IP Library Granted Patent US 12,430,457
Granted Patent B2
US 12,430,457 · App. 18/297,118 · Granted Sep 30, 2025

Reversing symmetric encryptions using keys found in snapshots—per-file keys, random and transmitted outside

Inventors: Ofir Ezrielev (Be'er Sheba, IL); Yehiel Zohar (Sderot, IL); Yevgeni Gehtman (Modi'in, IL); Tomer Shachar (Beer-Sheva, IL); Maxim Balin (Gan-Yavne, IL)
Assignee: Dell Products L.P.
G06F21/6218G06F21/566H04L9/0822
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,430,457
App. No.
18/297,118
Granted
Sep 30, 2025
Kind
B2
Abstract

One example method includes identifying a process that includes both a write operation and a transmit operation, wherein the write operation comprises performing a malicious process on data that renders the data unusable to an owner of the data, and the transmit operation comprises transmitting the data after the data has been acted upon by the malicious process, performing a snapshot operation to create a snapshot that comprises a copy of the data after the data has been acted upon by the malicious process and/or while the data is being acted upon by the malicious process, and intercepting the data before, or while, the transmit operation is performed.

Claims (26)

1. A method, comprising:

in a kernel space, identifying a process taking place in the kernel space that includes both a write operation and a transmit operation, wherein the write operation comprises performing a malicious process on data that renders the data unusable to an owner of the data, and the transmit operation comprises transmitting, out of the kernel space to an attacker, the data after the data has been acted upon by the malicious process;

performing a snapshot operation to create a snapshot that comprises a copy of the data after the data has been acted upon by the malicious process and/or while the data is being acted upon by the malicious process;

searching the snapshot for a key that was used by the malicious process to encrypt the data; and

intercepting the data before, or while, the transmit operation is performed.

2. The method as recited in claim 1 , wherein the malicious process performed on the data is a symmetric encryption process.

3. The method as recited in claim 1 , wherein the snapshot comprises a snapshot of the malicious process as the malicious process is being performed.

4. The method as recited in claim 1 , wherein the process comprises a ransomware process.

5. The method as recited in claim 1 , wherein the snapshot comprises a snapshot of the transmit operation as the transmit operation is being performed.

6. The method as recited in claim 1 , wherein the malicious process is allowed to continue to run for a period of time after the snapshot is created.

7. The method as recited in claim 1 , wherein the data comprises a file, and the malicious process comprises encrypting the file with the key, and the key is specific to the file.

8. The method as recited in claim 1 , wherein the malicious process comprises encrypting the data using the key, and the transmit operation transmits the encrypted data and the key to the attacker.

9. The method as recited in claim 1 , wherein the intercepting prevents the transmit operation from being performed.

10. A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

in a kernel space, identifying a process taking place in the kernel space that includes both a write operation and a transmit operation, wherein the write operation comprises performing a malicious process on data that renders the data unusable to an owner of the data, and the transmit operation comprises transmitting, out of the kernel space to an attacker, the data after the data has been acted upon by the malicious process;

performing a snapshot operation to create a snapshot that comprises a copy of the data after the data has been acted upon by the malicious process and/or while the data is being acted upon by the malicious process;

searching the snapshot for a key that was used by the malicious process to encrypt the data; and

intercepting the data before, or while, the transmit operation is performed.

11. The non-transitory storage medium as recited in claim 10 , wherein the malicious process performed on the data is a symmetric encryption process.

12. The non-transitory storage medium as recited in claim 10 , wherein the snapshot comprises a snapshot of the malicious process as the malicious process is being performed.

13. The non-transitory storage medium as recited in claim 10 , wherein the process comprises a ransomware process.

14. The non-transitory storage medium as recited in claim 10 , wherein the snapshot comprises a snapshot of the transmit operation as the transmit operation is being performed.

15. The non-transitory storage medium as recited in claim 10 , wherein the malicious process is allowed to continue to run for a period of time after the snapshot is created.

16. The non-transitory storage medium as recited in claim 10 , wherein the data comprises a file, and the malicious process comprises encrypting the file with the key, and the key is specific to the file.

17. The non-transitory storage medium as recited in claim 10 , wherein the malicious process comprises encrypting the data using the key, and the transmit operation transmits the encrypted data and the key to the attacker.

18. The non-transitory storage medium as recited in claim 10 , wherein the intercepting prevents the transmit operation from being performed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2023
From: EZRIELEV, OFIR; ZOHAR, YEHIEL; GEHTMAN, YEVGENI; SHACHAR, TOMER; BALIN, MAXIM
To: DELL PRODUCTS L.P.
Reel/Frame 063256/0654 →
Continuity (1)
Related Publication 20240338472A1 · Oct 10, 2024
References Cited (11)
US 11349855B1 · Amit · 2022 [cited by examiner]
US 11663336B1 · Armangau · 2023 [cited by examiner]
US 20180114020A1 · Hirschberg et al. · 2018 [cited by applicant]
US 20180157834A1 · Continella · 2018 [cited by examiner]
US 20180351969A1 · MacLeod · 2018 [cited by examiner]
US 20190018961A1 · Kostyushko · 2019 [cited by examiner]
US 20190109869A1 · Bailey · 2019 [cited by applicant]
US 20230060606A1 · Dubey · 2023 [cited by examiner]
GB 2627941A · 2022 [cited by examiner]
KR 1020220098952A · 2022 [cited by applicant]
Bajpai. P. et al., “Attacking key management in ransomware,” IT Professional, vol. 22, Issue 2, 2020, pp. 21-27. [cited by applicant]