A computer-implemented method for detecting symptoms of ransomware attacks in a computer network, a system adapted to implement this method and a computer program element comprising computer program code

The method addresses the challenge of detecting zero-day ransomware by employing a software solution with a monitoring component and machine learning module to identify symptoms of ransomware attacks in computer networks, enhancing detection capabilities and reducing false positives.

WO2025133680A1PCT designated stage expired Publication Date: 2025-06-26SAGENSO SP ZOO

Patent Information

Application Number
PCT/IB2023/063049
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-20
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing solutions lack the capability to detect zero-day ransomware attacks by identifying symptoms of the malware rather than the malware itself.

Method used

A computer-implemented method that includes installing software on each computer in a network with a monitoring component, a machine learning module, and an effector unit. The module continuously monitors processor and memory usage, OS API calls, and registry entries, predicts the likelihood of a ransomware attack using machine learning, and sends warnings to the server and other computers upon detection.

Benefits of technology

Effectively detects symptoms of ransomware attacks, including zero-day variants, by using machine learning to analyze network activity and resource usage, minimizing false positives through rigorous training on virtual and physical machine data, and providing timely warnings to alert network administrators.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2023063049_26062025_PF_FP_ABST
    Figure IB2023063049_26062025_PF_FP_ABST
Patent Text Reader

Abstract

The objects of the invention are: a computer-implemented method for detecting symptoms of ransomware attacks in a computer network, a system adapted to implement this method, and a computer program element comprising computer program code.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] A computer-implemented method for detecting symptoms of ransomware attacks in a computer network, a system adapted to implement this method and a computer program element comprising computer program code

[0002] The objects of the invention are: a computer-implemented method for detecting symptoms of ransomware attacks in a computer network, a system adapted to implement this method, and a computer program element comprising computer program code.

[0003] From patent publication US20180157834A1 are known a protection system and a protection method for protecting a computer system against ransomware attacks. The system and method effectively detect the effects of ransomware attacks by combining automatic detection and transparent file-recovery capabilities at the filesystem level.

[0004] From patent publication EP3O38OO3B1 is known a method for real-time protection against unsolicited encryption of computer files in a computer system, particularly as a result of the operation of ransomware in the computer system. The method comprises the following steps: monitoring access of a running process to a file in a file system, the file being in a first state in which it is accessed as input by the process and in a second state in which the file is processed by the process as output, the first state of the file in the file system being associated with a first set of data values and the second state of the file in the file system being associated with a second set of data values, measuring a first magnitude representative of the randomness of the first set of data values and a second magnitude representative of the randomness of the second set of data values, comparing the first magnitude and the second magnitude, and interrupting the process if the second magnitude exceeds the first magnitude by a given threshold value.

[0005] From patent publication US11055411B2 is known a method for protecting a file server from a ransomware attack. An exemplary method comprises assigning a session identifier to a remote session initiated with the file server, monitoring operations associated with the session identifier, determining whether the operations are suspicious according to a policy, creating a volume-level snapshot of files on the file server, determining that encryption of the data is occurring when the entropy of the monitored data is growing faster than the predetermined threshold rate, classifying the remote session as having a calculated degree of danger when the operations match operations contained in previously observed suspicious behavior patterns, interrupting the remote session when a combination of the degree of danger and the entropy is greater than a predetermined threshold value and restoring the data on the file server using the volume-level snapshot to a state prior to the encryption and dangerous activity.

[0006] From patent publication US11200315B2 is known an Al-based malware detection method. The method includes inputting malware binary data, extracting metadata from the inputted malware binary data, converting the extracted metadata into image data, and training a neural network on the converted image data to classify malware. Malware binary data can be effectively classified by converting the binary data to image data and analyzed through deep learning-based image models. In addition, results from the Al detection algorithm technology can be displayed visually for easy interpretation.

