IP Library Granted Patent US 10,193,918
Granted Patent B1
US 10,193,918 · App. 15/939,273 · Granted Jan 29, 2019

Behavior-based ransomware detection using decoy files

Inventors: Mark William Patton (San Jose, CA); Nathan Scott (Coconut Creek, FL); Ramon Royo Gutierrez (Baracaldo, ES); Sherab Giovannini (Portugalete, ES)
Assignee: Malwarebytes Inc.
H04L63/1425H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,193,918
App. No.
15/939,273
Granted
Jan 29, 2019
Kind
B1
Abstract

An anti-malware application analyzes behavior of an executing process to identify ransomware. The anti-malware application detects an untrusted process requesting enumeration of a directory of user files and causes the untrusted process to initially operate on a decoy file that mimics the user files. If the behavior of the untrusted process with respect to the decoy file is indicative of ransomware, the process can be terminated without loss of the user files. The decoy file may be deployed in a way that is undetectable to the user.

Claims (72)

1. A method for detecting and remediating ransomware, the method comprising:

monitoring a plurality of processes executing on a client device;

identifying, from the plurality of processes, an untrusted process that is absent from a whitelist of trusted processes;

monitoring the untrusted process executing on the client device;

detecting a request by the untrusted process to enumerate a directory containing one or more user files;

causing a decoy file to be returned to the untrusted process in response to the request;

monitoring actions of the untrusted process performed on the decoy file;

determining sub-scores associated with each of the monitored actions performed on the decoy file;

generating a cumulative score for the untrusted process based on a combination of the sub-scores associated with the monitored actions;

determining that the cumulative score for the untrusted process exceeds a predefined threshold score;

responsive to determining that the cumulative score exceeds the predefined threshold score, determining that behavior of untrusted process exhibited malicious behavior with respect to the decoy file;

identifying, by a processor, the untrusted process as corresponding to the ransomware based at least in part on determining that the untrusted process exhibited the malicious behavior with respect to the decoy file; and

remediating the untrusted process responsive to identifying the process as corresponding to the ransomware.

2. The method of claim 1 , wherein identifying the untrusted process as corresponding to the ransomware comprises:

storing a count of decoy files on which the untrusted process exhibited malicious behavior; and

identifying the untrusted process as corresponding to the ransomware responsive to the count exceeding a predefined threshold.

3. The method of claim 1 , wherein causing the decoy file to be returned to the untrusted process in response to the request comprises:

determining a location of the decoy file in a storage of the computing device; and

retrieving the decoy file from the storage.

4. The method of claim 1 , wherein causing the decoy file to be returned to the process in response to the request comprises:

generating the decoy file in response to detecting the request.

5. The method of claim 1 , wherein the decoy file comprises a copy of the one or more user files.

6. A non-transitory computer-readable storage medium storing instructions for detecting and remediating ransomware, the instructions when executed by a processor cause the processor to perform steps including:

monitoring a plurality of processes executing on a client device;

identifying, from the plurality of processes, an untrusted process that is absent from a whitelist of trusted processes;

monitoring the untrusted process executing on the client device;

detecting, by a processor, a request by the untrusted process to enumerate a directory containing one or more user files;

causing a decoy file to be returned to the untrusted process in response to the request;

monitoring actions of the untrusted process performed on the decoy file;

determining sub-scores associated with each of the monitored actions performed on the decoy file;

generating a cumulative score for the untrusted process based on a combination of the sub-scores associated with the monitored actions;

determining that the cumulative score for the untrusted process exceeds a predefined threshold score;

responsive to determining that the cumulative score exceeds the predefined threshold score, determining that behavior of untrusted process exhibited malicious behavior with respect to the decoy file;

identifying the untrusted process as corresponding to the ransomware based at least in part on determining that the untrusted process exhibited the malicious behavior with respect to the decoy file; and

remediating the untrusted process responsive to identifying the process as corresponding to the ransomware.

