IP Library › Granted Patent US 12,651,066
Granted Patent B2
US 12,651,066 · App. 18/201,654 · Granted Jun 9, 2026

Ransomware mitigation system and method for mitigating a ransomware attack

Inventor: Christopher Martinic (Cherrybrook, AU)
G06F21/568G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,651,066
App. No.
18/201,654
Granted
Jun 9, 2026
Kind
B2
Abstract

A ransomware mitigation system and corresponding methods are provided. The ransomware mitigation system monitors the rate of modification of files on computing devices to determine whether the monitored rate of modifications exceeds a predetermined threshold. If the threshold is exceeded, then the ransomware mitigation system actuates a forced shutdown of the computing device and/or a forced disconnection of the network connection to the computing device. The ransomware mitigation system includes a software monitoring portion as well as a hardware switching unit. The software monitoring portion is in synchronous bidirectional communication with the hardware switching unit on a separate network. If the software monitoring portion is shutdown then the hardware unit actuates the shutdown and/or disconnection of the computing device(s). The hardware unit includes a hardware lock that requires physical presence of a person to allow for maintenance.

Claims (57)

1 . A ransomware mitigation system for mitigating damage done to one or more computing devices connected to a network from a ransomware attack, the ransomware mitigation system comprising:

a monitoring portion comprising:

digital storage media configured for storing data and/or instructions;

a processor operationally connected to the digital storage media and configured to be directed by instructions; and

a monitoring transceiver operably connected to the processor for transmitting and/or receiving digital information;

wherein the processor is configured to be guided by the instructions to carry out the steps of:

monitoring a plurality of digital files on a network of at least one computing device for the rate of modifications carried out on the plurality of digital files;

determining whether the monitored rate of modifications meets a predetermined activity threshold; and

maintaining bidirectional synchronous communication with a shutdown switch on a dedicated communications line by transmitting a confirmation signal, and

at least one shutdown switch configured for:

shutting down, in a shutdown event, one or more selected from:

power to the at least one or more computing devices, and

network communications to the at least one or more computing devices, and

wherein the monitoring transceiver is configured for independent communication with the shutdown switch on a network independent of the network traffic on the network that the one or more computing devices are connected to, and

wherein the shutdown switch is configured to actuate a shutdown event if an expected confirmation signal is not received as part of the bidirectional synchronous communication between the at least one or more shutdown switches and the monitoring portion.

2 . The ransomware mitigation system as claimed in claim 1 , wherein the processor is configured to be guided by the instructions to carry out the step of:

allocating a whitelist of shutdown files that are part of the shutdown process and only allowing whitelisted shutdown files to operate on actuation of the forced shutdown; and

preventing modification of the whitelisted files during the forced shutdown of the one or more computing devices.

3 . The ransomware mitigation system as claimed in claim 1 , wherein the processor is configured to be guided by the instructions to carry out the step of:

actuating a forced shutdown of the one or more computing devices by actuating one or more shutdown switches, wherein actuation of the shutdown switch shuts off power to at least one or more of the one or more computing devices.

4 . The ransomware mitigation system as claimed in claim 1 , wherein the processor is configured to be guided by the instructions to carry out the step of:

actuating a forced shutdown of one or more network communications devices in a network connecting the one or more computing devices by actuating at least one or more shutdown switches, wherein actuation of the at least one or more shutdown switches shuts off power to at least one or more of the one or more network communications devices.

5 . The ransomware mitigation system as claimed in claim 1 , wherein the processor is configured to be guided by the instructions to carry out the step of:

determining the network location of the computing devices on which the rate of file modification has exceeded the threshold (the “affected computing devices”).

6 . The ransomware mitigation system as claimed in claim 1 , wherein the ransomware mitigation system includes a hardware lock.

7 . The ransomware mitigation system as claimed in claim 6 , wherein the hardware lock is configured for being operated by a hardware key between

an unlocked condition; and

a locked condition.

8 . The ransomware mitigation system as claimed in claim 7 , wherein the processor is configured to be guided by the instructions to carry out the step of:

receiving a request for modification of the system files of the ransomware mitigation system;

determining whether the hardware lock is in its unlocked condition; and

only allowing the processing of the request for modification of the system files of the ransomware mitigation system in the event that the hardware lock is in its unlocked condition.

9 . The ransomware mitigation system as claimed in claim 1 , wherein the shutdown switch includes a shutdown switch transceiver configured for communicating with one or more selected from the monitoring transceiver and with one or more shutdown switch transceivers on other similar shutdown switches.

10 . The ransomware mitigation system as claimed in claim 9 , wherein the shutdown switch transceiver is configured for communicating with one or more selected from the monitoring transceiver and with one or more shutdown switch transceivers on other similar shutdown switches on a network independent of the network that the computing devices are connected to.

11 . The ransomware mitigation system as claimed in claim 9 , wherein the shutdown switch transceiver is configured for receiving an actuation signal from the monitoring transceiver.