[0007] Patent publication US11010472B1 discloses an embodiment of systems, methods, and products providing real-time anti-malware detection and protection. The computer uses artificial intelligence techniques to learn and detect new exploits in real time and protect the full system from harm. The computertrains a first machine learning model for executable files. The computer trains a second machine learning model for non-executable files. The computer trains a third machine learning model for network traffic. The computer identifies malware using the various machine learning models. The computer restores to a clean, uncorrupted state using virtual machine technology. The computer reports the detected malware to a security server, such as security information and even management (SIEM) systems, by transmitting detection alert message regarding the malware. The computer interacts with an administrative system over an isolated control network to allow the system administrator to correct the corruption caused by the malware.

[0008] Patent publication US 2017 / 0214701 Al discloses a computer security system based on artificial intelligence, wherein the system has a memory that stores programmed instructions, a processor that is coupled to the memory and executes the programmed instructions and at least one database, wherein the system comprising a computer-implemented system of providing designated function.

[0009] Lacking among the known solutions are those that can detect attacks using so-called zero- day ransomware by detecting the symptoms of the malware, rather than identifying it.

[0010] The above problems are solved by the inventions being the subject of the present application.

[0011] A computer-implemented method of detecting symptoms of ransomware attacks in a computer network, characterized in that it consists of the following steps: installing software on each computer of the internal network, with one of the computers being the server, with the software including the following: a) a monitoring component, which continuously monitors processor and memory usage, OS API calls and registry entries. b) a machine learning (ML) module, which extracts features from the gathered data, then for each time point predicts the likelihood of an ongoing ransomware attack; if the likelihood is above a specified threshold, the prediction is classified as "attack". c) an effector unit, which, in case an attack is detected, sends a warning to the server and a report which describes why the model predicted an "attack"; whereas the server is configured, in the way that: a) it communicates with all computers on the internal network, collecting reports on their status; b) it displays statistics of the status of every computer, available for a person managing the network; c) in case of ransomware detection on a single computer it sends a warning to all other computers, which puts them in a state of heightened alert; it also issues a warning to the person managing the network, in particular via email or SMS; whereas the whole thing is configured in such a way that: a) the lightweight monitoring component continuously gathers data on machine status, without straining computer resources. b) similarly, the machine learning model is light and only uses minimal resources. c) the monitoring process happens in the background. d) each computer reports its status to a central server which in turn displays a concise report to the person managing the network; whereas ) when a local computer is infected by ransomware, the local ML model will detect changes in the features extracted from API calls, resource use and registry; it will determine the probability of an attack, and if it is above a set threshold, it will declare an attack; The local response may include shutting down the machine, disabling the ransomware, and / or displaying a warning for the user; ) the local machine will warn the server, which will, in turn, warn the remaining machines, in particular, by sharing the "attack" / "no attack" status; if at least one computer reports an "attack", the server instructs all other machines to lower their detection threshold;) the server will issue a warning to the person managing the network and possibly to the management and / or IT department of the organization using the network. whereas the machine learning model (ML model) is trained based on data generated on virtual machines (VMs), supplemented with data recorded on physical machines (PMs); the VMs are an isolated environment for safe testing; they have an operating system, harmless software and scripts simulating user behaviour, including opening, closing, executing, modifying, and deleting files; at a pre-determined time point, aransomware is executed; only one ransomware from an extensive collection is executed during each experimental repeat. API calls, resource usage and registry entries are continuously recorded, before and during the ransomware attack; the VMs collect and send data which is then used to train an ML model; the ML model is highly interpretable, with the results plotted to illustrate how each feature contributed to the final prediction; this allows detecting unexpected trends, anomalies and outliers, which, in turn, facilitates diagnosing the cause of the problem and adjusting the training environment and model accordingly; in particular, if the prediction of an attack is a false positive, the cause of the misclassification can be determined based on the visualization, and the training environment or the model itself can be improved to avoid repeating errors. whereas whenever a computer reports an attack, a report is generated with the data necessary for the visualization; in this way it can be stated, which features were used to make the correct / incorrect prediction and, if necessary, adjust the training environment and model. whereas the machine learning modules installed on computers are static: they do not alter and learn continuously. Instead, they provide data required to improve the model in a safe, controlled environment.

[0012] Preferably, the improved ML model version will be then delivered to computers as a software update.

[0013] Preferably, the status of a particular computer is displayed on the monitor of that computer. A system composed of virtual machines and an internal network containing computers and a server which contain memory storing the computer program code for executing the steps of a method as claimed in any of claims 1 to 3.

