Intent-based security system for preventing data breaches and ransomware attacks in a computing environment

WO2026202929A1PCT designated stage Publication Date: 2026-10-01IOZ SOT PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/IN2026/050091
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-22
Filing Date
2026-01-20
Publication Date
2026-10-01

Smart Images

  • Figure IN2026050091_01102026_PF_FP_ABST
    Figure IN2026050091_01102026_PF_FP_ABST
Patent Text Reader

Abstract

An intent-based security system (100) is provided for preventing data breaches and data destruction by monitoring system activity at both the operating system kernel and application levels, including actions by users (118) with root or administrator privileges. The system detects deviations from expected behavior that potentially indicate a data breach or data destruction attempt. Upon detecting a deviation, the system blocks the activity and generates an alert containing contextual information, including a visual representation of the action causing the deviation. This alert is transmitted to a designated authorization entity, separate from the entity that caused the deviation. The system receives and executes the authorization decision, terminating the associated process if the decision is to prevent, even for actions initiated by privileged users.
Need to check novelty before this filing date? Find Prior Art

Description

INTENT-BASED SECURITY SYSTEM FOR PREVENTING DATA BREACHES AND RANSOMWARE ATTACKS IN A COMPUTING ENVIRONMENT BACKGROUNDTechnical Field

[0001] The disclosure relates generally to the field of cybersecurity and, more particularly, to a system and a method for preventing data breaches and data destruction by proactively interrogating the intent behind system activities.Description of the Related Art

[0002] Data breaches are significant and growing threats to organizations of all sizes. Despite the widespread deployment of traditional cybersecurity systems, such as firewalls, intrusion detection / prevention systems (IDS / IPS), antivirus software, and data loss prevention (DLP) tools, data breaches continue to occur with alarming frequency and severity. These breaches often result in significant financial losses, reputational damage, and legal liabilities.

[0003] Traditional security systems primarily rely on predefined rules, signatures, and known attack patterns to identify and block malicious activity. For example, antivirus software uses databases of known malware signatures to detect and remove malicious files. The IDS / IPS systems monitor network traffic for patterns that match known attacks and DLP systems typically rely on content inspection and keyword matching to prevent sensitive data from leaving the organization's control.

[0004] However, these traditional approaches suffer from several limitations, rendering them inadequate against modern threats. The signature-based systems or even the behavior-based Endpoint Detection and Response (EDR) systems are inherently incapable of detecting new or unknown threats, such as zero-day exploits, because no pre-existing signature exists or behavior has not been trained in the Machine Learning (ML) model. Attackers constantly develop new malware and exploit techniques to evade these defenses. Furthermore, traditional security measures are often vulnerable to sophisticated attacks, including Advanced Persistent Threats (APTs), fileless malware, and insider threats. Fileless malware, operating entirely in memory, leaves no file-based signatures fortraditional antivirus to detect. Rule -based systems are similarly limited, i.e., the attackers can often circumvent restrictions by slightly modifying their techniques or exploiting unforeseen loopholes. Traditional systems also struggle to distinguish between legitimate and malicious actions performed by authorized users, making them vulnerable to insider threats. Finally, once an attacker gains elevated privileges, such as root or administrator access, traditional, or even the most modern, security measures are frequently ineffective in preventing data exfiltration or destruction, as attackers can often disable or bypass safeguards due to their increased access rights as demonstrated by the recent Salt Typhoon APT attack on US Telecom Companies and Solar Winds APT attack.

[0005] Several existing systems attempt to address some of these limitations; however, none effectively address the problem of proactively preventing data breaches based on the intent of the system’s actions, or the actions of the users and administrators especially in cases of privilege escalation.

[0006] An existing system discloses detecting unauthorized file access by analyzing user behavior. While this existing system mentions behavioral analysis, it focuses on user behavior (i.e., mouse movements, etc.) rather than the system-level actions themselves. It does not disclose a real-time questioning mechanism that interrogates the intent behind actions before execution, nor does it address the specific challenges of root / administrator privilege escalation or in-application security modules.

[0007] Another existing system adjusts Application Programming Interface (API) access permissions based on detected malicious activity in text-based conversations. This is limited to a specific context (i.e., API access) and does not address the problem of intentbased security at the operating system and application levels. It lacks the proactive questioning mechanism and the comprehensive monitoring of the system activities.

[0008] The existing cybersecurity systems are largely reactive, relying on identifying known threats or analyzing past behavior. They lack the ability to proactively question the intent behind any system activity, regardless of the user's privilege level or the specific nature of the action, before that action is executed. This leaves a critical gap in security, particularly against zero-day exploits, insider threats, and attacks that leverage privilege escalation.

