IP Library › Granted Patent US 12,437,070
Granted Patent B2
US 12,437,070 · App. 18/194,624 · Granted Oct 7, 2025

Ransomware detection via monitoring open file or process

Inventors: Ofir Ezrielev (Be'er Sheba, IL); Yeh'iel Zohar (Sderot, IL); Yevgeni Gehtman (Modi'in, IL); Tomer Shachar (Beer-Sheva, IL); Maxim Balin (Gan-Yavne, IL)
Assignee: Dell Products L.P.
G06F21/566G06F21/562H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,437,070
App. No.
18/194,624
Filed
Apr 1, 2023
Granted
Oct 7, 2025
Kind
B2
Art Unit
2433
USPC
726/23
Abstract

A bait file owned by a bait process is created and locked in a computing system. Attempts or access the bait file or kill the bait process are detected. The process attempting to access the bait file or kill the bait process is viewed as malicious and protective operations are performed in the computing system.

Claims (26)

1. A method comprising:

monitoring a bait file stored in a storage system of a computing system, wherein the bait file is owned by a bait process such that the bait file is locked by a locking process that is not a malware process, wherein the monitoring the bait file includes monitoring the bait process;

detecting an access attempt to the bait file by a process operating in the computing system;

determining that the process attempting to access the locked bait file is a malware process, wherein the access attempt includes an attempt to remove a lock on the bait file or kill the bait process; and

performing a protection operation on the malware process.

2. The method of claim 1 , further comprising creating the bait file in the storage system.

3. The method of claim 2 , further comprising locking the bait file in the storage system by a locking process.

4. The method of claim 1 , further comprising detecting the access attempt by a malware detection engine operating in a kernel space of the computing system.

5. The method of claim 1 , wherein the protection operation comprises blocking the process.

6. The method of claim 1 , wherein the protection operation comprises terminating the process.

7. The method of claim 1 , wherein the protection operation comprises generating an infected snapshot and allowing the process to operate in a forensic environment, wherein the process is blocked in the computing system.

8. The method of claim 1 , wherein the access attempt comprises accessing the bait file by any process other than the bait process or interfering with the bait process.

9. The method of claim 1 , further comprising configuring the bait file or attributes of the bait file such that the bait file appears valuable in the computing system to cause the process to perform the access attempt.

10. A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

monitoring a bait file stored in a storage system of a computing system, wherein the bait file is owned by a bait process such that the bait file is locked by a locking process that is not a malware process, wherein the monitoring the bait file includes monitoring the bait process;

detecting an access attempt to the bait file by a process operating in the computing system;

determining that the process attempting to access the locked bait file is a malware process, wherein the access attempt includes an attempt to remove a lock on the bait file or kill the bait process; and

performing a protection operation on the malware process.

11. The non-transitory storage medium of claim 10 , further comprising creating the bait file in the storage system.

12. The non-transitory storage medium of claim 11 , further comprising locking the bait file in the storage system by a locking process.

13. The non-transitory storage medium of claim 10 , further comprising detecting the access attempt by a malware detection engine operating in a kernel space of the computing system.

14. The non-transitory storage medium of claim 10 , wherein the protection operation comprises blocking the process.

15. The non-transitory storage medium of claim 10 , wherein the protection operation comprises terminating the process.

16. The non-transitory storage medium of claim 10 , wherein the protection operation comprises generating an infected snapshot and allowing the process to operating operate in a forensic environment, wherein the process is blocked in the computing system.

17. The non-transitory storage medium of claim 10 , wherein the access attempt comprises accessing the bait file by any process other than the bait process or interfering with the bait process.

18. The non-transitory storage medium of claim 10 , further comprising configuring the bait file or attributes of the bait file such that the bait file appears valuable in the computing system to cause the process to perform the access attempt.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2023
From: EZRIELEV, OFIR; ZOHAR, YEH'IEL; GEHTMAN, YEVGENI; SHACHAR, TOMER; BALIN, MAXIM
To: DELL PRODUCTS L.P.
Reel/Frame 063198/0499 →
Continuity (1)
Related Publication 20240330460A1 · Oct 3, 2024
References Cited (26)
US 9740870B1 · Shepard · 2017 [cited by applicant]
US 10503904B1 · Singh · 2019 [cited by examiner]
US 10963583B1 · Shimony · 2021 [cited by applicant]
US 12175124B2 · Strathman et al. · 2024 [cited by applicant]
US 20020162017A1 · Sorkin et al. · 2002 [cited by applicant]
US 20070271614A1 · Capalik · 2007 [cited by applicant]
US 20090241187A1 · Troyansky · 2009 [cited by applicant]
US 20170206353A1 · Jai et al. · 2017 [cited by applicant]
US 20170324755A1 · Dekel · 2017 [cited by examiner]
US 20180018458A1 · Schmugar · 2018 [cited by examiner]
US 20180189490A1 · Maciejak et al. · 2018 [cited by applicant]
US 20190109870A1 · Bedhapudi et al. · 2019 [cited by applicant]
US 20190114439A1 · De et al. · 2019 [cited by applicant]
US 20200106808A1 · Schütz · 2020 [cited by examiner]
US 20210012002A1 · Rosenthal · 2021 [cited by applicant]
US 20210117543A1 · Araujo · 2021 [cited by examiner]
US 20210182392A1 · Hargrove · 2021 [cited by applicant]
US 20220083645A1 · Kanai · 2022 [cited by applicant]
US 20230231881A1 · Radhakrishnan et al. · 2023 [cited by applicant]
US 20240330447A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240333764A1 · Ezrielev et al. · 2024 [cited by applicant]
BR 112018070251B1 · 2023 [cited by examiner]
CN 106650423A · 2017 [cited by examiner]
‘Royal Ransomware’, Vedere Labs, Dated Jan. 10, 2023, 7 pages (Year: 2023). [cited by applicant]
LockFileEx—Microsoft Learn, Dated Oct. 6, 2023, 4 pages (Year: 2023). [cited by applicant]
(Salem, Eli et al., 'Royal Rumble: Analysis of Royal Ransomware', Cyberreason, published Dec. 16, 2022) (Year: 2022). [cited by applicant]