Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

242 results about "Ransomware" patented technology

Ransomware is a type of malware from cryptovirology that threatens to publish the victim's data or perpetually block access to it unless a ransom is paid. While some simple ransomware may lock the system in a way which is not difficult for a knowledgeable person to reverse, more advanced malware uses a technique called cryptoviral extortion, in which it encrypts the victim's files, making them inaccessible, and demands a ransom payment to decrypt them. In a properly implemented cryptoviral extortion attack, recovering the files without the decryption key is an intractable problem – and difficult to trace digital currencies such as Ukash or Bitcoin and other cryptocurrency are used for the ransoms, making tracing and prosecuting the perpetrators difficult.

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Ai-generated virtual file honeypots for computing systems behavior-based protection against ransomware attacks

Systems and methods for protecting computing systems against ransomware attacks using AI-generated virtual file honeypots. Generative AI comprising a large language model generates virtual file honeypots automatically in response to attack vectors associated with suspect actors and ransomware families.
Owner:ACRONIS INT

Ransomware detection accuracy based on machine learning analysis of filename extension patterns

Ransomware detection accuracy is improved by analyzing patterns of changes in filename extension counts, relative to each other, that occur in a file system over time. The disclosed approach is malware-agnostic and does not rely on recognizing malware extensions or on real-time monitoring of the target file system. Instead, during each successive backup job of the target file system, the disclosed technology counts different types of filename extensions and compares the counts to each other and to corresponding counts taken in earlier backup jobs. Preferably, the anomaly detection analysis uses machine learning to discern a behavior pattern of the file system, which indicates how filename extensions are distributed and how much they change between backup jobs over time.
Owner:COMMVAULT SYSTEMS INC

Scalable automated training framework

Techniques for implementing a scalable automated training framework for anomaly and ransomware detection are disclosed. In some embodiments, a computer system performs operations comprising: instantiating a plurality of virtual machines, each one of the virtual machines being loaded with a corresponding file system; simulating user actions and ransomware on the virtual machines, the simulating of user actions and ransomware on the virtual machines causing changes to the corresponding file systems of the virtual machines; for each one of the plurality of virtual machines, generating a corresponding metadata file based on one or more corresponding snapshots of the virtual machine, the one or more corresponding snapshots indicating the changes to the corresponding file system of the virtual machine; and training a ransomware detection model using a machine learning algorithm and training data, the training data being based on the corresponding metadata files of the virtual machines.
Owner:RUBRIK INC

AI Identification of Computer Resources Subjected to Ransomware Attack

A method of causing ransomware to be executed includes obtaining a set of ransomware samples and automatically performing a set of scripted detonations of a first subset of the ransomware samples according to a schedule. The set of scripted detonations includes executing the first subset of ransomware samples on a virtual machine. During the execution of the first subset of ransomware samples, use of computing resources by the first subset of ransomware samples is monitored until a shutdown threshold is reached. Upon reaching the shutdown threshold, any pending detonation tasks of the execution of the first subset of ransomware samples are purged. Detonation-infected disk images are generated to include files resulting from the execution of the first subset of ransomware samples, and the detonation-infected disk images are used in training a machine learning system to assess a likelihood of a presence of a ransomware attack.
Owner:T W STORAGE

Virtual file honey pots for computing systems behavior-based protection against ransomware attacks

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

Adaptive authentication for ransomware intervention

Security in a computing environment is enhanced by analyzing telemetry data from an agent on a device, along with user integrity information, to detect events that suggest compromised credentials. When such an event is detected, a risk level is assigned based on the analysis. This risk level is then correlated with a corresponding authentication difficulty level, which specifies the types and strengths of authentication mechanisms to be used. The selected authentication difficulty level is applied across multiple devices within the environment, enabling adaptive and dynamic protection against unauthorized access due to compromised credentials.
Owner:HALCYON TECH

