IP Library Patent Application 18452319
Patent Application
App. No. 18/452,319

CONTINUAL BACKUP VERIFICATION FOR RANSOMWARE DETECTION AND RECOVERY

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/452,319
Abstract

Aspects of the disclosure provide continual backup verification for ransomware detection and recovery of fileless malicious logic. On an ongoing basis, even prior to detecting an attack within a production environment, each of a plurality of backup virtual machines (VMs) is executed in an isolation environment and subject to behavior monitoring to detect malicious logic (e.g., ransomware). If malicious logic is detected in a backup VM, an alert is generated and/or that backup VM is marked as unavailable for use as a restoration backup, in order to avoid re-infecting the production environment. In some examples, a backup VM with malicious logic is cleaned and returned to the pool of available backups that are suitable for use. Because the production environment is not burdened, in some examples, the probability of detection for finding malicious logic in the isolation environment is set higher than what is used in the production environment.

Claims (60)

1 . A computerized method comprising:

prior to detecting a cyberattack within a production environment, executing each backup virtual machine (VM) of a plurality of backup VMs in an isolation environment;

for each executing backup VM, monitoring behavior to detect malicious logic; and

based on at least detecting malicious logic from the behavior monitoring of a first backup VM of the plurality of backup VMs:

marking the first backup VM as unavailable for backup restore use; or

generating an alert on a user interface for the first backup VM.

2 . The computerized method of claim 1 , wherein marking the first backup VM as unavailable for backup restore use comprises:

setting a flag associated with the first backup VM; or

moving the first backup VM out from a folder of available backup VMs.

3 . The computerized method of claim 1 , further comprising:

cleaning the detected malicious logic from the first backup VM.

4 . The computerized method of claim 1 , further comprising:

generating a memory snapshot for the first backup VM.

5 . The computerized method of claim 1 , wherein executing each backup VM comprises:

incrementally relaxing a network isolation level for the executing backup VM.

6 . The computerized method of claim 1 , wherein monitoring behavior to detect malicious logic comprises:

monitoring behavior with a higher probability of detection (Pd) for detection of malicious logic in the isolation environment than a Pd for detection of malicious logic used in the production environment.

7 . The computerized method of claim 1 , further comprising:

based on at least a forensics investigating verifying an absence of malicious logic in the first backup VM, marking the first backup VM as available for backup restore use, wherein marking the first backup VM as available for backup restore use comprises:

setting a flag associated with the first backup VM; or

moving the first backup VM into a folder of available backup VMs.

8 . The computerized method of claim 1 , further comprising:

instrumenting each backup VM of the plurality of backup VMs for the behavior monitoring.

9 . The computerized method of claim 1 , further comprising:

generating an execution schedule for the plurality of backup VMs, wherein executing each backup VM comprises executing each backup VM according to the execution schedule.

10 . The computerized method of claim 1 , further comprising:

based on at least detecting malicious logic from the behavior monitoring of the first backup VM, cleaning the malicious logic from the first backup VM; and

verifying an absence of malicious logic in the first backup VM.

11 . A system comprising:

an execution controller for executing each backup virtual machine (VM) of a plurality of backup VMs in an isolation environment, prior to detecting a cyberattack within a production environment;

a behavior monitor for monitoring behavior of each executing backup VM to detect malicious logic; and

response logic to, based on at least detecting malicious logic from the behavior monitoring of a first backup VM of the plurality of backup VMs:

mark the first backup VM as unavailable for backup restore use; or

generate an alert for the first backup VM.

12 . The system of claim 11 , wherein marking the first backup VM as unavailable for backup restore use comprises:

setting a flag associated with the first backup VM; or

moving the first backup VM out from a folder of available backup VMs.

13 . The system of claim 11 , further comprising:

a snapshot manager for generating a memory snapshot for the first backup VM.

14 . The system of claim 11 , further comprising:

a scheduler for generating an execution schedule for the plurality of backup VMs.

15 . The system of claim 11 , further comprising:

an instrumenter for instrumenting each backup VM of the plurality of backup VMs for the behavior monitoring.

16 . The system of claim 11 , further comprising:

a cleaner for cleaning the malicious logic from the first backup VM.

17 . One or more computer storage media having computer-executable instructions that, upon execution by a processor, cause the processor to at least:

prior to detecting a cyberattack within a production environment, execute each backup virtual machine (VM) of a plurality of backup VMs in an isolation environment;

for each executing backup VM, monitor behavior to detect malicious logic with a higher probability of detection (Pd) for detection of malicious logic in the isolation environment than a Pd for detection of malicious logic used in the production environment; and

based on at least detecting malicious logic from the behavior monitoring of a first backup VM of the plurality of backup VMs:

mark the first backup VM as unavailable for backup restore use; and

generate an alert for the first backup VM.

18 . The computer storage media of claim 17 , wherein marking the first backup VM as unavailable for backup restore use comprises:

set a flag associated with the first backup VM; or

move the first backup VM out from a folder of available backup VMs.

19 . The computer storage media of claim 17 , wherein the computer-executable instructions, upon execution by a processor, further cause the processor to at least:

transmit behavior data from the isolation environment to an endpoint detection and response (EDR) node.

20 . The computer storage media of claim 17 , wherein the computer-executable instructions, upon execution by a processor, further cause the processor to at least:

based on at least a forensics investigating verifying an absence of malicious logic in the first backup VM, mark the first backup VM as available for backup restore use, wherein marking the first backup VM as available for backup restore use comprises:

setting a flag associated with the first backup VM; or

moving the first backup VM into a folder of available backup VMs.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2025
From: WEISSMAN, BORIS; KAMATH, KIRAN; CASARES-CHARLES, JUAN PABLO; KOTHARI, PIYUSH; KOLECHKIN, MICHAEL; SREEKUMAR, DEEPA; BHAVSAR, MAMTA
To: VMWARE, INC.
Reel/Frame 070698/0178 →
CHANGE OF NAME Recorded Apr 1, 2025
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 070704/0117 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 8, 2024
From: KAMATH, KIRAN; CASARES-CHARLES, JUAN PABLO; KOTHARI, PIYUSH; KOLECHKIN, MICHAEL; SREEKUMAR, DEEPA; WEISSMAN, BORIS
To: VMWARE, INC.
Reel/Frame 067349/0586 →
CHANGE OF NAME Recorded May 8, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067355/0001 →