IP Library › Granted Patent US 12,579,266
Granted Patent B2
US 12,579,266 · App. 19/327,792 · Granted Mar 17, 2026

Ransomware infection detection in filesystems

Inventors: Oscar Chen (Palo Alto, CA); Di Wu (Newark, CA); Benjamin Reisner (San Francisco, CA); Matthew Edward Noe (San Francisco, CA)
Assignee: Rubrik, Inc.
G06F21/565G06F11/1458G06F16/128G06F11/1469G06F21/568G06F2201/84G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,579,266
App. No.
19/327,792
Filed
Sep 12, 2025
Granted
Mar 17, 2026
Kind
B2
Art Unit
2407
USPC
726/23
Abstract

Described herein is a system that detects ransomware infection in filesystems. The system detects ransomware infection by using backup data of machines. The system detects ransomware infection in two stages. In the first stage, the system analyzes a filesystem's behavior. The filesystem's behavior can be obtained by loading the backup data and crawling the filesystem to create a filesystem metadata including information about file operations during a time interval. The filesystem determines a pattern of the file operations and compares the pattern to a normal patter to analyze the filesystem's behavior. If the filesystem's behavior is abnormal, the system proceeds to the second stage to analyze the content of the files to look for signs of encryption in the filesystem. The system combines the analysis of both stages to determine whether the filesystem is infected by ransomware.

Claims (41)

1 . A method, comprising:

accessing a data store to obtain a first set of snapshots corresponding to a machine, each snapshot indicating data of the machine at a corresponding point in time, the first set of snapshots comprising a plurality of snapshots spanning a period of time;

generating metadata indicating operations to one or more files in a filesystem of the machine over time intervals corresponding to the first set of snapshots;

training, using the metadata, a ransomware detection model operative to define a normal pattern of behavior of the filesystem and to detect an infection of the filesystem of the machine by ransomware, wherein the ransomware detection model comprises a first model feature that is based at least in part on the metadata corresponding to the first set of snapshots, and wherein the ransomware detection model further comprises a second model feature that is based at least in part on respective entropies of the one or more files in the filesystem of the machine;

receiving, by the ransomware detection model, a second snapshot of the machine, the second snapshot indicating data of the machine at a corresponding point in time subsequent to the first set of snapshots, wherein the second snapshot indicates operations to one or more files in the filesystem of the machine over a second time interval;

applying the ransomware detection model to the second snapshot to screen for abnormal behavior of the filesystem, wherein the ransomware detection model is operative to assess changes in the filesystem over the second time interval and entropies of one or more files in the filesystem associated with the second time interval, wherein the ransomware detection model is further operative to calculate one or more scores indicating a respective probability that a behavior of the filesystem is anomalous;

comparing the one or more scores to a respective threshold value;

based at least in part on at least one of the one or more scores crossing the respective threshold value, generating a user interface for presenting a determination that the filesystem is infected; and

providing the user interface for display.

2 . The method of claim 1 , wherein the machine is a virtual machine.

3 . The method of claim 1 , wherein the changes in the filesystem are recorded in the metadata, the metadata including a list of entries corresponding to data changes in the filesystem.

4 . The method of claim 1 , wherein the period of time comprises a plurality of time intervals corresponding to the first set of snapshots and wherein the period of time is greater than the second time interval.

5 . The method of claim 1 , wherein the ransomware detection model is operative to generate a combined anomaly score by combining the one or more scores.

6 . The method of claim 1 , further comprising:

training the ransomware detection model using additional training data, the additional training data including at least one of filesystem data of filesystems owned by multiple users, and filesystem data of multiple filesystems owned by a user.

7 . The method of claim 1 , wherein the training of the ransomware detection model is performed in a cloud platform.

8 . The method of claim 1 , wherein the ransomware detection model is hosted in a cloud platform.

