Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

334 results about "Ransomware" patented technology

Ransomware is a type of malware from cryptovirology that threatens to publish the victim's data or perpetually block access to it unless a ransom is paid. While some simple ransomware may lock the system in a way which is not difficult for a knowledgeable person to reverse, more advanced malware uses a technique called cryptoviral extortion, in which it encrypts the victim's files, making them inaccessible, and demands a ransom payment to decrypt them. In a properly implemented cryptoviral extortion attack, recovering the files without the decryption key is an intractable problem – and difficult to trace digital currencies such as Ukash or Bitcoin and other cryptocurrency are used for the ransoms, making tracing and prosecuting the perpetrators difficult.

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Offensive cybersecurity appliance

An artificial intelligence based Offensive Cybersecurity Appliance or OCA for launching a cyber-offensive countermeasure aimed at effectively mitigating sophisticated cyber threats such as real-time Ransomware as a Service (RaaS) directives and emergent killware instigated by malicious-threat actors or cyber attackers. The system covertly uses a vast array of penetrative counter cyber attacks, based on an Advanced Persistent Threat or APT model, to circumvent encountered information security controls instituted by security-based components of a cyber attacker's Local Area Network or LAN. Intrinsically, the penetrative counter cyber attacks are constituted of multiple blended artificial intelligence based cyber attacks. The OCA subsequently uses these blended artificial intelligence based cyber attacks to render the hardware (including the cyber attacker's computer system used to instigate the cyber attack, discovered peripheral smart devices, and network-edge device such as a modem-router) interconnected to the cyber attacker's LAN inoperable by destroying the electronic components associated with that hardware.
Owner:PAYNE ORVILLE

Ai-generated virtual file honeypots for computing systems behavior-based protection against ransomware attacks

Systems and methods for protecting computing systems against ransomware attacks using AI-generated virtual file honeypots. Generative AI comprising a large language model generates virtual file honeypots automatically in response to attack vectors associated with suspect actors and ransomware families.
Owner:ACRONIS INT

Ransomware protection in advanced injection-based attacks

Systems and methods for ransomware protection in advanced injection-based attacks. The call stack(s) of injected threads are analyzed and a preliminary verdict of benign or malicious can be determined. Additional sensors collect data to associate injected threads with other activities or actors to further estimate the injected thread being benign or malicious. If the threat level is high enough, such as over a given threshold, the preliminary verdict can be determined to be malicious. Subsequently, one or more virtual honeypots are generated for the suspicious threads and the injected thread's response to the virtual honeypots included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

Mitigating ransomware activity of a host system using a kernel monitor

A kernel monitor can be used to mitigate ransomware activity of a host system. In some aspects, a computing system can use the kernel monitor to monitor a set of system calls generated by the host system within a time window to perform a functionality. The kernel monitor can include a respective kernel program monitoring each system call in the set of system calls. The set of system calls can be filtered by the kernel monitor to identify a subset of system calls associated with encrypting a filesystem of the host system. The computing system can determine that the subset of system calls is indicative of ransomware activity associated with the host system based on the subset of system calls exceeding a predefined threshold. Subsequently, the computing system can perform a mitigation operation to mitigate the ransomware activity.
Owner:RED HAT INC

Virtual file honey pots for computing systems behavior-based protection against ransomware attacks

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

Devices, systems, and methods for ransomware protection and mitigation

Disclosed herein are devices, systems, and methods for detecting, mitigating, and protecting against malicious actions and / or malicious computer software, including malware and ransomware. Specifically, disclosed embodiments mitigate the threat of ransomware across a wide range of devices including, for example, servers, storage systems, computers, and portable storage devices. At least one embodiment stealthily detects malicious actions by interposing when a file is opened for writing, creating a temporary checkpoint, comparing existing data in the file to what will be written to determine if it is destructive, and, if the behavior is malicious and / or destructive, preserving the checkpoint. At least a further embodiment can be implemented on, and / or ported in, a portable storage device (e.g., a USB device).
Owner:OCEANIT LABORATORIES INC +1

