IP Library Patent Application 14815452
Patent Application
App. No. 14/815,452

REMEDIATING RANSOMWARE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/815,452
Filed
Jul 31, 2015
Art Unit
2491
USPC
726/23
Abstract

Methods and apparatus for ransonnware remediation are disclosed. Network traffic for at least one network user is monitored. A data signature is detected, indicating that one network user has been infected by a ransonnware application. An encryption key is extracted from the detected data signature. The encryption key is stored with an identifier of the network user. The encryption key is used to decrypt one or more files of the network user.

Claims (44)

1 . A method for remediating a ransomware infection, the method comprising:

monitoring network traffic of at least one network users;

detecting a data signature indicating that one network user of the at least one network users has been infected by a ransomware application;

extracting an encryption key from the detected data signature; and

storing the encryption key with an identifier of the network user.

2 . The method of claim 1 , further comprising:

retrieving the encryption key using the identifier of the network user; and

decrypting at least one file of the network user using the encryption key.

3 . The method of claim 1 , wherein the detected data signature comprises a request transmitted to a command and control server of the ransomware application.

4 . The method of claim 2 , wherein a request to decrypt at least one file of the network user is automatically generated in response to storing the encryption key.

5 . The method of claim 1 , further comprising automatically sending a notification to the network user in response to storing the encryption key.

6 . The method of claim 1 , wherein detecting the data signature comprises detecting one of a plurality of data signatures, each of the plurality of data signatures corresponding to a detectable ransomware application.

7 . The method of claim 3 , further comprising:

determining an address for the command and control server; and

adding the address for the command and control server to a block list.

8 . An apparatus comprising:

a ransomware signature repository;

memory storing an infection log; and

a network traffic analyzer to:

monitor network traffic of at least one network user;

analyze the network traffic using the ransomware signature repository;

detect a data signature indicating that one network user of the at least one network users has been infected by a ransomware application;

extract an encryption key from the detected data signature; and

storing the encryption key in the infection log, with an identifier of the network user.

9 . The apparatus of claim 8 , wherein the network traffic analyzer is to retrieve the encryption key from the infection log, and decrypt at least one file of the network user using the encryption key.

10 . The apparatus of claim 8 , wherein the detected data signature comprises a request transmitted to a command and control server of the ransomware application.

11 . The apparatus of claim 9 , wherein the network traffic analyzer is further to automatically generate a request to decrypt at least one file of the network user in response to storing the encryption key.

12 . The apparatus of claim 8 , wherein the network traffic analyzer is further to automatically send a notification to the network user in response to storing the encryption key.

13 . The apparatus of claim 8 , wherein detecting the data signature comprises detecting one of a plurality of data signatures, each of the plurality of data signatures corresponding to a detectable ransomware application.

14 . The apparatus of claim 10 , wherein the network traffic analyzer is further to:

determine an address for the command and control server; and

add the address for the command and control server to a block list.

15 . A non-transitory computer readable medium storing instructions, that when executed by one or more processors, cause the one or more processors to perform steps comprising:

monitoring network traffic of at least one network users;

detecting a data signature indicating that one network user of the at least one network users has been infected by a ransomware application;

extracting an encryption key from the detected data signature; and

storing the encryption key with an identifier of the network user.

16 . The non-transitory computer readable medium of claim 15 , wherein execution of the instructions further causes the one or more processors to perform steps comprising:

retrieving the encryption key using the identifier of the network user; and

decrypting at least one file of the network user using the encryption key.

17 . The non-transitory computer readable medium of claim 16 , wherein execution of the instructions further causes the one or more processors to automatically generate a request to decrypt at least one file of the network user in response to storing the encryption key.

18 . The non-transitory computer readable medium of claim 15 , wherein the data signature comprises a request transmitted to a command and control server of the ransomware application.

19 . The non-transitory computer readable medium of claim 15 , wherein execution of the instructions further causes the one or more processors to detect the data signature by detecting one of a plurality of data signatures, each of the plurality of data signatures corresponding to a detectable ransomware application.

20 . The non-transitory computer readable medium of claim 15 , wherein execution of the instructions further causes the one or more processors to automatically generate a notification to the network user in response to storing the encryption key.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2016
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: TREND MICRO INCORPORATED
Reel/Frame 038303/0704 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2016
From: TREND MICRO INCORPORATED
To: TREND MICRO INCORPORATED
Reel/Frame 038303/0950 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP; HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 036987/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2015
From: POWELL, MAT ROB
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 036231/0435 →