Managed run-time environment-based detection of a ransomware attack

An illustrative method includes a data protection system detecting an anomaly associated with a managed run-time environment; determining, based on the detecting the anomaly, that the managed run-time environment is possibly being targeted by a security threat; and performing, based on the determining that the managed run-time environment is possibly being targeted by the security threat, a remedial action associated with the managed run-time environment. The performing the remedial action may include identifying a recovery dataset generated prior to the detecting the anomaly, the recovery dataset for data associated with the managed run-time environment and stored by a storage system, and converting the recovery dataset into a protected recovery dataset that cannot be deleted without a specific instruction provided by an authorized entity.
Owner:PURE STORAGE INC

Ransomware detection

The technology disclosed relates to detecting a data attack on a local file system. The detecting includes scanning a list to identify files of the local file system that have been updated within a timeframe, reading payloads of files identified by the scanning, calculating current content properties from the payload of the files, obtaining historical content properties of the files, determining that a malicious activity is in process by analyzing the current content properties and the historical content properties to identify a pattern of changes that exceeds a predetermined change velocity. Further, the detecting includes determining that the malicious activity is in process by analyzing the current content properties and known patterns of malicious metadata to identify a match between the current metadata and the known patterns of malicious metadata, determining a machine / user that initiated the malicious activity, and implementing a response mechanism that restricts file modifications by the machine / user.
Owner:NETSKOPE INC

Method for detecting backup file and related device

Embodiments of this application disclose a method for detecting a backup file and a related device. The method includes: obtaining an encryption heatmap of each of a plurality of backup files; determining an encryption score of the backup file based on distribution of a target color in the encryption heatmap; constructing a sequence from the encryption score of each backup file, and performing sampling on the sequence by using a sliding window, to obtain a plurality of subsequences; and performing time sequence anomaly detection on the plurality of subsequences, and determining that a backup file corresponding to an encryption score in an abnormal subsequence is ransomware-encrypted. In this way, it can be detected, without parsing the backup file, whether the backup file is ransomware-encrypted.
Owner:HUAWEI TECH CO LTD

System and method for preventing ransomware

A system and method for detecting and preventing ransomware is provided. The system and method may include the creation / addition of a number of watch files to a filesystem, wherein a location and a timestamp of the watch files may be added to an ingest log. In some embodiments, a number of native files of the filesystem may be cataloged, wherein the location and timestamp of each native file is added to the ingest log. Periodically, the timestamps and / or locations of each entry in the ingest log are compared to current timestamps and / or locations of the corresponding file in the filesystem to determine a count of watch files and / or native files that have changed, which may indicate that a ransomware program is running on the computer. Suspected programs may then subsequently be suspended and reported.
Owner:WATCHPOINT DATA INC DBA CRYPTOSTOPPER

Recovering from ransomware attacks

The disclosed embodiments disclose techniques for decrypting an encrypted file. During operation, a recovery system receives an encryption key and a program executable that were previously used to encrypt an encrypted file using an unknown encryption technique. The program executable is executed in a sandbox environment that includes a known file containing a known pattern; the executing program generates a subsequent key and encrypts the known file. The subsequent key is extracted, and then characteristics of the known file, subsequent key, and the encrypted known file are compared to patterns determined for a set of standard encryption techniques to identify the specific encryption technique that was used. Knowledge of the identified encryption technique can then be used in combination with the original encryption key to decrypt the original encrypted file.
Owner:NUBEVA INC

Ransomware detection via monitoring open file or process

A bait file owned by a bait process is created and locked in a computing system. Attempts or access the bait file or kill the bait process are detected. The process attempting to access the bait file or kill the bait process is viewed as malicious and protective operations are performed in the computing system.
Owner:DELL PROD LP

Migrating ransomware activity of an operating system by monitoring from user space