[0009] Therefore, there is a need to address the aforementioned drawbacks by providing an intent-based security system to prevent data breaches and ransomware attacks in a computing environment.SUMMARY

[0010] According to the first aspect of the invention, an intent-based security system for preventing data breaches and ransomware attacks in a computing environment is provided. The system includes a hardware processor, a memory unit and an encrypted data store. The hardware processor continuously monitors system activity across one or more layers of the computing environment, including an operating system kernel level, an application level, an application level implementation via a kernel-space monitoring implemented on the hardware processor based on security inside an application, or a memory space, to identify operations including at least one of file access, modification, deletion, encryption, network communication, data exfiltration, data chunking, or actions of artificial intelligence (Al) agents. The hardware processor detects deviations from a stored baseline of expected behavior indicative of a potential data breach or ransomware attack in real-time and at hardware processor assisted kernel hooks. Upon detecting a deviation, the hardware processor generates by a secure snapshot engine implemented on the hardware processor, a contextual alert comprising at least one screenshot of a file or memory region associated with the deviation, and at least one of an action flow map and a process flow map, wherein the action flow map visualizes potential outcomes of allowing or preventing the action, and wherein the process flow map reconstructs events leading to the deviation. The hardware processor proactively blocks execution of the deviation causing action pending authorization by an enforced interlock mechanism. The hardware processor securely transmits via an encrypted communication implemented on the hardware processor, the contextual alert to at least one designated authorization entity separate from the entity that triggered the deviation. The authorization entity is selected from a user, administrator, a security operations centre (SOC), or an Al engine. The hardware processor receives from the authorization entity, an authorization decision to either allow or prevent continuation of the action. The hardware processor enforces the authorization decision by terminating or allowing the associated process, even if initiated by a user or the processwith root or administrator privileges. The encrypted data store is configured to store the contextual alert, screenshots, action flow maps, process flow maps, and encrypted backups. The encrypted backups are accessible only by the intent-based security system

[0011] The system further enforces a multi-entity hierarchical workflow such that, if a first authorization entity accepts the action despite the process flow map and action flow map favouring rejection. The contextual alert is automatically generated to at least one higher-hierarchy authorization entity for secondary decision-making, and disabling, uninstalling, or stopping the system in hardware-space or kernel space or user space requires multi-person authorization, thereby preventing data breaches and ransomware attacks in the computing environment.

[0012] In some embodiments, the system monitors the system activity by observing malwares including fileless malware activity operating in a Random Access Memory (RAM) without disk artifacts for data exfiltration and data encryption. In some embodiments, the hardware processor is configured to interrogate actions originating from one or more Al agents, including covert or overt edge-deployed models or cloud-hosted agents, and block any unauthorized exfiltration or encryption attempts. In some embodiments, the hardware processor generates a visual indicator or a telemetry highlighting the specific files or memory addresses attempted for exfiltration or encryption.

[0013] In some embodiments, the hardware processor employs end-to-end encryption to transmit the contextual alert to a mobile device or an enterprise system configured for security operations. In some embodiments, the authorization decision in a non-AI-driven workflow requires additional authentication, including biometric authentication, multi-factor authentication or multi user authorization on enterprise mobile devices or desktop devices.

[0014] In some embodiments, in an Al-driven workflow, the Al engine determines whether to generate the authorization request to an administrator or SOC based on a calculated criticality level of the deviation, including at least one of active directory compromise, persistence, data encryption, data exfiltration, lateral movement, or insider threats. In some embodiments, the system enforces hierarchical workflow escalation suchthat if a lower-level user authorizes an action flagged as potentially malicious. The contextual alert is automatically generated to at least one administrator, SOC, or superadmin.

[0015] In some embodiments, the encrypted data store in the hardware prevents any read or write operation by external applications or users, and access to backups is restricted to the system through cryptographic binding between the intent-based security system on the hardware processor, memory unit and the data store in the hardware. The disabling, uninstalling, or stopping the system requires multi-person authorization, including at least two distinct authorization entities selected from a user, administrator, SOC, or Al engine.

[0016] According to the second aspect of the invention, a computer-implemented method for preventing data breaches and ransomware attacks in a computing environment, using an intent-based security system is provided. The method includes continuously monitoring, using a hardware processor of the intent-based security system, via kernelspace monitoring implemented on the hardware processor, system activity across one or more layers of the computing environment, including an operating system kernel level, an application level, an application level implementation based on security inside an application, and a memory space, to identify operations comprising at least one of file access, modification, deletion, encryption, network communication, data exfiltration, data chunking, or actions of artificial intelligence (Al) agents. The method includes detecting, using the hardware processor, in real-time and at hardware processor-assisted kernel hooks, deviations from a stored baseline of expected behavior indicative of a potential data breach or ransomware attack. The method includes generating, using the hardware processor, upon detecting the deviation, a contextual alert including at least one screenshot of a file or memory region associated with the deviation, and at least one of an action flow map and a process flow map. The action flow map visualizes potential outcomes of allowing or preventing the action, and the process flow map reconstructs events leading to the deviation. The method includes proactively blocking, using the hardware processor, by an enforced interlock mechanism, execution of the deviation-causing action pending authorization. The method includes securely transmitting, using the hardware processor, via encrypted communication implemented on the hardware processor, the contextual alert to atleast one designated authorization entity separate from the entity that triggered the deviation. The authorization entity is selected from a user, administrator, a security operations centre (SOC), or an Al engine.

[0017] The method includes receiving, using the hardware processor, from the authorization entity, an authorization decision to either allow or prevent continuation of the action. The method includes enforcing, using the hardware processor, the authorization decision by terminating or allowing the associated process, even if initiated by a user or the process with root or administrator privileges. The method includes implementing, via an encrypted hardware data store of the intent-based security system, storage of contextual alerts, screenshots, action flow maps, process flow maps, and encrypted backups. The encrypted backups are exclusively accessible to the intent-based security system. The method includes enforcing, using the hardware processor, a multi-entity hierarchical workflow such that if a first authorization entity approves an action despite the process flow map and action flow map favouring rejection, the contextual alert is automatically generated to at least one higher-hierarchy authorization entity for secondary decisionmaking, and disabling, uninstalling, or stopping the system in hardware-space or kernel space or user space requires multi-person authorization, thereby preventing unauthorized override and ensuring defense against data breaches and ransomware attacks.