[0014] A computer program element comprising computer program code, which, when loaded into a computer system and executed thereon, causes the computer to perform the steps of a method as claimed in any of claims 1 to 3.

[0015] Examples of the implementation of the invention are disclosed in the figure, in which:

[0016] Fig. 1 shows a schematic of the components of the systems according to the invention

[0017] Fig. 2 shows a schematic of the ransomware detector

[0018] Fig. 3 shows a schematic of the operation of the method according to the invention

[0019] Fig. 4 shows a diagram of the operation of the Al model of continuous training

[0020] 1. Installing the software on all computers on the internal network (with one of the computers being the server). The software contains:

[0021] 1) A monitoring component, which continuously monitors processor and memory usage, storage, OS API calls and registry entries. ) A machine learning module (ML module), which extracts features from the gathered data, then for each time point predicts the likelihood of an ongoing ransomware attack. If the likelihood is above a specified threshold, the prediction is classified as "attack". ) An effector unit, which, in case an attack is detected, sends a warning to the server and a report which describes why the model predicted an "attack". The effector will also control a local response, which may include shutting down the machine and / or displaying a warning to the user. gure the server in such a way that: ) It communicates with all computers within the organisation, collecting reports on their status. ) it displays statistics of the status of every computer, available for a person managing the network. ) If ransomware is detected on a single machine it sends a warning to all other computers, which puts them in a state of heightened. It also issues a warning to the person managing the network. al operations. ) The lightweight monitoring component continuously gathers data on machine status. It does so without straining computer resources. ) Similarly, the machine learning model is light and only uses minimal resources. ) The status of the machine is displayed for the user. ) Each computer reports its status to the central server which in turn displays a concise report to the person supervising the network. tion. ) When a user's computer is infected by ransomware, the local ML model will detect changes in the features extracted from API calls, resource use and registry. It will determine the probability of an attack, and if it is above a predefined threshold, it will declare an "attack". The local response may include shutting down the machine, disabling the ransomware, and / or displaying a warning for the user. ) The user's machine will warn the server, which will in turn warn the remaining machines. If at least one computer reports "attack", the server instructs all other machines to lower their detection threshold, thus heightening their alert status. The value of the threshold is experimentally determined for each iteration of the model. ) The server will issue a warning to the person supervising the network. ving the ML model. ) The main challenges of developing a ransomware detector are: i. To assure that the model does not impede normal operations on a personal computer. This is done by designing a light-weight implementation which does not strain the computer's resources ii. The ability to detect previously unseen ransomware, including day zero attacks. The approach outlined in this solution should be particularly effective, because, while the code of ransomware may greatly vary from variant to variant and hence be difficult to recognise, the sequence of actions leading to the encryption of user files will still leave characteristic marks on API calls, registry, and resource use. iii. Avoid false-positive predictions The patent presents a rigorous training method, based on data generated on VMs and collected on physical machines, which reduces the number of false-positive predictions and, when such a prediction does occur, allows determining their cause and correcting the model.. ) The model is trained based on data generated on VMs and supplemented by data collected on physical machines. The VMs are an isolated environment for safe testing. They have an operating system, harmless software and scripts simulating user behaviour (opening, closing, executing, modifying, and deleting files, etc.). At a set point in time, a single ransomware is executed; we have an extensive collection from which the ransomware is chosen. Continuously record API calls, resource use and registry entries, before and during the ransomware attack. The VMs collect and send data which is then used to train our ML model. The model is highly interpretable, with the results plotted to visualize how each feature contributed to the final prediction. Thanks to this, we can detect unexpected trends, anomalies, and outliers. This helps us form a hypothesis as to the root of potential problems, such as limitations in the way we generate training data, which can be then corrected. If the prediction of an attack is a false positive, we gain insight into why it was misclassified and how to adjust the training or modify model itself.) Whenever a customer's computerdetects an attack, a report is sent, with data sufficient to visualize and assess the reasons the "attack" prediction was made. If necessary, changes to the training environment and model can be then made to facilitate future predictions. ) The machine learning modules installed on customers' machines are static: they do not alter and learn. Instead, they provide data required to improve the model in a safe, controlled environment. The improved model version will be then provided as a software update.

