IP Library Granted Patent US 11,768,936
Granted Patent B2
US 11,768,936 · App. 16/050,581 · Granted Sep 26, 2023

Anomaly-based ransomware detection for encrypted files

Inventors: Or Herman Saffar (Beer Sheva, IL); Amihai Savir (Sansana, IL)
Assignee: EMC IP Holding Company LLC
G06F21/565G06F21/552G06F21/554G06N20/00G06F11/1435G06F11/1451G06F2201/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,768,936
App. No.
16/050,581
Granted
Sep 26, 2023
Kind
B2
Abstract

Techniques are provided for anomaly-based ransomware detection of encrypted files. One exemplary method comprises obtaining metadata for an encrypted file; applying an anomaly detection technique to the metadata to compare at least one attribute in the metadata to one or more corresponding historical baseline values for the at least one attribute; and determining whether the encrypted file comprises a ransomware encryption based on the comparison. In some embodiments, one or more of file extension attributes, file size attributes and file name attributes in the metadata are compared to the one or more corresponding historical baseline values to identify a ransomware attack.

Claims (34)

1. A method, comprising:

performing the following steps, in response to receiving an encrypted file, secured by a first encryption, sent from a user to a backup service as part of a backup of the encrypted file;

obtaining metadata for the encrypted file, wherein the metadata comprises a file name extension attribute of the encrypted file;

applying, using at least one processing device of the backup service, an anomaly detection technique to the metadata to compare at least one attribute in the metadata to one or more corresponding historical baseline values for the at least one attribute, wherein the anomaly detection technique comprises a machine learning technique that employs at least one trained machine learning model that is trained using historical time-series data for each of a plurality of file types each having a corresponding file name extension attribute; and

determining, using the at least one processing device of the backup service, whether the encrypted file, secured by the first encryption, was also encrypted using a ransomware encryption, in addition to the first encryption, based at least in part on the comparison, wherein the ransomware encryption is distinct from the first encryption, wherein the comparison comprises a comparison of (i) a count of files in a repository having the file name extension attribute of the encrypted file to (ii) a corresponding historical baseline value of the count of files in the repository having the file name extension attribute of the encrypted file to identify the ransomware encryption based at least in part on a deviation from an expected file name extension distribution.

2. The method of claim 1 , wherein the encrypted file is one or more of a portion of an incremental file backup and a snapshot.

3. The method of claim 1 , wherein the comparison of the count of files in the repository having the file name extension attribute of the encrypted file to the one or more corresponding historical baseline values identifies the ransomware encryption based at least in part on a renaming of at least one file name extension attribute.

4. The method of claim 1 , wherein the at least one attribute in the metadata comprises a file size attribute of the encrypted file and wherein the comparison to the one or more corresponding historical baseline values reveals one or more of a deviation in size of one or more increments of an incremental backup and a file size of the encrypted file is larger than a corresponding historical baseline value.

5. The method of claim 1 , wherein the comparison of the count of files in the repository having the file name extension attribute of the encrypted file to the one or more corresponding historical baseline values identifies that a snapshot file has been sent more than once.

6. The method of claim 1 , further comprising the step of evaluating a number of encrypted files sent within a predefined time window.

7. The method of claim 1 , wherein the historical time-series data is further used to evaluate a behavior of one or more of the encrypted file and the metadata for the encrypted file.

8. A system, comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

performing the following steps, in response to receiving an encrypted file, secured by a first encryption, sent from a user to a backup service as part of a backup of the encrypted file;

obtaining metadata for the encrypted file, wherein the metadata comprises a file name extension attribute of the encrypted file;

applying, using at least one processing device of the backup service, an anomaly detection technique to the metadata to compare at least one attribute in the metadata to one or more corresponding historical baseline values for the at least one attribute, wherein the anomaly detection technique comprises a machine learning technique that employs at least one trained machine learning model that is trained using historical time-series data for each of a plurality of file types each having a corresponding file name extension attribute; and

determining, using the at least one processing device of the backup service, whether the encrypted file, secured by the first encryption, was also encrypted using a ransomware encryption, in addition to the first encryption, based at least in part on the comparison, wherein the ransomware encryption is distinct from the first encryption, wherein the comparison comprises a comparison of (i) a count of files in a repository having the file name extension attribute of the encrypted file to (ii) a corresponding historical baseline value of the count of files in the repository having the file name extension attribute of the encrypted file to identify the ransomware encryption based at least in part on a deviation from an expected file name extension distribution.

