Method for ransomware impact assessment and remediation assisted by data compression

US10318743B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10318743-B2
Application numberUS-201615392848-A
CountryUS
Kind codeB2
Filing dateDec 28, 2016
Priority dateDec 28, 2016
Publication dateJun 11, 2019
Grant dateJun 11, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Assessing ransomware impact includes receiving an indication of a first plurality of files stored on a user device and a classification for each of the first plurality of files, determining a second plurality of files stored in a remote storage, wherein the second plurality of files corresponds to an indication of files stored on the user device at a first prior time, wherein each of the second plurality of files are associated with a second classification, determining a third plurality of files comprising files included in the first plurality of files and not included in the second plurality of files, and calculating a risk assessment based on classifications for each of the third plurality of files.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer readable medium storing software for assessing ransomware impact, comprising instructions that when installed and executed cause one or more processors to: based on an identification of a ransomware attack, an indication of a first plurality of files stored on a user device, and a classification for each of the first plurality of files, determine a second plurality of files stored in a remote storage, wherein the second plurality of files corresponds to an indication of files stored on the user device at a first prior time, wherein each of the second plurality of files are associated with a second classification; determine a third plurality of files including files included in the first plurality of files and not included in the second plurality of files; calculate a risk assessment based on a third classification for each of the third plurality of files, the third classification formed based on the first classification and the second classification; and output the risk assessment and a signature representing the third plurality of files for remediation of the third plurality of files based on the risk assessment. 2. The computer readable medium of claim 1 , wherein the third classification of the third plurality of files indicates a relative recovery value of the third plurality of files. 3. The computer readable medium of claim 1 , wherein the instructions to calculate the risk assessment further include instructions that cause the one or more processors to: determine that the second plurality of files are corrupt; in response to determining that the second plurality of files are corrupt, identifying a fourth plurality of files corresponding to an indication of files stored on the user device at a second prior time; and calculating the risk assessment further based on classifications for each of the first plurality of files not included in the fourth plurality of files. 4. The computer readable medium of claim 3 , wherein the second plurality of files are hosted by a first cloud storage service, and wherein the fourth plurality of files are hosted by a second cloud storage service. 5. A method for improving assessment of ransomware impact, comprising: based on an identification of a ransomware attack, an indication of a first plurality of files stored on a user device, and a classification for each of the first plurality of files, determining a second plurality of files stored in a remote storage, wherein the second plurality of files corresponds to an indication of files stored on the user device at a first prior time, wherein each of the second plurality of files are associated with a second classification; determining a third plurality of files including files included in the first plurality of files and not included in the second plurality of files; calculating a risk assessment based on classifications for each of the third plurality of files, the third classification formed based on the first classification and the second classification; and outputting the risk assessment and a signature representing the third plurality of files for remediation of the third plurality of files based on the risk assessment. 6. The method of claim 5 , wherein the third classification of the third plurality of files indicates a relative recovery value of the third plurality of files. 7. The method of claim 5 , wherein calculating the risk assessment further includes: determining that the second plurality of files are corrupt; in response to determining that the second plurality of files are corrupt, identifying a fourth plurality of files corresponding to an indication of files stored on the user device at a second prior time; and calculating the risk assessment further based on classifications for each of the first plurality of files not included in the fourth plurality of files. 8. The method of claim 7 , wherein the second plurality of files are hosted by a first cloud storage service, and wherein the fourth plurality of files are hosted by a second cloud storage service. 9. A system for assessing ransomware impact, comprising: one or more processors; and a memory coupled to the one or more processors and including instructions executable by the one or more processors to cause the system to distribute software to at least: based on an identification of a ransomware attack, an indication of a first plurality of files stored on a user device, and a classification for each of the first plurality of files, determine a second plurality of files stored in a remote storage, wherein the second plurality of files corresponds to an indication of files stored on the user device at a first prior time, wherein each of the second plurality of files are associated with a second classification; determine a third plurality of files including files included in the first plurality of files and not included in the second plurality of files; calculate a risk assessment based on classifications for each of the third plurality of files, the third classification formed based on the first classification and the second classification; and output the risk assessment and a signature representing the third plurality of files for remediation of the third plurality of files based on the risk assessment. 10. The system of claim 9 , wherein the third classification of the third plurality of files indicates a relative recovery value of the third plurality of files. 11. The system of claim 9 , wherein the instructions to calculate the risk assessment further include instructions that cause the system to: determine that the second plurality of files are corrupt; in response to determining that the second plurality of files are corrupt, identify a fourth plurality of files corresponding to an indication of files stored on the user device at a second prior time; and calculate the risk assessment further based on classifications for each of the first plurality of files not included in the fourth plurality of files. 12. The system of claim 11 , wherein the second plurality of files are hosted by a first cloud storage service, and wherein the fourth plurality of files are hosted by a second cloud storage service. 13. A computer readable medium comprising instructions for improving risk assessment, executable by one or more processors to: identify a first plurality of files stored in a user device at a first time; determine a first value classification for each of the first plurality of files; generate an indication of the first plurality of files at the first time, the indication including the first value classification and information regarding the first plurality of files to form a signature for remediation of malware with respect to the first plurality of files; and transmit, to a recovery server, the indication of the first plurality of files at the first time for backup storage. 14. The computer readable medium of claim 13 , wherein the first value classification is based on a relative replacement value of each of the first plurality of files. 15. The computer readable medium of claim 13 , wherein the value classification is based on a uniqueness of each of the first plurality of files. 16. The computer readable medium of claim 13 , wherein the instructions to generate the indication of the first plurality of files at the first time includes instructions executable by the one or more processors to: compress the first plurality of files; and store the compressed first plurality of files with a timestamp for the first time. 17. The computer readable medium

Assignees

Inventors

Classifications

  • Vulnerability analysis · CPC title

  • eliminating virus, restoring damaged files · CPC title

  • Computer malware detection or handling, e.g. anti-virus arrangements · CPC title

  • G06F21/577Primary

    Assessing vulnerabilities and evaluating computer system security · CPC title

  • Applying verification of the received information (cryptographic mechanisms or cryptographic arrangements for data integrity or data verification H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10318743B2 cover?
Assessing ransomware impact includes receiving an indication of a first plurality of files stored on a user device and a classification for each of the first plurality of files, determining a second plurality of files stored in a remote storage, wherein the second plurality of files corresponds to an indication of files stored on the user device at a first prior time, wherein each of the second…
Who is the assignee on this patent?
Mcafee Inc, Mcafee Llc
What technology area does this patent fall under?
Primary CPC classification G06F21/577. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jun 11 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).