9 . The method of claim 1 , wherein the ransomware detection model comprises a first machine learning model and a second machine learning model, wherein the first machine learning model includes the first model feature and is operative to determine whether the behavior of the filesystem is anomalous, wherein the second machine learning model includes the second model feature and is operative to detect a ransomware encryption event.

10 . The method of claim 9 , wherein the ransomware detection model applies the second machine learning model to the second snapshot when the first machine learning model identifies that the filesystem behavior of the machine is anomalous.

11 . An apparatus for data management, comprising:

at least one processor;

memory coupled with the at least one processor; and

instructions stored in the memory and executable by the at least one processor to cause the apparatus to perform operations comprising:

accessing a data store to obtain a first set of snapshots corresponding to a machine, each snapshot indicating data of the machine at a corresponding point in time, the first set of snapshots comprising a plurality of snapshots spanning a period of time;

generating metadata indicating operations to one or more files in a filesystem of the machine over time intervals corresponding to the first set of snapshots;

training, using the metadata, a ransomware detection model operative to define a normal pattern of behavior of the filesystem and to detect an infection of the filesystem of the machine by ransomware, wherein the ransomware detection model comprises a first model feature that is based at least in part on the metadata corresponding to the first set of snapshots, and wherein the ransomware detection model further comprises a second model feature that is based at least in part on respective entropies of the one or more files in the filesystem of the machine;

receiving, by the ransomware detection model, a second snapshot of the machine, the second snapshot indicating data of the machine at a corresponding point in time subsequent to the first set of snapshots, wherein the second snapshot indicates operations to one or more files in the filesystem of the machine over a second time interval;

applying the ransomware detection model to the second snapshot to screen for abnormal behavior of the filesystem, wherein the ransomware detection model is operative to assess changes in the filesystem over the second time interval and entropies of one or more files in the filesystem associated with the second time interval, wherein the ransomware detection model is further operative to calculate one or more scores indicating a respective probability that a behavior of the filesystem is anomalous;

comparing the one or more scores to a respective threshold value;

based at least in part on at least one of the one or more scores crossing the respective threshold value, generating a user interface for presenting a determination that the filesystem is infected; and

providing the user interface for display.

12 . The apparatus of claim 11 , wherein the machine is a virtual machine.

13 . The apparatus of claim 11 , wherein the changes in the filesystem are recorded in the metadata, the metadata including a list of entries corresponding to data changes in the filesystem.

14 . The apparatus of claim 11 , wherein the period of time comprises a plurality of time intervals corresponding to the first set of snapshots and wherein the period of time is greater than the second time interval.

15 . The apparatus of claim 11 , wherein the ransomware detection model is operative to generate a combined anomaly score by combining the one or more scores.

16 . The apparatus of claim 11 , the operations further comprising:

training the ransomware detection model using additional training data, the additional training data including at least one of filesystem data of filesystems owned by multiple users, and filesystem data of multiple filesystems owned by a user.

17 . The apparatus of claim 11 , wherein the training of the ransomware detection model is performed in a cloud platform.

18 . The apparatus of claim 11 , wherein the ransomware detection model is hosted in a cloud platform.

19 . The apparatus of claim 11 , wherein the ransomware detection model comprises a first machine learning model and a second machine learning model, wherein the first machine learning model includes the first model feature and is operative to determine whether the behavior of the filesystem is anomalous, wherein the second machine learning model includes the second model feature and is operative to detect a ransomware encryption event.

