SYSTEMS AND METHODS FOR RANSOMWARE DETECTION AND MITIGATION

ABSTRACT

System and method for protecting a computing device of a target system against ransomware attacks employs a file system having a data structure used by an operating system of the computing device for managing files. A software or a hardware installed agent in the computing device performs one or more actions autonomously on behalf of the target system. The agent autonomously creates one or more trap files in the data structure of the filing system. A trap file is a file access to which indicates a probability of ransomware attack. The agent monitors access to the one or more trap files. Upon detecting access to a trap file, remedial action is performed by the target system against the probability of ransomware attack.

BACKGROUND

TECHNICAL FIELD

The present disclosure relates generally to cybersecurity technology. More specifically, the present disclosure relates to systems and methods for ransomware detection and mitigation.

RELATED ART

In the cybersecurity field, ransomware is malware that denies a victim access to data or equipment until an attacker allows access to be returned. Typically, access is denied due to the attacker encrypting the victim's data, and decryption capability is provided after the victim pays the ransom. Defensive and attacker ransomware-focused capabilities have matured in capability and complexity of encryption capability, scope of resources denied, and payment methodologies.

Current strong encryption that is certified by the National Institute of Standards and Technology ("NIST"), 256-bit AES encryption, is estimated to take (9.63 \times 10^{52}) years for an unintended party to decrypt.

Encryption algorithm vulnerabilities affect encrypted material's (ciphertext's) robustness against being exposed by unintended parties. These vulnerabilities can be categorized by vulnerabilities in the logic of the encryption itself, and vulnerabilities introduced by improvements in computing power.

SUMMARY

Briefly, according to the present invention, a system and method for protecting a computing device of a target system against ransomware attacks employs a file system having a data structure used by an operating system of the computing device for managing files. A software or a hardware installed agent in the computing device performs one or more actions autonomously on behalf of the target system. The agent autonomously creates one or more trap files in the data structure of the filing system. A trap file is a file access to which indicates a probability of ransomware attack. The agent monitors access to the one or more trap files. Upon detecting access to a trap file, remedial action is performed by the target system against the probability of ransomware attack.

FIGURES

  • FIG. 1: Diagram illustrating the system of the present disclosure.
  • FIG. 2: Possible operations of the software agent and the hardware agent.
  • FIG. 3: Components of the hardware agent.
  • FIG. 4: Example connection options of the hardware agent to the user device.
  • FIG. 5: Example of multiple user devices transmitting data to the artifacts database.
  • FIG. 6: Example analytics performed by the agent of the present disclosure.