IP Library Granted Patent US 12,306,945
Granted Patent B2
US 12,306,945 · App. 17/979,004 · Granted May 20, 2025

Advanced ransomware detection

Inventors: Erez Levy (Petach Tikva, IL); Or Chechik (Rishon Lezion, IL); Liav Zigelbaum (Holon, IL); Eldar Aharoni (Holon, IL)
Assignee: Palo Alto Networks Israel Services Ltd
G06F21/566G06F21/554G06F21/565G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,306,945
App. No.
17/979,004
Granted
May 20, 2025
Kind
B2
Abstract

Methods, apparatuses and computer program products implement embodiments of the present invention that include protecting a computer system coupled to a storage device by detecting an executing process that performed a specific type of modification to a number of files stored on the storage device. A processor compares the detected number to a specified threshold and initiates, on the executing process, a preventive action in response to determining that the detected number exceeds the specified threshold.

Claims (32)

1. A method for protecting a computer system coupled to a storage device, comprising:

specifying one or more original file extensions that are applied in naming files that store documents, spreadsheets, or images;

detecting an executing process that performed a specific type of modification to a number of files stored on the storage device, wherein the specific type of modification includes renaming respective file extensions of the files having one of the specified original file extensions from the one of the specified original file extensions to a new file extension;

comparing, by a processor, the detected number of files to a specified threshold; and

initiating, on the executing process, a preventive action in response to determining that the detected number exceeds the specified threshold,

wherein initiating the preventive action comprises identifying a causality chain for the executing process by analyzing a context of a thread of the executing process that was found to be malicious, applying the analyzed context to identify additional malicious threads in the causality chain, and applying the preventive action to all the identified threads in the causality chain.

2. The method according to claim 1 , wherein initiating the preventive a comprises terminating the executing process and the threads in the causality chain.

3. The method according to claim 1 , wherein the specific type of modification comprises renaming the file extensions of the files to identical file extensions.

4. The method according to claim 1 , wherein the specific type of modification comprises encrypting the files.

5. The method according to claim 4 , wherein detecting the executing process comprises parsing headers of the files to detect that the files have been encrypted.

6. An apparatus for protecting a computer system, comprising:

a storage device configured to store a plurality of files;

a memory; and

a processor configured:

to receive one or more specified original file extensions that are applied in naming files that store documents, spreadsheets, or images,

to detect, in the memory, an executing process that performed a specific type of modification to a number of files stored on the storage device, wherein the specific type of modification includes renaming respective file extensions of the files having one of the specified original file extensions from the one of the specified original file extensions to a new file extension,

to compare, the detected number of files to a specified threshold; and

to initiate, on the executing process, a preventive action in response to determining that the detected number exceeds the specified threshold,

wherein the processor is configured to initiate the preventive action by identifying a causality chain for the executing process by analyzing a context of a thread of the executing process that was found to be malicious, applying the analyzed context to identify additional malicious threads in the causality chain, and applying the preventive action to all the identified threads in the causality chain.

7. The apparatus according to claim 6 , wherein the preventive action comprises terminating the executing process and the threads in the causality chain.

8. The apparatus according to claim 6 , wherein the specific type of modification comprises renaming the file extensions of the files to identical file extensions.

9. The apparatus according to claim 6 , wherein the specific type of modification comprises encrypting the files.

10. The apparatus according to claim 9 , wherein the processor is configured to detect the executing process by parsing headers of the files to detect that the files have been encrypted.

11. A computer software product for protecting a computing system, the product comprising a non-transitory computer-readable medium, in which program instructions are stored, which instructions, when read by a computer, cause the computer:

to receive one or more specified original file extensions that are applied in naming files that store documents, spreadsheets, or images;

to detect an executing process that performed a specific type of modification to a number of files stored on a storage device, wherein the specific type of modification includes renaming respective file extensions of the files having one of the specified original file extensions from the one of the specified original file extensions to a new file extension;

to compare the detected number of files to a specified threshold; and

to initiate, on the executing process, a preventive action in response to determining that the detected number exceeds the specified threshold,

wherein the instructions cause the computer to initiate the preventive action by identifying a causality chain for the executing process by analyzing a context of a thread of the executing process that was found to be malicious, applying the analyzed context to identify additional malicious threads in the causality chain, and applying the preventive action to all the identified threads in the causality chain.

12. The product according to claim 11 , wherein the specific type of modification comprises renaming the file extensions of the files to identical file extensions.