Ransomware activity in operating systems can be mitigated by monitoring from user space. For example, a computing environment can generate an affinity score indicating a likelihood of ransomware activity associated with an operating system based on a first set of system calls detected from a user space of the operating system within a first time window. The computing environment can buffer one or more write operations from the first set of system calls during a second time window based on the affinity score. The computing environment can update the affinity score based on a second set of system calls detected from the user space of the operating system within the second time window. The computing environment can block execution of the one or more write operations based on the updated affinity score exceeding a predefined threshold.
Owner:RED HAT INC

Real-time ransom and security breach detection and prevention

The real-time ransom and security breach detection and prevention system empowers users and system administrators by providing real-time threat detection and prevention by detecting any phishing links, malicious executables and objects, and manipulation of authentication tokens that could potentially escalate a threat into ransom attacks, security breaches or other cyber attacks, and take immediate action by blocking and reporting the potential security breach before escalating into a real attack. The real-time ransom and security breach detection and prevention system generates a first hash of the link, executable, object, or authentication token. Utilizing this generated first hash, the real-time ransom and security breach detection and prevention system calculates a second hash upon user interaction or at runtime and compares the two unique hashes to determine if the link, executable, object, or authentication token is corrupt and terminates the gateway to prevent the cyber-threat from infecting the system.
Owner:IMPERVIOUS WORLD CORP

Method for detecting ransomware-encrypted file, storage medium and electronic device

A method for detecting a ransomware-encrypted file includes: acquiring a designated file; extracting bytes from a file header, a file middle portion and a file trailer of the designated file respectively; extracting features from the extracted bytes, where the extracted features include at least a variance of a distribution of a first preset type of characters; inputting the extracted features into more than one first machine learning model to obtain a probability distribution, outputted by each of the more than one first machine learning model, indicating a likelihood that the designated file is ransomware-encrypted; and determining, based on the probability distribution, whether the designated file is ransomware-encrypted. The present disclosure improves efficiency and accuracy of ransomware detection by extracting bytes and features from different portions of the designated file and utilizing a plurality of machine learning models for ransomware detection.
Owner:RIVER SECURITY TECHNOLOGY (SHANGHAI) CO LTD

Ransomware infection detection in filesystems

Described herein is a system that detects ransomware infection in filesystems. The system detects ransomware infection by using backup data of machines. The system detects ransomware infection in two stages. In the first stage, the system analyzes a filesystem's behavior. The filesystem's behavior can be obtained by loading the backup data and crawling the filesystem to create a filesystem metadata including information about file operations during a time interval. The filesystem determines a pattern of the file operations and compares the pattern to a normal patter to analyze the filesystem's behavior. If the filesystem's behavior is abnormal, the system proceeds to the second stage to analyze the content of the files to look for signs of encryption in the filesystem. The system combines the analysis of both stages to determine whether the filesystem is infected by ransomware.
Owner:RUBRIK INC

Ransomware Detecting Using Decoy Files

Disclosed herein are systems, methods, and software for the operation of a ransomware detection system. The ransomware detection system generates a decoy file based on characteristics of an existing file in a file system. The decoy file is effectively indistinguishable from the existing file from the perspective of the ransomware but contains simulated data rather than authentic data. The ransomware detection system identifies a location in the file system and deploys the decoy file to the location. The decoy is then monitored to detect changes by comparing a ground truth for the decoy file to the current state of the decoy file. The decoy file is checked for changes at a rate associated with the identified location. Where a change is detected, an alert is sent to a ransomware mitigation process, which initiates ransomware mitigation.
Owner:NETAPP INC

System and method for utilizing DHCP relay to accomplish quarantining client endpoints in a ransomware protected network

A technique to stop lateral movement of ransomware between endpoints in a VLAN is disclosed. A security appliance is set as the default gateway for intra-LAN communication by overwriting the DHCP responses. Message traffic from compromised endpoints is detected. Attributes of ransomware may be detected in the message traffic, as well as attempts to circumvent the security appliance. Compromised devices may be quarantined by assigning them the default gateway to a preset blackhole IP address.
Owner:AIRGAP NETWORKS INC

