IP Library Granted Patent US 12,174,952
Granted Patent B2
US 12,174,952 · App. 18/170,421 · Granted Dec 24, 2024

Advanced file modification heuristics

Inventors: Eric Klonowski (Broomfield, CO); Sesha Sailendra Chetlur (Boulder, CO)
G06F21/554G06F21/552G06F21/566G06F21/6218G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,174,952
App. No.
18/170,421
Granted
Dec 24, 2024
Kind
B2
Abstract

Examples of the present disclosure describe systems and methods for providing advanced file modification heuristics. In aspects, software content is selected for monitoring. The monitoring comprises determining when the software content performs file accesses that are followed by read and/or write operations. The read/write operations are analyzed in real-time to determine whether the software content is modifying file content. If the monitoring indicates the software content is modifying accessed files, mathematical calculations are applied to the read-write operations to determine the nature of the modifications. Based on the determined nature of the file modifications, the actions of the software content may be categorized and halted prior to completion; thereby, mitigating malicious cyberattacks and/or unauthorized accesses.

Claims (41)

1. A system comprising:

a processor; and

a non-transitory computer readable media storing instructions that are executable by the processor for:

obtaining monitoring results of monitoring of selected software content, the monitoring results indicating that the selected software content performs accesses of data content followed by input/output (I/O) operations on the data content;

analyzing, in real time, actions of the I/O operations to determine whether the actions of the I/O operations are modifying the data content, wherein the analyzing of the actions excludes any evaluation of the data content on which the I/O operations are performed;

responsive to determining that the actions of the I/O operations are modifying the data content, determining a categorization of the actions of the I/O operations; and

responsive to determining the categorization, determining in real time whether to halt the actions of the I/O operations prior to completion.

2. The system of claim 1 , wherein the instructions are executable by the processor for:

selecting the selected software content for monitoring.

3. The system of claim 1 , wherein the monitoring of the selected software content includes monitoring an event file.

4. The system of claim 1 , wherein the accesses of data content comprise an access of a file, wherein the I/O operations on the data content comprise I/O operations on the accessed file.

5. The system of claim 1 , wherein determining the categorization of the actions of the I/O operations comprises determining whether the actions of the I/O operations comprise data compression or data encryption.

6. The system of claim 1 , wherein the instructions are executable by the processor for:

restoring a previous version of the data content.

7. The system of claim 1 , wherein determining the categorization of the actions of the I/O operations comprises evaluating randomness in accessed data content.

8. A method, comprising:

obtaining monitoring results of monitoring of selected software content, the monitoring results indicating that the selected software content performs accesses of data content followed by input/output (I/O) operations on the data content;

analyzing, in real time, actions of the I/O operations to determine whether the actions of the I/O operations are modifying the data content, wherein the analyzing of the actions excludes any evaluation of the data content on which the I/O operations are performed;

responsive to determining that the actions of the I/O operations are modifying the data content, determining a categorization of the actions of the I/O operations; and

responsive to determining the categorization, determining in real time whether to halt the actions of the I/O operations prior to completion.

9. The method of claim 8 , further comprising:

selecting the selected software content for monitoring.

10. The method of claim 8 , wherein the monitoring of the selected software content includes monitoring an event file.

11. The method of claim 8 , wherein the accesses of data content comprise an access of a file, wherein the I/O operations on the data content comprise I/O operations on the accessed file.

12. The method of claim 8 , wherein determining the categorization of the actions of the I/O operations comprises determining whether the actions of the I/O operations comprise data compression or data encryption.

13. The method of claim 8 , further comprising:

restoring a previous version of the data content.

14. The method of claim 8 , wherein determining the categorization of the actions of the I/O operations comprises evaluating randomness in accessed data content.

15. A non-transitory computer readable medium, comprising instructions for:

obtaining monitoring results of monitoring of selected software content, the monitoring results indicating that the selected software content performs accesses of data content followed by input/output (I/O) operations on the data content;

analyzing, in real time, actions of the I/O operations to determine whether the actions of the I/O operations are modifying the data content, wherein the analyzing of the actions excludes any evaluation of the data content on which the I/O operations are performed;

responsive to determining that the actions of the I/O operations are modifying the data content, determining a categorization of the actions of the I/O operations; and

responsive to determining the categorization, determining in real time whether to halt the actions of the I/O operations prior to completion.

16. The non-transitory computer readable medium of claim 15 , wherein the instructions are for:

selecting the selected software content for monitoring.

17. The non-transitory computer readable medium of claim 15 , wherein the monitoring of the selected software content includes monitoring an event file.

18. The non-transitory computer readable medium of claim 15 , wherein the accesses of data content comprise an access of a file, wherein the I/O operations on the data content comprise I/O operations on the accessed file.

19. The non-transitory computer readable medium of claim 15 , wherein determining the categorization of the actions of the I/O operations comprises determining whether the actions of the I/O operations comprise data compression or data encryption.

20. The non-transitory computer readable medium of claim 15 , wherein the instructions are for:

restoring a previous version of the data content.

21. The non-transitory computer readable medium of claim 15 , wherein determining the categorization of the actions of the I/O operations comprises evaluating randomness in accessed data content.

Assignments (4)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2023
From: KLONOWSKI, ERIC; CHETLUR, SESHA SAILENDRA
To: WEBROOT INC.
Reel/Frame 062810/0671 →
Continuity (3)
Continuation 17119707 · Dec 11, 2020
Continuation 15637455 · Jun 29, 2017
Related Publication 20230195895A1 · Jun 22, 2023