13. The product according to claim 11 , wherein the specific type of modification comprises encrypting the files.

14. The product according to claim 13 , wherein the instructions cause the computer to detect the executing process by parsing headers of the files to detect that the files have been encrypted.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
To: PALO ALTO NETWORKS INC.
Reel/Frame 068823/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2022
From: LEVY, EREZ; CHECHIK, OR; ZIGELBAUM, LIAV; AHARONI, ELDAR
To: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
Reel/Frame 061624/0608 →
Continuity (2)
Division 16939013 · Jul 26, 2020
Related Publication 20230084691A1 · Mar 16, 2023
References Cited (38)
US 8205257B1 · Satish · 2012 [cited by examiner]
US 8646076B1 · Lim et al. · 2014 [cited by applicant]
US 9659182B1 · Roundy et al. · 2017 [cited by applicant]
US 10860718B2 · Seetharamaiah et al. · 2020 [cited by applicant]
US 11216559B1 · Gu et al. · 2022 [cited by applicant]
US 11409868B2 · Reid et al. · 2022 [cited by applicant]
US 11616810B2 · Hansen · 2023 [cited by examiner]
US 11934801B2 · Rahmani et al. · 2024 [cited by applicant]
US 20040049693A1 · Douglas · 2004 [cited by applicant]
US 20150213260A1 · Park · 2015 [cited by applicant]
US 20150215335A1 · Giuliani et al. · 2015 [cited by applicant]
US 20160055337A1 · El-Moussa · 2016 [cited by applicant]
US 20160232347A1 · Badishi · 2016 [cited by applicant]
US 20180115577A1 · Shukla · 2018 [cited by examiner]
US 20180189490A1 · Maciejak · 2018 [cited by examiner]
US 20190109870A1 · Bedhapudi · 2019 [cited by examiner]
US 20190121978A1 · Kraemer · 2019 [cited by examiner]
US 20190138727A1 · Dontov · 2019 [cited by examiner]
US 20190318090A1 · Sandoval et al. · 2019 [cited by applicant]
US 20200342100A1 · Goldstein et al. · 2020 [cited by applicant]
US 20210152595A1 · Hansen · 2021 [cited by examiner]
US 20220284095A1 · Ahmed · 2022 [cited by applicant]
WO 2008056944A1 · 2008 [cited by applicant]
WO WO2022109664A1 · 2022 [cited by examiner]
WO 2022248920A1 · 2022 [cited by applicant]
AU Application # 2021319159 Office Action dated May 25, 2023. [cited by applicant]
Cristalli et al., “Trusted Execution Path for Protecting Java Applications Against Deserialization of Untrusted Data,” Proceedings, International Conference, ICB 2007—Advances in Biometrics, Springer Nature Switzerland … [cited by applicant]
Wikipedia, “Java Remote Method Invocation,” pp. 1-4, last edited Dec. 26, 2020. [cited by applicant]
Wikipedia, “Metasploit Project,” pp. 1-7, last edited Jun. 7, 2022. [cited by applicant]
Cynet, “Cobalt Strike: White Hat Hacker Powerhouse in the Wrong Hands,” pp. 1-6, last updated Jun. 27, 2022, as downloaded from https://web.archive.org/web/20220627023847/https://www.cynet.com/network-attacks/cobalt-str… [cited by applicant]
Shah, “Analyzing CVE-2017-9791: Apache StrutsVulnerability Can Lead to Remote Code Execution,”, McAfee, pp. 1-7, Jul. 19, 2017, as downloaded from https://www.mcafee.com/blogs/other-blogs/mcafee-labs/analyzing-cve-2017-… [cited by applicant]
Frohoff, “A Proof-of-Concept Tool for Generating Payloads that Exploit unsafe Java Object Deserialization,” github.com, pp. 1-3, Jul. 16, 2022, as downloaded from https://github.com/frohoff/ysoserial. [cited by applicant]
Wikipedia, “Return-oriented Programming,” pp. 1-6, last edited Mar. 31, 2020, as downloaded from https://web.archive.org/web/20200403142512/https://en.wikipedia.org/wiki/Return-oriented_programming. [cited by applicant]
McNab, “Network Security Assessment”, 2nd edition, Chapter 16 (Exploitation Frameworks), pp. 393-414, Oct. 2007. [cited by applicant]
Balakrishnan, “Understanding Java Agents,” Tutorial, pp. 1-8, Jul. 6, 2020, as downloaded from https://dzone.com/articles/java-agent-1. [cited by applicant]
Wikipedia, “Java Virtual Machine,” pp. 1-8, last update Oct. 25, 2022. [cited by applicant]
International Application # PCT/IB2024/051414 Search Report dated Apr. 17, 2024. [cited by applicant]
U.S. Pat. No. 118886585 B1, Jan. 30, 2024, Davis. [cited by applicant]