an escaping sub-module 122. The determining unit 110 includes a ransomware property extraction sub-module 112. The determining unit 110 determines one or more investigating properties of the detected ransomware by extracting the one or more investigating properties of the detected ransomware using the ransomware property extraction sub-module 112.

[0048] The generating unit 114 includes a first bait files creation sub-module 116, a process generation sub-module 118, and a second bait files creation sub-module 120. The generating unit 114 generates one or more bait files corresponding to the one or more investigating properties with the first bait files creation sub-module 116. The generating unit 114 generates the one or more processes corresponding to the one or more investigating properties by the process generation sub-module 118. The one or more bait files and the one or more processes vary to each of the one or more investigating properties.

[0049] Below table 1 depicts examples of the one or more bait files that can be used to extract ransomware properties of the detected ransomware:

[0050] The one or more bait files may include different file formats affected by the detected ransomware, i.e. the first bait files creation sub-module 116 generates the different file formats affected by the detected ransomware. The one or more bait files include specific file names, file sizes, or directories that are affected by the detected ransomware. The one or more processes include at least one of (i) whether the detected ransomware is aware of a monitoring tool or (ii) whether the detected ransomware can terminate the monitoring tool. Below table 2 depicts examples of other extracted investigating properties that are not related to the one or more bait files:

[0051] The ransomware property extraction sub-module 112 determines the other investigating properties that are not related to the one or more bait files, as the ransomware (i) inspects the processes of the Address Verification Service, AVS or open Database, DB, and / or a querying system including Splunk, and Structured Query Language, SQL before the ransomware attack initiates an encryption and (ii) inspects the processes of the AVS after the encryption and / or other malicious activity has been initiated.

[0052] The inspecting unit 108 inspects the ransomware during the runtime using the one or more bait files and the one or more processes of the ransomware to mitigate the ransomware. The mitigating unit 124 analyzes the network device 126 to identify the Indicators of Compromises, IOCS, and behaviors of the ransomware. The mitigating unit 124 mitigates or eliminates the ransomware in the network device 126 based on the IOCs, and the behaviors of the ransomware. The second bait files creation sub-module 120 generates bait files in the network device 126 to delay the ransomware that is running on the network device 126 until the mitigating unit 124 mitigates or eliminates the ransomware running on the network device 126. Optionally, the apparatus 100 allows human operators to perform a further investigation or mitigation by generating further bait files to further delay the ransomware attack.

[0053] The ransomware does not lock or access data in the network device 126 while the one or more bait files delay the ransomware running on the network device 126. The data in the network device 126 is transmitted and / or received by the network device 126 for communication within a network. The escaping sub-module 122 halts the process of investigating the ransomware attack on the network device 126 during the runtime when the mitigating unit 124 mitigates or eliminates the ransomware in the network device 126. The system 100 generates signatures, IOCs, and rules to prevent the detected ransomware, especially unknown ransomware.

[0054] FIGS. 2A-2D are flow diagrams that illustrate a method of detecting an unknown ransomware running on a network device using one or more decoy files and investigating the unknown ransomware present in the one or more decoy files using one or more bait files in accordance with an implementation of the disclosure. Turning first to FIG. 2A, at a step 202, the method includes monitoring one or more processes executing on the network device. The one or more processes may be an authorized process or an unauthorized process. At a step 204, the method includes detecting a request that is sent from the unauthorized processes running in the network device. The request includes attempting to access the files in the network device. At a step 206, the method includes initiating a detection process to detect a malware attack associated with the request. At a step 208, the method includes initiating one or more detection sensors to activate one or more decoy files in the network device while starting the detection process. Turning to FIG. 2B, at a step 210, the method includes monitoring actions of the unauthorized processes present in the one or more decoy files. At a step 212, the method includes determining whether the actions of the unauthorized processes indicate the ransomware or not. If the actions of the unauthorized processes are not ransomware, (i) monitoring and detecting the actions of the one or more processes at step 202, or (ii) halting the process of monitoring and investigating the ransomware.

[0055] Turning to FIG. 2C, at a step 216, the method includes initiating the investigation of the ransomware that is present in the one or more decoy files if the actions of the unauthorized processes are the ransomware. At a step 218, the method includes monitoring the ransomware that is present in the one or more decoy files and initiating an extraction process of one or more investigating properties of the ransomware. At a step 220, the method includes determining the one or more investigating properties of the ransomware based on the extraction process. At a step 222, the method includes generating one or more bait files and one or more processes, where each of the one or more bait files and each of the one or more processes corresponds to at least one of the one or more investigating properties.

[0056] Turning to FIG. 2D, at a step 224, the method includes creating a profile of the ransomware based on the one or more bait files and the one or more processes for the one or more investigating properties of the ransomware. The profile of the ransomware includes insights and details about the ransomware. At a step 226, the method includes inspecting the ransomware during the runtime using the profile of the ransomware to mitigate the ransomware. At a step 228, the method includes monitoring the network device until mitigating the ransomware. The ransomware is delayed by the one or more bait files until mitigating the ransomware runs on the network device. The ransomware may be mitigated according to a mitigation policy. At a step 230, the method includes halting the process of investigating the ransomware when the ransomware is mitigated or eliminated on the network device.

