Invention Grant
- Patent Title: Methods for behavioral detection and prevention of cyberattacks, and related apparatus and techniques
-
Application No.: US17233236Application Date: 2021-04-16
-
Publication No.: US11657152B2Publication Date: 2023-05-23
- Inventor: Jeffrey Albin Kraemer , Adam Karol Malinowski
- Applicant: Carbon Black, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: VMWare, Inc.
- Current Assignee: VMWare, Inc.
- Current Assignee Address: US CA Palo Alto
- Agency: Barta, Jones & Foley, PLLC
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/55 ; H04L9/40

Abstract:
A security engine may use event-stream processing and behavioral techniques to detect ransomware. The engine may detect process behavior associated with encrypting a file, encrypting a storage device, or disabling a backup file, and may assign a ransomware category to the process based thereon. The engine may initiate protection actions to protect system resources from the process, which may continue to execute. The engine may monitor the process for specific behavior corresponding to its ransomware category. Based on the extent to which such specific behavior is detected, the engine may determine that the process is not ransomware, assign a ransomware subcategory to the process, or adjust the process's threat score. Monitoring of the process may continue, and the threat score may be updated based on the process's behavior. If the threat score exceeds a threshold corresponding to the ransomware category (or subcategory), a corresponding policy action may be initiated.
Public/Granted literature
- US20210232685A1 METHODS FOR BEHAVIORAL DETECTION AND PREVENTION OF CYBERATTACKS, AND RELATED APPARATUS AND TECHNIQUES Public/Granted day:2021-07-29
Information query