Invention Grant
- Patent Title: Detection of encrypting malware attacks
-
Application No.: US16844856Application Date: 2020-04-09
-
Publication No.: US11698965B2Publication Date: 2023-07-11
- Inventor: M Corneliu Constantinescu , Frank Schmuck , Deepavali M. Bhagwat
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Zilka-Kotab, P.C.
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F16/17 ; G06N20/00 ; G06F16/182

Abstract:
A computer-implemented method includes monitoring file access activity and generating an audit log based on the file access activity. The method also includes collecting samples of file usage activity, running a pattern recognition algorithm on the samples of the file usage activity for detecting malware activity, and, in response to detecting malware activity, restoring at least one file based on the audit log. A computer program product includes one or more computer readable storage media and program instructions collectively stored on the one or more computer readable storage media. The program instructions include program instructions to perform the foregoing method. A system includes a processor and logic integrated with the processor, executable by the processor, or integrated with and executable by the processor. The logic is configured to perform the foregoing method.
Public/Granted literature
- US20210319103A1 DETECTION OF ENCRYPTING MALWARE ATTACKS Public/Granted day:2021-10-14
Information query