Ransomware detection accuracy based on machine learning analysis of filename extension patterns

Ransomware detection accuracy is improved by analyzing patterns of changes in filename extension counts, relative to each other, that occur in a file system over time. The disclosed approach is malware-agnostic and does not rely on recognizing malware extensions or on real-time monitoring of the target file system. Instead, during each successive backup job of the target file system, the disclosed technology counts different types of filename extensions and compares the counts to each other and to corresponding counts taken in earlier backup jobs. Preferably, the anomaly detection analysis uses machine learning to discern a behavior pattern of the file system, which indicates how filename extensions are distributed and how much they change between backup jobs over time.
Owner:COMMVAULT SYSTEMS INC

Harmless verification method and device for ransomware virus encryption behavior protection capability

The invention discloses a harmless verification method and device for ransomware encryption behavior protection capability, and the method comprises the steps: responding to a verification signal of a target system for the ransomware encryption behavior protection capability, constructing a bait file in the target system, and determining an original identity verification value of the bait file; simulating the behavior of the ransomware virus, encrypting the bait file at the preset encryption starting time in a preset encryption mode, and in the encryption process, obtaining response information of a target system to the encryption process; if the response information is the restoration response information of the encrypted bait file, acquiring restoration starting time and restoration finishing time for restoring the encrypted bait file by the target system, and acquiring a current identity verification value of the restored bait file; and based on the original identity verification value, the current identity verification value, the preset encryption starting time, the restoration starting time and the restoration completion time, verifying the protection capability of the target system for the ransomware encryption behavior.
Owner:SHANGHAI SHIAN TECH CO LTD

Scalable automated training framework

Techniques for implementing a scalable automated training framework for anomaly and ransomware detection are disclosed. In some embodiments, a computer system performs operations comprising: instantiating a plurality of virtual machines, each one of the virtual machines being loaded with a corresponding file system; simulating user actions and ransomware on the virtual machines, the simulating of user actions and ransomware on the virtual machines causing changes to the corresponding file systems of the virtual machines; for each one of the plurality of virtual machines, generating a corresponding metadata file based on one or more corresponding snapshots of the virtual machine, the one or more corresponding snapshots indicating the changes to the corresponding file system of the virtual machine; and training a ransomware detection model using a machine learning algorithm and training data, the training data being based on the corresponding metadata files of the virtual machines.
Owner:RUBRIK INC

Ransomware automatic acquisition and analysis method and system based on large language model

The invention discloses an automatic ransomware collection and analysis method and system based on a large language model in the technical field of network security, and the method comprises the steps: constructing a target data source, collecting a first sample of a ransomware, and capturing the first sample which is actually triggered in an enterprise-level network environment and context behavior data of the first sample from the first sample; an automatic crawler system is established by adopting an open source web crawler framework to establish real-time connection with a malicious code platform, the popularity of a first sample on the malicious code platform is analyzed, and an optimization task is set. According to the method, the natural language processing capacity and the automation technology of a large language model are combined, efficient capture, accurate analysis and quick response of the samples are achieved, an anti-virtualization detection mechanism of the blackmail virus is effectively coped with by implementing an anti-virtualization detection confrontation strategy, and an intelligent protection chain is constructed for network security.
Owner:JIANGSU TAIHU HUIYUN DATA SYST CO LTD

Database anti-ransomware method and device based on user SQL feature behavior analysis

The invention provides a database anti-ransomware method and device based on user SQL (Structured Query Language) feature behavior analysis, and relates to the technical field of database security. The method comprises the following steps: constructing an SQL data set by utilizing a multi-source data aggregation algorithm, a real-time and historical combination algorithm and a data cleaning and checking algorithm; extracting SQL statement structure features according to BERT and a semantic matching method; according to the features, training a user SQL behavior model based on a Transform; in the real-time monitoring stage, a monitoring engine captures a new SQL operation in real time, rapidly extracts features and inputs the features into the trained behavior model for evaluation. Once the deviation between the operation and a normal behavior model exceeds a preset threshold value and suspicious behavior modes such as data encryption, large-scale data deletion or abnormal high-authority operation similar to ransomware are presented, an alarm mechanism is triggered immediately, and a preset protection strategy is executed automatically, so that data loss and business influence are reduced to the greatest extent.
Owner:UNIV OF SCI & TECH BEIJING

