IP Library Granted Patent US 12,445,484
Granted Patent B2
US 12,445,484 · App. 18/128,789 · Granted Oct 14, 2025

Inline ransomware detection via server message block (SMB) traffic

Inventors: Zhibin Zhang (Santa Clara, CA); Mengying Jiang (Campbell, CA); Bo Qu (Saratoga, CA); Sultanbek Omurzakov (Los Gatos, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1466H04L63/1416H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,484
App. No.
18/128,789
Granted
Oct 14, 2025
Kind
B2
Abstract

Inline detection of ransomware attacks using network traffic, such as server message block (SMB) traffic, is disclosed. A network communication between a client and a server is received. A determination is made, using the received network traffic, that a ransomware attack is being attempted against the server. In response to detecting the attempted ransomware attack, a remedial action is performed.

Claims (28)

1. A system, comprising:

a processor configured to:

receive, at a firewall appliance interposed between a client and a server, a server message block (SMB) network communication between the client and the server as part of a session between the client and the server;

determine, at the firewall appliance, and using the received SMB network communication, an attempted creation of a ransom note associated with an attempted ransomware attack on the server by the client, wherein the determining includes detecting at least one of a file creation or file open request made by the client to the server and applying at least one of a trained model or a set of rules to identify the attempted creation on the server by the client of the ransom note; and

in response to detecting the attempted ransomware attack, perform a remedial action, including by terminating, by the firewall appliance, the session between the client and the server; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the processor is further configured to detect a file encryption of a file on the server and initiated by the client.

3. The system of claim 1 , wherein the model was trained on ransomware notes.

4. The system of claim 1 , wherein the applying includes using a set of heuristics.

5. The system of claim 2 , wherein detecting the file encryption includes detecting a file entropy change.

6. The system of claim 2 , wherein the file encryption is a partial encryption.

7. The system of claim 1 , wherein the applying includes forwarding, by the firewall appliance, at least a portion of the network communication to a remote device.

8. The system of claim 1 , wherein performing the remedial action includes generating an alert.

9. A method, comprising:

receiving, at a firewall appliance interposed between a client and a server, a server message block (SMB) network communication between the client and the server as part of a session between the client and the server;

determining, at the firewall appliance, and using the received SMB network communication, an attempted creation of a ransom note associated with an attempted ransomware attack on the server by the client, wherein the determining includes detecting at least one of a file creation or file open request made by the client to the server and applying at least one of a trained model or a set of rules to identify the attempted creation on the server by the client of the ransom note; and

in response to detecting the attempted ransomware attack, performing a remedial action, including by terminating, by the firewall appliance, the session between the client and the server.

10. The method of claim 9 , further comprising detecting a file encryption of a file on the server and initiated by the client.

11. The method of claim 10 , wherein detecting the file encryption includes detecting a file entropy change.

12. The method of claim 10 , wherein the file encryption is a partial encryption.

13. The method of claim 10 , wherein the model was trained on ransomware notes.

14. The method of claim 9 , wherein the applying includes using a set of heuristics.

15. The method of claim 9 , wherein the applying includes forwarding, by the firewall appliance, at least a portion of the network communication to a remote device.

16. The method of claim 9 , wherein performing the remedial action includes generating an alert.

17. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

receiving, at a firewall appliance interposed between a client and a server, a server message block (SMB) network communication between the client and the server as part of a session between the client and the server;

determining, at the firewall appliance, and using the received SMB network communication, an attempted creation of a ransom note associated with an attempted ransomware attack on the server by the client, wherein the determining includes detecting at least one of a file creation or file open request made by the client to the server and applying at least one of a trained model or a set of rules to identify the attempted creation on the server by the client of the ransom note; and

in response to detecting the attempted ransomware attack, performing a remedial action, including by terminating, by the firewall appliance, the session between the client and the server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2023
From: ZHANG, ZHIBIN; JIANG, MENGYING; QU, BO; OMURZAKOV, SULTANBEK
To: PALO ALTO NETWORKS, INC.
Reel/Frame 064476/0135 →
Continuity (1)
Related Publication 20240333759A1 · Oct 3, 2024
References Cited (13)
US 10469525B2 · Hittel · 2019 [cited by examiner]
US 10554688B1 · Wueest · 2020 [cited by examiner]
US 10628585B2 · Tamir · 2020 [cited by examiner]
US 11349855B1 · Amit · 2022 [cited by examiner]
US 11374964B1 · Agrawal · 2022 [cited by examiner]
US 20180351969A1 · MacLeod · 2018 [cited by examiner]
US 20190102533A1 · Sagar · 2019 [cited by examiner]
US 20210152595A1 · Hansen · 2021 [cited by examiner]
US 20220060498A1 · Head, Jr. · 2022 [cited by examiner]
US 20220231991A1 · Blum Shem-Tov · 2022 [cited by examiner]
US 20220329442A1 · Bulusu · 2022 [cited by examiner]
US 20230007023A1 · Andrabi · 2023 [cited by examiner]
Lemmou et al., In-Depth Analysis of Ransom Note Files, Computers, 2021, https://doi.org/10.3390/ computers 10110145. [cited by applicant]