IP Library Granted Patent US 12,468,805
Granted Patent B2
US 12,468,805 · App. 18/617,424 · Granted Nov 11, 2025

Detecting ransomware

Inventors: Kunal Mehta (Hillsboro, OR); Sherin Mary Mathews (Santa Clara, CA); Carl D. Woodward (Santa Clara, CA); Celeste R. Fralick (Lubbock, TX); Jonathan B. King (Hillsboro, OR)
Assignee: McAfee, LLC
G06F21/56G06N3/08G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,468,805
App. No.
18/617,424
Granted
Nov 11, 2025
Kind
B2
Abstract

There is disclosed in one example a ransomware mitigation engine, including: a processor; a convolutional neural network configured to provide file type identification (FTI) services including: identifying an access operation of a file as a write to the file or newly creating the file; computing a byte correlation factor for the file; classifying the file as belonging to a file type; determining with a screening confidence that the file type is correct for the file; determining that the screening confidence is below a screening confidence threshold; and circuitry and logic to provide heuristic analysis including: receiving notification that the confidence is below the confidence threshold; performing a statistical analysis of the file to determine a difference between an expected value and a computed value; determining from the difference, with a detection confidence, that the file has been compromised; and identifying the file as having been compromised by a ransomware attack.

Claims (35)

1 . An apparatus, comprising:

a memory that stores an instruction; and

a processor configured to execute the instruction to

determine a file type of a file,

identify an access operation on the file,

perform a statistical analysis of the file to determine a difference between an expected byte distribution value of the file type and a computed byte distribution value of the file, and

performing a remediation at least in part based on the access operation.

2 . The apparatus of claim 1 , wherein the statistical analysis is performed at least in part based on a determination that a screening confidence that the file type is correct for the file is below a screening confidence threshold.

3 . The apparatus of claim 1 , wherein the access operation is a write to the file, and the remediation includes reverting the file.

4 . The apparatus of claim 1 , wherein the statistical analysis is at least in part based on a plurality of bytes from the start or the end of the file.

5 . The apparatus of claim 1 , wherein the processor is further configured to extract a file header or extension associated with the type of the file.

6 . The apparatus of claim 1 , wherein the access operation is a deletion of the file, and the remediation includes restoring the file from a backup file of the file.

7 . The apparatus of claim 1 , wherein the access operation is a creation of the file, and the remediation includes killing a process that created the file.

8 . A non-transitory, computer-readable medium having stored thereon instructions that, when executed, cause a processor to perform operations comprising:

determining a file type of a file;

identifying an access operation on the file;

performing a statistical analysis of the file to determine a difference between an expected byte distribution value of the file type and a computed byte distribution value of the file; and

performing a remediation at least in part based on the access operation.

9 . The medium of claim 8 , wherein the statistical analysis is performed at least in part based on a determination that a screening confidence that the file type is correct for the file is below a screening confidence threshold.

10 . The medium of claim 8 , wherein the access operation is a write to the file, and the remediation includes reverting the file.

11 . The medium of claim 8 , wherein the statistical analysis is at least in part based on a plurality of bytes from the start or the end of the file.

12 . The medium of claim 8 , the operations further comprising:

extracting a file header or extension associated with the type of the file.

13 . The medium of claim 8 , wherein the access operation is a deletion of the file, and the remediation includes restoring the file from a backup file of the file.

14 . The medium of claim 8 , wherein the access operation is a creation of the file, and the remediation includes killing a process that created the file.

15 . A method, comprising:

determining a file type of a file;

identifying an access operation on the file;

performing a statistical analysis of the file to determine a difference between an expected byte distribution value of the file type and a computed byte distribution value of the file; and

performing a remediation at least in part based on the access operation.

16 . The method of claim 15 , wherein the access operation is a write to the file, and the remediation includes reverting the file.

17 . The method of claim 15 , wherein the statistical analysis is at least in part based on a plurality of bytes from the start or the end of the file.

18 . The method of claim 15 , wherein the processor is further configured to extract a file header or extension associated with the type of the file.

19 . The method of claim 15 , wherein the access operation is a deletion of the file, and the remediation includes restoring the file from a backup file of the file.

20 . The method of claim 15 , wherein the access operation is a creation of the file, and the remediation includes killing a process that created the file.

Continuity (4)
Continuation 17867259 · Jul 18, 2022
Continuation 17063024 · Oct 5, 2020
Continuation 16142316 · Sep 26, 2018
Related Publication 20240346139A1 · Oct 17, 2024
References Cited (24)
US 5987610A · Franczek et al. · 1999 [cited by applicant]
US 6073142A · Geiger et al. · 2000 [cited by applicant]
US 6460050B1 · Pace et al. · 2002 [cited by applicant]
US 7392544B1 · Pavlyushchik · 2008 [cited by applicant]
US 7506155B1 · Stewart et al. · 2009 [cited by applicant]
US 9910986B1 · Saxe et al. · 2018 [cited by applicant]
US 10140553B1 · Vasisht et al. · 2018 [cited by applicant]
US 20090013405A1 · Schipka · 2009 [cited by applicant]
US 20090023405A1 · Forstner · 2009 [cited by examiner]
US 20120150793A1 · Carroll · 2012 [cited by examiner]
US 20140298470A1 · Yablokov · 2014 [cited by examiner]
US 20150248556A1 · Sickendick et al. · 2015 [cited by applicant]
US 20170223031A1 · Gu et al. · 2017 [cited by applicant]
US 20180232508A1 · Kursun · 2018 [cited by applicant]
US 20180248896A1 · Challita et al. · 2018 [cited by applicant]
US 20180349796A1 · Gibbs et al. · 2018 [cited by applicant]
US 20190236273A1 · Saxe et al. · 2019 [cited by applicant]
US 20200042645A1 · Douthit · 2020 [cited by examiner]
KR 1020160005489A · 2016 [cited by applicant]
Gharib, Amirhoessin et al “DNA-Droid: A Real-Time Android Ransomware Detection Framework” Jul. 26, 2017 (Jul. 26, 2017), Advances Inbiometrics : International Conference, ICB 2007, Seoul, Korea, Aug. 27-29, 2007; Procee… [cited by applicant]
International Preliminary Report on Patentability and Written Opinion in International Patent Application PCT/US2019/052344 dated Apr. 8, 2021, 7 pages. [cited by applicant]
International Search Report and Written Opinion in International Application No. PCT/US2019/052344 dated Jan. 14, 2020, 10 pages. [cited by applicant]
Supplementary Extended European Search Report in EP Patent Application EP19866168 dated May 10, 2022, 9 pages. [cited by applicant]
Aug. 12, 2025 EPO Extended European Search Report from EP Application No. 25176126.8; 9 pages. [cited by applicant]