Ransomware detection method and apparatus

A computer device creates a first snapshot of a storage system at a first moment at which an abnormal operation behavior for the storage system is detected; creates a second snapshot of the storage system at a second moment at which it is determined that the storage system meets an attack detection condition; and then determines, based on a result of comparison between the first snapshot and the second snapshot and data content of one or more groups of operation abnormality data generated by the storage system between the first moment and the second moment, whether the storage system is attacked by ransomware.
Owner:HUAWEI TECH CO LTD

Ransomware double-layer defense method combining bait file monitoring and letter verification

The invention discloses a ransomware double-layer defense method combining bait file monitoring and letter verification, and belongs to the field of network security. Firstly, a ransomware double-layer defense mechanism in which a user mode module and a kernel mode module cooperatively work is constructed, and the user mode module generates a bait file and a letter white list and transmits the bait file and the letter white list to the kernel mode module. Then, the bait file monitoring module judges whether the target file of the ransomware is a bait file or not, and if the target file of the ransomware is the bait file, the bait file monitoring module directly blocks malicious behaviors and feeds back the malicious behaviors to the user mode module; and if the ransomware tries to directly encrypt the real user file, the bait file monitoring module transmits the operation request to the dynamic letter verification module for deep verification, and feeds back the processing result to the user mode module. And finally, the malicious process processing module executes a termination and isolation strategy on the malicious process. According to the method, various behaviors of ransomware are comprehensively covered, the false alarm rate is reduced, and the defense real-time performance and effectiveness are improved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

AI Identification of Computer Resources Subjected to Ransomware Attack

A method of causing ransomware to be executed includes obtaining a set of ransomware samples and automatically performing a set of scripted detonations of a first subset of the ransomware samples according to a schedule. The set of scripted detonations includes executing the first subset of ransomware samples on a virtual machine. During the execution of the first subset of ransomware samples, use of computing resources by the first subset of ransomware samples is monitored until a shutdown threshold is reached. Upon reaching the shutdown threshold, any pending detonation tasks of the execution of the first subset of ransomware samples are purged. Detonation-infected disk images are generated to include files resulting from the execution of the first subset of ransomware samples, and the detonation-infected disk images are used in training a machine learning system to assess a likelihood of a presence of a ransomware attack.
Owner:T W STORAGE

Isolated test environment for ransomware analysis

Techniques are provided for an isolated test environment for ransomware analysis. One or more enterprise applications are assigned to one or more server systems to be provisioned in an isolated test environment. An enterprise replica is generated in the isolated test environment by provisioning the one or more server systems and deploying the one or more enterprise applications on the one or more server systems. A kernel monitoring component is deployed on the one or more server systems in the isolated test environment. The kernel monitoring component is configured to generate kernel telemetry data for a plurality of system calls initiated by processes executing on the one or more server systems. A selected ransomware variant is deployed in the isolated test environment. An effect of the selected ransomware variant on the enterprise replica is determined based on analyzing the kernel telemetry data.
Owner:MIMIC NETWORKS INC

Encrypted ransomware attack rapid detection method and system based on semantic traceability graph

The invention relates to an encrypted ransomware attack rapid detection method and system based on a semantic traceability graph, and the method comprises the steps: synchronously carrying out the high-speed detection and depth detection of a preprocessed mixed log stream, and obtaining a corresponding high-speed detection result and a corresponding depth detection result; wherein the priority of the high-speed detection result is greater than that of the depth detection result; the high-speed detection result is obtained by performing malicious command matching and blacklist keyword detection on the preprocessed mixed log stream; the depth detection result is related to a semantic traceability graph generated by using semantic information related to the encrypted ransomware attack behavior in the preprocessed mixed log stream; when the high-speed detection result is that the encrypted ransomware attack behavior exists, all detection is stopped, and an alarm is triggered; and under the condition that the high-speed detection result is that the encrypted ransomware attack behavior does not exist, continuing to execute deep detection so as to determine whether to trigger an alarm according to a deep detection result. The method can effectively improve the detection precision and reduce the detection hysteresis.
Owner:XIDIAN UNIV

