IP Library Granted Patent US 11,636,204
Granted Patent B2
US 11,636,204 · App. 17/005,478 · Granted Apr 25, 2023

Systems and methods for countering removal of digital forensics information by malicious software

Inventors: Vladimir Strogov (Moscow, RU); Oleg Ishanov (Moscow, RU); Alexey Dod (Moscow, RU); Serguei Beloussov (Costa del Sol, SG); Stanislav Protasov (Moscow, RU)
Assignee: Acronis International GmbH
G06F21/566G06F21/554G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,636,204
App. No.
17/005,478
Granted
Apr 25, 2023
Kind
B2
Abstract

Disclosed herein are systems and methods for preventing anti-forensics actions. In one exemplary aspect, a method may identify a suspicious object from a plurality of objects on a computing device and monitor actions performed by the suspicious object. The method may intercept a first command by the suspicious object to create and/or modify a digital artifact on the computing device and subsequent to intercepting the first command, intercept a second command by the suspicious object to delete at least one of the suspicious object and the digital artifact. In response to intercepting both the first command to create and/or modify the digital artifact and the second command to delete at least one of the suspicious object and the digital artifact, the method may block the second command, and may store the suspicious object and the digital artifact in a digital repository.

Claims (80)

1. A method for preventing anti-forensics actions, the method comprising:

monitoring, from a plurality of objects on a computing device, a plurality of suspicious objects for a threshold period of time;

identifying a subset of the suspicious objects that have not performed, over the threshold period of time, actions that degrade a performance of the computing device or compromise user privacy on the computing device;

determining that the subset of the suspicious objects are not suspicious;

ceasing monitoring of the subset;

identifying a suspicious object from the plurality of suspicious objects not in the subset;

monitoring actions performed by the suspicious object, wherein the actions comprise commands and requests originating from the suspicious object;

intercepting a first command by the suspicious object to create and/or modify a digital artifact on the computing device;

subsequent to intercepting the first command, intercepting a second command by the suspicious object to delete at least one of the suspicious object and the digital artifact;

in response to intercepting both the first command to create and/or modify the digital artifact and the second command to delete at least one of the suspicious object and the digital artifact:

blocking the second command; and

storing the suspicious object and the digital artifact in a digital repository.

2. The method of claim 1 , further comprising:

storing contents of the digital repository with a backup of system and user data on the computing device.

3. The method of claim 1 , further comprising:

storing respective locations of the suspicious object and the digital artifact in the digital repository.

4. The method of claim 1 , further comprising:

storing a record of all monitored actions of the suspicious object in the digital repository.

5. The method of claim 1 , wherein identifying the suspicious object from the plurality of objects on the computing device comprises:

for each respective object of the plurality of objects:

extracting a digital signature of the respective object;

determining whether the digital signature of the respective object matches any trusted digital signature in a whitelist of digital signatures; and

in response to determining that no match exists, identifying the respective object as the suspicious object.

6. The method of claim 1 , further comprising:

detecting that the digital artifact has created and/or modified another digital artifact on the computing device;

in response to intercepting a third command by one of the digital artifact and the another digital artifact to delete the suspicious object:

blocking the third command; and

storing the suspicious object, the digital artifact, and the another digital artifact in the digital repository.

7. A system for preventing anti-forensics actions, the system comprising:

a hardware processor configured to:

monitor, from a plurality of objects on a computing device, a plurality of suspicious objects for a threshold period of time;

identify a subset of the suspicious objects that have not performed, over the threshold period of time, actions that degrade a performance of the computing device or compromise user privacy on the computing device;

determine that the subset of the suspicious objects are not suspicious;

cease monitoring of the subset;

identify a suspicious object from the plurality of suspicious objects not in the subset;

monitor actions performed by the suspicious object, wherein the actions comprise commands and requests originating from the suspicious object;

intercept a first command by the suspicious object to create and/or modify a digital artifact on the computing device;

subsequent to intercepting the first command, intercept a second command by the suspicious object to delete at least one of the suspicious object and the digital artifact;

in response to intercepting both the first command to create and/or modify the digital artifact and the second command to delete at least one of the suspicious object and the digital artifact:

block the second command; and

store the suspicious object and the digital artifact in a digital repository.

