The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 09, 2023

Filed:

Dec. 28, 2017
Applicant:

Morphisec Information Security 2014 Ltd., Beer-Sheva, IL;

Inventors:

Mordechai Guri, Nof Ayalon, IL;

Ronen Yehoshua, Matan, IL;

Michael Gorelik, Brookline, MA (US);

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/54 (2013.01); G06N 20/00 (2019.01); G06F 21/55 (2013.01); G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
G06F 21/54 (2013.01); G06F 21/554 (2013.01); G06F 21/564 (2013.01); G06F 21/566 (2013.01); G06N 20/00 (2019.01); G06F 2221/2123 (2013.01);
Abstract

Various automated techniques are described herein for the runtime detection/neutralization of malware executing on a computing device. The foregoing is achievable during a relatively early phase, for example, before the malware manages to encrypt any of the user's files. For instance, a malicious process detector may create decoy file(s) in a directory. The decoy file(s) may have attributes that cause such file(s) to reside at the beginning and/or end of a file list. By doing so, a malicious process targeting files in the directory will attempt to encrypt the decoy file(s) before any other file. The detector monitors operations to the decoy file(s) to determine whether a malicious process is active on the user's computing device. In response to determining that a malicious process is active, the malicious process detector takes protective measure(s) to neutralize the malicious process.


Find Patent Forward Citations

Loading…