IP Library Granted Patent US 12,511,385
Granted Patent B2
US 12,511,385 · App. 18/641,798 · Granted Dec 30, 2025

Ransomware attack onset detection

Inventors: Ajaykumar Rajasekharan (Longmont, CO); Matthew Mills Parker (Denver, CO); Daniel L. Sullivan (Denver, CO)
Assignee: CrashPlan Group LLC
G06F21/565G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,511,385
App. No.
18/641,798
Granted
Dec 30, 2025
Kind
B2
Abstract

A method of detecting the onset of a ransomware attack is presented. In an example embodiment, file backup metadata for each of a plurality of computing devices is accessed and analyzed to detect anomalous file backup activity of individual ones of the computing devices. A determination is made as to whether the detected anomalous file backup activity of at least some of the computing devices is correlated in time. File description metadata for each of the computing devices is also accessed and analyzed to identify files in the computing devices that are anomalous to other files in the computing devices. A determination whether a ransomware attack has begun is based on a determination that the detected anomalous file backup activity of at least some of the computing devices is correlated in time, as well as on the identified anomalous files.

Claims (55)

1 . A method for detecting a ransomware attack, the method comprising:

accessing file backup metadata for a first computing device and a second computing device;

analyzing, using at least one hardware processor of a machine, the file backup metadata to detect first anomalous file backup activity at the first computing device and second anomalous file backup activity at the second computing device, wherein the first anomalous file backup activity has an associated first detected time and the second anomalous file backup activity has an associated second detected time;

determining that the first anomalous file backup activity and the second anomalous file backup activity are correlated based on the first anomalous file backup activity and the second anomalous file backup activity, wherein determining that the first anomalous file backup activity is correlated with the second anomalous file backup activity comprises determining that the second detected time is within a predetermined time period of the first detected time;

accessing file description metadata for the first computing device and the second computing device;

analyzing the file description metadata to identify anomalous files at the first computing device and the second computing device; and

determining that a ransomware attack has begun based on the determination that the first anomalous file backup activity and the second anomalous file backup activity are correlated, and based on the identified anomalous files at the first computing device and the second computing device.

2 . The method of claim 1 , further comprising:

accessing file backup metadata for a third computing device;

analyzing the file backup metadata for the third computing device to detect third anomalous file backup activity at the third computing device;

determining that the third anomalous file backup activity is correlated with the first anomalous file backup activity and the second anomalous file backup activity;

accessing file description metadata for the third computing device;

analyzing the file description metadata for the third computing device to identify anomalous files at the third computing device; and

wherein the determination that a ransomware attack has begun is further based on the determination that the third anomalous file backup activity is correlated in time with the first anomalous file backup activity and the second anomalous file backup activity, and further based on the identified anomalous files at the third computing device.

3 . The method of claim 1 , wherein the file description metadata comprises file extensions, wherein analyzing the file description metadata to identify anomalous files at the first computing device and the second computing device comprises determining file extensions of the anomalous files at the first computing device are different than file extensions of other files at the first computing device and that file extensions of the anomalous files at the second computing device are different than file extensions of other files at the second computing device.

4 . The method of claim 1 , wherein the file description metadata comprises at least one of a filename, a file MIME type, a file size, a file hash, and a time of file creation, reading, updating, or deletion.

5 . The method of claim 1 , wherein analyzing the file description metadata comprises identifying a first file on the first computing device as being anomalous based on the first file having the same filename and at least one of a different file extension and a different MIME type as a second file on the second computing device, wherein the second file has been identified as anomalous.

6 . The method of claim 1 , wherein the first anomalous file backup activity comprises a change in file backup activity of a file backup operation at the first computing device compared to a plurality of other file backup operations at the first computing device.