8. The system of claim 7 , wherein the hardware processor is further configured to:

store contents of the digital repository with a backup of system and user data on the computing device.

9. The system of claim 7 , wherein the hardware processor is further configured to:

store respective locations of the suspicious object and the digital artifact in the digital repository.

10. The system of claim 7 , wherein the hardware processor is further configured to:

store a record of all monitored actions of the suspicious object in the digital repository.

11. The system of claim 7 , wherein the hardware processor is further configured to identify the suspicious object from the plurality of objects on the computing device by:

for each respective object of the plurality of objects:

extracting a digital signature of the respective object;

determining whether the digital signature of the respective object matches any trusted digital signature in a whitelist of digital signatures; and

in response to determining that no match exists, identifying the respective object as the suspicious object.

12. The system of claim 7 , wherein the hardware processor is further configured to:

detect that the digital artifact has created and/or modified another digital artifact on the computing device;

in response to intercepting a third command by one of the digital artifact and the another digital artifact to delete the suspicious object:

block the third command; and

store the suspicious object, the digital artifact, and the another digital artifact in the digital repository.

13. A non-transitory computer readable medium storing thereon computer executable instructions for preventing anti-forensics actions, comprising instructions for:

monitoring, from a plurality of objects on a computing device, a plurality of suspicious objects for a threshold period of time;

identifying a subset of the suspicious objects that have not performed, over the threshold period of time, actions that degrade a performance of the computing device or compromise user privacy on the computing device;

determining that the subset of the suspicious objects are not suspicious;

ceasing monitoring of the subset;

identifying a suspicious object from the plurality of suspicious objects not in the subset;

monitoring actions performed by the suspicious object, wherein the actions comprise commands and requests originating from the suspicious object;

intercepting a first command by the suspicious object to create and/or modify a digital artifact on the computing device;

subsequent to intercepting the first command, intercepting a second command by the suspicious object to delete at least one of the suspicious object and the digital artifact;

in response to intercepting both the first command to create and/or modify the digital artifact and the second command to delete at least one of the suspicious object and the digital artifact:

blocking the second command; and

storing the suspicious object and the digital artifact in a digital repository.

14. The non-transitory computer readable medium of claim 13 , further comprising instructions for:

storing contents of the digital repository with a backup of system and user data on the computing device.

15. The non-transitory computer readable medium of claim 13 , further comprising instructions for:

storing respective locations of the suspicious object and the digital artifact in the digital repository.

16. The non-transitory computer readable medium of claim 13 , further comprising instructions for:

storing a record of all monitored actions of the suspicious object in the digital repository.

17. The non-transitory computer readable medium of claim 13 , wherein the instructions for identifying the suspicious object from the plurality of objects on the computing device further comprises instructions for:

for each respective object of the plurality of objects:

extracting a digital signature of the respective object;

determining whether the digital signature of the respective object matches any trusted digital signature in a whitelist of digital signatures; and

in response to determining that no match exists, identifying the respective object as the suspicious object.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENTS LISTED BY DELETING PATENT APPLICATION NO. 18388907 FROM SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 66797 FRAME 766. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Nov 13, 2024
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 069594/0136 →
SECURITY INTEREST Recorded Mar 14, 2024
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 066797/0766 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2023
From: STROGOV, VLADIMIR; ISHANOV, OLEG; DOD, ALEXEY; BELOUSSOV, SERGUEI; PROTASOV, STANISLAV
To: ACRONIS INTERNATIONAL GMBH
Reel/Frame 063041/0414 →
REAFFIRMATION AGREEMENT Recorded Aug 28, 2022
From: ACRONIS AG; ACRONIS INTERNATIONAL GMBH; ACRONIS SCS, INC.; ACRONIS, INC.; GROUPLOGIC, INC.; NSCALED INC.; ACRONIS MANAGEMENT LLC; 5NINE SOFTWARE, INC.; ACRONIS GERMANY GMBH; ACRONIS NETHERLANDS B.V.; ACRONIS BULGARIA EOOD; DEVICELOCK, INC.; DEVLOCKCORP LTD; ACRONIS INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 061330/0818 →