IP Library Patent Application 15623401
Patent Application
App. No. 15/623,401

Agentless ransomware detection and recovery

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/623,401
Abstract

A network security apparatus includes an interface and a processor. The interface is configured to communicate at least with an endpoint computer over a network. The processor is configured to create a trap resource that is shared between the network security apparatus and an operating system of the endpoint computer, to detect ransomware activity in the shared resource, and to initiate a responsive action in response to the detected ransomware activity.

Claims (25)

1 . A network security apparatus, comprising:

an interface, configured to communicate at least with an endpoint computer over a network; and

a processor, which is configured to create a trap resource that is shared between the network security apparatus and an operating system of the endpoint computer, to detect ransomware activity in the shared resource, and to initiate a responsive action in response to the detected ransomware activity.

2 . The apparatus according to claim 1 , wherein the processor is configured to create the trap resource in the network security apparatus and to share the trap resource with the operating system of the endpoint computer.

3 . The apparatus according to claim 1 , wherein the processor is configured to create the trap resource in the operating system of the endpoint computer and to share the trap resource with the network security apparatus.

4 . The apparatus according to claim 1 , wherein the processor is configured to detect the ransomware activity without adding any agent to the endpoint computer.

5 . The apparatus according to claim 1 , wherein the shared resource comprises a directory that is shared between the network security apparatus and the operating system of the endpoint computer.

6 . The apparatus according to claim 1 , wherein the shared resource comprises a file that is shared between the network security apparatus and the operating system of the endpoint computer.

7 . The apparatus according to claim 1 , wherein the processor is configured to create the trap resource by running a command-line in the endpoint computer.

8 . The apparatus according to claim 1 , wherein the processor is configured to create the trap resource in the network security apparatus on-the-fly, in response to an access attempt by the endpoint computer.

9 . The apparatus according to claim 1 , wherein the processor is configured to assign first and second clones of the trap resource, having identical names but addressed by different IP addresses, to the endpoint computer and to another endpoint computer.

10 . A method for network security, comprising:

creating a trap resource that is shared between a network security system and an operating system of an endpoint computer;

using the network security system, detecting ransomware activity in the shared resource; and

initiating a responsive action in response to the detected ransomware activity.

11 . The method according to claim 10 , wherein creating the trap resource comprises creating the trap resource in the network security system and sharing the trap resource with the operating system of the endpoint computer.

12 . The method according to claim 10 , wherein creating the trap resource comprises creating the trap resource in the operating system of the endpoint computer and sharing the trap resource with the network security system.

13 . The method according to claim 10 , wherein detecting the ransomware activity is performed without adding any agent to the endpoint computer.

14 . The method according to claim 10 , wherein the shared resource comprises a directory that is shared between the network security system and the operating system of the endpoint computer.

15 . The method according to claim 10 , wherein the shared resource comprises a file that is shared between the network security system and the operating system of the endpoint computer.

16 . The method according to claim 10 , wherein creating the trap resource comprises running a command-line in the endpoint computer.

17 . The method according to claim 10 , wherein creating the trap resource comprises creating the trap resource on-the-fly in the network security system, in response to an access attempt by the endpoint computer.

18 . The method according to claim 10 , wherein creating the trap resource comprises assigning first and second clones of the trap resource, having identical names but addressed by different IP addresses, to the endpoint computer and to another endpoint computer.

19 . A computer software product, the product comprising a tangible non-transitory computer-readable medium in which program instructions are stored, which instructions, when read by a processor of a network security system, cause the processor to communicate at least with an endpoint computer over a network, to create a trap resource that is shared between the network security system and an operating system of the endpoint computer, to detect ransomware activity in the shared resource, and to initiate a responsive action in response to the detected ransomware activity.

20 . The product according to claim 19 , wherein the instructions cause the processor to detect the ransomware activity without adding any agent to the endpoint computer.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Oct 12, 2021
From: SILICON VALLEY BANK
To: GUARDICORE LTD
Reel/Frame 057768/0936 →
SECURITY INTEREST Recorded Jan 14, 2019
From: GUARDICORE LTD
To: SILICON VALLEY BANK
Reel/Frame 047989/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2017
From: VOLFMAN, MICHAEL; GURVICH, PAVEL; ZEITLIN, ARIEL
To: GUARDICORE LTD.
Reel/Frame 042715/0239 →