Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

144 results about "Ransomware" patented technology

Ransomware is a type of malware from cryptovirology that threatens to publish the victim's data or perpetually block access to it unless a ransom is paid. While some simple ransomware may lock the system in a way which is not difficult for a knowledgeable person to reverse, more advanced malware uses a technique called cryptoviral extortion, in which it encrypts the victim's files, making them inaccessible, and demands a ransom payment to decrypt them. In a properly implemented cryptoviral extortion attack, recovering the files without the decryption key is an intractable problem – and difficult to trace digital currencies such as Ukash or Bitcoin and other cryptocurrency are used for the ransoms, making tracing and prosecuting the perpetrators difficult.

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

AI Identification of Computer Resources Subjected to Ransomware Attack

A method of causing ransomware to be executed includes obtaining a set of ransomware samples and automatically performing a set of scripted detonations of a first subset of the ransomware samples according to a schedule. The set of scripted detonations includes executing the first subset of ransomware samples on a virtual machine. During the execution of the first subset of ransomware samples, use of computing resources by the first subset of ransomware samples is monitored until a shutdown threshold is reached. Upon reaching the shutdown threshold, any pending detonation tasks of the execution of the first subset of ransomware samples are purged. Detonation-infected disk images are generated to include files resulting from the execution of the first subset of ransomware samples, and the detonation-infected disk images are used in training a machine learning system to assess a likelihood of a presence of a ransomware attack.
Owner:T W STORAGE

Adaptive authentication for ransomware intervention

Security in a computing environment is enhanced by analyzing telemetry data from an agent on a device, along with user integrity information, to detect events that suggest compromised credentials. When such an event is detected, a risk level is assigned based on the analysis. This risk level is then correlated with a corresponding authentication difficulty level, which specifies the types and strengths of authentication mechanisms to be used. The selected authentication difficulty level is applied across multiple devices within the environment, enabling adaptive and dynamic protection against unauthorized access due to compromised credentials.
Owner:HALCYON TECH

Ransomware detection

The technology disclosed relates to detecting a data attack on a local file system. The detecting includes scanning a list to identify files of the local file system that have been updated within a timeframe, reading payloads of files identified by the scanning, calculating current content properties from the payload of the files, obtaining historical content properties of the files, determining that a malicious activity is in process by analyzing the current content properties and the historical content properties to identify a pattern of changes that exceeds a predetermined change velocity. Further, the detecting includes determining that the malicious activity is in process by analyzing the current content properties and known patterns of malicious metadata to identify a match between the current metadata and the known patterns of malicious metadata, determining a machine / user that initiated the malicious activity, and implementing a response mechanism that restricts file modifications by the machine / user.
Owner:NETSKOPE INC

Ransomware infection detection in filesystems

Described herein is a system that detects ransomware infection in filesystems. The system detects ransomware infection by using backup data of machines. The system detects ransomware infection in two stages. In the first stage, the system analyzes a filesystem's behavior. The filesystem's behavior can be obtained by loading the backup data and crawling the filesystem to create a filesystem metadata including information about file operations during a time interval. The filesystem determines a pattern of the file operations and compares the pattern to a normal patter to analyze the filesystem's behavior. If the filesystem's behavior is abnormal, the system proceeds to the second stage to analyze the content of the files to look for signs of encryption in the filesystem. The system combines the analysis of both stages to determine whether the filesystem is infected by ransomware.
Owner:RUBRIK INC

Real-time ransom and security breach detection and prevention

The real-time ransom and security breach detection and prevention system empowers users and system administrators by providing real-time threat detection and prevention by detecting any phishing links, malicious executables and objects, and manipulation of authentication tokens that could potentially escalate a threat into ransom attacks, security breaches or other cyber attacks, and take immediate action by blocking and reporting the potential security breach before escalating into a real attack. The real-time ransom and security breach detection and prevention system generates a first hash of the link, executable, object, or authentication token. Utilizing this generated first hash, the real-time ransom and security breach detection and prevention system calculates a second hash upon user interaction or at runtime and compares the two unique hashes to determine if the link, executable, object, or authentication token is corrupt and terminates the gateway to prevent the cyber-threat from infecting the system.
Owner:IMPERVIOUS WORLD CORP

