The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 14, 2021

Filed:

Dec. 15, 2016
Applicant:

Hewlett-packard Development Company, L.p., Houston, TX (US);

Inventors:

Daniel Ellam, Bristol, GB;

Adrian Baldwin, Bristol, GB;

Remy Husson, Bristol, GB;

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 7/04 (2006.01); G06F 21/56 (2013.01); G06F 21/12 (2013.01); G06F 21/55 (2013.01); G06F 7/16 (2006.01);
U.S. Cl.
CPC ...
G06F 21/561 (2013.01); G06F 21/12 (2013.01); G06F 21/554 (2013.01); G06F 21/56 (2013.01); G06F 21/566 (2013.01); G06F 21/568 (2013.01); G06F 2221/034 (2013.01); G06F 2221/2101 (2013.01);
Abstract

Examples associated with ransomware attack monitoring are described. One example includes a monitor module to monitor files stored on the system for sequences of file accesses that match a predefined pattern of file accesses. An investigation module is activated when a number of sequences of file accesses that match the predefined pattern exceeds a first threshold. The investigation module logs actions taken by processes to modify files. A reaction module pauses a set of processes operating on the system when the number of sequences of file accesses that match the predefined pattern exceeds a second threshold. The reaction module then identifies processes associated with a suspected ransomware attack based on the logging performed by the investigation module, and resumes legitimate processes.


Find Patent Forward Citations

Loading…