The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 10, 2023

Filed:

Jul. 08, 2021
Applicant:

Rubrik, Inc., Palo Alto, CA (US);

Inventors:

Oscar Chen, Palo Alto, CA (US);

Di Wu, Newark, CA (US);

Benjamin Reisner, San Francisco, CA (US);

Matthew Edward Noe, San Francisco, CA (US);

Assignee:

Rubrik, Inc., Palo Alto, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 16/951 (2019.01); G06F 11/14 (2006.01); G06F 16/11 (2019.01);
U.S. Cl.
CPC ...
G06F 21/565 (2013.01); G06F 11/1458 (2013.01); G06F 16/128 (2019.01); G06F 16/951 (2019.01); G06F 2201/84 (2013.01); G06F 2221/034 (2013.01);
Abstract

Described herein is a system that detects ransomware infection in filesystems. The system detects ransomware infection by using backup data of machines. The system detects ransomware infection in two stages. In the first stage, the system analyzes a filesystem's behavior. The filesystem's behavior can be obtained by loading the backup data and crawling the filesystem to create a filesystem metadata including information about file operations during a time interval. The filesystem determines a pattern of the file operations and compares the pattern to a normal patter to analyze the filesystem's behavior. If the filesystem's behavior is abnormal, the system proceeds to the second stage to analyze the content of the files to look for signs of encryption in the filesystem. The system combines the analysis of both stages to determine whether the filesystem is infected by ransomware.


Find Patent Forward Citations

Loading…