20 . The apparatus of claim 19 , wherein the ransomware detection model applies the second machine learning model to the second snapshot when the first machine learning model identifies that the filesystem behavior of the machine is anomalous.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2025
From: CHEN, OSCAR; WU, DI; REISNER, BENJAMIN; NOE, MATTHEW EDWARD
To: RUBRIK, INC.
Reel/Frame 072600/0944 →
Continuity (4)
Continuation 18458466 · Aug 30, 2023
Continuation 17370203 · Jul 8, 2021
Continuation 16049574 · Jul 30, 2018
Related Publication 20260010626A1 · Jan 8, 2026
References Cited (105)
US 6671811B1 · Diep · 2003 [cited by examiner]
US 7181768B1 · Ghosh et al. · 2007 [cited by applicant]
US 7765217B2 · Yamakawa et al. · 2010 [cited by applicant]
US 7802300B1 · Liu et al. · 2010 [cited by applicant]
US 7934103B2 · Kidron · 2011 [cited by applicant]
US 7941855B2 · Sung et al. · 2011 [cited by applicant]
US 7962956B1 · Liao et al. · 2011 [cited by applicant]
US 9116722B2 · Shenfield et al. · 2015 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9678981B1 · Taylor · 2017 [cited by examiner]
US 9734337B1 · Patton et al. · 2017 [cited by applicant]
US 9779240B2 · Feroz et al. · 2017 [cited by applicant]
US 10032033B2 · Gu et al. · 2018 [cited by applicant]
US 10073856B1 · Cooper · 2018 [cited by examiner]
US 10133866B1 · Kumar et al. · 2018 [cited by applicant]
US 10229269B1 · Patton et al. · 2019 [cited by applicant]
US 10230745B2 · Singh · 2019 [cited by examiner]
US 10572993B2 · Tanaka et al. · 2020 [cited by applicant]
US 10609066B1 · Nossik et al. · 2020 [cited by applicant]
US 10839072B2 · Pohl · 2020 [cited by examiner]
US 10867040B2 · Gibbons et al. · 2020 [cited by applicant]
US 10929031B2 · Sapuntzakis et al. · 2021 [cited by applicant]
US 10992699B1 · Sites et al. · 2021 [cited by applicant]
US 11086987B2 · Brown · 2021 [cited by applicant]
US 11120131B2 · Chen et al. · 2021 [cited by applicant]
US 11146581B2 · Lotem et al. · 2021 [cited by applicant]
US 11170104B1 · Stickle et al. · 2021 [cited by applicant]
US 11449607B2 · Annen et al. · 2022 [cited by applicant]
US 11522889B2 · Annen et al. · 2022 [cited by applicant]
US 11606379B1 · Pratt et al. · 2023 [cited by applicant]
US 11657152B2 · Kraemer et al. · 2023 [cited by applicant]
US 11770391B1 · Bakthavatchalam et al. · 2023 [cited by applicant]
US 20040111632A1 · Halperin · 2004 [cited by examiner]
US 20060074824A1 · Li · 2006 [cited by applicant]
US 20080010683A1 · Baddour et al. · 2008 [cited by applicant]
US 20080127346A1 · Oh et al. · 2008 [cited by applicant]
US 20080209138A1 · Sheldon et al. · 2008 [cited by applicant]
US 20090055604A1 · Lemar et al. · 2009 [cited by applicant]
US 20100125911A1 · Bhaskaran · 2010 [cited by applicant]
US 20130305373A1 · Lim et al. · 2013 [cited by applicant]
US 20140013434A1 · Ranum et al. · 2014 [cited by applicant]
US 20150106652A1 · Mei et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150264077A1 · Berger et al. · 2015 [cited by applicant]
US 20160012227A1 · Tuvell et al. · 2016 [cited by applicant]
US 20160239661A1 · Kawauchi · 2016 [cited by applicant]
US 20160292418A1 · Wojnowicz et al. · 2016 [cited by applicant]
US 20170053118A1 · Malkov et al. · 2017 [cited by applicant]
US 20170063906A1 · Muddu et al. · 2017 [cited by applicant]