7 . A system comprising:

one or more hardware processors; and

a memory storing instructions that, when executed by the one or more hardware processors, cause the system to perform operations comprising:

accessing file backup metadata for a first computing device and a second computing device;

analyzing the file backup metadata to detect first anomalous file backup activity at the first computing device and second anomalous file backup activity at the second computing device, wherein the first anomalous file backup activity has an associated first detected time and the second anomalous file backup activity has a second detected time;

determining that the first anomalous file backup activity and the second anomalous file backup activity are correlated based on the first anomalous file backup activity and the second anomalous file backup activity, wherein determining that the first anomalous file backup activity is correlated with the second anomalous file backup comprises determining that the second detected time is within a predetermined time period of the first detected time;

accessing file description metadata for the first computing device and the second computing device;

analyzing the file description metadata to identify anomalous files at the first computing device and the second computing device; and

determining that a ransomware attack has begun based on the determination that the first anomalous file backup activity and the second anomalous file backup activity are correlated, and based on the identified anomalous files at the first computing device and the second computing device.

8 . The system of claim 7 , wherein the operations further comprise:

accessing file backup metadata for a third computing device;

analyzing the file backup metadata for the third computing device to detect third anomalous file backup activity at the third computing device;

determining that the third anomalous file backup activity is correlated with the first anomalous file backup activity and the second anomalous file backup activity;

accessing file description metadata for the third computing device;

analyzing the file description metadata for the third computing device to identify anomalous files at the third computing device; and

wherein the determination that a ransomware attack has begun is further based on the determination that the third anomalous file backup activity is correlated with the first anomalous file backup activity and the second anomalous file backup activity, and further based on the identified anomalous files at the third computing device.

9 . The system of claim 7 , wherein the file description metadata comprises file extensions, wherein analyzing the file description metadata to identify anomalous files at the first computing device and the second computing device comprises determining file extensions of the anomalous files at the first computing device are different than file extensions of other files at the first computing device and that file extensions of the anomalous files at the second computing device are different than file extensions of other files at the second computing device.

10 . The system of claim 7 , wherein the file description metadata comprises at least one of a filename, a file MIME type, a file size, a file hash, and a time of file creation, reading, updating, or deletion.

11 . The system of claim 7 , wherein the first anomalous file backup activity comprises a change in file backup activity of a file backup operation at the first computing device compared to a plurality of other file backup operations at the first computing device.

12 . One or more non-transitory computer readable media encoding instructions which, when executed by one or more hardware processors, cause the one or more processors to perform operations comprising:

accessing file backup metadata for a first computing device and a second computing device;

analyzing the file backup metadata to detect first anomalous file backup activity at the first computing device and second anomalous file backup activity at the second computing device, wherein the first anomalous file backup activity has an associated first detected time and the second anomalous file backup activity has an associated second detected time;

determining that the first anomalous file backup activity and the second anomalous file backup activity are correlated based on the first anomalous file backup activity and the second anomalous file backup activity, wherein determining that the first anomalous file backup activity is correlated with the second anomalous file backup activity comprises determining that the second detected time is within a predetermined time period of the first detected time;

accessing file description metadata for the first computing device and the second computing device;

analyzing the file description metadata to identify anomalous files at the first computing device and the second computing device; and

determining that a ransomware attack has begun based on the determination that the first anomalous file backup activity and the second anomalous file backup activity are correlated, and based on the identified anomalous files at the first computing device and the second computing device.

13 . The one or more non-transitory computer readable media of claim 12 , wherein the operations further comprise:

accessing file backup metadata for a third computing device;

analyzing the file backup metadata for the third computing device to detect third anomalous file backup activity at the third computing device;

determining that the third anomalous file backup activity is correlated with the first anomalous file backup activity and the second anomalous file backup activity;

accessing file description metadata for the third computing device;

analyzing the file description metadata for the third computing device to identify anomalous files at the third computing device; and

wherein the determination that a ransomware attack has begun is further based on the determination that the third anomalous file backup activity is correlated with the first anomalous file backup activity and the second anomalous file backup activity, and further based on the identified anomalous files at the third computing device.

14 . The one or more non-transitory computer readable media of claim 12 , wherein the file description metadata comprises file extensions, wherein analyzing the file description metadata to identify anomalous files at the first computing device and the second computing device comprises determining file extensions of the anomalous files at the first computing device are different than file extensions of the other files at the first computing device and that file extensions of the anomalous files at the second computing device are different than file extensions of the other files at the second computing device.

15 . The one or more non-transitory computer readable media of claim 12 , wherein the file description metadata comprises at least one of a filename, a file MIME type, a file size, a file hash, and a time of file creation, reading, updating, or deletion.

