Ransomware mitigation system and method for mitigating a ransomware attack
View Patent ↗A ransomware mitigation system and corresponding methods are provided. The ransomware mitigation system monitors the rate of modification of files on computing devices to determine whether the monitored rate of modifications exceeds a predetermined threshold. If the threshold is exceeded, then the ransomware mitigation system actuates a forced shutdown of the computing device and/or a forced disconnection of the network connection to the computing device. The ransomware mitigation system includes a software monitoring portion as well as a hardware switching unit. The software monitoring portion is in synchronous bidirectional communication with the hardware switching unit on a separate network. If the software monitoring portion is shutdown then the hardware unit actuates the shutdown and/or disconnection of the computing device(s). The hardware unit includes a hardware lock that requires physical presence of a person to allow for maintenance.
1 . A ransomware mitigation system for mitigating damage done to one or more computing devices connected to a network from a ransomware attack, the ransomware mitigation system comprising:
a monitoring portion comprising:
digital storage media configured for storing data and/or instructions;
a processor operationally connected to the digital storage media and configured to be directed by instructions; and
a monitoring transceiver operably connected to the processor for transmitting and/or receiving digital information;
wherein the processor is configured to be guided by the instructions to carry out the steps of:
monitoring a plurality of digital files on a network of at least one computing device for the rate of modifications carried out on the plurality of digital files;
determining whether the monitored rate of modifications meets a predetermined activity threshold; and
maintaining bidirectional synchronous communication with a shutdown switch on a dedicated communications line by transmitting a confirmation signal, and
at least one shutdown switch configured for:
shutting down, in a shutdown event, one or more selected from:
power to the at least one or more computing devices, and
network communications to the at least one or more computing devices, and
wherein the monitoring transceiver is configured for independent communication with the shutdown switch on a network independent of the network traffic on the network that the one or more computing devices are connected to, and
wherein the shutdown switch is configured to actuate a shutdown event if an expected confirmation signal is not received as part of the bidirectional synchronous communication between the at least one or more shutdown switches and the monitoring portion.
2 . The ransomware mitigation system as claimed in claim 1 , wherein the processor is configured to be guided by the instructions to carry out the step of:
allocating a whitelist of shutdown files that are part of the shutdown process and only allowing whitelisted shutdown files to operate on actuation of the forced shutdown; and
preventing modification of the whitelisted files during the forced shutdown of the one or more computing devices.
3 . The ransomware mitigation system as claimed in claim 1 , wherein the processor is configured to be guided by the instructions to carry out the step of:
actuating a forced shutdown of the one or more computing devices by actuating one or more shutdown switches, wherein actuation of the shutdown switch shuts off power to at least one or more of the one or more computing devices.
4 . The ransomware mitigation system as claimed in claim 1 , wherein the processor is configured to be guided by the instructions to carry out the step of:
actuating a forced shutdown of one or more network communications devices in a network connecting the one or more computing devices by actuating at least one or more shutdown switches, wherein actuation of the at least one or more shutdown switches shuts off power to at least one or more of the one or more network communications devices.
5 . The ransomware mitigation system as claimed in claim 1 , wherein the processor is configured to be guided by the instructions to carry out the step of:
determining the network location of the computing devices on which the rate of file modification has exceeded the threshold (the “affected computing devices”).
6 . The ransomware mitigation system as claimed in claim 1 , wherein the ransomware mitigation system includes a hardware lock.
7 . The ransomware mitigation system as claimed in claim 6 , wherein the hardware lock is configured for being operated by a hardware key between
an unlocked condition; and
a locked condition.
8 . The ransomware mitigation system as claimed in claim 7 , wherein the processor is configured to be guided by the instructions to carry out the step of:
receiving a request for modification of the system files of the ransomware mitigation system;
determining whether the hardware lock is in its unlocked condition; and
only allowing the processing of the request for modification of the system files of the ransomware mitigation system in the event that the hardware lock is in its unlocked condition.
9 . The ransomware mitigation system as claimed in claim 1 , wherein the shutdown switch includes a shutdown switch transceiver configured for communicating with one or more selected from the monitoring transceiver and with one or more shutdown switch transceivers on other similar shutdown switches.
10 . The ransomware mitigation system as claimed in claim 9 , wherein the shutdown switch transceiver is configured for communicating with one or more selected from the monitoring transceiver and with one or more shutdown switch transceivers on other similar shutdown switches on a network independent of the network that the computing devices are connected to.
11 . The ransomware mitigation system as claimed in claim 9 , wherein the shutdown switch transceiver is configured for receiving an actuation signal from the monitoring transceiver.
12 . The ransomware mitigation system as claimed in claim 11 , wherein the shutdown switch is configured to open and close or close one or more electrical circuits on receiving the actuation signal.
13 . The ransomware mitigation system as claimed in claim 9 , wherein the shutdown switch transceiver is configured for receiving a synchronised confirmation signal from the monitoring transceiver at regular intervals.
14 . The ransomware mitigation system as claimed in claim 13 , wherein the shutdown switch is configured for opening and/or closing the electrical circuit in the event that a confirmation signal is not received at an expected interval.
15 . The ransomware mitigation system as claimed in claim 13 , wherein the shutdown switch is configured for opening and/or closing the electrical circuit in the event that a confirmation signal is not received continuously.
16 . The ransomware mitigation system as claimed in claim 1 , wherein the shutdown switch includes a switch processor and switch digital storage media configured for storing one or more selected from data and software instructions, and the switch processor is configured for being directed by the switch software instructions to
open and/or close the electrical circuit at a switching device configured for switching one or more selected from:
a power connection to the one or more computing devices; and
a network connection of the one or more computing devices.
17 . A method of mitigating damage done to one or more computing devices on a network connection from a ransomware attack, the method being carried out on an electronic device and comprising the steps of:
Monitoring, by a monitoring portion, a plurality of digital files on a network of at least one or more computing devices for the rate of modifications carried out on the plurality of digital files in order to determine whether the monitored rate of modifications meets a predetermined activity threshold;
and
maintaining bidirectional synchronous communication between the monitoring portion and at least one shut down switch on a dedicated communications line on a network independent of the network traffic on the network that the at least one or more computing devices are connected to by sending confirmation signals between the monitoring portion and the shutdown switch; and
in the event of the shutdown switch not receiving an expected confirmation signal as part of the bidirectional synchronous communication between the at least one or more shutdown switches and the monitoring portion, actuating by the shutdown switch of one or more selected from:
a forced shutdown of the one or more computing devices; and
a forced disconnection of the network connection of the one or more computing devices.
18 . The ransomware mitigation system as claimed in claim 1 , wherein the monitoring portion is configured to actuate a shutdown event in at least one of the at least one or more shutdown switches upon determining that the monitored rate of modifications meets a predetermined activity threshold.
19 . A tamper prevention system for preventing the likelihood of tampering with a ransomware mitigation system by ransomware, the tamper prevention system comprising:
a monitoring portion configured for monitoring activities relating to one or more files on at least one or more computing devices;
a switching device configured for shutting down, in a shutdown event, one or more selected from:
power to the at least one or more computing devices, and
network communications with the at least one or more computing devices; and
wherein the switching device and the monitoring portion are configured for bidirectional synchronous communication with each other on a network independent of the network traffic on the network that the one or more computing devices are connected to, and wherein at least one or more selected from the switching device and the monitoring portion are configured for actuating a shutdown event in the event that synchronous communication between the monitoring portion and the switching device is not synchronized.