[0018] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating preferred embodiments and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications may be made within the scope of the embodiments herein without departing from the spirit thereof, and the embodiments herein include all such modifications.BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The embodiments herein will be better understood from the following detailed description with reference to the drawings, in which:

[0020] FIG. 1 is a block diagram that illustrates an intent-based security system for preventing data breaches and ransomware attacks in a computing environment according toan embodiment herein;

[0021] FIG. 2 is a flowchart illustrating a process for providing intent-based security according to an embodiment herein;

[0022] FIGS. 3A & 3B are data flow diagrams that illustrate a computer implemented method for preventing data breaches and ransomware attacks in a computing environment according to an embodiment herein; and

[0023] FIG. 4 is an illustration of a computer system in which the various architectures and functionalities of the various previous implementations may be implemented.DETAILED DESCRIPTION OF PREFERRED EMBODIMENTS

[0024] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein may be practiced and to further enable those of skill in the art to practice the embodiments herein. Accordingly, the examples should not be construed as limiting the scope of the embodiments herein. As mentioned, there remains a need for an intent-based security system and a method for preventing data breaches and ransomware attacks in a computing environment. Referring now to the drawings, and more particularly to FIGS. 1 through 4, where similar reference characters denote corresponding features consistently throughout the figures, there are shown preferred embodiments.

[0025] FIG. 1 is a block diagram that illustrates an intent-based security system 100 for preventing data breaches and ransomware attacks in a computing environment according to an embodiment herein. The intent-based security system 100 includes a hardware processor 102, a memory unit 104 and an encrypted data store 114. The memory unit 104 stores processing instructions that, when executed by the hardware processor 102, configure the intent-based security system 100 to perform several critical securityfunctions. As shown in FIG. 1, the hardware processor 102 includes a monitoring module 106, a blocking module 108 and a secure snapshot engine 110. The monitoring module 106, implemented as a set of instructions executed by the hardware processor 102, continuously monitors system activity across multiple layers of the computing environment. The monitoring module 106 observes activity occurring at an operating system kernel level, an application level, an application level implementation based on security inside an application, or a memory space, to identify operations comprising at least one of file access, modification, deletion, encryption, network communication, data exfiltration, data chunking, or actions of artificial intelligence (Al) agents. The monitoring module 106, in a preferred implementation, incorporates the functionality of an OS kernel module, which monitors disk, RAM, external drives, and cloud connectivity for file accesses, modifications, deletions, exfiltration, uploads, and executions.

[0026] The monitored activities encompass a wide range of operations, including, but not limited to, file access (read, write, execute, copy), file modification, file deletion, network communication, data exfiltration, file carving, data chunking / segmentation, data fragmentation, data slicing, and memory access. The inclusion of memory access monitoring is particularly important for detecting fileless malware, which operates entirely in a Random Access Memory (RAM) without writing malicious files to disk. The monitoring module 106 is designed to monitor actions performed by all users, including those with root or administrator 120 privileges. The monitoring module 106 monitors the system activity by observing all malwares including fileless malware activity operating in the RAM without disk artifacts for data exfiltration and data encryption. This comprehensive monitoring enables the intent-based security system 100 to detect potentially malicious actions, regardless of the user's privilege level.

[0027] In addition to monitoring traditional system actors, the monitoring module 106 extends its vigilance to the actions of Al agents and similar Al software. This includes Al agents deployed both overtly and covertly at the edge, as well as Al systems, scripts, algorithms, or models that might be introduced through a vulnerability or reside in the cloud. The intent-based security system 100 is designed to detect and question any action by these Al entities that could lead to data breach, data exfiltration, or data destruction.

[0028] The intent-based security system 100 further comprises a deviation detection capability, realized through the hardware processor's 102 execution of the processing instructions stored in memory unit 104. This detection identifies deviations from expected behavior, indicating a potential data breach or destruction attempt. The hardware processor 102, based on the data stream from the monitoring module 106, determines if current activity deviates from an established baseline of normal operation. Upon detection of a potential threat, the blocking module 108 is activated.

[0029] The blocking module 108, implemented within the hardware processor 102 as a set of executable instructions, immediately intervenes to prevent the potentially harmful action from continuing. This proactive blocking is a crucial step in preventing data loss or damage. The hardware processor 102 is configured to interrogate actions originating from one or more Al agents, comprising covert or overt edge-deployed models or cloud-hosted agents, and block any unauthorized exfiltration or encryption attempts.

[0030] For example, in a practical scenario, the intent-based security system 100 might detect a web browser suddenly accessing files from system memory, an action not initiated by a user 118 and potentially indicative of fileless malware exploiting a browser vulnerability. Alternatively, the intent-based security system 100 may detect a user 118 or administrator 120 account accessing and copying an unusually large number of files to external storage (such as a cloud service, Universal Serial Bus (USB) drive, or via Bluetooth, Near Field Communication (NFC), other wireless technologies), which may indicate an insider threat or an active directory compromise. In either case, the deviation from normal behavior triggers the blocking module 108 to prevent the action, and the system 100 then proceeds to alert the appropriate authorities and / or systems.

