IP Library Granted Patent US 12,339,965
Granted Patent B2
US 12,339,965 · App. 18/147,468 · Granted Jun 24, 2025

Malware detection and content item recovery

Inventors: Ishita Arora (San Francisco, CA); Anton Mityagin (San Francisco, CA); Ray Zhang (San Jose, CA); Sam Keller (Millbrae, CA); Stacey Sern (Edison, NJ)
Assignee: Dropbox, Inc.
G06F21/566G06F8/71G06F21/562G06F21/563G06F21/567G06F21/568G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,339,965
App. No.
18/147,468
Granted
Jun 24, 2025
Kind
B2
Abstract

Disclosed are systems, methods, and non-transitory computer-readable storage media for malware detection and content item recovery. For example, a content management system can receive information describing changes made to content items stored on a user device. The content management system can analyze the information to determine if the described changes are related to malicious software on the user device. When the changes are related to malicious software, the content management system can determine which content items are effected by the malicious software and/or determine when the malicious software first started making changes to the user device. The content management system can recover effected content items associated with the user device by replacing the effected versions of the content items with versions of the content items that existed immediately before the malicious software started making changes to the user device.

Claims (56)

1. A method comprising:

identifying, by a content management system, a change set including change entries describing changes made at a client device to content contained in content items;

analyze, by the content management system, the change set based on one or more malware detection rules;

determining, by the content management system, a number of the change entries in the change set that satisfy at least one of the one or more malware detection rules;

based on the number of the change entries that satisfy at least one of the one or more malware detection rules, initiating, by the content management system, a scan of other change sets associated with the client device to determine whether the client device has malicious software;

during the scan of the other change sets associated with the client device, confirming, by the content management system, that the client device has the malicious software;

identifying, by the content management system, a target content item affected by the malicious software;

identifying, by the content management system, a first change entry in the other change sets corresponding to a first indication of the malicious software affecting the target content item; and

restoring, by the content management system, the target content item to a prior version predating the first change entry.

2. The method of claim 1 , wherein the content management system is configured to apply the described changes to original versions of the respective content items to generate current versions of the respective content items.

3. The method of claim 1 , further comprising:

responsive to confirming that the client device has the malicious software during the scan of the other change sets, suspending synchronization of content items between the content management system and the client device.

4. The method of claim 1 , wherein restoring, by the content management system, the target content item to the prior version predating the first change entry comprises:

identifying, by the content management system, a target change set corresponding to the target content item;

identifying, by the content management system, a first subset of change entries predating the first change entry and a second subset of change entries succeeding the first change entry; and

applying, by the content management system, the first subset of change entries to an original version of the target content item to restore the target content item to the prior version of the target content item predating the first change entry.

5. The method of claim 1 , further comprising:

determining, by the content management system, that the malicious software has been removed from the client device; and

responsive to determining that the malicious software has been removed, resuming, by the content management system, synchronization of content items between the content management system and the client device.

6. A non-transitory computer readable medium comprising one or more sequences of instructions, which, when executed by one or more processors, causes a computing system to perform operations comprising:

identifying, by a content management system, a change set including change entries describing changes made at a client device to content contained in content items;

analyzing, by the content management system, the change set based on one or more malware detection rules;

determining, by the content management system, a number of the change entries in the change set that satisfy at least one of the one or more malware detection rules;

based on the number of the change entries that satisfy at least one of the one or more malware detection rules, initiating, by the content management system, a remedial action to remove malicious software from the client device;

during the remedial action to remove malicious software from the client device, confirming, by the content management system, that the client device has the malicious software;

identifying, by the content management system, a target content item affected by the malicious software;

identifying, by the content management system, a first change entry in other change sets corresponding to a first indication of the malicious software affecting the target content item; and

restoring, by the content management system, the target content item to a prior version predating the first change entry.

7. The non-transitory computer readable medium of claim 6 , wherein the content management system is configured to apply the described changes to original versions of the respective content items to generate current versions of the respective content items.

8. The non-transitory computer readable medium of claim 6 , wherein initiating, by the content management system, the remedial action to remove the malicious software from the client device comprises:

initiating a scan of other change sets associated with the client device to determine whether the client device has the malicious software.

9. The non-transitory computer readable medium of claim 6 , wherein restoring, by the content management system, the target content item to the prior version predating the first change entry comprises:

identifying, by the content management system, a target change set corresponding to the target content item;

identifying, by the content management system, a first subset of change entries predating the first change entry and a second subset of change entries succeeding the first change entry; and

applying, by the content management system, the first subset of change entries to an original version of the target content item to restore the target content item to the prior version of the target content item predating the first change entry.

10. The non-transitory computer readable medium of claim 6 , wherein initiating, by the content management system, the remedial action to remove the malicious software from the client device comprises:

suspending synchronization of content items between the content management system and the client device.