7. The non-transitory computer-readable storage medium of claim 6 ,

wherein identifying the untrusted process as corresponding to the ransomware comprises:

storing a count of decoy files on which the untrusted process exhibited malicious behavior; and

identifying the untrusted process as corresponding to the ransomware responsive to the count exceeding a predefined threshold.

8. The non-transitory computer-readable storage medium of claim 6 , wherein

causing the decoy file to be returned to the untrusted process in response to the request comprises:

determining a location of the decoy file in a storage of the computing device; and

retrieving the decoy file from the storage.

9. The non-transitory computer-readable storage medium of claim 6 , wherein causing the decoy file to be returned to the process in response to the request comprises:

generating the decoy file in response to detecting the request.

10. The non-transitory computer-readable storage medium of claim 6 , wherein the decoy file comprises a copy of the one or more user files.

11. A computing system comprising:

a processor; and

a non-transitory computer-readable storage medium storing instructions for detecting and remediating ransomware, the instructions when executed by the processor cause the processor to perform steps including:

monitoring a plurality of processes executing on a client device;

identifying, from the plurality of processes, an untrusted process that is absent from a whitelist of trusted processes;

monitoring the untrusted process executing on the client device;

detecting, by a processor, a request by the untrusted process to enumerate a directory containing one or more user files;

causing a decoy file to be returned to the untrusted process in response to the request;

monitoring actions of the untrusted process performed on the decoy file;

determining sub-scores associated with each of the monitored actions performed on the decoy file;

generating a cumulative score for the untrusted process based on a combination of the sub-scores associated with the monitored actions;

determining that the cumulative score for the untrusted process exceeds a predefined threshold score;

responsive to determining that the cumulative score exceeds the predefined threshold score, determining that behavior of untrusted process exhibited malicious behavior with respect to the decoy file;

identifying the untrusted process as corresponding to the ransomware based at least in part on determining that the untrusted process exhibited the malicious behavior with respect to the decoy file; and

remediating the untrusted process responsive to identifying the process as corresponding to the ransomware.

12. The computing system of claim 11 , wherein identifying the

untrusted process as corresponding to the ransomware comprises:

storing a count of decoy files on which the untrusted process exhibited malicious behavior; and

identifying the untrusted process as corresponding to the ransomware responsive to the count exceeding a predefined threshold.

13. The computing system of claim 11 , wherein causing the decoy file to be

returned to the untrusted process in response to the request comprises:

determining a location of the decoy file in a storage of the computing device; and

retrieving the decoy file from the storage.

14. The computing system of claim 11 , wherein causing the decoy file to be

returned to the process in response to the request comprises:

generating the decoy file in response to detecting the request.

Assignments (8)
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Oct 21, 2024
From: COMPUTERSHARE TRUST COMPANY, N.A.
To: MALWAREBYTES INC.
Reel/Frame 069193/0505 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Oct 21, 2024
From: COMPUTERSHARE TRUST COMPANY, N.A.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 069193/0563 →
SECURITY INTEREST Recorded Oct 18, 2024
From: MALWAREBYTES INC.; MALWAREBYTES CORPORATE HOLDCO INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 068943/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2024
From: MALWAREBYTES INC.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 066900/0386 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 26, 2024
From: MALWAREBYTES CORPORATE HOLDCO INC.
To: COMPUTERSHARE TRUST COMPANY, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 066373/0912 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 1, 2023
From: MALWAREBYTES INC.
To: COMPUTERSHARE TRUST COMPANY, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 062599/0069 →
SECURITY INTEREST Recorded Oct 10, 2019
From: MALWAREBYTES INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 050681/0271 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2018
From: PATTON, MARK WILLIAM; SCOTT, NATHAN; GUTIERREZ, RAMON ROYO; GIOVANNINI, SHERAB
To: MALWAREBYTES INC.
Reel/Frame 045644/0246 →
Cited By (10)
US 12,229,261 US 12,361,130 US 12,363,165 US 12,464,020 US 12,493,697 US 12,536,284 US 12,625,961 US 12,664,255 US 12,681,777 US 12,711,232