Ransomware identification method and system based on multi-source data fusion

PendingCN122263100AEffectively respond to attack situationsAchieve full-range accurate identificationPlatform integrity maintainanceNetwork connectionAttack
The application discloses a ransomware identification method and system based on multi-source data fusion, and relates to the field of ransomware detection. The method obtains file system event data, system resource running indexes, process behavior data and industrial control system behavior data, identifies file features, system running behavior situation features, process features and industrial scene features from the data, judges whether each feature meets the essential behavior features of ransomware encrypted files, and divides the features into strong indication features, medium indication features and basic situation features. Different mapping methods are used to determine sub-risk scores for different features, and finally a weighted scoring mechanism is used to obtain an overall urgency score, based on which a ransomware attack is determined, and then suspicious process operations are automatically triggered and terminated in parallel, and network connections are blocked to prevent the spread of ransomware attacks. The application can accurately identify known ransomware and unknown variants, and has good interpretability.
Owner:NAT IND INFORMATION SECURITY DEV RES CENT

Virtual canary files to mitigate ransomware attacks

ActiveUS12694101B2Virtual memoryAttack
Provided is a computer agent and method to detect and prevent ransomware attacks early without losing customer data, without polluting the customer's file system or consuming any space on a storage device. The computer agent installs a kernel mode layered file system driver which is attached to encryption level group of a filter manager. With this layered file system filter driver design, it creates virtual canary files in directories which appear like normal files to any user or application though these files will not reside on disk. These virtual canary files are spread as baits across the file system to detect and prevent any malicious attack from any process or application. So that the Virtual Canary Files do not consume a large amount of memory, internal structures representing Virtual Canary Files are placed in virtual memory, but actual contents of the Virtual Canary Files do not reside in virtual memory. Other embodiments disclosed.
Owner:THALES DIS CPL USA INC

Harmless protection capability verification method and system based on ransomware virus behavior simulation

The invention provides a harmless protection capability verification method and system based on ransomware behavior simulation, and relates to the technical field of network security, and the method comprises the steps: firstly generating reference behavior information based on the attack behavior characteristics of ransomware; then simulating and executing an operation defined by the reference behavior information in a target server environment, and obtaining actual physical layer behavior information; performing space-time consistency comparison on the actual physical layer behavior information and expected physical layer behavior information corresponding to the reference behavior information so as to identify an abnormal behavior mode; reconstructing the abnormal behavior modes to establish a target behavior field model, and calculating through the model to obtain topological feature data and an entropy change gradient; and finally, in combination with the topological feature data and the entropy change gradient, evaluating the harmless protection capability of the protection system to the ransomware virus in the target server environment. According to the invention, the active protection verification capability for the high-grade ransomware avoidance behavior is improved.
Owner:BEIJING DISTRICT HEATING GRP CO LTD

Ransomware detection method and device based on eBPF and machine learning

The invention provides a ransomware detection method and device based on eBPF and machine learning, and relates to the technical field of information security, the method comprises the following steps: mounting an eBPF program to a key system of a target system for calling, and capturing file operation behavior data such as a process identifier and an operation type in real time through an event-driven mechanism; extracting features based on a preset time window, counting process file operation cumulative times, screening out abnormal operation behaviors through threshold filtering, and constructing context features at the same time; utilizing a support vector machine algorithm to train feature data to generate a classification model, and optimizing kernel function parameters to improve small sample scene classification accuracy; and continuously collecting real-time file operation data through an eBPF program, inputting the real-time file operation data into the model, carrying out dynamic classification, and triggering alarm and blocking when the ransomware is detected. According to the method, the system performance overhead is effectively reduced, the detection real-time performance and accuracy are improved, and the model stability is enhanced.
Owner:PICC INFORMATION TECH CO LTD

Mitigating ransomware activity of a host system using a kernel monitor

A kernel monitor can be used to mitigate ransomware activity of a host system. In some aspects, a computing system can use the kernel monitor to monitor a set of system calls generated by the host system within a time window to perform a functionality. The kernel monitor can include a respective kernel program monitoring each system call in the set of system calls. The set of system calls can be filtered by the kernel monitor to identify a subset of system calls associated with encrypting a filesystem of the host system. The computing system can determine that the subset of system calls is indicative of ransomware activity associated with the host system based on the subset of system calls exceeding a predefined threshold. Subsequently, the computing system can perform a mitigation operation to mitigate the ransomware activity.
Owner:RED HAT INC

A hardware-software co-operated secure AI NAS storage system and access authentication method

