IP Library › Granted Patent US 12,197,585
Granted Patent B2
US 12,197,585 · App. 17/113,464 · Granted Jan 14, 2025

Machine learning based vulnerable target identification in ransomware attack

Inventors: Mu Qiao (Belmont, CA); Wenqi Wei (Atlanta, GA); Eric Kevin Butler (San Jose, CA); Divyesh Jadav (San Jose, CA)
Assignee: International Business Machines Corporation
G06F21/577G06F16/9024G06F18/214G06F21/552G06F21/561G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,197,585
App. No.
17/113,464
Granted
Jan 14, 2025
Kind
B2
Abstract

A processor can be configured to receive data associated with, and/or access to, a computing system's file system structure. The processor can also be configured to determine file patterns, file path patterns and/or graph patterns associated with the computing system. The processor can also be configured to build a graph structure having nodes and edges, the graph structure representing the file patterns, file path patterns and graph patterns, wherein the nodes of the graph structure represent files and attributes of the files and the edges of the graph structure represent connectivity between the files. The processor can also be configured to train, based on the graph structure, a first machine learning model to learn a feature vector associated with a file. The processor can also be configured to train, based on the feature vector, a second machine learning model to identify a vulnerable ransomware target.

Claims (36)

1. A computer-implemented method comprising:

receiving data associated with a computing system's file system structure;

determining file patterns, file path patterns and graph patterns associated with the computing system, which are susceptible to a ransomware attack, the graph patterns including at least search paths of infecting files in the computer system's file system structure and search strategies of infecting files along travel paths of directories of the computing system's file system structure, the search strategies specifying a graph traversal algorithm which is being used;

building a graph structure having nodes and edges, the graph structure representing the file patterns, the file path patterns and the graph patterns, wherein the nodes of the graph structure represent files and attributes of the files and the edges of the graph structure represent connectivity between the files;

training, based on the graph structure, a first machine learning model to learn a feature vector associated with a file, wherein the first machine learning model learns importance of the file patterns, the file path patterns and the graph patterns in the ransomware attack; and

training, based on the feature vector, a second machine learning model to identify a vulnerable ransomware target;

wherein the first machine learning model includes a graph convolutional network, the graph convolutional network transforming the attributes of the files and the connectivity between the files into a feature vector associated with each of the nodes in the graph structure, wherein the feature vector associated with each of the nodes in the graph structure is a k-dimensional representation of node features and structure features of the graph structure, wherein k is a hyperparameter of the graph convolutional network and is configurable, wherein k is user-defined;

deploy the second machine learning model for identifying a future ransomware target; and

trigger the computing system to perform a mitigating action based on the second machine learning model identifying the future ransomware target.

2. The method of claim 1 , wherein the mitigating action includes increasing security checks on the identified future ransomware target.

3. The method of claim 1 , wherein the second machine learning model includes a classifier.

4. The method of claim 1 , wherein the second machine learning model includes a binary classifier.

5. A system comprising:

a processor; and

a memory device coupled with the processor,

the processor configured to at least:

receive data associated with a computing system's file system structure;

determine file patterns, file path patterns and graph patterns associated with the computing system, which are susceptible to a ransomware attack, the graph patterns including at least search paths of infecting files in the computer system's file system structure and search strategies of infecting files along travel paths of directories of the computing system's file system structure, the search strategies specifying a graph traversal algorithm which is being used;

build a graph structure having nodes and edges, the graph structure representing the file patterns, the file path patterns and the graph patterns, wherein the nodes of the graph structure represent files and attributes of the files and the edges of the graph structure represent connectivity between the files;

train, based on the graph structure, a first machine learning model to learn a feature vector associated with a file, wherein the first machine learning model learns importance of the file patterns, the file path patterns and the graph patterns in the ransomware attack; and

train, based on the feature vector, a second machine learning model to identify a vulnerable ransomware target;

wherein the first machine learning model includes a graph convolutional network, the graph convolutional network transforming the attributes of the files and the connectivity between the files into a feature vector associated with each of the nodes in the graph structure, wherein the feature vector associated with each of the nodes in the graph structure is a k-dimensional representation of node features and structure features of the graph structure, wherein k is a hyperparameter of the graph convolutional network and is configurable, wherein k is user-defined;

deploy the second machine learning model for identifying a future ransomware target; and

trigger the computing system to perform a mitigating action based on the second machine learning model identifying the future ransomware target.

6. 5 , wherein the mitigating action includes increasing security checks on the identified future ransomware target.