Detecting ransomware activity in data storage systems

A computer-implemented method, according to one approach, is for detecting ransomware activity in storage systems. The computer-implemented method includes: receiving a write request having a plurality of sectors, and each of the sectors further includes a number of sub-sectors. A degree of randomness is determined across the sub-sectors of each of the respective sectors, and a determination is made as to whether any deviations exist in the degrees of randomness. In response to determining a deviation exists in the degrees of randomness, this information on the deviation is used as an indicator of the write request including ransomware activity.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Methods and systems for per-resource anomaly detection

Disclosed herein are system, method, and computer program product embodiments for detecting ransomware and creating ransomware incidents by way of analyzing for ransomware signals in a backup data stream on a file-by-file basis. The ransomware detection system comprises a ransomware detection engine that includes a tracking component. The tracking component may track the byte distribution and extension of a file from a backup data stream. Further, the tracking component may perform a ransomware analysis on the file and identify, using a machine learning model, that the file is encrypted by ransomware based on an anomaly score and a confidence threshold. Subsequently, the tracking component may create a ransomware incident based on the identification that the file is encrypted by ransomware. Disclosed herein are additional embodiments directed towards training and updating a machine learning model within the ransomware detection engine.
Owner:VEEAM VAAS CORP

Memory controller, storage device, and operating method of storage device

A storage device may include a non-volatile memory device including a plurality of memory blocks, and processing circuitry configured to determine whether data associated with a memory operation received from a host device is infected with ransomware, the determining whether the data is infected with ransomware including, determining a first detection result value by calculating a distribution of bit values in the data, and outputting a second detection result value by detecting a similarity of the memory operation received from the host device with a memory operation transmitted by the processing circuitry to the non-volatile memory device in response to the first detection result value being less than or equal to a first threshold.
Owner:SAMSUNG ELECTRONICS CO LTD

Real-time ransom and security breach detection and prevention

The real-time ransom and security breach detection and prevention system empowers users and system administrators by providing real-time threat detection and prevention by detecting any phishing links, malicious executables and objects, and manipulation of authentication tokens that could potentially escalate a threat into ransom attacks, security breaches or other cyber attacks, and take immediate action by blocking and reporting the potential security breach before escalating into a real attack. The real-time ransom and security breach detection and prevention system generates a first hash of the link, executable, object, or authentication token. Utilizing this generated first hash, the real-time ransom and security breach detection and prevention system calculates a second hash upon user interaction or at runtime and compares the two unique hashes to determine if the link, executable, object, or authentication token is corrupt and terminates the gateway to prevent the cyber-threat from infecting the system.
Owner:IMPERVIOUS WORLD CORP

Ransomware identification method and system based on multi-source data fusion

PendingCN122263100AEffectively respond to attack situationsAchieve full-range accurate identificationPlatform integrity maintainanceNetwork connectionAttack
The application discloses a ransomware identification method and system based on multi-source data fusion, and relates to the field of ransomware detection. The method obtains file system event data, system resource running indexes, process behavior data and industrial control system behavior data, identifies file features, system running behavior situation features, process features and industrial scene features from the data, judges whether each feature meets the essential behavior features of ransomware encrypted files, and divides the features into strong indication features, medium indication features and basic situation features. Different mapping methods are used to determine sub-risk scores for different features, and finally a weighted scoring mechanism is used to obtain an overall urgency score, based on which a ransomware attack is determined, and then suspicious process operations are automatically triggered and terminated in parallel, and network connections are blocked to prevent the spread of ransomware attacks. The application can accurately identify known ransomware and unknown variants, and has good interpretability.
Owner:NAT IND INFORMATION SECURITY DEV RES CENT