[0057] FIG. 3 is an illustration of a computer system (e.g., an apparatus, a network device, and / or an edge device) in which the various architectures and functionalities of the various previous implementations may be implemented. As shown, the computer system 300 includes at least one processor 303 that is connected to a bus 302, wherein the computer system 300 may be implemented using any suitable protocol, such as Peripheral Component Interconnect, PCI-Express, Accelerated Graphics Port, AGP, Hyper Transport, or any other bus or point-to-point communication protocol. The computer system 300 also includes a memory 306.

[0058] Control logic (software) and data are stored in the memory 306 which may take a form of random-access memory, RAM. In the disclosure, a single semiconductor platform may refer to a sole unitary semiconductor-based integrated circuit or chip. It should be noted that the term single semiconductor platform may also refer to multi-chip modules with increased connectivity which simulate on-chip modules with increased connectivity which simulate on-chip operation, and make substantial improvements over utilizing a conventional central processing unit, CPU and bus implementation. Of course, the various modules may also be situated separately or in various combinations of semiconductor platforms per the desires of the user.

[0059] The computer system 300 may also include a secondary storage 310. The secondary storage 310 includes, for example, a hard disk drive and a removable storage drive, representing a floppy disk drive, a magnetic tape drive, a compact disk drive, digital versatile disk, DVD drive, recording device, universal serial bus, USB flash memory. The removable storage drive at least one of reads from and writes to a removable storage unit in a well-known manner.

[0060] Computer programs, or computer control logic algorithms, may be stored in at least one of the memory 306 and the secondary storage 310. Such computer programs, when executed, enable the computer system 300 to perform various functions as described in the foregoing. The memory 306, the secondary storage 310, and any other storage are possible examples of computer-readable media.

[0061] In an implementation, the architectures and functionalities depicted in the various previous figures may be implemented in the context of the processor 304, a graphics processor coupled to a communication interface 312, an integrated circuit (not shown) that is capable of at least a portion of the capabilities of both the processor 304 and a graphics processor, a chipset (namely, a group of integrated circuits designed to work and sold as a unit for performing related functions, and so forth).

[0062] Furthermore, the architectures and functionalities depicted in the various previous-described figures may be implemented in a context of a general computer system, a circuit board system, a game console system dedicated to entertainment purposes, an application-specific system. For example, the computer system 300 may take the form of a desktop computer, a laptop computer, a server, a workstation, a game console, or an embedded system.

[0063] Furthermore, the computer system 300 may take the form of various other devices including, but not limited to a personal digital assistant, PDA device, a mobile phone device, a smart phone, a television, and so forth. Additionally, although not shown, the computer system 300 may be coupled to a network (for example, a telecommunications network, a local area network, LAN, a wireless network, a wide area network, WAN such as the Internet, a peer-to-peer network, a cable network, or the like) for communication purposes through an I / O interface 308.

[0064] It should be understood that the arrangement of components illustrated in the figures described are exemplary and that other arrangement may be possible. It should also be understood that the various system components (and means) defined by the claims, described below, and illustrated in the various block diagrams represent components in some systems configured according to the subject matter disclosed herein. For example, one or more of these system components (and means) may be realized, in whole or in part, by at least some of the components illustrated in the arrangements illustrated in the described figures.

[0065] In addition, while at least one of these components are implemented at least partially as an electronic hardware component, and therefore constitutes a machine, the other components may be implemented in software that when included in an execution environment constitutes a machine, hardware, or a combination of software and hardware.

[0066] Although the disclosure and its advantages have been described in detail, it should be understood that various changes, substitutions, and alterations can be made herein without departing from the spirit and scope of the disclosure as defined by the appended claims.

Claims

CLAIMS1. A method of investigating a ransomware attack on a network device (126) during runtime, comprising steps of: detecting the ransomware attack on the network device (126); determining a plurality of investigating properties of the detected ransomware attack; generating a plurality of bait files and a plurality of processes, where each one of the plurality of bait files and each one of the plurality of processes corresponds to at least one of the plurality of investigating properties; and inspecting the ransomware attack during the runtime using the plurality of bait files and the plurality of processes, to mitigate the ransomware attack.

2. The method of claim 1 further comprising a step of: during the inspecting step, generating further bait files, and using the generated further bait files to delay the ransomware attack.

3. The method of claim 2 wherein the generating further bait files and using the generated further bait files to delay the ransomware attack occurs throughout the inspecting step.

4. The method of claim 1 wherein the plurality of investigating properties which correspond to the plurality of bait files include file formats affected by the ransomware attack, whether the ransomware attack is targeted to specific file names, file sizes, or specific directories.

5. The method of claim 1 wherein the plurality of investigation properties which correspond to the plurality of processes include whether the ransomware attack is aware of a monitoring tool.

6. The method of claim 5 wherein the plurality of investigation properties which correspond to the plurality of processes include whether the ransomware attack is aware of the monitoring tool and can terminate the monitoring tool.

7. A computer program comprising instructions for carrying out all the steps of the method according to any preceding method claim, when said computer program is executed on a computer system.

8. An apparatus (100) for investigating a ransomware attack on a network device (126), comprising: a detecting unit (104) configured to detect a ransomware attack on the network device (126); a determining unit (110) configure to determine a plurality of investigating properties of the detected ransomware attack; a generating unit (114) configured to generate a plurality of bait files and a plurality of processes, where each one of the plurality of bait files and each one of the plurality of processes corresponds to at least one of the plurality of investigating properties; and an inspecting unit (108) configured to inspect the ransomware attack during runtime using the plurality of bait files and the plurality of processes, to mitigate the ransomware attack.