7. The system of claim 5 , wherein the second machine learning model includes a classifier.

8. The system of claim 5 , wherein the second machine learning model includes a binary classifier.

9. A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions readable by a device to cause the device to:

receive data associated with a computing system's file system structure;

determine file patterns, file path patterns and graph patterns associated with the computing system, which are susceptible to a ransomware attack, the graph patterns including at least search paths of infecting files in the computer system's file system structure and search strategies of infecting files along travel paths of directories of the computing system's file system structure, the search strategies specifying a graph traversal algorithm which is being used;

build a graph structure having nodes and edges, the graph structure representing the file patterns, the file path patterns and the graph patterns, wherein the nodes of the graph structure present files and attributes of the files and the edges of the graph structure represent connectivity between the files;

train, based on the graph structure, a first machine learning model to learn a feature vector associated with a file, wherein the first machine learning model learns importance of the file patterns, the file path patterns and the graph patterns in the ransomware attack; and

train, based on the feature vector, a second machine learning model to identify a vulnerable ransomware target;

wherein the first machine learning model includes a graph convolutional network, the graph convolutional network transforming the attributes of the files and the connectivity between the files into a feature vector associated with each of the nodes in the graph structure, wherein the feature vector associated with each of the nodes in the graph structure is a k-dimensional representation of node features and structure features of the graph structure, wherein k is a hyperparameter of the graph convolutional network and is configurable, wherein k is user-defined;

deploy the second machine learning model for identifying a future ransomware target; and

trigger the computing system to perform a mitigating action based on the second machine learning model identifying the future ransomware target.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2020
From: QIAO, MU; WEI, WENQI; BUTLER, ERIC KEVIN; JADAV, DIVYESH
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 054564/0257 →
Continuity (1)
Related Publication 20220179964A1 · Jun 9, 2022
References Cited (31)
US 9516053B1 · Muddu · 2016 [cited by examiner]
US 10055582B1 · Weaver · 2018 [cited by examiner]
US 10609079B2 · Crabtree et al. · 2020 [cited by applicant]
US 10664619B1 · Marelas · 2020 [cited by applicant]
US 10673903B2 · Chesla et al. · 2020 [cited by applicant]
US 10893068B1 · Khalid · 2021 [cited by examiner]
US 11238176B1 · Vax · 2022 [cited by examiner]
US 20100211924A1 · Begel · 2010 [cited by examiner]
US 20170169230A1 · Zheng · 2017 [cited by examiner]
US 20180288087A1 · Hittel · 2018 [cited by examiner]
US 20190319987A1 · Levy · 2019 [cited by examiner]
US 20190347418A1 · Strogov et al. · 2019 [cited by applicant]
US 20200076835A1 · Ladnai · 2020 [cited by examiner]
US 20200204589A1 · Strogov · 2020 [cited by examiner]
US 20200301892A1 · Florin · 2020 [cited by examiner]
US 20200342116A1 · Agarwal · 2020 [cited by examiner]
US 20210026961A1 · Underwood · 2021 [cited by examiner]
US 20210027133A1 · Ludwig · 2021 [cited by examiner]
US 20210056211A1 · Olson · 2021 [cited by examiner]
US 20210084073A1 · Crabtree · 2021 [cited by examiner]
US 20210160257A1 · Elyashiv · 2021 [cited by examiner]
US 20210294901A1 · Agarwwal · 2021 [cited by examiner]
Exabeam, “The Anatomy of a Ransomware Attack”, Threat Report, 2016, 13 pages. [cited by applicant]
Alhawi, O., et al., “Leveraging Machine Learning Techniques for Windows Ransomware Network Traffic Detection”, Cyber Threat Intelligence, Advances in Information Security, First Online Apr. 24, 2018, 11 pages, vol. 70. [cited by applicant]
P-PAEP, “The Future of Ransomware and Social Engineering”, 2017 Public-Private Analytic Exchange Program, Aug. 24, 2017, 31 pages. [cited by applicant]
Anonymous, “Automatic Event-Driven Backup Recommendation Engine in Database Deployments”, An IP.com Prior Art Data Base Technical Disclosure, IP.com No. IPCOM000263492D, Sep. 4, 2020, 6 pages. [cited by applicant]
Anonymous, “Vulnerability Mitigation in a Cloud Environment”, An IP.com Prior Art Data Base Technical Disclosure, IP.com No. IPCOM000260267D, Nov. 8, 2019, 4 pages. [cited by applicant]
Anonymous, “Method and System for Dynamic Identification of Cyber Threats by Ingesting Backup Data”, An IP.com Prior Art Data Base Technical Disclosure, IP.com No. IPCOM000258575D, May 24, 2019, 3 pafes. [cited by applicant]
Scaife, N., et al., “CryptoLock (and Drop It): Stopping Ransomware Attacks on User Data”, In 2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS), Jun. 27-30, 2016, pp. 303-312. [cited by applicant]
Hammond, D.K., et al., “Wavelets on graphs via spectral graph theory”, Applied and Computational Harmonic Analysis 30 (2011), Received Nov. 14, 2009, Revised Apr. 21, 2010, Accepted Apr. 25, 2010, Available online Apr. … [cited by applicant]
Kipf. T.N., et al., “Semi-supervised classification with graph convolutional networks”, Published as a conference paper at ICLR 2017, arXiv:1609.02907v4, Feb. 22, 2017, 14 pages. [cited by applicant]