Invention Grant
- Patent Title: Detecting ransomware
-
Application No.: US16142316Application Date: 2018-09-26
-
Publication No.: US10795994B2Publication Date: 2020-10-06
- Inventor: Kunal Mehta , Sherin Mary Mathews , Carl D. Woodward , Celeste R. Fralick , Jonathan B. King
- Applicant: McAfee, LLC
- Applicant Address: US CA Santa Clara
- Assignee: McAfee, LLC
- Current Assignee: McAfee, LLC
- Current Assignee Address: US CA Santa Clara
- Agency: Patent Capital Group
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06N3/08

Abstract:
There is disclosed in one example a ransomware mitigation engine, including: a processor; a convolutional neural network configured to provide file type identification (FTI) services including: identifying an access operation of a file as a write to the file or newly creating the file; computing a byte correlation factor for the file; classifying the file as belonging to a file type; determining with a screening confidence that the file type is correct for the file; determining that the screening confidence is below a screening confidence threshold; and circuitry and logic to provide heuristic analysis including: receiving notification that the confidence is below the confidence threshold; performing a statistical analysis of the file to determine a difference between an expected value and a computed value; determining from the difference, with a detection confidence, that the file has been compromised; and identifying the file as having been compromised by a ransomware attack.
Public/Granted literature
- US20200097653A1 DETECTING RANSOMWARE Public/Granted day:2020-03-26
Information query