Patent No.: US 11,720,678 B2

SYSTEMS AND METHODS FOR RANSOMWARE DETECTION AND MITIGATION

Date of Patent: Aug. 8, 2023

Applicant: Cyber Crucible Inc., Severna Park, MD (US)

Assignee: Cyber Crucible, Pittsburgh, PA (US)

Notice:

Subject to any disclaimer, the term of this patent is extended or adjusted under 35 U.S.C.154(b) by 214 days.

Appl. No.: 16/934,997

Filed: Jul. 21, 2020

International Classification:

  • G06F 21/56
  • G06F 16/22

U.S. Classification:

  • CPC G06F 21/566 (2013.01); G06F 16/2246 (2019.01); G06F 2221/034 (2013.01)

References Cited

U.S. PATENT DOCUMENTS

Patent Type Date Inventor Classification
8,769,685 B1 7/2014 Conrad G06F 21/562
10,609,066 B1 3/2020 Nossik H04L 63/1408
10,810,304 B2 10/2020 Gupta G06F 8/70
11,093,625 B2 8/2021 Vijayvargiya G06F 21/552
2007/0136341 A1 6/2007 Schopp
2008/0052300 A1 2/2008 Horgan
2008/0133531 A1 6/2008 Baskerville G06F 21/6254

ABSTRACT

System and method for protecting a computing device of a target system against ransomware attacks employs a file system having a data structure used by an operating system of the computing device for managing files. A software or a hardware installed agent in the computing device performs one or more actions autonomously on behalf of the target system. The agent autonomously creates one or more trap files in the data structure of the filing system. A trap file is a file access to which indicates a probability of ransomware attack. The agent monitors access to the one or more trap files. Upon detecting access to a trap file, remedial action is performed by the target system against the probability of ransomware attack.

20 Claims, 11 Drawing Sheets

BACKGROUND

Technical Field

The present disclosure relates generally to cybersecurity technology. More specifically, the present disclosure relates to systems and methods for ransomware detection and mitigation.

Related Art

In the cybersecurity field, ransomware is malware which denies a victim access to data or equipment until an attacker allows access to be returned. Defensive and attacker ransomware-focused capabilities have matured in capability and complexity of encryption capability, scope of resources denied, and payment methodologies.

The quality of an encryption algorithm is assessed based on the inability of a party with modern computing hardware to decrypt without access to the intended decryption method. Modern ransomware typically utilizes sophisticated encryption methods to deny access, leveraging strong encryption algorithms that can significantly slow down unauthorized decryption efforts.

SUMMARY

According to the present invention, a system and method for protecting a computing device of a target system against ransomware attacks employs a file system having a data structure used by an operating system of the computing device for managing files. A software or hardware agent performs actions autonomously on behalf of the target system by creating trap files that are monitored for access indicative of potential ransomware activity.

The agent's remedial action when detecting access to a trap file may involve notifying the user or automatically uploading the affected file for analysis or decryption.

BRIEF DESCRIPTION OF THE DRAWINGS

  • FIG. 1 is a diagram illustrating the system of the present disclosure;
  • FIG. 2 illustrates possible operations of the software and hardware agents;
  • FIG. 3 shows components of the hardware agent;
  • FIG. 4 depicts connection options of the hardware agent;
  • FIG. 5 shows data transmission to the artifacts database;
  • FIG. 6 outlines analytics performed by the agents;
  • FIG. 7-10 illustrate various operational systems and processes;
  • FIG. 11 presents a role hierarchy within the system.

DETAILED DESCRIPTION

The Ransomware Rewind software monitors file access activity for possible ransomware attacks by utilizing artifacts such as trap files placed within the system files. The software can act independently of the operating system functionalities to monitor and assess activities, including cryptographic operations.

Remedial actions taken in response to detected activities include alerting users, suspending or isolating processes identified as malicious, with a focus on minimizing corruption or loss of user data during encryption attempts by ransomware.

CLAIMS

  1. A method for protecting a computing device against ransomware, involving installing an agent that monitors and manages trap files within the device's file system, performing autonomous actions to detect and respond to ransomware threats.