Virtual file honey pots for computing systems behavior-based protection against ransomware attacks

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

Adaptive authentication for ransomware intervention

Security in a computing environment is enhanced by analyzing telemetry data from an agent on a device, along with user integrity information, to detect events that suggest compromised credentials. When such an event is detected, a risk level is assigned based on the analysis. This risk level is then correlated with a corresponding authentication difficulty level, which specifies the types and strengths of authentication mechanisms to be used. The selected authentication difficulty level is applied across multiple devices within the environment, enabling adaptive and dynamic protection against unauthorized access due to compromised credentials.
Owner:HALCYON TECH

Apparatus and method for recovering a data block at a production station

An apparatus and method for recovering a data block at a production site are provided. A device detects, at a detection point in time, that one or more of a plurality of data blocks of user data are encrypted by a ransomware process. The apparatus determines one or more points in time earlier than the detection point in time, and obtains one or more snapshots of replicated copies of the plurality of data blocks from the storage device. Each snapshot is generated by the storage device at the respective determined one or more points in time. The device determines a latest version of each data block before being encrypted by the ransomware process based on the ransomware configuration, the ransomware encryption key, and the snapshot. The device restores, at the production site, each of the data blocks encrypted by the ransomware process to a corresponding latest version of the data block.
Owner:HUAWEI TECH CO LTD

Ransomware behavioral kernel model

Time series behavioral data derived from operating system events on a monitored computing device is monitored at a kernel level. Based on this monitoring, a feature vector is populated or updated with features indicative of ransomware. These features are extracted or otherwise derived from the time series behavioral data. The feature vector can be input into a machine learning model (e.g., a modified gated recurrent unit, etc.) to characterize whether the time series behavioral data is indicative of a ransomware event. Data indicating a probability of a ransomware event occurring is provided to a consuming application or process. One or more remediation actions to thwart the ransomware event can be initiated when the probability level is above a threshold.
Owner:HALCYON TECH

System and Method For Eliminating Ransomware Infections on Network Shares

There is provided a system and method for eliminating ransomware infections on network shares. The system and method determines if a file on a shared network drive is written to, then the system buffers the data into memory and does not allow writing to the disk. After buffering, it sends this data for verification in user mode through a system service to an antivirus engine crypto-locker scanner. The anti-virus engine makes a verdict and if it does not detect encryption, then the data is recorded. If encryption was detected, the recording is blocked and localized to prevent spreading across a network.
Owner:NURD LLC

Ransomware detection accuracy based on machine learning analysis of filename extension patterns

Ransomware detection accuracy is improved by analyzing patterns of changes in filename extension counts, relative to each other, that occur in a file system over time. The disclosed approach is malware-agnostic and does not rely on recognizing malware extensions or on real-time monitoring of the target file system. Instead, during each successive backup job of the target file system, the disclosed technology counts different types of filename extensions and compares the counts to each other and to corresponding counts taken in earlier backup jobs. Preferably, the anomaly detection analysis uses machine learning to discern a behavior pattern of the file system, which indicates how filename extensions are distributed and how much they change between backup jobs over time.
Owner:COMMVAULT SYSTEMS INC

Managed run-time environment-based detection of a ransomware attack

An illustrative method includes a data protection system detecting an anomaly associated with a managed run-time environment; determining, based on the detecting the anomaly, that the managed run-time environment is possibly being targeted by a security threat; and performing, based on the determining that the managed run-time environment is possibly being targeted by the security threat, a remedial action associated with the managed run-time environment. The performing the remedial action may include identifying a recovery dataset generated prior to the detecting the anomaly, the recovery dataset for data associated with the managed run-time environment and stored by a storage system, and converting the recovery dataset into a protected recovery dataset that cannot be deleted without a specific instruction provided by an authorized entity.
Owner:PURE STORAGE INC