[0031] In an embodiment, the intent-based security system 100 implemented with or without artificial intelligence, is configured to detect anomalous events such as abrupt file access, unauthorized file modifications, or unexpected execution of code originating from an external network connection. Such deviations may be identified using neural-network models trained to recognize abnormal patterns, or through deterministic, logic-driven programming approaches employing technologies such as eBPF or comparable frameworks.

[0032] Simultaneously, upon detecting a deviation, the secure snapshot engine 110 is triggered. The secure snapshot engine 110 creates an alert that includes contextual information about the detected deviation, including, at a minimum, a visual representation, such as a screenshot of a file or a memory region associated with the deviation. The secure snapshot engine 110 generates a visual indicator or a telemetry highlighting the specific files or memory addresses attempted for exfiltration or encryption.

[0033] The secure snapshot engine 110 runs as a part of kernel (implemented using an extended Berkley Packet Filter (eBPF), as soon as a deviation is detected by the intentbased security system 100, the application / process / user activity is blocked and the screenshot of the action, for example, exploiting a browsers zero day vulnerability, a malicious code gets injected, privilege gets escalated and from the browsers RAM, browser starts scanning files, chunks the files in little Kilo Bytes and makes an attempt to exfiltrate the files, intent-based security system 100 directs the secure snapshot engine 110 to take screen shot of the process (that is the browser, involving in a malicious activity) and the screen shots of the files, that are divided in to small chunks and share it with the user 118 / administrator 120 / SOC 122 mobile device or to their PCs or to a SIEM system.

[0034] To further aid in the authorization process, the intent-based security system 100 may also generate an action flow map and a process flow map. The action flow map visualizes the potential outcomes of either allowing or preventing the detected action, providing the authorization entity with a clear understanding of the risks and benefits of each choice. The process flow map provides a step-by-step reconstruction of the events that led to the deviation, including, for example, the execution of a malicious script within a browser's memory following the exploitation of a zero-day vulnerability, or the establishment of a command-and-control (C2) channel after a phishing attack. This information helps to identify the root cause of the deviation and inform remediation efforts.

[0035] The generated alert, along with the action flow map and the process flow map, is then transmitted via an encrypted communication module 112, which, more particularly, is an end-to-end encrypted secure communication module. The encrypted communication module 112 ensures secure and confidential communication between the system components and the designated authorization entities by using end-to-endencryption. The alerts are sent to at least one designated authorization entity, selected from a user(s) 118, an administrator(s) 120, a security operations center (SOC) 122, and / or an Al engine 124. The authorization entity receiving the alert is always separate from the entity (administrator 120, user 118, process, or application) that triggered the deviation. This separation of duties prevents compromised users or processes from authorizing malicious actions. The transmission of the alert may utilize a radio network 116 (or any communications network leveraging any type of electromagnetic waves), such as the Internet, to reach the user(s) 118, administrator(s) 120, SOC 122, and Al engine 124, often via enterprise mobile devices or other configured systems.

[0036] The encrypted data store 114 providing secure storage (disk or cloud) for screenshots, logs and data related to detected deviations and alerts. The encrypted data store 114 ensures the integrity and confidentiality of this information, preventing unauthorized access or modification.

[0037] The authorization decision, either to allow or prevent the continuation of the action, is received by the hardware processor 102, which executes the decision. If the decision is to prevent the action, the hardware processor 102 terminates the associated process, even if initiated by a user (e.g., 118 or 120) with root or administrator privileges, providing crucial protection against insider threats and privilege escalation attacks.

[0038] The intent-based security system 100 supports two primary workflows for authorization. In a non-AI-driven scenario, the intent-based security system 100, upon detecting a deviation, blocks the action and alerts the designated user 118, administrator 120, or SOC 122. These entities then review the alert, including the contextual information, visual representation, action flow map, and process flow map, and provide an authorization decision (allow or prevent). In one implementation, this decision may require additional authentication, such as answering predefined security questions or performing physical biometric authentication on the enterprise mobile devices or on a designated system. The decision is then relayed back to the intent-based security system 100 for execution. The intent-based security system 100 also provides an end-to-end secure mobile / desktop application that allows manual review by the user 118, administrator 120, and SOC 122when Al is not deployed, providing insights into detected anomalies and potential outcomes.

[0039] Alternatively, in an Al-driven scenario, the intent-based security system 100, upon detecting a deviation, blocks the action and alerts the Al engine 124 (which may be located on the same device — edge Al — or remotely, such as in the cloud). The Al engine 124, which is an end-to-end secure Al agent, analyzes the alert, including the contextual information, visual representation, action flow map, and process flow map, and provides an authorization decision. This decision is then sent back to the intent based security system 100 for execution.

[0040] In an embodiment, in an Al-driven workflow, the Al engine 124 determines whether to generate the authorization request to an administrator 120 or SOC 122 based on a calculated criticality level of the deviation, comprising at least one of active directory compromise, persistence, data encryption, data exfiltration, lateral movement, or insider threats.

