Ransomware Detection via File Access Pattern Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods to combat ransomware are inadequate in detecting and preventing ransomware attacks, especially given the increasing sophistication of cybercriminals' tactics and the use of stronger cryptography, which makes it difficult to decrypt files after infection.

Innovation Solution

A system and method that involves monitoring processes accessing files on a device, identifying access indicators characteristic of ransomware behavior, and interrupting suspicious processes by analyzing file types, frequency, and other access metrics to prompt user intervention or cloud-based classification and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional decryption methods are used to combat ransomware, then file recovery is attempted, but the sophistication of cybercriminal cryptography makes decryption increasingly difficult and ineffective

Engineering Contradiction:
Improvefile recovery effectivenessVSAvoidcryptography sophistication
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by monitoring file access patterns and process behavior before ransomware encryption completes. The system establishes baseline behavior profiles for legitimate applications and detects deviations in real-time, interrupting suspicious processes before they can encrypt files. This proactive approach prevents the need for decryption of already-encrypted files, bypassing the cryptography sophistication problem entirely.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by preemptively blocking processes that exhibit ransomware-like behavior patterns. By analyzing file access frequency, multiple file type targeting, and rapid sequential access patterns, the system interrupts suspicious processes before encryption occurs, effectively counteracting the ransomware's intended harmful action before it can execute.

Inventive Principle:
Principle #9Preliminary anti-action

2Measurement precision

If real-time monitoring of all file access is implemented to detect ransomware, then detection accuracy improves, but system performance and resource consumption increase

Engineering Contradiction:
Improveransomware detection accuracyVSAvoidsystem performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies local quality by focusing monitoring resources on specific high-risk file types and processes rather than uniformly monitoring all file access. The system identifies and prioritizes monitoring of critical file types (documents, databases, media) and processes exhibiting suspicious behavior patterns, allocating computational resources selectively to maintain detection accuracy while minimizing overall system performance impact.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements partial action by monitoring only the most indicative behavior patterns rather than analyzing every possible file access parameter. It focuses on key metrics such as rapid sequential access, multiple file type targeting, and access patterns inconsistent with normal application behavior, achieving effective detection with reduced computational overhead compared to comprehensive monitoring.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If comprehensive file access analysis is performed to identify ransomware behavior, then detection reliability improves, but the time required for analysis increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system establishes baseline behavior profiles and detection thresholds in advance, before ransomware attacks occur. By pre-configuring what constitutes suspicious behavior patterns for different file types and processes, the system can make rapid real-time decisions without performing comprehensive analysis during the actual detection event, thus maintaining high reliability while minimizing analysis time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements skipping by implementing real-time interrupt mechanisms that immediately halt suspicious processes upon detecting ransomware-like behavior patterns. Rather than completing full analysis of all file access patterns, the system identifies critical indicator patterns and rapidly interrupts the process, reducing analysis time while maintaining detection reliability through focused pattern recognition.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11689562B2Detection of ransomware
Publication Date: 2023.06.27 MCAFEE LLC
  • US11689562B2 patent drawing
  • US11689562B2 patent drawing
  • US11689562B2 patent drawing

AI summary

An apparatus, including systems and methods, for detecting ransomware is disclosed herein. For example, in some embodiments, an apparatus includes a memory element operable to store instructions; and a processor operable to execute the instructions, such that the apparatus is configured to receive data identifying a process and a plurality of files accessed by the process; identify an access indicator associated with each of the plurality of files accessed by the process, wherein the access indicator includes file type; determine whether the access indicator exceeds a threshold; interrupt, based on a determination that the access indicator exceeds a threshold, the process; and prompt a user to allow or disallow the process to proceed.