IP Library Granted Patent US 12,470,595
Granted Patent B2
US 12,470,595 · App. 18/301,145 · Granted Nov 11, 2025

Cloud ransomware protection

Inventors: Adam S. Hyder (Cupertino, CA); Raghuram Sri Sivalanka (San Ramon, CA); Atanu Podder (Dublin, CA); Thomas R. Gissel (Apex, NC); Brian P. Morehead (Manteca, CA)
Assignee: Malwarebytes Corporate Holdco Inc.
H04L63/1466G06F21/604G06F21/6218H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,595
App. No.
18/301,145
Granted
Nov 11, 2025
Kind
B2
Abstract

A newly created or modified object is sent to a networked local or remote server for analysis. While the object is being analyzed for vulnerabilities, the object is locked and made inaccessible to users, devices, and networks. If the object is identified as malicious, it may be marked for review, deleted, placed in quarantine, or have its permissions changed so that it cannot cause harm by propagating through the environment. Conversely, if the object is identified as safe, the risk of ransomware attacks may also be mitigated by replicating the object across multiple cloud storage platforms.

Claims (66)

1 . A non-transitory computer-readable medium including stored instructions, the instructions, when executed by a computing system, causing the computing system to perform operations comprising:

obtaining scan results indicating a cloud storage object from a cloud storage platform is safe;

obtaining attributes of the cloud storage object;

determining, based on the attributes of the cloud storage object, to secure the cloud storage object against ransomware attacks, wherein determining to secure the cloud storage object against ransomware attacks comprises:

calculating a significance score of the cloud storage object using the attributes of the cloud storage object;

comparing the significance score to a threshold; and

determining to secure the cloud storage object against ransomware attacks responsive to the significance score exceeding the threshold; and

responsive to determining to secure the cloud storage object, replicating the cloud storage object to one or more additional cloud storage platforms.

2 . The non-transitory computer-readable medium of claim 1 , wherein obtaining the scan results comprises:

downloading a copy of the cloud storage object from the cloud storage platform; and

scanning the copy of the cloud storage object using a platform-agnostic scanner to generate the scan results.

3 . The non-transitory computer-readable medium of claim 1 , wherein the attributes of the cloud storage object include one or more of a size, frequency of access, total number of accesses, time since last use, frequency of edits, source, or storage location.

4 . The non-transitory computer-readable medium of claim 1 , wherein determining to secure the cloud storage object against ransomware attacks comprises:

classifying the cloud storage object into a significance category of a plurality of significance categories using the attributes of the cloud storage object; and

determining to secure the cloud storage object against ransomware attacks based on the significance category.

5 . The non-transitory computer-readable medium of claim 4 , wherein the cloud storage object is replicated to a greater number of additional cloud storage platforms than a second cloud storage object that is classified into a lower significance category than the significance category of the cloud storage object.

6 . The non-transitory computer-readable medium of claim 1 , wherein replicating the cloud storage object to one or more additional cloud storage platforms comprises storing a copy of the cloud storage object in all available cloud storage platforms.

7 . The non-transitory computer-readable medium of claim 1 , wherein the operations further comprise:

receiving, from the cloud storage platform, an event identifying the cloud storage object;

determining, using the event, to scan the cloud storage object;

responsive to determining to scan the cloud storage object, downloading a copy of the cloud storage object from the cloud storage platform;

scanning the copy of the cloud storage object using a platform-agnostic scanner to generate the scan results; and

providing instructions to the cloud storage platform to unlock the cloud storage object responsive to the scan results indicating that the cloud storage object is safe.

8 . A method comprising:

obtaining scan results indicating a cloud storage object from a cloud storage platform is safe;

obtaining attributes of the cloud storage object;

determining, based on the attributes of the cloud storage object, to secure the cloud storage object against ransomware attacks, wherein determining to secure the cloud storage object against ransomware attacks comprises:

calculating a significance score of the cloud storage object using the attributes of the cloud storage object;

comparing the significance score to a threshold; and

determining to secure the cloud storage object against ransomware attacks responsive to the significance score exceeding the threshold; and

responsive to determining to secure the cloud storage object, replicating the cloud storage object to one or more additional cloud storage platforms.

9 . The method of claim 8 , wherein obtaining the scan results comprises:

downloading a copy of the cloud storage object from the cloud storage platform; and

scanning the copy of the cloud storage object using a platform-agnostic scanner to generate the scan results.

10 . The method of claim 8 , wherein the attributes of the cloud storage object include one or more of a size, frequency of access, total number of accesses, time since last use, frequency of edits, source, or storage location.

11 . The method of claim 8 , wherein determining to secure the cloud storage object against ransomware attacks comprises:

classifying the cloud storage object into a significance category of a plurality of significance categories using the attributes of the cloud storage object; and

determining to secure the cloud storage object against ransomware attacks based on the significance category.

12 . The method of claim 11 , wherein the cloud storage object is replicated to a greater number of additional cloud storage platforms than a second cloud storage object that is classified into a lower significance category than the significance category of the cloud storage object.

