The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 27, 2022

Filed:

Aug. 02, 2017
Applicant:

Code42 Software, Inc., Minneapolis, MN (US);

Inventors:

Ajaykumar Rajasekharan, Longmont, CO (US);

Matthew Mills Parker, Denver, CO (US);

Daniel L. Sullivan, Denver, CO (US);

Assignee:

CRASHPLAN GROUP LLC, New York, NY (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/55 (2013.01);
U.S. Cl.
CPC ...
G06F 21/565 (2013.01); G06F 21/554 (2013.01); G06F 2221/034 (2013.01);
Abstract

A method of detecting the onset of a ransomware attack is presented. In an example embodiment, file backup metadata for each of a plurality of computing devices is accessed and analyzed to detect anomalous file backup activity of individual ones of the computing devices. A determination is made as to whether the detected anomalous file backup activity of at least some of the computing devices is correlated in time. File description metadata for each of the computing devices is also accessed and analyzed to identify files in the computing devices that are anomalous to other files in the computing devices. A determination whether a ransomware attack has begun is based on a determination that the detected anomalous file backup activity of at least some of the computing devices is correlated in time, as well as on the identified anomalous files.


Find Patent Forward Citations

Loading…