Virtual canary files to mitigate ransomware attacks

ActiveUS12694101B2Virtual memoryAttack
Provided is a computer agent and method to detect and prevent ransomware attacks early without losing customer data, without polluting the customer's file system or consuming any space on a storage device. The computer agent installs a kernel mode layered file system driver which is attached to encryption level group of a filter manager. With this layered file system filter driver design, it creates virtual canary files in directories which appear like normal files to any user or application though these files will not reside on disk. These virtual canary files are spread as baits across the file system to detect and prevent any malicious attack from any process or application. So that the Virtual Canary Files do not consume a large amount of memory, internal structures representing Virtual Canary Files are placed in virtual memory, but actual contents of the Virtual Canary Files do not reside in virtual memory. Other embodiments disclosed.
Owner:THALES DIS CPL USA INC

Harmless protection capability verification method and system based on ransomware virus behavior simulation

The invention provides a harmless protection capability verification method and system based on ransomware behavior simulation, and relates to the technical field of network security, and the method comprises the steps: firstly generating reference behavior information based on the attack behavior characteristics of ransomware; then simulating and executing an operation defined by the reference behavior information in a target server environment, and obtaining actual physical layer behavior information; performing space-time consistency comparison on the actual physical layer behavior information and expected physical layer behavior information corresponding to the reference behavior information so as to identify an abnormal behavior mode; reconstructing the abnormal behavior modes to establish a target behavior field model, and calculating through the model to obtain topological feature data and an entropy change gradient; and finally, in combination with the topological feature data and the entropy change gradient, evaluating the harmless protection capability of the protection system to the ransomware virus in the target server environment. According to the invention, the active protection verification capability for the high-grade ransomware avoidance behavior is improved.
Owner:BEIJING DISTRICT HEATING GRP CO LTD

Ransomware detection method and device based on eBPF and machine learning

The invention provides a ransomware detection method and device based on eBPF and machine learning, and relates to the technical field of information security, the method comprises the following steps: mounting an eBPF program to a key system of a target system for calling, and capturing file operation behavior data such as a process identifier and an operation type in real time through an event-driven mechanism; extracting features based on a preset time window, counting process file operation cumulative times, screening out abnormal operation behaviors through threshold filtering, and constructing context features at the same time; utilizing a support vector machine algorithm to train feature data to generate a classification model, and optimizing kernel function parameters to improve small sample scene classification accuracy; and continuously collecting real-time file operation data through an eBPF program, inputting the real-time file operation data into the model, carrying out dynamic classification, and triggering alarm and blocking when the ransomware is detected. According to the method, the system performance overhead is effectively reduced, the detection real-time performance and accuracy are improved, and the model stability is enhanced.
Owner:PICC INFORMATION TECH CO LTD

MAYA: a hardware-based cyber-deception framework to combat malware

A hardware framework for cyber-deception operations provides flexibility in formulating counterattacks and leverages hardware support for efficiency. Hardware-assisted deception primitives are provided at kernel crossing boundaries to privileged system features that propel the security defenses to dynamically manipulate the malware execution and present a deceptive view of the system state to the attackers. Malware may be in the form of various attack vectors including ransomware, infostealers, buffer overflow, and side-channels.
Owner:GEORGE WASHINGTON UNIVERSITY

Mitigating ransomware activity of a host system using a kernel monitor

A kernel monitor can be used to mitigate ransomware activity of a host system. In some aspects, a computing system can use the kernel monitor to monitor a set of system calls generated by the host system within a time window to perform a functionality. The kernel monitor can include a respective kernel program monitoring each system call in the set of system calls. The set of system calls can be filtered by the kernel monitor to identify a subset of system calls associated with encrypting a filesystem of the host system. The computing system can determine that the subset of system calls is indicative of ransomware activity associated with the host system based on the subset of system calls exceeding a predefined threshold. Subsequently, the computing system can perform a mitigation operation to mitigate the ransomware activity.
Owner:RED HAT INC