Invention Grant
- Patent Title: Methods and systems for detecting ransomware attack in incremental backdrop
-
Application No.: US17825496Application Date: 2022-05-26
-
Publication No.: US11886606B2Publication Date: 2024-01-30
- Inventor: Kurt Hansen
- Applicant: Datto, Inc.
- Applicant Address: US CT Norwalk
- Assignee: DATTO, INC.
- Current Assignee: DATTO, INC.
- Current Assignee Address: US CT Norwalk
- Agency: MASCHOFF BRENNAN
- Main IPC: G06F21/62
- IPC: G06F21/62 ; G06F11/14 ; G06F16/16 ; G06F16/23 ; G06F21/55 ; G06F21/57 ; G06F21/60

Abstract:
Ransomware attack (RWA) detection is performed during an incremental or differential backup of a system of folders or directories of a computer or network of computers via an electronic network. The RWA detection includes processing incremental or differential backup metadata acquired during the incremental or differential backup to determine whether a RWA alert is issued. RWA remediation is performed at least in part on the RWA alert being issued. The RWA alert may be issued based on processing of the incremental or differential backup metadata to identify candidate new files and candidate deleted files in which the candidate new files are candidates for being encrypted copies of the candidate deleted files. RWA alert criterion may be based on counts of new versus deleted files in a folder or directory, and comparison of file sizes of the new versus deleted files.
Public/Granted literature
- US20220284117A1 METHODS AND SYSTEMS FOR DETECTING RANSOMWARE ATTACK IN INCREMENTAL BACKDROP Public/Granted day:2022-09-08
Information query