Ransomware detection

The technology disclosed relates to detecting a data attack on a local file system. The detecting includes scanning a list to identify files of the local file system that have been updated within a timeframe, reading payloads of files identified by the scanning, calculating current content properties from the payload of the files, obtaining historical content properties of the files, determining that a malicious activity is in process by analyzing the current content properties and the historical content properties to identify a pattern of changes that exceeds a predetermined change velocity. Further, the detecting includes determining that the malicious activity is in process by analyzing the current content properties and known patterns of malicious metadata to identify a match between the current metadata and the known patterns of malicious metadata, determining a machine / user that initiated the malicious activity, and implementing a response mechanism that restricts file modifications by the machine / user.
Owner:NETSKOPE INC

Method for detecting backup file and related device

Embodiments of this application disclose a method for detecting a backup file and a related device. The method includes: obtaining an encryption heatmap of each of a plurality of backup files; determining an encryption score of the backup file based on distribution of a target color in the encryption heatmap; constructing a sequence from the encryption score of each backup file, and performing sampling on the sequence by using a sliding window, to obtain a plurality of subsequences; and performing time sequence anomaly detection on the plurality of subsequences, and determining that a backup file corresponding to an encryption score in an abnormal subsequence is ransomware-encrypted. In this way, it can be detected, without parsing the backup file, whether the backup file is ransomware-encrypted.
Owner:HUAWEI TECH CO LTD

System and method for preventing ransomware

A system and method for detecting and preventing ransomware is provided. The system and method may include the creation / addition of a number of watch files to a filesystem, wherein a location and a timestamp of the watch files may be added to an ingest log. In some embodiments, a number of native files of the filesystem may be cataloged, wherein the location and timestamp of each native file is added to the ingest log. Periodically, the timestamps and / or locations of each entry in the ingest log are compared to current timestamps and / or locations of the corresponding file in the filesystem to determine a count of watch files and / or native files that have changed, which may indicate that a ransomware program is running on the computer. Suspected programs may then subsequently be suspended and reported.
Owner:WATCHPOINT DATA INC DBA CRYPTOSTOPPER

Recovering from ransomware attacks

The disclosed embodiments disclose techniques for decrypting an encrypted file. During operation, a recovery system receives an encryption key and a program executable that were previously used to encrypt an encrypted file using an unknown encryption technique. The program executable is executed in a sandbox environment that includes a known file containing a known pattern; the executing program generates a subsequent key and encrypts the known file. The subsequent key is extracted, and then characteristics of the known file, subsequent key, and the encrypted known file are compared to patterns determined for a set of standard encryption techniques to identify the specific encryption technique that was used. Knowledge of the identified encryption technique can then be used in combination with the original encryption key to decrypt the original encrypted file.
Owner:NUBEVA INC

Intelligent terminal cloud security protection system and behavior characteristic analysis system

The invention relates to the technical field of intelligent terminal cloud security, in particular to an intelligent terminal cloud security protection system and behavior characteristic analysis system, which comprises an access / output unit, a request unit, an authentication and identification unit, a traceability tracking unit, a judgment and analysis unit and a shielding protection unit, the output end of the access / output unit is in communication connection with the input ends of the request unit and the authentication and identification unit; according to the method, the data needing to be downloaded by the intelligent terminal can be simulated and analyzed in advance, whether the data are safe or not can be obtained according to analysis, most of the data downloaded by the intelligent terminal are safe data, and the simulation analysis module can perform simulation analysis through sandbox operation and historical efficiency comparison (S value calculation). Encryption confusion attacks (for example, ransomware is disguised as a normal file) are accurately identified, and the missing report rate is reduced to be lt; and through modular architecture design, multi-modal data fusion and an intelligent decision-making mechanism, full-process closed-loop protection from data acquisition to threat response is realized.
Owner:ZHEJIANG COLLEGE OF SECURITY TECH