11. The non-transitory computer readable medium of claim 10 , further comprising: determining, by the content management system, that the malicious software has been removed from the client device; and

responsive to determining that the malicious software has been removed, resuming, by the content management system, synchronization of content items between the content management system and the client device.

12. A content management system comprising:

one or more processors; and

a memory having programming instructions stored thereon, which, when executed by the one or more processors, causes the content management system to perform operations comprising:

identifying, by the content management system, a change set including change entries describing changes made at a client device to content contained in content items;

analyzing, by the content management system, the change set based on one or more malware detection rules;

determining, by the content management system, a number of the change entries in the change set that satisfy at least one of the one or more malware detection rules; and

based on the number of the change entries that satisfy at least one of the one or more malware detection rules, initiating, by the content management system, a scan of other change sets associated with the client device to determine whether the client device has malicious software;

during the scan of the other change sets associated with the client device, confirming, by the content management system, that the client device has the malicious software;

identifying, by the content management system, a target content item affected by the malicious software;

identifying, by the content management system, a first change entry in the other change sets corresponding to a first indication of the malicious software affecting the target content item; and

restoring, by the content management system, the target content item to a prior version predating the first change entry.

13. The content management system of claim 12 , further comprising:

responsive to confirming that the client device has the malicious software during the scan of the other change sets, suspending synchronization of content items between the content management system and the client device.

14. The content management system of claim 12 , wherein restoring, by the content management system, the target content item to the prior version predating the first change entry comprises:

identifying, by the content management system, a target change set corresponding to the target content item;

identifying, by the content management system, a first subset of change entries predating the first change entry and a second subset of change entries succeeding the first change entry; and

applying, by the content management system, the first subset of change entries to an original version of the target content item to restore the target content item to the prior version of the target content item predating the first change entry.

Assignments (2)
SECURITY INTEREST Recorded Dec 12, 2024
From: DROPBOX, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069604/0611 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2022
From: ARORA, ISHITA; MITYAGIN, ANTON; ZHANG, RAY; KELLER, SAM; SERN, STACEY
To: DROPBOX, INC.
Reel/Frame 062227/0477 →
Continuity (2)
Continuation 15394385 · Dec 29, 2016
Related Publication 20230139473A1 · May 4, 2023
References Cited (26)
US 7934262B1 · Natanzon et al. · 2011 [cited by applicant]
US 7962956B1 · Liao et al. · 2011 [cited by applicant]
US 8484737B1 · Swift et al. · 2013 [cited by applicant]
US 8689209B2 · Meller et al. · 2014 [cited by applicant]
US 9317686B1 · Ye et al. · 2016 [cited by applicant]
US 10715533B2 · Iwanir · 2020 [cited by examiner]
US 11580221B2 · Arora · 2023 [cited by examiner]
US 20060041942A1 · Edwards · 2006 [cited by applicant]
US 20070260643A1 · Borden et al. · 2007 [cited by applicant]
US 20130198141A1 · Khan et al. · 2013 [cited by applicant]
US 20170223031A1 · Gu et al. · 2017 [cited by applicant]
US 20170308698A1 · Mityagin · 2017 [cited by examiner]
US 20180034835A1 · Iwanir et al. · 2018 [cited by applicant]
JP 2002351723A · 2002 [cited by applicant]
JP 2004013607A · 2004 [cited by applicant]
JP 2019505919A · 2019 [cited by applicant]
Advisory Action from U.S. Appl. No. 15/394,385, mailed Dec. 12, 2019, 2 pages. [cited by applicant]
Communication Pursuant to Rules 161(1) and 162 EPC for European Application No. 17805065.4 malled on Aug. 6, 2019, 3 pages. [cited by applicant]
Communication under Rule 71(3) EPC of Intention to Grant for European Application No. 17805065.4 mailed on Jun. 8, 2020, 68 pages. [cited by applicant]
Final Office Action from U.S. Appl. No. 15/394,385, mailed Sep. 23, 2020, 10 pages. [cited by applicant]
Final Office Action from U.S. Appl. No. 15/394,385, mailed Sep. 25, 2019, 8 pages. [cited by applicant]
International Search Report and Written Opinion for PCT Application No. PCT/US2017/061207 dated Jan. 24, 2018, 8 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 15/394,385, mailed Mar. 18, 2020, 8 pages. [cited by applicant]
Notice of Acceptance for Australian Application No. 2017366900 mailed on Nov. 26, 2019, 3 pages. [cited by applicant]
Notice of Allowance from U.S. Appl. No. 15/394,385, mailed Oct. 5, 2022, 5 pages. [cited by applicant]
Notification of Reasons for Refusal for Japanese Application No. 2019-508898 mailed on Jun. 29, 2020, 9 pages. [cited by applicant]