IP Library › Granted Patent US 12,541,595
Granted Patent B2
US 12,541,595 · App. 18/194,725 · Granted Feb 3, 2026

Ransomware detection via detecting system calls pattern in encryption phase

Inventors: Ofir Ezrielev (Be'er Sheba, IL); Yehiel Zohar (Sderot, IL); Yevgeni Gehtman (Modi'in, IL); Tomer Shachar (Beer-Sheva, IL); Maxim Balin (Gan-Yavne, IL)
Assignee: Dell Products L.P.
G06F21/566G06F21/565G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,541,595
App. No.
18/194,725
Granted
Feb 3, 2026
Kind
B2
Abstract

System calls performed by processes in a computing system are monitored and scored. The score is maintained over a time window. When the score exceeds a threshold score for a process in the time window, the process is determined to be a malware process and a protective operation is performed.

Claims (32)

1 . A method comprising:

labeling files, by a computing system, that are believed to be valuable to a malware process with a valuable label;

monitoring system call patterns to files performed by a process operating in the computing system, which includes detecting patterns by a model trained with system calls made by known malware, wherein the model is configured to account for pattern variations in the call patterns of processes;

generating a score for the process based on system call patterns made by the process, wherein each score represents a likelihood of the process being a malware process;

increasing the score of the process when a core pattern is detected for the process or when a system call pattern that includes the core pattern for the process is detected, wherein the core pattern includes a specified series of system calls;

increasing the score of the process when a file targeted by the system calls made by the process have the valuable label, wherein the score for the file is different when the file is not labeled with the valuable label;

determining that a process is the malware process when the score of the process exceeds a threshold score; and

performing a protective operation in the computing system.

2 . The method of claim 1 , wherein the series of system calls of the core pattern include an open file call, a read file call, a write file call, and a close file call.

3 . The method of claim 1 , further comprising adjusting the score of the process for each system call performed by the process.

4 . The method of claim 1 , wherein the score of the process is based on the system call patterns performed within a time window.

5 . The method of claim 1 , further comprising tracking accesses by associating the accesses of the process while accounting for system calls that cause changes to the files that are not indicative of values of the files.

6 . The method of claim 1 , further comprising categorizing the files based on how the computing system presumes that the malware values the files, wherein a first category includes files labeled as valuable.

7 . The method of claim 6 , wherein categories include one or more of financial, valuable, personal, confidential, or medical.

8 . The method of claim 6 , where the processes is associated with an overall score and a score for each of the categories.

9 . The method of claim 8 , wherein the score of the process is a combination of the overall score and the scores for the categories.

10 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

labeling files, by a computing system, that are believed to be valuable to a malware process with a valuable label;

monitoring system call patterns to files performed by a process operating in the computing system, which includes detecting patterns by a model trained with system calls made by known malware, wherein the model is configured to account for pattern variations in the call patterns of processes;

generating a score for the process based on system call patterns made by the process, wherein each score represents a likelihood of the process being a malware process;

increasing the score of the process when a core pattern is detected for the process or when a system call pattern that includes the core pattern for the process is detected, wherein the core pattern includes a specified series of system calls;

increasing the score of the process when a file targeted by the system calls made by the process have the valuable label, wherein the score for the file is different when the file is not labeled with the valuable label;

determining that a process is the malware process when the score of the process exceeds a threshold score; and

performing a protective operation in the computing system.

11 . The non-transitory storage medium of claim 10 , wherein the series of system calls of the core pattern include an open file call, a read file call, a write file call, and a close file call.

12 . The non-transitory storage medium of claim 10 , further comprising adjusting the score of the process for each system call performed by the process.

13 . The non-transitory storage medium of claim 10 , wherein the score of the process is based on the system call patterns performed within a time window.

14 . The non-transitory storage medium of claim 10 , further comprising tracking accesses by associating the accesses of the process while accounting for system calls that cause changes to the files that are not indicative of values of the files.

15 . The non-transitory storage medium of claim 10 , further comprising categorizing the files based on how the computing system presumes that the malware values the files, wherein a first category includes files labeled as valuable.

16 . The non-transitory storage medium of claim 15 , wherein categories include one or more of financial, valuable, personal, confidential, or medical.

17 . The non-transitory storage medium of claim 15 , where each of the processes is associated with an overall score and a score for each of the categories.

18 . The non-transitory storage medium of claim 17 , wherein the score of the process is a combination of the overall score and the scores for the categories.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: EZRIELEV, OFIR; ZOHAR, YEHIEL; GEHTMAN, YEVGENI; SHACHAR, TOMER; BALIN, MAXIM
To: DELL PRODUCTS L.P.
Reel/Frame 063201/0720 →
Continuity (1)
Related Publication 20240330461A1 · Oct 3, 2024
References Cited (7)
US 10505960B2 · Kong · 2019 [cited by examiner]
US 20140282814A1 · Barney · 2014 [cited by examiner]
US 20180082060A1 · Tolpin · 2018 [cited by examiner]
US 20230229761A1 · Laplante · 2023 [cited by examiner]
US 20240346143A1 · Ezrielev · 2024 [cited by examiner]
KR 20200067044A · 2020 [cited by examiner]
WO WO2022221202A1 · 2022 [cited by examiner]