The application provides a soft and hard cooperative security AI NAS storage and calculation system and an access authentication method, and belongs to the technical field of network storage. The system comprises a hardware security layer, a lobster security core module, a compulsory authentication gateway, an encrypted storage engine, an intelligent access control module and a security audit and monitoring module. The hardware security layer comprises a lobster security chip and a hardware root of trust module. The lobster security chip is an independent security processor, and is internally provided with a true random number generator, an encryption acceleration engine and a security storage area. The hardware root of trust module is used for system startup verification and root key hardware protection. Through the soft and hard cooperative architecture and the compulsory authentication mechanism, the application realizes a complete trust chain from the hardware root of trust to the application layer, can effectively prevent ransomware attacks and data leakage risks, and improves data operation efficiency.
Owner:QUANTUM CORE CLOUD (BEIJING) MICROELECTRONICS TECH CO LTD

Cloud Ransomware Protection

A newly created or modified object is sent to a networked local or remote server for analysis. While the object is being analyzed for vulnerabilities, the object is locked and made inaccessible to users, devices, and networks. If the object is identified as malicious, it may be marked for review, deleted, placed in quarantine, or have its permissions changed so that it cannot cause harm by propagating through the environment. Conversely, if the object is identified as safe, the risk of ransomware attacks may also be mitigated by replicating the object across multiple cloud storage platforms.
Owner:THREATDOWN INC

Lightweight real-time ransomware detection method and related equipment

The embodiment of the invention provides a lightweight real-time ransomware detection method and related equipment, and belongs to the technical field of network security. The method comprises the following steps: deploying a bait file according to attribute characteristics of a real file; malicious behavior monitoring is carried out according to the preset monitoring point, and a system process triggering the preset monitoring point is determined as a first suspicious process; performing primary monitoring on the first suspicious process, and extracting lightweight features; performing primary fine granularity detection on the first suspicious processes according to the lightweight features, and screening out benign processes in the first suspicious processes to obtain second suspicious processes; performing secondary monitoring on the second suspicious process, and extracting deep process behavior characteristics; and performing advanced fine-grained detection on the second suspicious process according to the deep process behavior characteristics to obtain the ransomware process. According to the embodiment of the invention, the calculation overhead can be reduced while the high detection performance is maintained, the real-time detection requirement can be met, and the alarm fatigue can be relieved.
Owner:GUANGZHOU UNIVERSITY

Distributed ledger-based hybrid quantum machine learning ransomware security

Disclosed are various approaches for distributed ledger-based hybrid quantum ransomware security. In some examples, ransomware detection can be performed on a file. The ransomware detection can include converting the file into image data comprising an image data format, processing the image data using a convolutional neural network to generate a feature map, and providing the feature map to a variational quantum circuit machine learning engine. An action can be performed based at least in part on an output from the variational quantum circuit machine learning engine.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Distributed ransomware protection

Distributed ransomware techniques for protecting a distributed computer system are presented. The techniques include detection actions and diagnosis actions, performed by each node. The detection actions include: generating random files of a plurality of file types; storing the random files in randomized locations; computing baseline hash values for the random files; encrypting a configuration file containing the baseline hash values; storing the encrypted configuration file; computing updated hash values; comparing the baseline hash values with the baseline hash values; and storing a fault condition indication based on at least a result of the comparing. The diagnosis actions include: maintaining a diagnostic record indicative of fault conditions of at least some of the of nodes; sending a request for a neighboring node diagnostic record to a neighboring node; receiving the neighboring node diagnostic record from the neighboring node; and updating the diagnostic record based on the neighboring node diagnostic record.
Owner:JOHNS HOPKINS UNIVERSITY

Defense method and device for dealing with ransomware attack, equipment, medium and program product

The invention provides a ransomware attack defense method and device, equipment, a medium and a program product, relates to the technical field of information security, and can be used in the field of financial science and technology or other fields. The method comprises the steps of sampling files in a monitoring directory according to a sampling frequency, and only calculating an entropy value of a file of which the state is changed in the monitoring directory in a current sampling period during each sampling so as to obtain a first entropy value of at least one to-be-analyzed file; if a target file with a first entropy value meeting a ransomware judgment condition exists in the at least one file to be analyzed, it is determined that the monitoring directory is subjected to ransomware attack, a bait file embedded with a binary code for triggering a response executor is generated in the monitoring directory, and when the bait file is accessed, the response executor is triggered to respond to the target file. The binary code is run to trigger execution of a response executor, where the response executor is used to counteract the ransomware attack.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Ransomware detection in deduplicated storage systems

