IP Library › Granted Patent US 11,949,710
Granted Patent B2
US 11,949,710 · App. 17/582,537 · Granted Apr 2, 2024

System and method for efficient early indication of ransomware attack for damage prevention and control

Inventor: Girish B. Doshi (Pune, IN)
Assignee: Dell Products L.P.
H04L63/1466H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,949,710
App. No.
17/582,537
Granted
Apr 2, 2024
Kind
B2
Abstract

In general, one or more embodiments of the invention relates to systems and methods for detecting ransomware attacks earlier and closer to the time of attack. The ransomware attack can be detect by determining a change rate of data blocks between snapshots. The ransomware attack can also be detected by determining the pattern of changes in the blocks deviates from a normal pattern. By making these determinations, a quick identification of possible ransomware attacks can be made and other methods of mitigating the attack can be deployed when they are may still be useful to mitigate potential damage to a user's data.

Claims (38)

1. A method for detecting a ransomware attack, comprising:

enabling changed block tracking of a data storage comprising of a plurality of data blocks;

taking snapshots of the plurality of data blocks at multiple times;

determining a rate of change between at least two snapshots of the plurality of data blocks;

determining a pattern of changes between the at least two snapshots of the plurality of data blocks; and

scanning the plurality of data blocks for ransomware when the determined rate of change between the at least two snapshots of the plurality of data blocks is greater than a threshold and/or the determined pattern of changes between the at least two snapshots of the plurality of data blocks deviates by more than a threshold from a normal pattern of changes of the plurality of data blocks.

2. The method of claim 1 , wherein the rate of change between the at least two snapshots of the plurality of data blocks is determined by calculating the difference between the at least two snapshots of the plurality of data blocks to determine the number of data blocks that have changed and dividing the difference by the total number of data blocks in the at least two snapshots to obtain the rate of change between the at least two snapshots of the plurality of data blocks.

3. The method of claim 1 , wherein determining if the pattern of changes between the at least two snapshots of the plurality of data blocks deviates by a threshold from the normal pattern of changes of the plurality of data blocks comprises determining the number of standard deviations that the current pattern of changes between the at least two snapshots differs from a historical pattern of changes.

4. The method of claim 1 , wherein the method is performed by a data protection manager during backup of the data blocks.

5. The method of claim 1 , wherein the snapshots are taken of active data.

6. The method of claim 1 , wherein the snapshots are taken at set intervals of time.

7. The method of claim 6 , wherein the set intervals of time are once a day.

8. An electronic device comprising:

a data storage that comprises of a plurality of blocks;

a data protection manager that monitors the data storage and includes a processor; and

a memory having computer program instructions stored thereon, the processor executing the computer program instructions in the memory to perform a method comprising of:

enabling changed block tracking of the data storage;

taking snapshots of the plurality of data blocks at multiple times;

determining a rate of change between at least two snapshots of the plurality of data blocks;

determining a pattern of changes between the at least two snapshots of the plurality of data blocks; and

scanning the plurality of data blocks for ransomware, when the determined rate of change between the at least two snapshots of the plurality of data blocks is greater than a threshold and/or the determined pattern of changes between the at least two snapshots of the plurality of data blocks deviates by more than a threshold from a normal pattern of changes of the plurality of data blocks.

9. The electronic device of claim 8 , wherein the rate of change between the at least two snapshots of the plurality of data blocks is determined by calculating the difference between the at least two snapshots of the plurality of data blocks to determine the number of data blocks that have changed and dividing the difference by the total number of data blocks in the two snapshots to obtain the rate of change between the at least two snapshots of the plurality of data blocks.

10. The electronic device of claim 9 , wherein determining if the pattern of changes between the at least two snapshots of the plurality of data blocks deviates by a threshold from the normal pattern of changes of the plurality of data blocks comprises determining the number of standard deviations that the current pattern of changes between the at least two snapshots differs from a historical pattern of changes.

11. The electronic device of claim 8 , wherein the method is performed by the data protection manager during backup of data.

12. The electronic device of claim 8 , wherein the snapshots are taken of active data.

13. The electronic device of claim 8 , wherein the snapshots are taken at set intervals of time.

14. The electronic device of claim 13 , wherein the set intervals of time are once a day.

15. A computer program product, which is tangibly stored in a non-transitory computer storage medium and includes machine-executable instructions, the machine-executable instructions, when executed by a device, causing the device to execute a method comprising:

enabling changed block tracking of a data storage comprising of a plurality of data blocks;

taking snapshots of the plurality of data blocks at multiple times;

determining a rate of change between at least two snapshots of the plurality of data blocks;

determining a pattern of changes between the at least two snapshots of the plurality of data blocks; and

scanning the plurality of data blocks for ransomware, when the determined rate of change between the at least two snapshots of the plurality of data blocks is greater than a threshold and/or the determined pattern of changes between the at least two snapshots of the plurality of data blocks deviates by more than a threshold from a normal pattern of changes of the plurality of data blocks.

16. The computer program of claim 15 , wherein the rate of change between the at least two snapshots of the plurality of data blocks is determined by calculating the difference between the at least two snapshots of the plurality of data blocks to determine the number of data blocks that have changed and dividing the difference by the total number of data blocks in the at least two snapshots to obtain the rate of change between the at least two snapshots of the plurality of data blocks.

17. The computer program of claim 15 , wherein determining if the pattern of changes between the at least two snapshots of the plurality of data blocks deviates by a threshold from the normal pattern of changes of the plurality of data blocks comprises determining the number of standard deviations that the current pattern of changes between the at least two snapshots differs from a historical pattern of changes.

18. The computer program of claim 15 , wherein the method is performed during backup of data.

19. The computer program of claim 15 , wherein the snapshots are taken of working data.

20. The computer program of claim 15 , wherein the snapshots are taken at set intervals of time.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2022
From: DOSHI, GIRISH B.
To: DELL PRODUCTS L.P.
Reel/Frame 058759/0604 →
Continuity (1)
Related Publication 20230239321A1 · Jul 27, 2023