[0041] The Al engine 124 performs the analysis based on, but not limited to, the following: screenshots of actions, information on where the action is originated; information on what triggered the action and current status; action flow map, and process flow map to assess security risks. If the Al engine 124 determines the action to be anomalous based on training data, it rejects the action and instructs the secure system kernel to terminate the process. If the Al engine 124 encounters an untrained or unclassified action, the Al engine 124 escalates the workflow to user 118, administrator 120, SOC 122, or a combination thereof with screenshots and accept / reject options for further decisionmaking. For such untrained or unclassified actions, the Al engine 124 adopts a Human-in-the-Loop concept, thereby sending the alerts to an admin 120, super admin, SOC 122 or a combination thereof.

[0042] In an additional implementation, the Al engine 124 determines the criticality of the action (i.e., deviation) and, based on training, decides whether to escalate the issue to administrator 120, SOC 122 instead of the user 118, particularly in cases of active directory (AD) compromise, lateral movement, persistence, previously unobserved actions, or insider threats. Based on the response from administrator 120 or SOC 122, the intent-basedsecurity system 100 either allows the action to proceed or terminates it to prevent a potential security breach.

[0043] By actively questioning the intent behind system activities, rather than relying solely on predefined rules or behaviors, the system (and method) provides robust security against a wide range of threats, including those that are unknown or exploit zero-day vulnerabilities. The novel interrogation mechanism, applicable to operating systems, applications, processes, users 118, administrators 120, and even Al agents, establishes a critical checkpoint preventing data exfiltration even with root or administrator privileges. This is achieved through a multi-layered approach, including a security module residing within applications. This security module could also reside at the OS kernel level for specific application monitoring. For example, it could monitor the Chrome browser’s RAM, registry, and files to detect potential deviations that could lead to a data breach. Furthermore, this approach includes the requirement for authorization from a separate entity, such as via an enterprise mobile device or a designated enterprise system like an SOC 122, even for actions initiated by privileged users 118. The system's ability to monitor and control actions at both the OS kernel and application levels, combined with its proactive blocking and contextual alerting capabilities, creates a secure environment where data remains protected regardless of the intent of an attacker or the sophistication of the attack.

[0044] In some embodiments, the hardware processor 102 employs end-to-end encryption to transmit the contextual alert to a mobile device or an enterprise system configured for security operations. In some embodiments, the system 100 enforces hierarchical workflow escalation such that if a lower-level user authorizes an action flagged as potentially malicious, wherein the contextual alert is automatically generated to at least one administrator 120, SOC 122, or super-admin.

[0045] In some embodiments, the encrypted data store 114 in the hardware prevents any read or write operation by external applications or users 118, and access to backups is restricted to the system through cryptographic binding between the intent based security system 100 on the hardware processor 102, memory unit 104 and the data store in the hardware 114, and disabling, uninstalling, or stopping the system requires multi-personauthorization, including at least two distinct authorization entities selected from a user 118, administrator 120, SOC 122, or Al engine 124.

[0046] The system 100 addresses the limitations of existing techniques by enabling the detection and prevention of malicious actions based on their intent, regardless of user privilege or whether the attack vector is known or unknown, generalizing to diverse operating systems, Central Processing Units (CPUs), firmware and application environments, and facilitating real-time intervention with proactive blocking, detailed contextual alerts, and a flexible authorization workflow.

[0047] The system 100 provides proactive and comprehensive protection against data breaches and data destruction in a computing environment. Unlike traditional security systems that rely on predefined rules or signatures, and pre-trained system behaviors, which means that a new exploit may evade detection if it doesn’t match known suspicious behaviors, the system focuses on identifying and responding to deviations from expected system behavior, regardless of the user's privilege level or the specific nature of the attempted action.

[0048] Central to this system 100 is a mechanism that, in real-time, actively “questions” (or interrogates) the intent behind any system activity whether originating from an application, script, process, operating system, user 118, administrator 120, or other system component (like CPU or firmware) that involves potentially compromising actions. These actions include, but are not limited to, copying, modifying, deleting, or dividing files into smaller parts, as well as attempts to exfiltrate data from system memory, which is indicative of fileless or in-memory malware. Additionally, the system 100 examines actions initiated by any scripts, operating system processes, applications (whether running from RAM or disk or external sources), or any entity attempting data exfiltration.

[0049] This approach allows the system 100 to detect and prevent both known and unknown threats, including insider threats, zero-day exploits, and privilege escalation attacks, by focusing on the intent behind actions rather than relying solely on identifying known malicious patterns. The system operates by continuously monitoring system activity, blocking potentially harmful deviations, generating contextual alerts, andenforcing authorization decisions from designated entities, including an Artificial Intelligence (Al) engine, users 118, administrators 120, or a security operations center (SOC) 122. The system can be implemented as part of the operating system kernel, as a component within an application, or as a combination of both kernel-level and applicationlevel components. For example, a security module implemented at the Operating System (OS) kernel level could monitor the activities of Microsoft Office components, including the Random-Access Memory (RAM) space and registry address. The system maintains secure and encrypted communication as well as secure and encrypted storage for records.