9. The system of claim 8 , wherein the comparison of the count of files in the repository having the file name extension attribute of the encrypted file to the one or more corresponding historical baseline values identifies the ransomware encryption based at least in part on a renaming of at least one file name extension attribute.

10. The system of claim 8 , wherein the at least one attribute in the metadata comprises a file size attribute of the encrypted file and wherein the comparison to the one or more corresponding historical baseline values reveals one or more of a deviation in size of one or more increments of an incremental backup and a file size of the encrypted file is larger than a corresponding historical baseline value.

11. The system of claim 8 , wherein the comparison of the count of files in the repository having the file name extension attribute of the encrypted file to the one or more corresponding historical baseline values identifies that a snapshot file has been sent more than once.

12. The system of claim 8 , further comprising the step of evaluating a number of encrypted files sent within a predefined time window.

13. The system of claim 8 , wherein the historical time-series data is further used to evaluate a behavior of one or more of the encrypted file and the metadata for the encrypted file.

14. A computer program product, comprising a tangible machine-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device perform the following steps:

performing the following steps, in response to receiving an encrypted file, secured by a first encryption, sent from a user to a backup service as part of a backup of the encrypted file;

obtaining metadata for the encrypted file, wherein the metadata comprises a file name extension attribute of the encrypted file;

applying, using at least one processing device of the backup service, an anomaly detection technique to the metadata to compare at least one attribute in the metadata to one or more corresponding historical baseline values for the at least one attribute, wherein the anomaly detection technique comprises a machine learning technique that employs at least one trained machine learning model that is trained using historical time-series data for each of a plurality of file types each having a corresponding file name extension attribute; and

determining, using the at least one processing device of the backup service, whether the encrypted file, secured by the first encryption, was also encrypted using a ransomware encryption, in addition to the first encryption, based at least in part on the comparison, wherein the ransomware encryption is distinct from the first encryption, wherein the comparison comprises a comparison of (i) a count of files in a repository having the file name extension attribute of the encrypted file to (ii) a corresponding historical baseline value of the count of files in the repository having the file name extension attribute of the encrypted file to identify the ransomware encryption based at least in part on a deviation from an expected file name extension distribution.

15. The computer program product of claim 14 , wherein the comparison of the count of files in the repository having the file name extension attribute of the encrypted file to the one or more corresponding historical baseline values identifies the ransomware encryption based at least in part on a renaming of at least one file name extension attribute.

16. The computer program product of claim 14 , wherein the at least one attribute in the metadata comprises a file size attribute of the encrypted file and wherein the comparison to the one or more corresponding historical baseline values reveals one or more of a deviation in size of one or more increments of an incremental backup and a file size of the encrypted file is larger than a corresponding historical baseline value.

17. The computer program product of claim 14 , wherein the comparison of the count of files in the repository having the file name extension attribute of the encrypted file to the one or more corresponding historical baseline values identifies that a snapshot file has been sent more than once.

18. The computer program product of claim 14 , wherein the encrypted file is one or more of a portion of an incremental file backup and a snapshot.

19. The computer program product of claim 14 , further comprising the step of evaluating a number of encrypted files sent within a predefined time window.

20. The computer program product of claim 14 , wherein the historical time-series data is further used to evaluate a behavior of one or more of the encrypted file and the metadata for the encrypted file.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (047648/0422) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060160/0862 →
RELEASE OF SECURITY INTEREST AT REEL 047648 FRAME 0346 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0510 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047648/0346 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 047648/0422 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2018
From: SAFFAR, OR HERMAN; SAVIR, AMIHAI
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 046513/0927 →