Patent No.: US 11,720,678 B2
SYSTEMS AND METHODS FOR RANSOMWARE DETECTION AND MITIGATION
Date of Patent: Aug. 8, 2023
Applicant: Cyber Crucible Inc., Severna Park, MD (US)
Assignee: Cyber Crucible, Pittsburgh, PA (US)
Notice:
Subject to any disclaimer, the term of this patent is extended or adjusted under 35 U.S.C.154(b) by 214 days.
Appl. No.: 16/934,997
Filed: Jul. 21, 2020
International Classification:
- G06F 21/56
- G06F 16/22
U.S. Classification:
- CPC G06F 21/566 (2013.01); G06F 16/2246 (2019.01); G06F 2221/034 (2013.01)
References Cited
U.S. PATENT DOCUMENTS
| Patent | Type | Date | Inventor | Classification |
|---|---|---|---|---|
| 8,769,685 | B1 | 7/2014 | Conrad | G06F 21/562 |
| 10,609,066 | B1 | 3/2020 | Nossik | H04L 63/1408 |
| 10,810,304 | B2 | 10/2020 | Gupta | G06F 8/70 |
| 11,093,625 | B2 | 8/2021 | Vijayvargiya | G06F 21/552 |
| 2007/0136341 | A1 | 6/2007 | Schopp | |
| 2008/0052300 | A1 | 2/2008 | Horgan | |
| 2008/0133531 | A1 | 6/2008 | Baskerville | G06F 21/6254 |
ABSTRACT
System and method for protecting a computing device of a target system against ransomware attacks employs a file system having a data structure used by an operating system of the computing device for managing files. A software or a hardware installed agent in the computing device performs one or more actions autonomously on behalf of the target system. The agent autonomously creates one or more trap files in the data structure of the filing system. A trap file is a file access to which indicates a probability of ransomware attack. The agent monitors access to the one or more trap files. Upon detecting access to a trap file, remedial action is performed by the target system against the probability of ransomware attack.
20 Claims, 11 Drawing Sheets
BACKGROUND
Technical Field
The present disclosure relates generally to cybersecurity technology. More specifically, the present disclosure relates to systems and methods for ransomware detection and mitigation.
Related Art
In the cybersecurity field, ransomware is malware which denies a victim access to data or equipment until an attacker allows access to be returned. Defensive and attacker ransomware-focused capabilities have matured in capability and complexity of encryption capability, scope of resources denied, and payment methodologies.
The quality of an encryption algorithm is assessed based on the inability of a party with modern computing hardware to decrypt without access to the intended decryption method. Modern ransomware typically utilizes sophisticated encryption methods to deny access, leveraging strong encryption algorithms that can significantly slow down unauthorized decryption efforts.
SUMMARY
According to the present invention, a system and method for protecting a computing device of a target system against ransomware attacks employs a file system having a data structure used by an operating system of the computing device for managing files. A software or hardware agent performs actions autonomously on behalf of the target system by creating trap files that are monitored for access indicative of potential ransomware activity.
The agent's remedial action when detecting access to a trap file may involve notifying the user or automatically uploading the affected file for analysis or decryption.
BRIEF DESCRIPTION OF THE DRAWINGS
- FIG. 1 is a diagram illustrating the system of the present disclosure;
- FIG. 2 illustrates possible operations of the software and hardware agents;
- FIG. 3 shows components of the hardware agent;
- FIG. 4 depicts connection options of the hardware agent;
- FIG. 5 shows data transmission to the artifacts database;
- FIG. 6 outlines analytics performed by the agents;
- FIG. 7-10 illustrate various operational systems and processes;
- FIG. 11 presents a role hierarchy within the system.
DETAILED DESCRIPTION
The Ransomware Rewind software monitors file access activity for possible ransomware attacks by utilizing artifacts such as trap files placed within the system files. The software can act independently of the operating system functionalities to monitor and assess activities, including cryptographic operations.
Remedial actions taken in response to detected activities include alerting users, suspending or isolating processes identified as malicious, with a focus on minimizing corruption or loss of user data during encryption attempts by ransomware.
CLAIMS
- A method for protecting a computing device against ransomware, involving installing an agent that monitors and manages trap files within the device's file system, performing autonomous actions to detect and respond to ransomware threats.