IP Library › Granted Patent US 12,536,284
Granted Patent B2
US 12,536,284 · App. 18/474,349 · Granted Jan 27, 2026

System and method for detecting and/or blocking malware attacks using decoys

Inventors: Gabe Hoogenboom (Iron River, MI); Jeffrey A. Lau (Fairfax, VA)
Assignee: Battelle Memorial Institute
G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,536,284
App. No.
18/474,349
Granted
Jan 27, 2026
Kind
B2
Abstract

In an approach to detecting and/or blocking malware attacks using decoys, one or more decoy files are created, files, where the one or more decoy files never return a read acknowledgement when read, thereby crippling at least a portion of a malware. The one or more decoy files are propagated to a system. Responsive to the malware initiating a read process on any of the one or more decoy files, the malware is detected.

Claims (46)

1 . A computer-implemented method for detecting and blocking malware attacks, the method comprising:

creating, by one or more computer processors, one or more decoy files, wherein:

the one or more decoy files never return a read acknowledgement when read, thereby crippling at least a portion of a malware;

propagating, by the one or more computer processors, the one or more decoy files to a system; and

responsive to the malware initiating a read process on any of the one or more decoy files, detecting, by the one or more computer processors, the malware without requiring a monitoring process.

2 . The method of claim 1 , further comprising:

detecting, by the one or more computer processors, that the malware has attempted to read any of the one or more decoy files; and

signaling, by the one or more computer processors, to the system that the malware has been detected.

3 . The method of claim 1 , wherein each of the one or more decoy files is a first in, first out (FIFO) pipe, wherein each of the FIFOs is empty.

4 . The method of claim 3 , wherein any of the one or more decoy files are a symbolic link (symlink) to the FIFO.

5 . The method of claim 3 , wherein creating the one or more decoy files further comprises:

creating, by the one or more computer processors, a software module in an operating system; and

creating, by the one or more computer processors, the FIFO using the software module in the operating system.

6 . The method of claim 3 , wherein creating the one or more decoy files further comprises:

creating, by the one or more computer processors, a Linux virtual machine on a Windows system; and

creating, by the one or more computer processors, the FIFO using a make FIFO command (mkfifo) of the Linux virtual machine.

7 . The method of claim 3 , wherein responsive to detecting that the malware has initiated the read process on any of the one or more decoy files, detecting the malware further comprises:

preventing, by the one or more computer processors, any write process from writing to the FIFO to leave the FIFO empty, wherein the read process cannot complete while the FIFO is empty.

8 . The method of claim 3 , wherein responsive to detecting that the malware has initiated the read process on any of the one or more decoy files, detecting the malware further comprises:

creating, by the one or more computer processors, a write process that writes continuously to the FIFO, wherein the read process cannot complete due to the write process continuously writing to the FIFO.

9 . The method of claim 1 , wherein the one or more decoy files are propagated based on research and analysis of the malware attacks.

10 . The method of claim 9 , wherein a number and location of the decoy files may be optimized based on the research and the analysis of the malware attacks.

11 . A system for detecting and/or blocking malware attacks, the system comprising:

one or more computer processors;

one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media for execution by at least one of the one or more computer processors, the stored program instructions including instructions to:

create one or more decoy files, wherein the one or more decoy files never return a read acknowledgement when read, thereby crippling at least a portion of a malware;

propagate the one or more decoy files to a target system; and

responsive to the malware initiating a read process on any of the one or more decoy files, detect the malware without requiring a monitoring process.

12 . The system of claim 11 , further comprises one or more of the following program instructions, stored on the one or more computer readable storage media, to:

detect that the malware has attempted to read any of the one or more decoy files; and

signal to the system that the malware has been detected.

13 . The system of claim 11 , wherein each of the one or more decoy files is a first in, first out (FIFO) pipe, wherein each of the FIFOs is empty.

14 . The system of claim 13 , wherein each of the one or more decoy files are a symbolic link (symlink) to the FIFO.

15 . The system of claim 13 , wherein create the one or more decoy files further comprises one or more of the following program instructions, stored on the one or more computer readable storage media, to:

create a software module in an operating system; and

create the FIFO using the software module in the operating system.

16 . The system of claim 13 , wherein create the one or more decoy files further comprises one or more of the following program instructions, stored on the one or more computer readable storage media, to:

create a Linux virtual machine on a Windows system; and

create the FIFO using a make FIFO command (mkfifo) of the Linux virtual machine.

17 . The system of claim 13 , wherein responsive to detecting that the malware has initiated the read process on any of the one or more decoy files, detect the malware further comprises one or more of the following program instructions, stored on the one or more computer readable storage media, to:

prevent a write process from writing to the FIFO to leave the FIFO empty, wherein the read process cannot complete due to the FIFO is empty.

18 . The system of claim 13 , wherein responsive to detecting that the malware has initiated the read process on any of the one or more decoy files, detect the malware further comprises one or more of the following program instructions, stored on the one or more computer readable storage media, to:

create a write process that writes continuously to the FIFO, wherein the read process cannot complete due to the write process continuously writing to the FIFO.

19 . The system of claim 11 , wherein the one or more decoy files are propagated based on research and analysis of the malware attacks.

20 . The system of claim 19 , wherein a number and location of the decoy files may be optimized based on the research and the analysis of the malware attacks.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2023
From: HOOGENBOOM, GABE; LAU, JEFFREY A.
To: BATTELLE MEMORIAL INSTITUTE
Reel/Frame 065058/0344 →
Continuity (2)
Provisional Application 63377845 · Sep 30, 2022
Related Publication 20240111871A1 · Apr 4, 2024
References Cited (14)
US 9418222B1 · Rivera · 2016 [cited by examiner]
US 10193918B1 · Patton · 2019 [cited by examiner]
US 10834130B2 · Erez · 2020 [cited by examiner]
US 11645383B2 · Guri · 2023 [cited by examiner]
US 20060206873A1 · Argade · 2006 [cited by applicant]
US 20180189490A1 · Maciejak · 2018 [cited by examiner]
US 20190332766A1 · Guri et al. · 2019 [cited by applicant]
US 20210312046A1 · Hicks · 2021 [cited by examiner]
US 20210319104A1 · Jagannathan · 2021 [cited by examiner]
US 20230185628A1 · Lo · 2023 [cited by examiner]
US 20230231881A1 · Radhakrishnan · 2023 [cited by examiner]
US 20250055880A1 · Goncalves · 2025 [cited by examiner]
International Search Report and Written Opinion of International Application No. PCT/US23/75072, mail date Jan. 18, 2024, 9 pages. [cited by applicant]
Genc, et al., “On Deception-Based Protection Against Cryptographic Ransomware”, Jun. 6, 2019, retrieved Jan. 25, 2024 from https://link.springer.com/chapter/10.1007/978-3-030-22038-9_11. pp. 1-21. [cited by applicant]