IP Library › Granted Patent US 11,010,469
Granted Patent B2
US 11,010,469 · App. 16/130,636 · Granted May 18, 2021

Preventing ransomware from encrypting files on a target machine

Inventors: Eldar Aharoni (Holon, IL); Vadim Goldstein (Rishon Lezion, IL); Mashav Sapir (Tel Aviv, IL); Jenny Kitaichik (Ramat-Gan, IL)
Assignee: Palo Alto Networks, Inc.
G06F21/554G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,010,469
App. No.
16/130,636
Filed
Sep 13, 2018
Granted
May 18, 2021
Kind
B2
Art Unit
2431
USPC
726/23
Abstract

Techniques for preventing ransomware from encrypting files on a target machine are disclosed. In some embodiments, a system/process/computer program product for preventing ransomware from encrypting files on a target machine includes monitoring file system activities on a computing device; detecting an unauthorized activity associated with a honeypot file or honeypot folder; and performing an action based on a policy in response to the unauthorized activity associated with the honeypot file or honeypot folder.

Claims (62)

1. A system, comprising:

a processor configured to:

monitor file system activities on a computing device;

detect an unauthorized activity associated with a honeypot file or a honeypot folder, wherein the honeypot file is a virtual file generated as a spoofed file system response using a filter driver or the honeypot folder is a virtual folder generated as the spoofed file system response using the filter driver, wherein the virtual file is dynamically generated with a spoofed header, a spoofed time stamp, and a spoofed file size using the filter driver;

perform an action based on a policy in response to the unauthorized activity associated with the honeypot file or the honeypot folder; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the processor is further configured to:

detect a file open event associated with the honeypot file.

3. The system of claim 1 , wherein the processor is further configured to:

detect a setting file information event associated with the honeypot file.

4. The system of claim 1 , wherein the processor is further configured to:

detect a writing into a file event associated with the honeypot file.

5. The system of claim 1 , wherein the processor is further configured to:

detect an enumerating a directory event associated with the honeypot folder.

6. The system of claim 1 , wherein the processor is further configured to:

generate a plurality of honeypot files.

7. The system of claim 1 , wherein the processor is further configured to:

generate a plurality of honeypot folders.

8. The system of claim 1 , wherein the processor is further configured to:

generate a plurality of honeypot files in a protected directory.

9. The system of claim 1 , wherein the processor is further configured to:

generate a plurality of honeypot folders in a protected directory.

10. The system of claim 1 , wherein the processor is further configured to:

kill a process based on the policy in response to the unauthorized activity associated with the honeypot file or the honeypot folder associated with the process.

11. The system of claim 1 , wherein the processor is further configured to:

generate an alert based on the policy in response to the unauthorized activity associated with the honeypot file or honeypot folder.

12. The system of claim 1 , wherein detect the unauthorized activity associated with the honeypot file or the honeypot folder further comprises:

detect an enumerating directory event on the computing device;

allow a default system behavior if the enumerating directory event is associated with a non-protected directory; and

inject fake start entries if the enumerating directory event is associated with an enumeration at a beginning of a protected directory or inject fake end entries if the enumerating directory event is associated with an enumeration at an end of the protected directory.

13. A method, comprising:

monitoring file system activities on a computing device;

detecting an unauthorized activity associated with a honeypot file or a honeypot folder, wherein the honeypot file is a virtual file generated as a spoofed file system response using a filter driver or the honeypot folder is a virtual folder generated as the spoofed file system response using the filter driver, wherein the virtual file is dynamically generated with a spoofed header, a spoofed time stamp, and a spoofed file size using the filter driver; and

performing an action based on a policy in response to the unauthorized activity associated with the honeypot file or the honeypot folder.

14. The method of claim 13 , further comprising detecting a file open event associated with the honeypot file.

15. The method of claim 13 , further comprising detecting a setting file information event associated with the honeypot file.

16. The method of claim 13 , further comprising detecting a writing into a file event associated with the honeypot file.

17. The method of claim 13 , further comprising detecting an enumerating a directory event associated with the honeypot folder.

18. The method of claim 13 , further comprising generating a plurality of honeypot files and/or honeypot folders.

19. The method of claim 13 , further comprising generating a plurality of honeypot files and/or honeypot folders in a protected directory.

20. The method of claim 13 , further comprising killing a process based on the policy in response to the unauthorized activity associated with the honeypot file or the honeypot folder associated with the process.

21. The method of claim 13 , further comprising generating an alert based on the policy in response to the unauthorized activity associated with the honeypot file or honeypot folder.

22. The method of claim 13 , further comprising:

detecting an enumerating directory event on the computing device;

allowing a default system behavior if the enumerating directory event is associated with a non-protected directory; and

injecting fake start entries if the enumerating directory event is associated with an enumeration at a beginning of a protected directory or inject fake end entries if the enumerating directory event is associated with an enumeration at an end of the protected directory.

23. A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

monitoring file system activities on a computing device;

detecting an unauthorized activity associated with a honeypot file or a honeypot folder, wherein the honeypot file is a virtual file generated as a spoofed file system response using a filter driver or the honeypot folder is a virtual folder generated as the spoofed file system response using the filter driver, wherein the virtual file is dynamically generated with a spoofed header, a spoofed time stamp, and a spoofed file size using the filter driver; and

performing an action based on a policy in response to the unauthorized activity associated with the honeypot file or the honeypot folder.

24. The computer program product of claim 23 , further comprising computer instructions for detecting a file open event associated with the honeypot file.

25. The computer program product of claim 23 , further comprising computer instructions for detecting a setting file information event associated with the honeypot file.

26. The computer program product of claim 23 , further comprising computer instructions for detecting a writing into a file event associated with the honeypot file.

27. The computer program product of claim 23 , further comprising computer instructions for detecting an enumerating a directory event associated with the honeypot folder.

28. The computer program product of claim 23 , further comprising computer instructions for generating a plurality of honeypot files and/or honeypot folders.

29. The computer program product of claim 23 , further comprising computer instructions for generating a plurality of honeypot files and/or honeypot folders in a protected directory.

30. The computer program product of claim 23 , further comprising killing a process based on the policy in response to the unauthorized activity associated with the honeypot file or the honeypot folder associated with the process.

31. The computer program product of claim 23 , further comprising generating an alert based on the policy in response to the unauthorized activity associated with the honeypot file or honeypot folder.

32. The computer program product of claim 23 , further comprising computer instructions for:

detecting an enumerating directory event on the computing device;

allowing a default system behavior if the enumerating directory event is associated with a non-protected directory; and

injecting fake start entries if the enumerating directory event is associated with an enumeration at a beginning of a protected directory or inject fake end entries if the enumerating directory event is associated with an enumeration at an end of the protected directory.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2019
From: AHARONI, ELDAR; GOLDSTEIN, VADIM; SAPIR, MASHAV; KITAICHIK, JENNY
To: PALO ALTO NETWORKS, INC.
Reel/Frame 048058/0853 →
Continuity (1)
Related Publication 20200089876A1 · Mar 19, 2020
Cited By (3)
US 12,423,411 US 12,464,020 US 12,481,754