[0050] FIG. 2 is a flowchart illustrating a process for providing intent-based security according to an embodiment herein. The process illustrates the intent-based security system 100 described in FIG. 1. The process can be implemented in various ways, including as part of the operating system kernel, as a component within an application, or as a combination of both. At step 200, the process begins with the monitoring of system activity. The monitoring is performed by the monitoring module 106, preferably implemented within the hardware processor 102. The monitoring encompasses multiple layers of the computing environment, including the operating system kernel level and individual application levels. The monitored activities include, but are not limited to, file access (read, write, execute, copy), file modification, file deletion, network communication, data exfiltration, file carving, data chunking / segmentation, data fragmentation, data slicing, memory access, and the actions of Al agents and similar Al software (including those deployed overtly or covertly, at the edge, or in the cloud). This comprehensive monitoring detects actions performed by all users 118, including those with root or administrator privileges, and even Al entities.

[0051] At step 202, the process determines if a deviation from expected behavior has been detected. This deviation detection is performed by the hardware processor 102, which compares the current system activity to an established baseline of normal operation. If the current activity does not deviate from the established baseline, the process returns to the step 200 and continues monitoring. If a deviation is detected at step 202, indicating a potential data breach or destruction attempt, the method proceeds to step 204. At step 204, the detected deviation is blocked. This proactive blocking prevents the potentially harmfulaction from continuing. At step 206, an alert is generated. The alert includes contextual information about the detected deviation. This contextual information comprises, at a minimum, a visual representation / visual telemetry of the action that caused the deviation, such as a screenshot. Additionally, the alert may include an action flow map and / or a process flow map. The action flow map visualizes the potential outcomes of allowing or preventing the action. The process flow map provides a step-by-step reconstruction of the events leading up to the deviation. At step 208, the generated alert, along with the optional action flow map and process flow map, is, as enabled by encryption techniques, securely transmitted to at least one designated authorization entity. The designated authorization entity can be a user 118, an administrator 120, a SOC 122, or an Al engine 124. The authorization entity is always separate from the entity (user 118, administrator 120, process, application, or Al agent) that triggered the deviation. At step 210, an authorization decision is received. This decision, which can be either to allow or prevent the continuation of the action, is received by the hardware processor 102.

[0052] The method further includes executing the authorization decision. If the decision is to prevent the action, at step 214, the process associated with the deviation is terminated, even if the process is initiated by a user 118 with root or administrator privileges. If the decision is to allow the action, the process is allowed to continue as outlined by step 212.

[0053] The authorization process may follow two primary workflows, viz., a non-Al-driven scenario and an Al-driven scenario. In a non-AI-driven scenario, the authorization decision is made by a human user 118, administrator 120, or SOC 122 personnel after reviewing the alert and associated contextual information. This decision may require additional authentication, such as security questions, biometric authentication, multi-factor authentication or multi user authorization. In an Al-driven scenario, the Al engine 124 analyzes the alert and contextual information and provides the authorization decision. In conclusion, the intent-based security system 100 and method described herein represents a significant advancement in data protection.

[0054] FIGS. 3A & 3B are data flow diagrams that illustrate a computer implemented method for preventing data breaches and ransomware attacks in a computingenvironment according to an embodiment herein. At step 302, system activity is continuously monitored across one or more layers of the computing environment, including an operating system kernel level, an application level, an application level implementation based on security inside an application, and a memory space, to identify operations comprising at least one of file access, modification, deletion, encryption, network communication, data exfiltration, data chunking, or actions of artificial intelligence (Al) agents, using a hardware processor 102 of the intent-based security system 100, via kernelspace monitoring implemented on the hardware processor 102. At step 304, deviations from a stored baseline of expected behavior indicative of a potential data breach or ransomware attack is detected in real-time and at hardware processor-assisted kernel hooks, using the hardware processor 102.

[0055] At step 306, upon detecting the deviation, a contextual alert is generated using the hardware processor 102. The contextual alert includes at least one screenshot of a file or memory region associated with the deviation, and at least one of an action flow map and a process flow map, and the action flow map visualizes potential outcomes of allowing or preventing the action, and wherein the process flow map reconstructs events leading to the deviation. At step 308, execution of the deviation-causing action pending authorization is proactively blocked, using the hardware processor 102, by an enforced interlock mechanism. At step 310, the contextual alert is securely transmitted to at least one designated authorization entity separate from the entity that triggered the deviation using the hardware processor 102, via encrypted communication implemented on the hardware processor 102. The authorization entity is selected from a user 118, administrator 120, a security operations centre (SOC) 122, or an Al engine 124. At step 312, an authorization decision is received to either allow or prevent continuation of the action, using the hardware processor 102, from the authorization entity.

[0056] At step 314, the authorization decision is enforced by terminating or allowing the associated process, even if initiated by a user 118 or the process with root or administrator privileges, using the hardware processor 102. At step 316, storage of contextual alerts, screenshots, action flow maps, process flow maps, and encrypted backups are implemented via an encrypted hardware data store of the intent-based security system100. The encrypted backups are exclusively accessible to the intent-based security system 100. At step 318, a multi-entity hierarchical workflow is enforced, using the hardware processor 102, such that if a first authorization entity approves an action despite the process flow map and action flow map favouring rejection, the contextual alert is automatically generated to at least one higher-hierarchy authorization entity for secondary decisionmaking, and disabling, uninstalling, or stopping the system in hardware-space or kernel space or user space requires multi-person authorization, thereby preventing unauthorized override and ensuring defense against data breaches and ransomware attacks.