Claims

laims A computer-implemented method for detecting symptoms of ransomware attacks in a computer network, characterized in that it consists of the following steps installing software on each computer of the internal network, with one of the computers being the server, with the software including the following: a) a monitoring component, which continuously monitors processor and memory usage, storage, OS API calls and registry entries. b) a machine learning (ML) module , which extracts features from the gathered data, then for each time point predicts the likelihood of an ongoing ransomware attack; if the likelihood is above a specified threshold, the prediction is classified as "attack". c) an effector unit, which, in case an attack is detected, sends a warning to a server and a report which describes why the model predicted an "attack"; whereas the server is configured, in the way that: a) it communicates with all computers on the internal network, collecting reports on their status; b) it displays statistics of the status of every computer, available for a person managing the network; c) in case of ransomware detection on a single computer it sends a warning to all other computers, which puts them in a state of heightened alert; it also issues a warning to the person managing the network in particular via email or SMS. whereas the whole thing is configured in such a way that::e) the lightweight monitoring component continuously gathers data on machine status without straining computer resources. f) similarly, the machine learning model is light and only uses minimal resources. g) the monitoring process happens in the background. h) each computer reports its status to a central server which in turn displays a concise report to the person managing the network; whereas1) when a local computer is infected by ransomware, the local ML model will detect changes in the features extracted from API calls, resource use and registry; it will determine the probability of an attack, and if it is above a set threshold, it will declare an attack; the local response, including shutting down the machine, is beyond the scope of this project;2) the local machine will warn the server, which will in turn warn the remaining machines, in particular, by sharing the "attack" / "no attack" status, if at least one computer reports an "attack", the server instructs all other machines to lower their detection threshold;3) the server will issue a warning to the person managing the network and possibly to the management and / or IT department of the organization using the network, whereas the machine learning model (ML model) is trained based on data generated on virtual machines (VMs), supplemented with data recorded on physical machines (PMs); the VMs are an isolated environment for safe testing; they have an operating system, harmless software and scripts simulating user behaviour including opening, closing, executing, modifying, and deleting files; at pre-determined time point, ransomware is executed; only one ransomware from an extensive collection is executed during each experimental repeat; API calls, resource usage and registry entries are continuously recorded, before and during the ransomware attack; the VMs collect and send data which is then used to train an ML model; the ML model is highly interpretable, with the results plotted to illustrate how each feature contributed to the final prediction; this allows detecting unexpected trends, anomalies and outliers; which, in turn, to facilitates diagnosing the cause of the problem and adjusting the training environment and model accordingly ; inparticular, if the prediction of an attack is a false positive, the cause of the misclassification can be determined based on the visualization, and the training environment or the model itself can be improved to avoid repeating errors; whereas whenever a computer reports an attack, a report is generated with the data necessary for the visualization; n this way it can be stated, which features were used to make the correct / incorrect prediction and, if necessary, adjust the training environment and model; whereas the machine learning modules installed on computers are static: they do not alter and learn continuously; instead, they provide data required to improve the model in a safe, controlled environment. The computer-implemented method according to claim 1, characterized in that the improved ML model version will be then delivered to computers as a software update. The computer-implemented method according to claim 1 -2 characterized in that the status of a particular computer is displayed on the monitor of that computer. A system composed of virtual machines and an internal network containing computers and a server which contain memory storing the computer program code for executing the steps of a method as claimed in any of claims 1 to 3. A computer program element comprising computer program code, which, when loaded into a computer system and executed thereon, cause the computer to perform the steps of a method as claimed in any of claims 1 to 3.

Citation Information

Patent Citations

  • Method for protection against ransomware

    EP3038003B1

  • Systems and methods for signature-less endpoint protection against zero-day malware attacks

    US11010472B1

  • System and method for protection against ransomware attacks

    US11055411B2

  • Artificial intelligence based malware detection system and method

    US11200315B2

  • Computer security based on artificial intelligence

    US20170214701A1

Cited By

  • Creating and extracting training data from storage systems to train machine learning models for ransomware detection

    US20260099597A1