IP Library › Granted Patent US 12,505,214
Granted Patent B2
US 12,505,214 · App. 18/046,622 · Granted Dec 23, 2025

Cyber recovery forensic kit—application-based granularity

Inventors: Ofir Ezrielev (Be'er Sheba, IL); Jehuda Shemer (Kfar Saba, IL); Amihai Savir (Newton, MA)
Assignee: Dell Products L.P.
G06F21/566G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,214
App. No.
18/046,622
Filed
Oct 14, 2022
Granted
Dec 23, 2025
Kind
B2
Art Unit
2434
USPC
726/24
Abstract

A forensic kit with a granular infected backup. A forensic engine may evaluate a production system that is infected with malware or other corruption and generate a forensic kit. The forensic kit may include copies of components of the production system that are infected or that are sufficiently related to infected components. The forensic kit may be provided to investigators.

Claims (28)

1 . A method comprising:

detecting malware in a production system that includes components;

identifying infected components from among the components of the production system;

identifying related components of the production system from among the components of the production system that are related to the infected components, wherein the related components may be infected with the malware; and

generating a granular infected backup that includes only the infected components and the related components and the malware, and not components of the production system that are both not infected components and not related components.

2 . The method of claim 1 , further comprising triggering a forensic operation upon detecting the malware, wherein the forensic operation is configured to generate the granular infected backup.

3 . The method of claim 1 , wherein the granular infected backup comprises a snapshot of the infected components and the related components.

4 . The method of claim 1 , wherein the components include servers, applications, data, storage devices, storage systems, active directory, networking, or combinations thereof.

5 . The method of claim 1 , further comprising identifying the infected components using a first model that is trained to detect the malware or other corruptions in the components.

6 . The method of claim 5 , further comprising generating a graph representing the components of the production system.

7 . The method of claim 6 , further comprising identifying the infected components in the graph.

8 . The method of claim 7 , further comprising inputting the graph that identifies the infected components into a second model trained to identify the related components to the infected components.

9 . The method of claim 8 , further comprising including the granular infected component in a forensic kit.

10 . The method of claim 9 , further comprising performing a forensic analysis based on the forensic kit and wherein the related components include attack vectors of the malware that do not appear to be infected.

11 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

detecting malware in a production system that includes components;

identifying infected components from among the components of the production system;

identifying related components of the production system from among the components of the production system that are related to the infected components, wherein the related components may be infected with the malware; and

generating a granular infected backup that includes only the infected components and the related components and the malware, and not components of the production system that are both not infected components and not related components.

12 . The non-transitory storage medium of claim 11 , further comprising triggering a forensic operation upon detecting the malware, wherein the forensic operation is configured to generate the granular infected backup.

13 . The non-transitory storage medium of claim 11 , wherein the granular infected backup comprises a snapshot of the infected components and the related components.

14 . The non-transitory storage medium of claim 11 , wherein the components include servers, applications, data, storage devices, storage systems, active directory, networking, or combinations thereof.

15 . The non-transitory storage medium of claim 11 , further comprising identifying the infected components using a first model that is trained to detect the malware or other corruptions in the components.

16 . The non-transitory storage medium of claim 15 , further comprising generating a graph representing the components of the production system.

17 . The non-transitory storage medium of claim 16 , further comprising identifying the infected components in the graph.

18 . The non-transitory storage medium of claim 17 , further comprising inputting the graph that identifies the infected components into a second model trained to identify the related components to the infected components.

19 . The non-transitory storage medium of claim 18 , further comprising including the granular infected component in a forensic kit.

20 . The non-transitory storage medium of claim 19 , further comprising performing a forensic analysis based on the forensic kit and wherein the related components include attack vectors of the malware that do not appear to be infected.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2022
From: EZRIELEV, OFIR; SHEMER, JEHUDA; SAVIR, AMIHAI
To: DELL PRODUCTS L.P.
Reel/Frame 061425/0991 →
Continuity (1)
Related Publication 20240126879A1 · Apr 18, 2024
References Cited (35)
US 5398196A · Chambers · 1995 [cited by applicant]
US 9009829B2 · Stolfo et al. · 2015 [cited by applicant]
US 10169585B1 · Pilipenko et al. · 2019 [cited by applicant]
US 10878084B1 · Voss et al. · 2020 [cited by applicant]
US 10885191B1 · Gupta · 2021 [cited by examiner]
US 20160080414A1 · Kolton et al. · 2016 [cited by applicant]
US 20160132351A1 · Kashyap et al. · 2016 [cited by applicant]
US 20170118241A1 · Call et al. · 2017 [cited by applicant]
US 20170237771A1 · Miroshnikov et al. · 2017 [cited by applicant]
US 20180114020A1 · Hirschberg et al. · 2018 [cited by applicant]
US 20180165451A1 · Kawakita · 2018 [cited by applicant]
US 20180167403A1 · Smith · 2018 [cited by applicant]
US 20200210575A1 · Huang et al. · 2020 [cited by applicant]
US 20210067553A1 · Ries et al. · 2021 [cited by applicant]
US 20210124826A1 · Matsuda · 2021 [cited by examiner]
US 20210157913A1 · Fralick et al. · 2021 [cited by applicant]
US 20210176257A1 · Yavo et al. · 2021 [cited by applicant]
US 20210209225A1 · Ghosh et al. · 2021 [cited by applicant]
US 20210243226A1 · El et al. · 2021 [cited by applicant]
US 20210336970A1 · Woo · 2021 [cited by applicant]
US 20210349748A1 · Dunfey · 2021 [cited by examiner]
US 20220100855A1 · Kumar et al. · 2022 [cited by applicant]
US 20220398315A1 · Young et al. · 2022 [cited by applicant]
US 20230009355A1 · Challener · 2023 [cited by applicant]
US 20230239323A1 · Seletskiy et al. · 2023 [cited by applicant]
US 20230254331A1 · Wright · 2023 [cited by applicant]
US 20230396646A1 · Wang · 2023 [cited by examiner]
US 20240086525A1 · Orazio · 2024 [cited by examiner]
US 20240111865A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240111866A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240111867A1 · Ezrielev et al. · 2024 [cited by applicant]
WO WO2018038718A1 · 2018 [cited by examiner]
Cybersecurity: Past, Present, and Future (Year: 2022). [cited by applicant]
IBM Security Solutions Architecture for Network, Server and Endpoint (Year: 2011). [cited by applicant]
Alhaidari et al. “ZeVigilante: Detecting Zero-Day Malware Using Machine Learning and Sandboxing Analysis Techniques” (Year: 2022). [cited by applicant]