IP Library Granted Patent US 10,887,339
Granted Patent B1
US 10,887,339 · App. 16/142,270 · Granted Jan 5, 2021

Systems and methods for protecting a cloud storage against suspected malware

Inventors: Ilya Sokolov (Boston, MA); Lei Gu (Bedford, MA); Mark Kennedy (Gardena, CA)
Assignee: NORTONLIFELOCK, INC.
H04L63/145G06F21/554G06F21/565G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,887,339
App. No.
16/142,270
Granted
Jan 5, 2021
Kind
B1
Abstract

The disclosed computer-implemented method for protecting a cloud storage against suspected malware may include (1) receiving a backup of one or more encrypted files over a network, (2) determining that the one or more encrypted files match one or more criteria associated with suspected malware, and (3) performing a security action that protects a computing device against the suspected malware. Various other methods, systems, and computer-readable media are also disclosed.

Claims (39)

1. A computer-implemented method for protecting a cloud storage against suspected malware, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

receiving, by a computing device, a backup of one or more encrypted files over a network;

determining, by the computing device, that the one or more encrypted files match one or more criteria associated with suspected malware, wherein determining that the one or more encrypted files match the criteria comprises determining that the backup of the one or more encrypted files matches a download sequence of a number of malware files and malware file types; and

performing, by the computing device, a security action that protects the computing device against the suspected malware.

2. The computer-implemented method of claim 1 , wherein performing the security action comprises at least one of:

flagging the one or more encrypted files for a reputation check upon a restore operation from the cloud storage;

generating a user notification for downloading an anti-malware solution;

changing a backup policy to maintain previous backups of the one or more encrypted files after a predetermined retention period;

changing the backup policy to store fewer revisions of the one or more encrypted files on the cloud storage; and

rejecting additional backups of the one or more encrypted files to the computing device.

3. The computer-implemented method of claim 1 , wherein determining that the one or more encrypted files match the criteria further comprises determining that a file size associated with the one or more encrypted files is a file size of an encrypted backup file that is within a file block size of a symmetric encryption file block.

4. The computer-implemented method of claim 1 , wherein determining that the one or more encrypted files match the criteria further comprises determining that the one or more encrypted files were uploaded to the computing device from a location associated with containing copies of malware.

5. The computer-implemented method of claim 1 , wherein determining that the one or more encrypted files match the criteria further comprises determining that the one or more encrypted files were uploaded to the computing device during a time period associated with a known malware occurrence.

6. The computer-implemented method of claim 1 , wherein determining that the one or more encrypted files match the criteria further comprises determining that a file type associated with the one or more encrypted files matches a file type associated with known malware.

7. The computer-implemented method of claim 1 , wherein determining that the one or more encrypted files match the criteria further comprises determining that a file header value associated with the one or more encrypted files matches a file header value associated with known malware.

8. The computer-implemented method of claim 1 , wherein determining that the one or more encrypted files match the criteria further comprises determining that the one or more encrypted files match a plurality of the criteria associated with the suspected malware.

9. The computer-implemented method of claim 1 , wherein the computing device comprises a cloud storage server.

10. A system for protecting a cloud storage against suspected malware, the system comprising:

at least one physical processor;

physical memory comprising a plurality of modules and computer-executable instructions that, when executed by the physical processor, cause the physical processor to:

receive, by a receiving module on a computing device, a backup of one or more encrypted files over a network;

determine, by a determining module, that the one or more encrypted files match one or more criteria associated with the suspected malware, wherein the determining module determines that the one or more encrypted files match the criteria by determining that the backup of the one or more encrypted files matches a download sequence of a number of malware files and malware file types; and

perform, by a security module, a security action that protects the computing device against the suspected malware.

11. The system of claim 10 , wherein the security module performs the security action by:

flagging the one or more encrypted files for a reputation check upon a restore operation from the cloud storage;

generating a user notification for downloading an anti-malware solution;

changing a backup policy to maintain previous backups of the one or more encrypted files after a predetermined retention period;

changing the backup policy to store fewer revisions of the one or more encrypted files on the cloud storage; and

rejecting additional backups of the one or more encrypted files to the computing device.

12. The system of claim 10 , wherein the determining module determines that the one or more encrypted files match the criteria by further determining that a file size associated with the one or more encrypted files is a file size of an encrypted backup file that is within a file block size of a symmetric encryption file block.

13. The system of claim 10 , wherein the determining module determines that the one or more encrypted files match the criteria by further determining that the one or more encrypted files were uploaded to the computing device from a location associated with containing copies of malware.

14. The system of claim 10 , wherein the determining module determines that the one or more encrypted files match the criteria by further determining that the one or more encrypted files were uploaded to the computing device during a time period associated with a known malware occurrence.

15. The system of claim 10 , wherein the determining module determines that the one or more encrypted files match the criteria by further determining that a file type associated with the one or more encrypted files matches a file type associated with known malware.

16. The system of claim 10 , wherein the determining module determines that the one or more encrypted files match the criteria by further determining that a file header value associated with the one or more encrypted files matches a file header value associated with known malware.

17. The system of claim 10 , wherein the determining module determines that the one or more encrypted files match the criteria by further determining that the one or more encrypted files match a plurality of the criteria associated with the suspected malware.

18. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

receive a backup of one or more encrypted files over a network;

determine that the one or more encrypted files match one or more criteria associated with suspected malware, wherein the one or more computer-executable instructions cause the computing device to determine that the one or more encrypted files match the criteria by determining that the backup of the one or more encrypted files matches a download sequence of a number of malware files and malware file types; and

perform a security action that protects the computing device against the suspected malware.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2018
From: SOKOLOV, ILYA; GU, LEI; KENNEDY, MARK
To: SYMANTEC CORPORATION
Reel/Frame 046976/0918 →
Cited By (8)
US 12,386,959 US 12,393,494 US 12,393,689 US 12,393,690 US 12,399,993 US 12,481,560 US 12,554,591 US 12,664,275