[0057] FIG. 4 is an illustration of a computer system in which the various architectures and functionalities of the various previous implementations may be implemented. As shown, the computer system 400 includes at least one processor 404 that is connected to a bus 402, wherein the computer system 400 may be implemented using any suitable protocol, such as PCI (Peripheral Component Interconnect), PCI Express, AGP (Accelerated Graphics Port), Hyper Transport, or any other bus or point-to-point communication protocol (s). The computer system 400 also includes a memory 406.

[0058] Control logic (software) and data are stored in the memory 406 which may take a form of random-access memory (RAM). In the disclosure, a single semiconductor platform may refer to a sole unitary semiconductor-based integrated circuit or chip. It should be noted that the term single semiconductor platform may also refer to multi-chip modules with increased connectivity which simulate on-chip modules with increased connectivity which simulate on-chip operation, and make substantial improvements over utilizing a conventional central processing unit (CPU) and bus implementation. Of course, the various modules may also be situated separately or in various combinations of semiconductor platforms per the desires of the user.

[0059] The computer system 400 may also include a secondary storage 410. The secondary storage 410 includes, for example, a hard disk drive and a removable storage drive, representing a floppy disk drive, a magnetic tape drive, a compact disk drive, digital versatile disk (DVD) drive, recording device, universal serial bus (USB) flash memory cloud storage, solid state drives (SSD), network attached storage (NAS) or future storagedevices and technologies. The removable storage drive at least one of reads from and writes to a removable storage unit in a well-known manner.

[0060] Computer programs, or computer control logic algorithms, may be stored in at least one of the memories 406 and the secondary storage 410. Such computer programs, when executed, enable the computer system 400 to perform various functions as described in the foregoing. The memory 406, the secondary storage 410, and any other storage are possible examples of computer-readable media.

[0061] In an implementation, the architectures and functionalities depicted in the various previous figures may be implemented in the context of the processor 404, a graphics processor coupled to a communication interface 412, an integrated circuit (not shown) that is capable of at least a portion of the capabilities of both the processor 404 and a graphics processor, a chipset (namely, a group of integrated circuits designed to work and sold as a unit for performing related functions, and so forth).

[0062] Furthermore, the architectures and functionalities depicted in the various previous-described figures may be implemented in a context of a general computer system, a circuit board system, a game console system dedicated for entertainment purposes, an application- specific system. For example, the computer system 400 may take the form of a desktop computer, a laptop computer, a server, a workstation, a game console, an embedded system, an Internet of Things (IoT) / Industrial Internet of Things (IIoT) device, or a System-on-Chip (SoC) device.

[0063] Furthermore, the computer system 400 may take the form of various other devices including, but not limited to a personal digital assistant (PDA) device, a mobile phone device, a smart phone, a television, and the like, or any relevant devices that might be developed in the future. Additionally, although not shown, the computer system 400 may be coupled to a network (for example, a telecommunications network, a local area network (LAN), a wireless network, a wide area network (WAN) such as the Internet, a peer-to-peer network, a cable network, or the like) for communication purposes through an Input / output (I / O) interface 408.

[0064] It should be understood that the arrangement of components illustrated in the figures described is exemplary and that other arrangements may be possible. It should alsobe understood that the various system components (and means) defined by the claims, described below, and illustrated in the various block diagrams represent components in some systems configured according to the subject matter disclosed herein. For example, one or more of these system components (and means) may be realized, in whole or in part, by at least some of the components illustrated in the arrangements illustrated in the described figures.

[0065] In addition, while at least one of these components are implemented at least partially as an electronic hardware component, and therefore constitutes a machine, the other components may be implemented in software that when included in an execution environment constitutes a machine, hardware, or a combination of software and hardware.

[0066] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and / or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modification within the spirit and scope.

Claims

CLAIMSI / We claim:

1. An intent-based security system (100) for preventing data breaches and ransomware attacks in a computing environment, the system (100) comprising:a hardware processor (102);a memory unit (104), when executed by the hardware processor (102), configures the hardware processor (102) to:continuously monitor, via a kernel-space monitoring implemented on the hardware processor (102), system activity across a plurality of layers of the computing environment, comprising an operating system kernel level, an application level, an application level implementation based on security inside an application, or a memory space, to identify operations comprising at least one of file access, modification, deletion, encryption, network communication, data exfiltration, data chunking, or actions of artificial intelligence (Al) agents;detect, in real-time and at hardware processor (102) assisted kernel hooks, deviations from a stored baseline of expected behavior indicative of a potential data breach or ransomware attack;characterized in that,upon detecting a deviation, generate, by a secure snapshot engine (110) implemented on the hardware processor (102), a contextual alert comprising at least one screenshot of a file or memory region associated with the deviation, and at least one of an action flow map and a process flow map, wherein the action flow map visualizes potential outcomes of allowing or preventing the action, and wherein the process flow map reconstructs events leading to the deviation;proactively block, by an enforced interlock mechanism, execution of the deviation causing action pending authorization;securely transmit via an encrypted communication implemented on the hardware processor (102), the contextual alert to at least one designated authorization entity separate from the entity that triggered the deviation, wherein theauthorization entity is selected from a user (118), administrator (120), a security operations centre (SOC) (122), or an Al engine (124);receive, from the authorization entity, an authorization decision to either allow or prevent continuation of the action; andenforce the authorization decision by terminating or allowing the associated process, even if initiated by a user (118) or the process with root or administrator privileges; andan encrypted data store (114) configured to store the contextual alert, screenshots, action flow maps, process flow maps, and encrypted backups, wherein the encrypted backups are accessible only by the intent-based security system (100); andwherein the system (100) further enforces a multi-entity hierarchical workflow such that, if a first authorization entity accepts the action despite the process flow map and action flow map favouring rejection, wherein the contextual alert is automatically generated to at least one higher-hierarchy authorization entity for secondary decision-making, and wherein disabling, uninstalling, or stopping the system in hardware-space or kernel space or user space requires multi-person authorization, thereby preventing data breaches and ransomware attacks in the computing environment.

