IP Library Granted Patent US 10,169,586
Granted Patent B2
US 10,169,586 · App. 15/396,531 · Granted Jan 1, 2019

Ransomware detection and damage mitigation

Inventors: David Maciejak (Singapore, SG); Low Chin Yick (Singapore, SG)
Assignee: Fortinet, Inc.
G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,169,586
App. No.
15/396,531
Granted
Jan 1, 2019
Kind
B2
Abstract

Systems and methods for file encrypting malware detection are provided. According to one embodiment, a monitoring module is installed within active processes running on a computer system by a kernel mode driver. Performance of a directory traversal operation on a directory of the computer system is detected by a monitoring module of a first process of the multiple active processes in which a parameter of the traversal operation includes a wildcard character. When a number of wildcard-based directory traversal operations performed by the first process exceeds a threshold, a decoy file is deployed by the monitoring module within the directory and the driver is notified. The driver monitors for and detects an attempt by the first process to tamper with the decoy file by intercepting and evaluating file system operations. Responsive to detection of the attempt, the first process is confirmed to be a malware process and is terminated.

Claims (34)

1. A method comprising:

installing, by a kernel mode driver running on a computer system, a file system event monitoring module within each of a plurality of active processes running on the computer system;

detecting, by a first file system event monitoring module installed within a first process of the plurality of active processes, performance of a directory traversal operation on a directory of a file system of the computer system in which a parameter of the directory traversal operation includes at least one wildcard character;

when a number of wildcard-based directory traversal operations performed by the first process meets or exceeds a false positive threshold, then deploying, by the first file system event monitoring module, a decoy file within the directory and notifying the kernel mode driver regarding deployment of the decoy file;

monitoring and detecting, by the kernel mode driver an attempt by the first process to tamper with the decoy file by intercepting and evaluating file system operations; and

responsive to detection of the attempt, identifying, by the kernel mode driver, the first process as a malware process and causing the malware process to be terminated.

2. The method of claim 1 , wherein said causing the malware process to be terminated comprises the kernel mode driver directing the first file system event monitoring module to terminate the first process.

3. The method of claim 1 , wherein the plurality of active processes include processes running on the computer system at a time at which the kernel mode driver is initiated on the computer system and new run-time processes that are created after initiation of the kernel mode driver.

4. The method of claim 1 , wherein the file system event monitoring module is implemented as a dynamically linked shared library.

5. The method of claim 1 , further comprising causing, by the kernel mode driver, the installed file system event monitoring modules to be unloaded after said causing the malware process to be terminated.

6. The method of claim 1 , further comprising removing, by the kernel mode driver, the decoy file from the directory.

7. The method of claim 1 , wherein the at least one wildcard character comprises an ‘*’, a ‘.’, or a ‘?’.

8. The method of claim 1 , wherein the plurality of active processes are tracked by inserting a reference to or a process identifier of each of the plurality of active processes within a data structure maintained by the kernel mode driver.

9. A computer system comprising:

a non-transitory storage device having embodied therein one or more routines operable to detect and terminate a detected malware process; and

one or more processors coupled to the non-transitory storage device and operable to execute the one or more routines, wherein the one or more routines include:

a file system event monitoring module, which when executed by the one or more processors, intercepts a directory traversal operation within a file system of the computer system that has been initiated by a process executing on the computer system and determines whether a parameter of the directory traversal operation includes a wildcard character;

a decoy file deployment module, which when executed by the one or more processors, determines whether a false positive threshold has been met or exceeded by a number of wildcard-based directory traversal operations performed by the process and responsive to an affirmative determination deploys a decoy file within a directory targeted by the directory traversal operation; and

a decoy file tampering detection module associated with a kernel mode driver, which when executed by the one or more processors, determines whether the decoy file is being tampered with by a malware process by intercepting and evaluating file system operations and responsive to an affirmative determination that the decoy file is being tampered with causes the malware process to be terminated.

10. The system of claim 1 , wherein the malware process is terminated by the file system event monitoring module responsive to being directed to do so by the decoy file tampering detection module.

11. The system of claim 1 , wherein the file system event monitoring module is implemented within a dynamically linked shared library, and wherein the dynamically linked shared library is injected into the processes.

12. A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by one or more processors of a computer systems, causes the one or more processors to perform a method comprising:

installing, by a kernel mode driver running on the computer system, a file system event monitoring module within each of a plurality of active processes running on the computer system;

detecting, by a first file system event monitoring module installed within a first process of the plurality of active processes, performance of a directory traversal operation on a directory of a file system of the computer system in which a parameter of the directory traversal operation includes at least one wildcard character;

when a number of wildcard-based directory traversal operations performed by the first process meets or exceeds a false positive threshold, then deploying, by the first file system event monitoring module, a decoy file within the directory and notifying the kernel mode driver regarding deployment of the decoy file;

monitoring and detecting, by the kernel mode driver an attempt by the first process to tamper with the decoy file by intercepting and evaluating file system operations; and

responsive to detection of the attempt, identifying, by the kernel mode driver, the first process as a malware process and causing the malware process to be terminated.

13. The non-transitory computer-readable storage medium of claim 12 , wherein said causing the malware process to be terminated comprises the kernel mode driver directing the first file system event monitoring module to terminate the first process.

14. The non-transitory computer-readable storage medium of claim 12 , wherein the plurality of active processes include processes running on the computer system at a time at which the kernel mode driver is initiated on the computer system and new run-time processes that are created after initiation of the kernel mode driver.

15. The non-transitory computer-readable storage medium of claim 12 , wherein the file system event monitoring module is implemented as a dynamically linked shared library.

16. The non-transitory computer-readable storage medium of claim 12 , wherein the method further comprises causing, by the kernel mode driver, the installed file system event monitoring modules to be unloaded after said causing the malware process to be terminated.

17. The non-transitory computer-readable storage medium of claim 12 , wherein the method further comprises removing, by the kernel mode driver, the decoy file from the directory after said causing the malware process to be terminated.

18. The non-transitory computer-readable storage medium of claim 12 , wherein the at least one wildcard character comprises an ‘*’, a ‘.’, or a ‘?’.

19. The non-transitory computer-readable storage medium of claim 12 , wherein the plurality of active processes are tracked by inserting a reference to or a process identifier of each of the plurality of active processes within a data structure maintained by the kernel mode driver.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2017
From: MACIEJAK, DAVID; YICK, LOW CHIN
To: FORTINET, INC.
Reel/Frame 042268/0778 →
Continuity (1)
Related Publication 20180189490A1 · Jul 5, 2018
Cited By (16)
US 12,206,698 US 12,235,962 US 12,244,626 US 12,259,967 US 12,261,884 US 12,341,814 US 12,363,151 US 12,418,565 US 12,423,078 US 12,432,253 US 12,450,351 US 12,452,273 US 12,468,810 US 12,579,268 US 12,664,258 US 12,681,777