13 . The method of claim 8 , wherein replicating the cloud storage object to one or more additional cloud storage platforms comprises storing a copy of the cloud storage object in all available cloud storage platforms.

14 . The method of claim 8 , further comprising:

receiving, from the cloud storage platform, an event identifying the cloud storage object;

determining, using the event, to scan the cloud storage object;

responsive to determining to scan the cloud storage object, downloading a copy of the cloud storage object from the cloud storage platform;

scanning the copy of the cloud storage object using a platform-agnostic scanner to generate the scan results; and

providing instructions to the cloud storage platform to unlock the cloud storage object responsive to the scan results indicating that the cloud storage object is safe.

15 . A cloud storage security system comprising:

a processor; and

a non-transitory computer-readable medium including instructions that, when executed by the processor, cause the cloud storage security system to perform operations comprising:

obtaining scan results indicating a cloud storage object from a cloud storage platform is safe;

obtaining attributes of the cloud storage object;

determining, based on the attributes of the cloud storage object, to secure the cloud storage object against ransomware attacks, wherein determining to secure the cloud storage object against ransomware attacks comprises:

calculating a significance score of the cloud storage object using the attributes of the cloud storage object;

comparing the significance score to a threshold; and

determining to secure the cloud storage object against ransomware attacks responsive to the significance score exceeding the threshold; and

responsive to determining to secure the cloud storage object, replicating the cloud storage object to one or more additional cloud storage platforms.

16 . The cloud storage security system of claim 15 , wherein determining to secure the cloud storage object against ransomware attacks comprises:

classifying the cloud storage object into a significance category of a plurality of significance categories using the attributes of the cloud storage object; and

determining to secure the cloud storage object against ransomware attacks based on the significance category,

wherein the cloud storage object is replicated to a greater number of additional cloud storage platforms than a second cloud storage object that is classified into a lower significance category than the significance category of the cloud storage object.

17 . The cloud storage security system of claim 15 , wherein the operations further comprise:

receiving, from the cloud storage platform, an event identifying the cloud storage object;

determining, using the event, to scan the cloud storage object;

responsive to determining to scan the cloud storage object, downloading a copy of the cloud storage object from the cloud storage platform;

scanning the copy of the cloud storage object using a platform-agnostic scanner to generate the scan results; and

providing instructions to the cloud storage platform to unlock the cloud storage object responsive to the scan results indicating that the cloud storage object is safe.

Assignments (8)
CHANGE OF NAME Recorded May 18, 2026
From: MALWAREBYTES CORPORATE HOLDCO INC.
To: THREATDOWN INC.
Reel/Frame 075592/0851 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Oct 21, 2024
From: COMPUTERSHARE TRUST COMPANY, N.A.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 069193/0563 →
SECURITY INTEREST Recorded Oct 18, 2024
From: MALWAREBYTES INC.; MALWAREBYTES CORPORATE HOLDCO INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 068943/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2024
From: GISSEL, THOMAS R.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 068184/0689 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2024
From: HYDER, ADAM S.; SIVALANKA, RAGHURAM SRI; PODDER, ATANU
To: MALWAREBYTES INC.
Reel/Frame 068184/0692 →
EMPLOYMENT AGREEMENT Recorded Aug 5, 2024
From: MOREHEAD, BRIAN PAUL
To: MALWAREBYTES INC.
Reel/Frame 068457/0040 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2024
From: MALWAREBYTES INC.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 066900/0386 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 26, 2024
From: MALWAREBYTES CORPORATE HOLDCO INC.
To: COMPUTERSHARE TRUST COMPANY, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 066373/0912 →
Priority Claims (1)
IN 202341006339 · Jan 31, 2023 · national
Continuity (1)
Related Publication 20240259424A1 · Aug 1, 2024
References Cited (16)
US 11687652B1 · Pinheiro · 2023 [cited by examiner]
US 11757975B1 · Pandey · 2023 [cited by examiner]
US 20130086683A1 · Thomas · 2013 [cited by examiner]
US 20160294851A1 · Langton · 2016 [cited by examiner]
US 20170093897A1 · Cochin · 2017 [cited by examiner]
US 20170235945A1 · Lee · 2017 [cited by examiner]
US 20180248896A1 · Challita · 2018 [cited by examiner]
US 20190303573A1 · Chelarescu · 2019 [cited by examiner]
US 20190306179A1 · Chelarescu · 2019 [cited by examiner]
US 20200034537A1 · Chen · 2020 [cited by examiner]
US 20210152595A1 · Hansen · 2021 [cited by examiner]
US 20210357504A1 · Saad · 2021 [cited by examiner]
US 20230078476A1 · Venkatachalam · 2023 [cited by examiner]
US 20230247003A1 · Chanak · 2023 [cited by examiner]
US 20230291763A1 · Soryal · 2023 [cited by examiner]
US 20240004993A1 · Rozenberg · 2024 [cited by examiner]