2. The system (100) as claimed in claim 1, wherein the system (100) monitors the system activity by observing malwares including fileless malware activity operating in a Random Access Memory (RAM) without disk artifacts for data exfiltration and data encryption.

3. The system (100) as claimed in claim 1, wherein the hardware processor (102) is configured to interrogate actions originating from a plurality of Al agents, comprising covert or overt edge-deployed models or cloud-hosted agents, and block any unauthorized exfiltration or encryption attempts.

4. The system (100) as claimed in claim 1, wherein the hardware processor (102) generates a visual indicator or a telemetry highlighting the specific files or memory addresses attempted for exfiltration or encryption.

5. The system (100) as claimed in claim 1, wherein the hardware processor (102) employs end-to-end encryption to transmit the contextual alert to a mobile device or an enterprise system configured for security operations.

6. The system (100) as claimed in claim 1, wherein the authorization decision in a non-AI-driven workflow requires additional authentication, comprising biometric authentication, multi-factor authentication or multi user authorization on enterprise mobile devices or desktop devices.

7. The system (100) as claimed in claim 1, wherein, in an Al-driven workflow, the Al engine (124) determines whether to generate the authorization request to an administrator (120) or SOC (122) based on a calculated criticality level of the deviation, comprising at least one of active directory compromise, persistence, data encryption, data exfiltration, lateral movement, or insider threats.

8. The system (100) as claimed in claim 1, wherein the system (100) enforces hierarchical workflow escalation such that if a lower-level user authorizes an action flagged as potentially malicious, wherein the contextual alert is automatically generated to at least one administrator (120), SOC (122), or super-admin.

9. The system (100) as claimed in claim 1, wherein the encrypted data store (114) in the hardware prevents any read or write operation by external applications or users (118), and wherein access to backups is restricted to the system through cryptographic binding between the intent based security system (100) on the hardware processor (102), memory unit (104) and the data store in the hardware, wherein disabling, uninstalling, or stopping the system requires multi-person authorization, comprising at least two distinct authorization entities selected from a user (118), administrator (120), SOC (122), or Al engine (124).

10. A computer-implemented method for preventing data breaches and ransomware attacks in a computing environment, using an intent-based security system (100), the method comprising:continuously monitoring, using a hardware processor (102) of the intent-based security system (100), via kernel-space monitoring implemented on the hardware processor (102), system activity across a plurality of layers of the computing environment, including an operating system kernel level, an application level, an application level implementation based on security inside an application, and a memory space, to identify operations comprising at least one of file access, modification, deletion, encryption, network communication, data exfiltration, data chunking, or actions of artificial intelligence (Al) agents;detecting, using the hardware processor (102), in real-time and at hardware processor-assisted kernel hooks, deviations from a stored baseline of expected behavior indicative of a potential data breach or ransomware attack;characterized in that,generating, using the hardware processor (102), upon detecting the deviation, a contextual alert including at least one screenshot of a file or memory region associated with the deviation, and at least one of an action flow map and a process flow map, wherein the action flow map visualizes potential outcomes of allowing or preventing the action, and wherein the process flow map reconstructs events leading to the deviation;proactively blocking, using the hardware processor (102), by an enforced interlock mechanism, execution of the deviation-causing action pending authorization;securely transmitting, using the hardware processor (102), via encrypted communication implemented on the hardware processor (102), the contextual alert to at least one designated authorization entity separate from the entity that triggered the deviation, wherein the authorization entity is selected from a user (118), administrator (120), a security operations centre (SOC) (122), or an Al engine (124);receiving, using the hardware processor (102), from the authorization entity, an authorization decision to either allow or prevent continuation of the action; andenforcing, using the hardware processor (102), the authorization decision by terminating or allowing the associated process, even if initiated by a user (118) or the process with root or administrator privileges;implementing, via an encrypted hardware data store of the intent-based security system (100), storage of contextual alerts, screenshots, action flow maps, process flow maps, and encrypted backups, wherein the encrypted backups are exclusively accessible to the intent-based security system (100); andenforcing, using the hardware processor (102), a multi-entity hierarchical workflow such that if a first authorization entity approves an action despite the process flow map and action flow map favouring rejection, the contextual alert is automatically generated to at least one higher-hierarchy authorization entity for secondary decision-making, and wherein disabling, uninstalling, or stopping the system in hardware-space or kernel space or user space requires multi-person authorization, thereby preventing unauthorized override and ensuring defense against data breaches and ransomware attacks.