This disclosure relates to ransomware detection in deduplication storage systems. Example implementations relate to deduplication operations in storage systems. Examples include: receiving data units of a backup stream to be stored in a deduplication storage system; performing a first matching operation for matching data units against a first container index among a plurality of container indexes, wherein the plurality of container indexes include metadata indicating the storage location of data units previously stored in persistent storage; calculating a first ratio, the first ratio indicating the amount of deduplication that occurred during the first matching operation against the first container index; and identifying at least a portion of the backup stream as potentially affected by a ransomware attack in response to determining that the first ratio violates a condition of local ratio history data regarding the first container index.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Using intermediate mappings to prevent data loss from ransomware

A storage driver for a storage space (e.g., hard disk volume) may use intermediate mappings for write, create, and delete requests to prevent data loss from ransomware. The storage driver receives a request to overwrite a data item (e.g., file or object) at a first location of a storage space and in response, writes data to a second location of the storage space. The storage driver also generates a write mapping that associates the first location with the second location. At a later point in time, the storage driver may determine whether to commit the request to overwrite the data item. If the storage driver determines not to commit the request to overwrite the data item (due to the data being the result of a ransomware attack), then the storage driver deletes the write mapping, preventing the first location from being overwritten (preventing data loss from a ransomware attack).
Owner:AMAZON TECH INC

Ransomware detection using cryptographic API call graph analysis

An agent executing on a monitored computing device intercepts runtime execution data associated with a process by utilizing hooks into cryptographic application programming interfaces (APIs). The agent constructs a dynamic execution graph, where each node represents an intercepted cryptographic API call and each edge reflects an inferred relationship between nodes derived from the runtime execution data. Cryptographic entanglement metrics are computed based on the dynamic execution graph, characterizing structural properties of cryptographic behavior within the process. When these computed metrics indicate that the process is part of a ransomware attack, one or more remediation actions are initiated to thwart the advancement of the attack.
Owner:HALCYON TECH

Semantic-driven encrypted ransomware detection method and system for unknown sample

The invention discloses an unknown sample-oriented semantic-driven encrypted ransomware detection method and system, and relates to the field of computer security. The method comprises the steps that original log data streams are collected, noise is removed through self-adaptive sampling and triple filtering, and effective candidate events are converted into a semantic structured event set containing standardized natural language description through a retrieval enhancement generation mechanism; performing multi-stage time sequence sorting on the semantic structured events, identifying high-density behavior stages, clustering to generate event clusters, generating macroscopic and microscopic language paragraphs based on event cluster information, and classifying and segmenting event operation information to obtain an inter-segment time alignment relationship; and based on the paragraph and the alignment relationship, carrying out maliciousness test on the behavior chain by adopting four gating verification mechanisms, carrying out quantitative evaluation through a weighted confidence model, and outputting a detection result. According to the method, semantic comprehension and multi-dimensional behavior analysis are deeply fused, and the detection precision, interpretability and system generalization ability of unknown ransomware variants and zero-day attacks are effectively improved.
Owner:XIDIAN UNIV

Ransomware detection method and device, terminal and computer readable storage medium

The embodiment of the invention discloses a ransomware detection method and device, a terminal and a computer readable storage medium, and the method comprises the steps: monitoring damaged file information corresponding to a file damage event, and building a file damage database based on the damaged file information; monitoring newly-added file information corresponding to the file newly-added event, and establishing a file newly-added database based on the newly-added file information; and performing file information matching processing based on the file damage database and the file newly-added database to obtain matched target file information, and determining a ransomware based on the target file information. According to the method, file information matching processing is performed on the basis of a file damage database and a file newly-added database, so that damaged file information and newly-added file information which are correspondingly generated when a ransomware executes an encryption task on a file in multiple threads can be accurately identified, and after matched target file information is obtained, the file information can be accurately identified. The corresponding ransomware can be accurately identified based on the target file information.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

Anomalous file detection

Systems and methods are provided for detecting an anomalous file in a dataset of files utilizing a set of computer resources executing instructions to establish computer processes. The computer processes include, for each file in the dataset, evaluating the file to produce a file profile, using the file profile to develop a score for the file as to its specific type, and processing the score in a machine learning model trained on anomalous file data to generate a probability that the file includes content that has been corrupted by a ransomware attack.
Owner:T W STORAGE

Data organizer optimizing reconciliation systems

A data organizer, optimizing, reconciliation system (DOORS) / method / program, provides capability to merge intuitively datasets created over users' digital lifetimes from multiple devices. Finds and gathers files from devices and may create master copies in Cloud or local storage. Enhanced functionality via artificial intelligence or machine learning provides more intuitive merging of datasets including file and folder name selection and may operate autonomously at times of low usage. Optimized by learning from training data, or legacy data, or learning in real time from user preferences, practices, and habits. Reducing loses of treasured photographs and important documents via preventing files getting marooned on inaccessible legacy devices. Because devices get lost, replaced, or may suffer ransomware attacks or may need to be re-set and suffer data loss for a variety of reasons. Compatible and useable across the proliferating number of data producing devices, including smart phones, tablets, cameras, and computers.
Owner:TAYLOR MARK