16 . The one or more non-transitory computer readable media of claim 12 , wherein analyzing the file description metadata comprises identifying a first file on the first computing device as being anomalous based on the first file having the same filename and at least one of a different file extension and a different MIME type as a second file on the second computing device, wherein the second file has been identified as anomalous.

17 . The one or more non-transitory computer readable media of claim 12 , wherein the first anomalous file backup activity comprises a change in file backup activity of a file backup operation at the first computing device compared to a plurality of other file backup operations at the first computing device.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2024
From: RAJASEKHARAN, AJAYKUMAR; PARKER, MATTHEW MILLS; SULLIVAN, DANIEL L.
To: CODE 42 SOFTWARE, INC.
Reel/Frame 068047/0905 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2024
From: CODE42 SOFTWARE, INC.
To: NORTH ACQUISITION LLC
Reel/Frame 068048/0073 →
CERTIFICATE OF AMENDMENT TO THE FOURTH AMENDED AND RESTATED CERTIFICATE OF INCORPORATION Recorded Jul 22, 2024
From: CODE 42 SOFTWARE, INC.
To: CODE42 SOFTWARE, INC.
Reel/Frame 068478/0090 →
CHANGE OF NAME Recorded Jul 22, 2024
From: NORTH ACQUISITION LLC
To: CRASHPLAN GROUP LLC
Reel/Frame 068478/0249 →
Continuity (3)
Continuation 18145222 · Dec 22, 2022
Continuation 15666906 · Aug 2, 2017
Related Publication 20240346144A1 · Oct 17, 2024
References Cited (36)
US 7134041B2 · Murray et al. · 2006 [cited by applicant]
US 8181251B2 · Kennedy · 2012 [cited by examiner]
US 8695095B2 · Baliga · 2014 [cited by examiner]
US 8918878B2 · Niemelä · 2014 [cited by applicant]
US 9792289B2 · Reininger et al. · 2017 [cited by applicant]
US 9935973B2 · Crofton · 2018 [cited by examiner]
US 10061516B2 · Wakchaure et al. · 2018 [cited by applicant]
US 10592352B1 · Tanaka et al. · 2020 [cited by applicant]
US 11216559B1 · Gu · 2022 [cited by examiner]
US 11537713B2 · Rajasekharan · 2022 [cited by examiner]
US 11995186B2 · Rajasekharan · 2024 [cited by examiner]
US 20050172339A1 · Costea et al. · 2005 [cited by applicant]
US 20130185800A1 · Miller · 2013 [cited by examiner]
US 20160185800A1 · Ren et al. · 2016 [cited by applicant]
US 20170046512A1 · Kedma · 2017 [cited by examiner]
US 20170104776A1 · Halfon et al. · 2017 [cited by applicant]
US 20170235950A1 · Gopalapura Venkatesh · 2017 [cited by examiner]
US 20170279330A1 · Willner et al. · 2017 [cited by applicant]
US 20170329660A1 · Salunke et al. · 2017 [cited by applicant]
US 20190042744A1 · Rajasekharan et al. · 2019 [cited by applicant]
US 20190236274A1 · Brenner · 2019 [cited by applicant]
US 20200042703A1 · Herman Saffar et al. · 2020 [cited by applicant]
US 20200082081A1 · Sarin · 2020 [cited by examiner]
US 20200192769A1 · Ishanov et al. · 2020 [cited by applicant]
US 20210312066A1 · Hansen · 2021 [cited by applicant]
US 20220318385A1 · Reid · 2022 [cited by examiner]
US 20230022044A1 · Lewis · 2023 [cited by examiner]
US 20230259623A1 · Rajasekharan et al. · 2023 [cited by applicant]
US 20250028828A1 · Yadav · 2025 [cited by examiner]
EP 4468185A1 · 2024 [cited by examiner]
KR 20190087720A · 2019 [cited by applicant]
KR 20240151994A · 2024 [cited by examiner]
WO WO2021098968A1 · 2021 [cited by examiner]
WO 2022002405A1 · 2022 [cited by applicant]
WO WO2023232239A1 · 2023 [cited by examiner]
WO WO2024051912A1 · 2024 [cited by examiner]