The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 26, 2024

Filed:

Oct. 06, 2020
Applicant:

Mcafee, Llc, San Jose, CA (US);

Inventors:

Craig D. Schmugar, Beaverton, OR (US);

Cedric Cochin, Portland, OR (US);

Andrew Furtak, Beaverton, OR (US);

Adam James Carrivick, Ashland, GB;

Yury Bulygin, Beaverton, OR (US);

John J. Loucaides, Forest Grove, OR (US);

Oleksander Bazhaniuk, Sunnyvale, CA (US);

Christiaan Beek, West-Linn, OR (US);

Carl D. Woodward, Santa Clara, CA (US);

Ronald Gallella, Beaverton, OR (US);

Gregory Michael Heitzmann, Beaverton, OR (US);

Joel R. Spurlock, Portland, OR (US);

Assignee:

McAfee, LLC, San Jose, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/55 (2013.01); G06F 21/62 (2013.01);
U.S. Cl.
CPC ...
G06F 21/566 (2013.01); G06F 21/554 (2013.01); G06F 21/6218 (2013.01); G06F 2221/2141 (2013.01);
Abstract

Particular embodiments described herein provide for an electronic device that can be configured to allow for the mitigation of ransomware. For example, the system can determine that an application begins to execute, determine that the application attempts to modify a file, determine a file type for the file, and create a security event if the application is not authorized to modify the file type. In another example, the system determines an entropy value between the file and the attempted modification of the file, and create a security event if the entropy value satisfies a threshold or determine a system entropy value that includes a rate at which other files on the system are being modified by the application, and create a security event if the system entropy value satisfies a threshold.


Find Patent Forward Citations

Loading…