US 20170103334A1 · Gusev et al. · 2017 [cited by applicant]
US 20170140156A1 · Gu et al. · 2017 [cited by applicant]
US 20170177867A1 · Crofton et al. · 2017 [cited by applicant]
US 20170180394A1 · Crofton et al. · 2017 [cited by applicant]
US 20170195353A1 · Taylor et al. · 2017 [cited by applicant]
US 20170214708A1 · Gukal et al. · 2017 [cited by applicant]
US 20170315979A1 · Boucher et al. · 2017 [cited by applicant]
US 20170339178A1 · Mahaffey et al. · 2017 [cited by applicant]
US 20180034835A1 · Iwanir et al. · 2018 [cited by applicant]
US 20180121650A1 · Brown · 2018 [cited by applicant]
US 20180173874A1 · Muttik et al. · 2018 [cited by applicant]
US 20180211039A1 · Tamir et al. · 2018 [cited by applicant]
US 20180307839A1 · Bhave et al. · 2018 [cited by applicant]
US 20190012458A1 · Fausak et al. · 2019 [cited by applicant]
US 20190042744A1 · Rajasekharan et al. · 2019 [cited by applicant]
US 20190163763A1 · Pandey et al. · 2019 [cited by applicant]
US 20190171966A1 · Rangasamy · 2019 [cited by applicant]
US 20190235973A1 · Brewer et al. · 2019 [cited by applicant]
US 20190236272A1 · Piatt · 2019 [cited by applicant]
US 20190251259A1 · Stepanek et al. · 2019 [cited by applicant]
US 20190286534A1 · O'Mahony et al. · 2019 [cited by applicant]
US 20190332766A1 · Guri et al. · 2019 [cited by applicant]
US 20190332769A1 · Fralick et al. · 2019 [cited by applicant]
US 20190347418A1 · Strogov et al. · 2019 [cited by applicant]
US 20190347578A1 · Bolding et al. · 2019 [cited by applicant]
US 20190354850A1 · Watson et al. · 2019 [cited by applicant]
US 20200004808A1 · Yao et al. · 2020 [cited by applicant]
US 20200004962A1 · Araujo et al. · 2020 [cited by applicant]
US 20200042703A1 · Herman et al. · 2020 [cited by applicant]
US 20200076812A1 · Spurlock et al. · 2020 [cited by applicant]
US 20200089886A1 · Oetken · 2020 [cited by applicant]
US 20200177612A1 · Kras et al. · 2020 [cited by applicant]
US 20200279043A1 · Thornton et al. · 2020 [cited by applicant]
US 20200311595A1 · Chen et al. · 2020 [cited by applicant]
US 20200342652A1 · Rowell et al. · 2020 [cited by applicant]
US 20210034994A1 · Stocker et al. · 2021 [cited by applicant]
US 20210044604A1 · Annen et al. · 2021 [cited by applicant]
US 20210089957A1 · Ermans et al. · 2021 [cited by applicant]
US 20210374027A1 · Joglekar et al. · 2021 [cited by applicant]
US 20220247766A1 · Annen et al. · 2022 [cited by applicant]
US 20220318203A1 · Kotwal et al. · 2022 [cited by applicant]
US 20230004749A1 · Jaganathan et al. · 2023 [cited by applicant]
US 20230026368A1 · Silverstein · 2023 [cited by applicant]
US 20230105500A1 · Annen et al. · 2023 [cited by applicant]
US 20240430278A1 · Tyborowski et al. · 2024 [cited by applicant]
CA 2984007A1 · 2018 [cited by applicant]
CN 101512522A · 2009 [cited by applicant]
CN 102799500A · 2012 [cited by applicant]
CN 106845223A · 2017 [cited by applicant]
EP 3374922B1 · 2019 [cited by applicant]
KR 101772439B1 · 2017 [cited by applicant]
KR 101828600B1 · 2018 [cited by applicant]
WO WO2005047862A2 · 2005 [cited by examiner]
WO 2020028152A1 · 2020 [cited by applicant]
International Preliminary Report on Patentability received for PCT Patent Application No. PCT/US19/43563, mailed on Feb. 11, 2021, 8 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US19/43563, mailed on Oct. 29, 2019, 9 pages. [cited by applicant]