Ransomware behavior simulation-based disinfection protection capability verification method and system

The application provides a harmless protection capability verification method and system based on ransomware behavior simulation, and relates to the technical field of network security. The method comprises the following steps: first, generating reference behavior information based on the attack behavior characteristics of ransomware; then, simulating the operation defined by the reference behavior information in the target server environment and obtaining actual physical layer behavior information; then, comparing the actual physical layer behavior information with the expected physical layer behavior information corresponding to the reference behavior information for spatiotemporal consistency, so as to identify abnormal behavior patterns; then, reconstructing the abnormal behavior patterns to establish a target behavior field model, and calculating the topology characteristic data and entropy change gradient through the model; finally, combining the topology characteristic data and the entropy change gradient to evaluate the harmless protection capability of the protection system in the target server environment against ransomware. The application improves the active protection verification capability against advanced ransomware evasion behavior.
Owner:BEIJING DISTRICT HEATING GRP CO LTD

Defense method and device for ransomware encrypted file and storage medium

The invention relates to the technical field of computer security, in particular to a ransomware encrypted file defense method and device and a storage medium. When the kernel driving layer senses that the process reads the file, the kernel driving layer automatically generates a substitute file, and the read file is replaced by the substitute file through API monitoring; the file is a preset protection file. According to the arrangement, the ransomware can be effectively prevented from encrypting the terminal file and leaking the file, and the risks of ransomware missing report, file encryption and leakage are avoided.
Owner:BEIJING ANTIY NETWORK SAFETY TECH CO LTD

Key length discriminator for ransomware attacks

An example computer system for providing countermeasures for a ransomware attack can include: one or more processors; and non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, causes the computer system to generate a key by to: create a salt using artificial intelligence; form a data section by the salt and an original key; and form a dummy section to fill out a length of the key.
Owner:WELLS FARGO BANK NA

Web-based electronic medical record database backup, business continuity & cyber resilience during EMR downtime

The web-based EMR backup system empowers Healthcare facility administrators by building cyber resilience to ransomware threats, data breaches, power outages, or planned downtimes. A web-based EMR backup process is provided in embodiments of the invention, enabling administrators to activate a web-based EMR system in the event of a debilitating cyber-attack, power outage, or planned downtime, that allows healthcare professionals to maintain their daily workflow using the web-based EMR backup system in order to maintain business continuity and clinical resiliency. The web-based EMR system minimizes the risks that would arise due to errors generated because of traditional record keeping methods, such as manual record keeping, while also maintaining the workflow efficiencies modern EMR systems provide. The web-based EMR backup system synchronizes any changes made during the cyber-threat, power outage, or planned downtime once the main EMR is restored to ensure data consistency and provide significant financial savings by preventing the need to reconcile the two databases by hand.
Owner:SHELTERZOOM CORP

Agent message bus

PCT designated stageWO2026147553A1RansomwareAttack
Applications and processes executing on an endpoint are monitored to identify behavior indicative of malicious activity such as a ransomware attack. Messages generated from this monitoring as well as messages derived from external sources are stored in a queue for routing. A router selects some messages from the queue based on a routing policy and sends them to a cloud-based platform that can initiate various actions based on received messages. The router also sends some messages from the queue to a module that analyzes the messages and reduces their size by aggregating, correlating, and detecting relevant information. The module puts the modified messages back into the queue for further routing by the router according to the policy. Related apparatus, systems, techniques and articles are also described.
Owner:HALCYON TECH

A ransomware detection method, device, equipment and medium

ActiveCN114936370BPlatform integrity maintainanceRansomwareVirtual business
The present application relates to the technical field of integrated circuits, and particularly relates to a ransomware detection method, device, equipment and medium.The method comprises the following steps: traversing a target service directory and creating a virtual service directory with higher search priority than the target service directory based on the traversal result; marking a new file according to a preset marking rule when the new file is created; in response to detecting that a certain file operates on the virtual service directory, determining whether the certain file is marked; in response to the certain file being marked, scoring the operation to generate a score value; and determining whether the certain file belongs to ransomware based on the score value.The scheme of the present application creates a virtual service directory to trap files from the perspective of the user's service, which improves the security and reliability of the protection of key services against ransomware.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD