IP Library Granted Patent US 11,516,236
Granted Patent B2
US 11,516,236 · App. 16/839,377 · Granted Nov 29, 2022

Systems and methods for detection and mitigation of malicious encryption

Inventor: Daniel Vernon Bailey (Pepperell, MA)
Assignee: CARBONITE, INC.
H04L63/1425G06F21/554H04L9/14H04L63/0428H04L63/1416H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,516,236
App. No.
16/839,377
Granted
Nov 29, 2022
Kind
B2
Abstract

The present disclosure describes systems and methods for detection and mitigation of malicious encryption. A security agent on an infected computing device may monitor data writes to disk, memory, or network transmission buffers for strings that may represent encryption keys or moduli. The security agent may apply one or more techniques to decode and parse the string to either identify or extract the keys, or rule out the string as containing an encryption key or modulus. If a key is identified, or its presence cannot be excluded, then the security agent may generate an alert and take mitigation actions.

Claims (54)

1. A method for detecting and mitigating malicious encryption, comprising:

detecting, by a security agent executed by a computing device, writing of a first item of data to memory of the computing device;

detecting, by the security agent, an encryption key in the first item of data based on the application of one or more of a plurality of tests to the first item of data, wherein the plurality of tests includes:

attempting to decode, by the security agent, the first item of data and analyzing the decoded data for the presence of predetermined strings or formats,

examining, by the security agent, the entropy of the first item of data,

examining, by the security agent, the first item of data to determine whether the first item of data is an RSA modulus by determining if a numeric representation of the first item of data is a composite number,

analyzing, by the security agent, the first item of data by attempting at least a partial factorization of the numeric representation; and

responsive to detecting an encryption key in the first item of data based on the application of the one or more of the plurality of tests:

generating an alert, by the security agent, indicating a likely malicious encryption attempt, and

taking, by the security agent, one or more actions to mitigate the malicious encryption attempt.

2. The method of claim 1 , wherein, prior to applying the one or more of the plurality of tests to the first item of data, determining, by the security agent, if the first item of data matches a predetermined size range.

3. The method of claim 2 , wherein if it is determined that the first item of data matches the predetermined size range, assuming that the first item of data includes an encryption key.

4. The method of claim 2 , wherein if it is determined that the first item of data does not match the predetermined size range, continuing with the application of one or more of the plurality of tests to the first item of data.

5. The method of claim 1 , wherein attempting to decode the first item of data further comprises decoding the first item of data according to a predetermined encryption key encoding system.

6. The method of claim 1 , wherein examining the entropy of the first item of data further comprises:

compressing a first portion of the first item of data;

calculating a ratio of a size of the first portion of the first item of data to a size of a compressed first portion of the first item of data;

determining that the ratio does not exceed a predetermined threshold; and

responsive to the determination that the ratio does not exceed the predetermined threshold, identifying the first item of data as comprising an encryption key.

7. The method of claim 1 , wherein further comprising generating the numeric representation of the first portion of the first item of data is via a base-64 decoding.

8. The method of claim 1 , further comprising:

determining, by the security agent, that the numeric representation of the first portion of the first item of data lacks factors within a predetermined range; and

wherein detecting that an encryption key is in the first item of data is further performed responsive to the determination that the numeric representation of the first portion of the first item of data lacks factors within the predetermined range.

9. The method of claim 1 , wherein the partial factorization of the numeric representation is attempted via one or more integer-factorization algorithms.

10. The method of claim 1 , wherein detecting writing of the first item of data to memory further comprises detecting writing of the first item of data to a transmission buffer of a network interface of the computing device.

11. A system for detecting and mitigating malicious encryption, comprising:

a memory unit of a computing device, the memory unit storing a first item of data; and

a security agent, executed by a processor of a computing device, configured to detect writing of the first item of data to the memory unit, and responsive to the detection:

detecting an encryption key in the first item of data based on the application of one or more of a plurality of tests to the first item of data, wherein the plurality of tests includes:

attempting to decode the first item of data and analyzing the decoded data for the presence of predetermined strings or formats,

examining the entropy of the first item of data,

examining the first item of data to determine whether the first item of data is an RSA modulus by determining if a numeric representation of the first item of data is a composite number,

analyzing the first item of data by attempting at least a partial factorization of the numeric representation; and

responsive to detecting an encryption key in the first item of data based on the application of the one or more of the plurality of tests:

generating an alert indicating a likely malicious encryption attempt, and

taking one or more actions to mitigate the malicious encryption attempt.

12. The system of claim 11 , wherein, prior to applying the one or more of the plurality of tests to the first item of data, determining, by the security agent, if the first item of data matches a predetermined size range.

13. The system of claim 12 , wherein if it is determined that the first item of data matches the predetermined size range, assuming that the first item of data includes an encryption key.

14. The system of claim 12 , wherein if it is determined that the first item of data does not match the predetermined size range, continuing with the application of one or more of the plurality of tests to the first item of data.

15. The method of claim 11 , wherein attempting to decode the first item of data further comprises decoding the first item of data according to a predetermined encryption key encoding system.

16. A method for mitigating malicious encryption, comprising:

detecting, by a security agent executed by a computing device, a likely malicious encryption attempt on the computing device; and

responsive to detecting the likely malicious encryption attempt on the computing device, taking, by the security agent, one or more actions to mitigate the malicious encryption attempt, wherein the one or more actions include:

generating an alert indicating the likely malicious encryption attempt,

preventing write commands to memory of the computing device,

creating one or more backups of data on the computing device,

generating a snapshot of system memory,

searching the one or more backups and generated snapshot for an encryption key,

if an encryption key is found, decrypting any encrypted files stored on the computing device, and

if an encryption key is not found, attempting to calculate an encryption key and using the calculated encryption key to decrypt any encrypted files stored on the computing device.

17. The method of claim 11 , wherein the one or more actions includes preventing the deletion of data on the computing device.

18. The method of claim 11 , wherein the one or more actions includes preventing any encryption threads from finishing.

19. The method of claim 11 , wherein the one or more actions includes throttling processing speeds while presenting the alert to a user.

20. The method of claim 11 , wherein attempting to calculate an encryption key includes calculating factorization of a received moduli.

Assignments (3)
CERTIFICATE OF CONVERSION Recorded Oct 12, 2023
From: CARBONITE, INC.
To: CARBONITE, LLC
Reel/Frame 065222/0303 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Oct 12, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 065222/0310 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2020
From: BAILEY, DANIEL VERNON
To: CARBONITE, INC.
Reel/Frame 053486/0192 →
Continuity (2)
Continuation 15727463 · Oct 6, 2017
Related Publication 20200236126A1 · Jul 23, 2020