IP Library Granted Patent US 11,689,562
Granted Patent B2
US 11,689,562 · App. 16/904,330 · Granted Jun 27, 2023

Detection of ransomware

Inventors: Oliver G. Devane (Upton, GB); Abhishek Karnik (Portland, OR); Sriram P (Bangalore, IN)
Assignee: McAfee, LLC
H04L63/145G06F16/1734G06F21/6218H04L43/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,689,562
App. No.
16/904,330
Granted
Jun 27, 2023
Kind
B2
Abstract

An apparatus, including systems and methods, for detecting ransomware is disclosed herein. For example, in some embodiments, an apparatus includes a memory element operable to store instructions; and a processor operable to execute the instructions, such that the apparatus is configured to receive data identifying a process and a plurality of files accessed by the process; identify an access indicator associated with each of the plurality of files accessed by the process, wherein the access indicator includes file type; determine whether the access indicator exceeds a threshold; interrupt, based on a determination that the access indicator exceeds a threshold, the process; and prompt a user to allow or disallow the process to proceed.

Claims (48)

1. An apparatus, comprising:

a memory element operable to store instructions; and

a processor operable to execute the instructions, such that the apparatus is configured to:

receive data identifying a process and a plurality of files accessed by the process;

identify a first access indicator of a plurality of access indicators for each of the plurality of files accessed by the process, wherein the first access indicator is a file type;

identify a second access indicator of the plurality of access indicators for each of the plurality of files accessed by the process, wherein the plurality of access indicators are selected from the group consisting of the file type, an age of a file that was accessed, a number of files per file type that were accessed, and a frequency that files were accessed;

based on a determination that a first threshold based on the first access indicator is satisfied, determine whether a second threshold based on the second access indicator of the plurality of access indicators is satisfied, wherein the first threshold is defined by exceeding at least five file types;

interrupt, based on a determination that the second threshold is satisfied, the process; and

prompt a user to allow or disallow the process to proceed.

2. The apparatus of claim 1 , wherein the first threshold is partially based on 12 file types being accessed by the process.

3. The apparatus of claim 1 , wherein the second access indicator from the plurality of access indicators is the number of files accessed for each file type.

4. The apparatus of claim 3 , wherein the first threshold is 10 different file types being accessed, and the second threshold is the file types being accessed at least 10 times.

5. The apparatus of claim 1 , wherein the second threshold is based on an age of the files accessed.

6. The apparatus of claim 5 , wherein the first threshold is equal to 10 file types that were accessed, and the second threshold is 10 files of the file types that were accessed being more than 6 months old.

7. The apparatus of claim 1 , wherein the second access indicator is based on a frequency of accessing the plurality of files.

8. The apparatus of claim 7 , wherein the first threshold is based on 20 different file types being accessed, and the second threshold is the file types being accessed in 30 seconds or less.

9. The apparatus of claim 1 , further configured to:

monitor the process accessing the plurality of files; and

store the plurality of access indicators identified for each of the plurality of files accessed by the process.

10. The apparatus of claim 1 , further configured to:

send, to a cloud server, metadata and access data associated with the process to determine whether the process includes ransomware.

11. At least one non-transitory computer-readable medium comprising one or more instructions that, when executed by a processor, cause the processor to:

monitor a process accessing a plurality of files;

identify a first access indicator of a plurality of access indicators for each of the plurality of files accessed by the process, wherein the first access indicator is a file type;

identify a second indicator of the plurality of access indicators associated with each of the plurality of files accessed by the process, wherein the plurality of access indicators are selected from the group consisting of the file type, an age of a file that was accessed, a number of files per file type that were accessed, and a frequency that files were accessed;

store the plurality of access indicators identified for each of the plurality of files accessed by the process;

based on a determination that a first threshold based on the first access indicator is satisfied, determine whether a second threshold based on the second access indicator of the plurality of access indicators is satisfied, wherein the first threshold is defined by exceeding at least five file types;

interrupt, based on a determination that the second threshold is satisfied, the process; and

prompt a user to allow or disallow the process to proceed.

12. The at least one non-transitory computer-readable medium of claim 11 , wherein the first threshold is partially based on 8 file types being accessed by the process.

13. The at least one non-transitory computer-readable medium of claim 11 , wherein the second access indicator from the plurality of access indicators is the number of files accessed for each file type.

14. The at least one non-transitory computer-readable medium of claim 13 , wherein the first threshold is 15 different file types being accessed, and the second threshold is the file types being accessed at least 5 times.

15. A method, comprising:

receiving data identifying a process and a plurality of files accessed by the process;

identifying a first access indicator of a plurality of access indicators for each of the plurality of files accessed by the process, wherein the first access indicator is a file type;

identifying a second access indicator of the plurality of access indicators associated with each of the plurality of files accessed by the process, wherein the plurality of access indicators are selected from the group consisting of the file type, an age of a file that was accessed, a number of files per file type that were accessed, and a frequency that files were accessed;

based on a determination that a first threshold based on the first access indicator is satisfied, determining whether a second threshold based on the second access indicator of the plurality of access indicators is satisfied, wherein the first threshold is defined by exceeding at least five file types;

interrupting, based on a determination that the second threshold is satisfied, the process; and

prompting a user to allow or disallow the process to proceed.

16. The method of claim 15 , wherein the first threshold is equal to 8 or more different file types being accessed by the process, the second threshold is the file types being accessed in 30 seconds or less, and the method further comprises:

determining that at least 10 files of the file types that were accessed are more than 6 months old.

17. The method of claim 15 , wherein the first threshold is equal to 12 or more different file types accessed by the process, the second threshold is the file types being accessed in 60 seconds or less, and the method further comprises:

determining that at least 10 files of the file types that were accessed are more than 6 months old.

18. The method of claim 15 , further comprising:

sending, to a cloud server, metadata and access data associated with the process to determine whether the process includes ransomware;

receiving, from the cloud server, processed data identifying whether the process includes ransomware;

identifying, based on a determination that the process includes ransomware, a corrective action; and

prompting the user to take the corrective action.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2020
From: DEVANE, OLIVER G.; KARNIK, ABHISHEK; P, SRIRAM
To: MCAFEE, LLC
Reel/Frame 052968/0323 →
Continuity (1)
Related Publication 20210400057A1 · Dec 23, 2021