IP Library › Granted Patent US 11,100,241
Granted Patent B2
US 11,100,241 · App. 16/698,510 · Granted Aug 24, 2021

Virtual trap protection of data elements

Inventor: Gil Barak (Ra'anana, IL)
Assignee: Palo Alto Networks, Inc.
G06F21/62H04L63/1408H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,100,241
App. No.
16/698,510
Granted
Aug 24, 2021
Kind
B2
Abstract

To prevent ransomware from encrypting data elements stored in a memory of a computer-based system, the system identifies at least one identifier associated with a data element. The identifiers indicate an attribute(s) of the corresponding data element within the memory. The system then determines an optimal number of virtual traps for the data elements respective of at least one identifier. The system then determines an optimal position for each virtual trap corresponding to the at least one identifier. The system then positions the virtual traps at the determined position within the memory. The system monitors the data elements stored in the memory in order to identify whether changes have occurred, and determines respectively updated optimal number and positions of virtual traps.

Claims (39)

1. A method comprising:

determining identifiers of a plurality of data elements stored in a memory;

based, at least in part, on the identifiers, determining virtual trap generation parameters that comprise, at least one of, virtual trap names and one or more virtual trap types;

generating virtual traps for the plurality of data elements at an amount that increases probability malware will affect a virtual trap before one of the plurality of data elements, wherein generating the virtual traps is according to the virtual trap generation parameters;

determining positions for storing the generated virtual traps in the memory relative to corresponding ones of the plurality of data elements; and

sending the virtual traps to be stored at the determined positions in the memory to protect the plurality of data elements from malware.

2. The method of claim 1 , wherein a data element is one of a folder, a sub-folder, a file, or a process.

3. The method of claim 1 , wherein a virtual trap is one of a virtual file, a virtual folder, a virtual sub-folder, a virtual process, a virtual memory object, a virtual registry key, a virtual removable device, a virtual physical device, a virtual network device, or a virtual network share.

4. The method of claim 1 , further comprising detecting a suspicious process based, at least in part, on detecting a change or attempted change to one of the virtual traps in the memory.

5. The method of claim 4 further comprising initializing at least one computerized process to prevent the detected suspicious process from changing at least one of the virtual traps in the memory.

6. The method of claim 1 further comprising monitoring the virtual traps stored within the memory for changes or attempted changes.

7. The method of claim 1 further comprising:

generating an additional amount of virtual traps for a first data element based, at least in part, on a detected change or attempted change to a first of the virtual traps that protects the first data element; and

sending the additional virtual traps to the memory to protect the first data element.

8. The method of claim 1 , wherein an identifier of a data element indicates at least one of a file name, a folder name, a file save time, a file creation date, a file creator, and a file type.

9. One or more non-transitory computer-readable media having program code stored thereon, the program code comprising instructions to:

determine identifiers of a plurality of data elements stored in a memory;

based, at least in part, on the identifiers, determine parameters for virtual traps to generate, wherein the virtual trap parameters comprise, at least one of, names for the virtual traps to generate and one or more types of virtual traps to generate;

generate an amount of the virtual traps for the plurality of data elements that increases probability that malware will affect a virtual trap before one of the plurality of data elements, wherein the instructions to generate the virtual traps comprise the instructions to generate the virtual traps according to the virtual trap parameters;

determine positions for storing the generated virtual traps in the memory relative to corresponding ones of the plurality of data elements; and

store the virtual traps at the determined positions in the memory to protect the plurality of data elements from malware.

10. The non-transitory computer-readable media of claim 9 , wherein a data element is one of a folder, a sub-folder, a file, or a process.

11. The non-transitory computer-readable media of claim 9 , wherein a virtual trap is one of a virtual file, a virtual folder, a virtual sub-folder, a virtual process, a virtual memory object, a virtual registry key, a virtual removable device, a virtual physical device, a virtual network device, or a virtual network share.

12. The non-transitory computer-readable media of claim 9 , wherein the program code further comprises instructions to monitor the virtual traps for attempted changes or changes to the virtual traps.

13. The non-transitory computer-readable media of claim 12 , wherein the program code further comprises instructions to initialize at least one computerized process to prevent a suspicious process detected from monitoring the virtual traps.

14. The non-transitory computer-readable media of claim 9 , wherein the program code further comprises instructions to:

generate an additional amount of virtual traps for a first of the plurality of data elements based, at least in part, on a detected change or attempted change to a first of the virtual traps that protects the first data element; and

store the additional virtual traps in the memory to protect the first data element.

15. An apparatus comprising:

a processor; and

a non-transitory machine-readable medium having program instructions stored thereon, wherein the program instructions are executable by the processor to cause the apparatus to, determine identifiers of a plurality of data elements stored in a memory;

based, at least in part, on the identifiers, determine parameters for virtual traps to generate, wherein the virtual trap parameters comprise, at least one of, names for the virtual traps to generate and one or more types of virtual traps to generate;

generate an amount of virtual traps for the plurality of data elements that increases probability that malware will affect a virtual trap before one of the plurality of data elements, wherein the instructions to generate the virtual traps comprise the instructions executable to cause the apparatus to generate the virtual traps according to the virtual trap parameters;

determine positions for storing the generated virtual traps in the memory relative to corresponding ones of the plurality of data elements; and

store the virtual traps at the determined positions in the memory to protect the plurality of data elements from malware.

16. The apparatus of claim 15 , wherein the program instructions further comprise program instructions executable by the processor to cause the apparatus to initialize at least one computerized process to prevent a suspicious process detected from monitoring the virtual traps.

17. The apparatus of claim 15 , wherein the program instructions further comprise program instructions to:

generate an additional amount of virtual traps for a first of the plurality of data elements based, at least in part, on a detected change or attempted change to a first of the virtual traps that protects the first data element; and

store the additional virtual traps in the memory to protect the first data element.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2019
From: BARAK, GIL
To: CYBER SECDO LTD.
Reel/Frame 051132/0976 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2019
From: CYBER SECDO LTD.
To: PALO ALTO NETWORKS INC.
Reel/Frame 051133/0048 →
Continuity (3)
Continuation 15492338 · Apr 20, 2017
Provisional Application 62325466 · Apr 21, 2016
Related Publication 20200193041A1 · Jun 18, 2020
Cited By (1)
US 12,681,777