IP Library Granted Patent US 11,997,132
Granted Patent B2
US 11,997,132 · App. 17/973,607 · Granted May 28, 2024

System and method for protecting network resources

Inventors: Vladimir Strogov (Moscow, RU); Alexey Dod (Moscow, RU); Valery Chernyakovskiy (Moscow, RU); Serguei Beloussov (Costa Del Sol, SG); Stanislav Protasov (Moscow, RU)
Assignee: Acronis International GmbH
H04L63/145H04L63/0227H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,997,132
App. No.
17/973,607
Granted
May 28, 2024
Kind
B2
Abstract

The present disclosure includes methods and systems for protecting network resources. A method may start, by a processor, copy-on-write snapshotting for modifications to a plurality of files stored on electronic storage. A method may monitor, by the processor, access to objects within a file system associated with the electronic storage for a set of operations. A method may intercept, by the processor, one or more operation of the set of operations for modifying a region of a file in the file system. A method may capture, by the processor, one or more of original contents, modified contents and written contents of the region. A method may end, by the processor, copy-on-write snapshotting. A method may perform malware and/or ransomware analysis on a process performing the modification to the region of the file in the file system.

Claims (46)

1. A method for protecting network resources comprising:

starting, by a processor, copy-on-write snapshotting for modifications to a plurality of files stored on electronic storage;

monitoring, by the processor, access to objects within a file system associated with the electronic storage for a set of operations;

intercepting, by the processor, one or more operation of the set of operations for modifying a region of a file in the file system;

capturing, by the processor, one or more of original contents, modified contents and written contents of the region;

ending, by the processor, copy-on-write snapshotting; and

performing malware and/or ransomware analysis on a process performing the modification to the region of the file in the file system.

2. The method of claim 1 , wherein the set of operations comprise a write operation, a set attribute truncate operation, and a pageout operation.

3. The method of claim 2 , further comprising:

in response to intercepting a write operation, capturing the original contents and modified contents of the region;

in response to intercepting a set attribute operation, capturing the original contents of the region; and

in response to intercepting a pageout operation, capturing the original contents and modified contents.

4. The method of claim 3 , wherein the intercepting is performed using callback functions.

5. The method of claim 4 , wherein the callback functions are KAUTH callbacks.

6. The method of claim 5 , wherein the KAUTH callbacks comprise: WRITE, SETATTR and PAGEOUT.

7. A system for protecting network resources comprising:

a hardware processor configured to:

start copy-on-write snapshotting for modifications to a plurality of files stored on electronic storage;

monitor access to objects within a file system associated with the electronic storage for a set of operations;

intercept one or more operation of the set of operations for modifying a region of a file in the file system;

capture one or more of original contents, modified contents and written contents of the region;

end copy-on-write snapshotting; and

perform malware and/or ransomware analysis on a process performing the modification to the region of the file in the file system.

8. The system of claim 7 , wherein the set of operations comprise a write operation, a set attribute truncate operation, and a pageout operation.

9. The system of claim 8 , wherein the hardware processor is further configured to:

in response to intercepting a write operation, capture the original contents and modified contents of the region;

in response to intercepting a set attribute operation, capture the original contents of the region; and

in response to intercepting a pageout operation, capture the original contents and modified contents.

10. The system of claim 9 , wherein the intercepting is performed using callback functions.

11. The system of claim 10 , wherein the callback functions are KAUTH callbacks.

12. The system of claim 11 , wherein the KAUTH callbacks comprise: WRITE, SETATTR and PAGEOUT.

13. A non-transitory computer readable medium storing thereon computer executable instructions for protecting network resources, including instructions for:

starting copy-on-write snapshotting for modifications to a plurality of files stored on electronic storage;

monitoring access to objects within a file system associated with the electronic storage for a set of operations;

intercepting one or more operation of the set of operations for modifying a region of a file in the file system;

capturing one or more of original contents, modified contents and written contents of the region;

ending copy-on-write snapshotting; and

performing malware and/or ransomware analysis on a process performing the modification to the region of the file in the file system.

14. The non-transitory computer readable medium of claim 13 , wherein the set of operations comprise a write operation, a set attribute truncate operation, and a pageout operation.

15. The non-transitory computer readable medium of claim 14 , further comprising instructions for:

in response to intercepting a write operation, capturing the original contents and modified contents of the region;

in response to intercepting a set attribute operation, capturing the original contents of the region; and

in response to intercepting a pageout operation, capturing the original contents and modified contents.

16. The non-transitory computer readable medium of claim 15 , wherein the intercepting is performed using callback functions.

17. The non-transitory computer readable medium of claim 16 , wherein the callback functions are KAUTH callbacks.

18. The non-transitory computer readable medium of claim 17 , wherein the KAUTH callbacks comprise: WRITE, SETATTR and PAGEOUT.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENTS LISTED BY DELETING PATENT APPLICATION NO. 18388907 FROM SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 66797 FRAME 766. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Nov 13, 2024
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 069594/0136 →
SECURITY INTEREST Recorded Mar 14, 2024
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 066797/0766 →