IP Library Patent Application 15201007
Patent Application
App. No. 15/201,007

Ransomware Protection For Cloud File Storage

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/201,007
Filed
Jul 1, 2016
Art Unit
2432
USPC
726/23
Abstract

A cloud storage server-based approach allows detection of ransomware activity in cloud storage systems caused by ransomware infections on an endpoint device. A heuristic or rule-based technique is employed for recognizing sequences of file operations that may indicate ransomware activity. In some embodiments, users may be offered an opportunity to approve or disapprove of the possible ransomware activity. In others, cloud system file activity may be suspended or halted for the affected user upon recognition of possible ransomware actions. Enhanced recovery of files affected prior to recognition of the ransomware activity may be performed in some embodiments.

Claims (71)

1 . A computer readable medium storing software for improving protection against ransomware by a cloud storage system, comprising instructions that when executed cause a cloud storage server to:

hook into a cloud storage server application programming interface;

intercept cloud storage server application programming interface calls for cloud storage operations requested by an endpoint device;

record the requested cloud storage operations;

analyze the recorded cloud storage operations to determine whether ransomware activity is occurring; and

block ransomware activity on the cloud storage server responsive to the analysis.

2 . The computer readable medium of claim 1 , wherein the instructions that when executed cause the cloud storage server to block ransomware activity comprise instructions that when executed cause the cloud storage server to:

block cloud storage operations requested by a user of the endpoint device.

3 . The computer readable medium of claim 1 , wherein the instructions that when executed cause the cloud storage server to block ransomware activity comprise instructions that when executed cause the cloud storage server to:

notify a user of the endpoint device of possible ransomware activity;

receive instructions from the user on whether to allow the cloud storage operations; and

block the cloud storage operations responsive to the instructions.

4 . The computer readable medium of claim 1 , wherein the instructions that when executed cause the cloud storage server to analyze the requested cloud storage operations comprise instructions that when executed cause the cloud storage server to:

identify a plurality of sequences of cloud storage operations in the recorded cloud storage operations that may indicate ransomware activity.

5 . The computer readable medium of claim 4 , wherein the instructions that when executed cause the cloud storage server to analyze the requested cloud storage operations further comprise instructions that when executed cause the cloud storage server to:

compare the plurality of sequences of cloud storage operations in the recorded cloud storage operations with a predetermined threshold value; and

determine whether ransomware activity is occurring responsive to the comparison.

6 . The computer readable medium of claim 4 , wherein the sequences of cloud storage operations comprise sequences of cloud storage operations that indicate replacement of existing data with new data.

7 . The computer readable medium of claim 4 , wherein the sequences of cloud storage operations comprise sequences of cloud storage operations that delete existing data and create new data with near-matching names.

8 . The computer readable medium of claim 1 , wherein the instructions further comprise instructions that when executed cause the cloud storage server to:

receive cloud storage context information from an agent on the endpoint device requesting the cloud storage operations; and

consider the cloud storage context information when analyzing the recorded cloud storage operations.

9 . A method of improving ransomware protection in cloud storage systems, comprising:

intercepting application programming interface calls for cloud storage operations at a cloud storage server;

recording cloud storage operations requested by an endpoint device;

analyzing the recorded cloud storage operations;

determining whether ransomware activity is indicated by the recorded cloud storage operations; and

blocking ransomware activity on the cloud storage server responsive to the determination.

10 . The method of claim 9 , wherein blocking ransomware activity comprises:

pausing the cloud storage operations;

notifying a user of the endpoint device of possible ransomware activity; and

rejecting the cloud storage operations responsive to instructions received from the user.

11 . The method of claim 9 , wherein blocking ransomware activity comprises:

blocking cloud storage operations; and

unblocking cloud storage operations responsive to reauthentication of a user of the endpoint device.

12 . The method of claim 9 , wherein analyzing the recorded cloud storage operations comprises:

identifying a plurality of sequences of cloud storage operations in the recorded cloud storage operations that may indicate ransomware activity.

13 . The method of claim 12 ,

wherein analyzing the recorded cloud storage operations further comprises:

comparing the plurality of sequences of cloud storage operations with a predetermined threshold value; and

wherein determining whether ransomware activity is indicated by the recorded cloud storage operations comprises:

determining whether the plurality of sequences of cloud storage operations indicates ransomware activity responsive to the comparison.

14 . The method of claim 12 , wherein the plurality of sequences of cloud storage operations comprises a plurality of sequences of cloud storage operations replacing existing data with new data.

15 . The method of claim 12 , wherein the plurality of sequences of cloud storage operations comprises a plurality of sequences of cloud storage operations that delete existing data and create new data with near matching names.

16 . The method of claim 9 , wherein analyzing the recorded cloud storage operations comprises:

receiving context information related to the recorded cloud storage operations from an agent on the endpoint device.

17 . The method of claim 16 , wherein the context information indicates the cloud storage operations originated remote to the endpoint device.

18 . A cloud storage server programmed to block ransomware activity, comprising:

a processing element;

a memory, coupled to the processing element, on which is stored improved anti-ransomware protection software comprising instructions that when executed program the processing element to:

hook into a cloud storage server application programming interface;

intercept cloud storage operations requested by an endpoint device;

record the requested cloud storage operations;

analyze the recorded cloud storage operations to determine whether ransomware activity is occurring; and

block ransomware activity responsive to the analysis.

19 . The cloud storage server of claim 18 , wherein the instructions that when executed program the processing element to block ransomware activity comprise instructions that when executed program the processing element to:

block cloud storage operations requested by a user of the endpoint device.

20 . The cloud storage server of claim 18 , wherein the instructions that when executed program the processing element to block ransomware activity comprise instructions that when executed program the processing element to:

notify a user of the endpoint device of possible ransomware activity;

receive instructions from the user on whether to allow the cloud storage operations; and

block the cloud storage operations responsive to the instructions.

21 . The cloud storage server of claim 18 , wherein the instructions that when executed program the processing element to analyze the requested cloud storage operations comprise instructions that when executed program the processing element to:

identify a plurality of sequences of cloud storage operations in the recorded cloud storage operations that may indicate ransomware activity.

22 . The cloud storage server of claim 21 , wherein the instructions that when executed program the processing element to analyze the requested cloud storage operations further comprise instructions that when executed program the processing element to:

compare the plurality of sequences of cloud storage operations in the recorded cloud storage operations with a predetermined threshold value; and

determine whether ransomware activity is occurring responsive to the comparison.

23 . The cloud storage server of claim 21 , wherein the sequences of cloud storage operations comprise sequences of cloud storage operations that indicate replacement of existing data with new data.

24 . The cloud storage server of claim 21 , wherein the sequences of cloud storage operations comprise sequences of cloud storage operations that delete existing data and create new data with near-matching names.

25 . The cloud storage server of claim 18 , wherein the instructions further comprise instructions that when executed program the processing element to:

receive cloud storage context information from an agent on the endpoint device requesting the cloud storage operations; and

consider the cloud storage context information when analyzing the recorded cloud storage operations.

Assignments (9)
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Sep 15, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043969/0057 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2016
From: HUNT, SIMON; TIERNAN, SEAN
To: INTEL CORPORATION
Reel/Frame 039769/0147 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2016
From: INTEL CORPORATION
To: MCAFEE, INC.
Reel/Frame 039769/0173 →