12 . The ransomware mitigation system as claimed in claim 11 , wherein the shutdown switch is configured to open and close or close one or more electrical circuits on receiving the actuation signal.

13 . The ransomware mitigation system as claimed in claim 9 , wherein the shutdown switch transceiver is configured for receiving a synchronised confirmation signal from the monitoring transceiver at regular intervals.

14 . The ransomware mitigation system as claimed in claim 13 , wherein the shutdown switch is configured for opening and/or closing the electrical circuit in the event that a confirmation signal is not received at an expected interval.

15 . The ransomware mitigation system as claimed in claim 13 , wherein the shutdown switch is configured for opening and/or closing the electrical circuit in the event that a confirmation signal is not received continuously.

16 . The ransomware mitigation system as claimed in claim 1 , wherein the shutdown switch includes a switch processor and switch digital storage media configured for storing one or more selected from data and software instructions, and the switch processor is configured for being directed by the switch software instructions to

open and/or close the electrical circuit at a switching device configured for switching one or more selected from:

a power connection to the one or more computing devices; and

a network connection of the one or more computing devices.

17 . A method of mitigating damage done to one or more computing devices on a network connection from a ransomware attack, the method being carried out on an electronic device and comprising the steps of:

Monitoring, by a monitoring portion, a plurality of digital files on a network of at least one or more computing devices for the rate of modifications carried out on the plurality of digital files in order to determine whether the monitored rate of modifications meets a predetermined activity threshold;

and

maintaining bidirectional synchronous communication between the monitoring portion and at least one shut down switch on a dedicated communications line on a network independent of the network traffic on the network that the at least one or more computing devices are connected to by sending confirmation signals between the monitoring portion and the shutdown switch; and

in the event of the shutdown switch not receiving an expected confirmation signal as part of the bidirectional synchronous communication between the at least one or more shutdown switches and the monitoring portion, actuating by the shutdown switch of one or more selected from:

a forced shutdown of the one or more computing devices; and

a forced disconnection of the network connection of the one or more computing devices.

18 . The ransomware mitigation system as claimed in claim 1 , wherein the monitoring portion is configured to actuate a shutdown event in at least one of the at least one or more shutdown switches upon determining that the monitored rate of modifications meets a predetermined activity threshold.

19 . A tamper prevention system for preventing the likelihood of tampering with a ransomware mitigation system by ransomware, the tamper prevention system comprising:

a monitoring portion configured for monitoring activities relating to one or more files on at least one or more computing devices;

a switching device configured for shutting down, in a shutdown event, one or more selected from:

power to the at least one or more computing devices, and

network communications with the at least one or more computing devices; and

wherein the switching device and the monitoring portion are configured for bidirectional synchronous communication with each other on a network independent of the network traffic on the network that the one or more computing devices are connected to, and wherein at least one or more selected from the switching device and the monitoring portion are configured for actuating a shutdown event in the event that synchronous communication between the monitoring portion and the switching device is not synchronized.

Priority Claims (1)
AU 2020904351 · Nov 24, 2020 · national
Continuity (2)
Continuation PCTAU2021051399 · Nov 24, 2021
Related Publication 20230297678A1 · Sep 21, 2023
References Cited (24)
US 5751950A · Crisan · 1998 [cited by examiner]
US 8910238B2 · Lukacs · 2014 [cited by examiner]
US 9888032B2 · Dekel · 2018 [cited by examiner]
US 10311234B2 · Bhashkar · 2019 [cited by examiner]
US 10503904B1 · Singh · 2019 [cited by examiner]
US 10607009B2 · Dahan · 2020 [cited by examiner]
US 10831893B2 · Schmugar · 2020 [cited by examiner]
US 20160219024A1 · Verzun et al. · 2016 [cited by applicant]
US 20160378988A1 · Bhashkar et al. · 2016 [cited by applicant]
US 20170148018A1 · Levin · 2017 [cited by applicant]
US 20170366563A1 · Volfman · 2017 [cited by examiner]
US 20180018458A1 · Schmugar et al. · 2018 [cited by applicant]
US 20180062764A1 · Borrill · 2018 [cited by applicant]
US 20180075239A1 · Boutnaru · 2018 [cited by examiner]
US 20180101678A1 · Rosa · 2018 [cited by examiner]
US 20180115577A1 · Shukla · 2018 [cited by examiner]
US 20180293379A1 · Dahan · 2018 [cited by applicant]
US 20180375826A1 · Chang · 2018 [cited by examiner]
US 20200097653A1 · Mehta · 2020 [cited by examiner]
US 20200159624A1 · Malkov · 2020 [cited by examiner]
CryptoLock_and_Drop_It_Stopping_Ransomware_Attacks_on_User_Data (Year: 2016). [cited by examiner]
Ransomware Detection And Mitigation Tool (Year: 2017). [cited by examiner]
Design_simulation_and_implementation_of_bidirectional_converter_using_synchronous_switching (Year: 2017). [cited by examiner]
International Search Report issued for International Patent Application No. PCT/AU2021/051399 mailed on Dec. 14, 2021. [cited by applicant]