Invention Grant
- Patent Title: Ransomware encryption algorithm determination
-
Application No.: US16568874Application Date: 2019-09-12
-
Publication No.: US11270016B2Publication Date: 2022-03-08
- Inventor: George Kallos , Fadi Ali El-Moussa
- Applicant: British Telecommunications Public Limited Company
- Applicant Address: GB London
- Assignee: British Telecommunications Public Limited Company
- Current Assignee: British Telecommunications Public Limited Company
- Current Assignee Address: GB London
- Agency: Patterson Thuente Pedersen, P.A.
- Priority: EP18193911 20180912
- Main IPC: G06F7/04
- IPC: G06F7/04 ; H04N7/16 ; G06F21/62 ; G06F21/56 ; G06F21/60 ; G06K9/62

Abstract:
A computer implemented method of identifying an encryption algorithm used by a ransomware algorithm, the ransomware algorithm encrypting a data store of a target computer system using a searchable encryption algorithm, the method including intercepting an ordered plurality of messages communicated from the target computer system to a ransomware server computer system, each message including a payload storing an encrypted unit of data from the target computer system; inspecting a final byte in the encrypted unit of data in each message to identify a byte value used by an encryption algorithm of the ransomware as a padding byte to pad messages to the size of an integral multiple of units of encryption for the encryption algorithm; training an autoencoder based on a position of a message in the ordered plurality of messages and the padding byte to provide a trained autoencoder adapted to differentiate the encryption algorithm used by the ransomware from other different encryption algorithms.
Public/Granted literature
- US20200082109A1 RANSOMWARE ENCRYPTION ALGORITHM DETERMINATION Public/Granted day:2020-03-12
Information query