Ransomware detection via monitoring open file or process

US12437070B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12437070-B2
Application numberUS-202318194624-A
CountryUS
Kind codeB2
Filing dateApr 1, 2023
Priority dateApr 1, 2023
Publication dateOct 7, 2025
Grant dateOct 7, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A bait file owned by a bait process is created and locked in a computing system. Attempts or access the bait file or kill the bait process are detected. The process attempting to access the bait file or kill the bait process is viewed as malicious and protective operations are performed in the computing system.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: monitoring a bait file stored in a storage system of a computing system, wherein the bait file is owned by a bait process such that the bait file is locked by a locking process that is not a malware process, wherein the monitoring the bait file includes monitoring the bait process; detecting an access attempt to the bait file by a process operating in the computing system; determining that the process attempting to access the locked bait file is a malware process, wherein the access attempt includes an attempt to remove a lock on the bait file or kill the bait process; and performing a protection operation on the malware process. 2. The method of claim 1 , further comprising creating the bait file in the storage system. 3. The method of claim 2 , further comprising locking the bait file in the storage system by a locking process. 4. The method of claim 1 , further comprising detecting the access attempt by a malware detection engine operating in a kernel space of the computing system. 5. The method of claim 1 , wherein the protection operation comprises blocking the process. 6. The method of claim 1 , wherein the protection operation comprises terminating the process. 7. The method of claim 1 , wherein the protection operation comprises generating an infected snapshot and allowing the process to operate in a forensic environment, wherein the process is blocked in the computing system. 8. The method of claim 1 , wherein the access attempt comprises accessing the bait file by any process other than the bait process or interfering with the bait process. 9. The method of claim 1 , further comprising configuring the bait file or attributes of the bait file such that the bait file appears valuable in the computing system to cause the process to perform the access attempt. 10. A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising: monitoring a bait file stored in a storage system of a computing system, wherein the bait file is owned by a bait process such that the bait file is locked by a locking process that is not a malware process, wherein the monitoring the bait file includes monitoring the bait process; detecting an access attempt to the bait file by a process operating in the computing system; determining that the process attempting to access the locked bait file is a malware process, wherein the access attempt includes an attempt to remove a lock on the bait file or kill the bait process; and performing a protection operation on the malware process. 11. The non-transitory storage medium of claim 10 , further comprising creating the bait file in the storage system. 12. The non-transitory storage medium of claim 11 , further comprising locking the bait file in the storage system by a locking process. 13. The non-transitory storage medium of claim 10 , further comprising detecting the access attempt by a malware detection engine operating in a kernel space of the computing system. 14. The non-transitory storage medium of claim 10 , wherein the protection operation comprises blocking the process. 15. The non-transitory storage medium of claim 10 , wherein the protection operation comprises terminating the process. 16. The non-transitory storage medium of claim 10 , wherein the protection operation comprises generating an infected snapshot and allowing the process to operating operate in a forensic environment, wherein the process is blocked in the computing system. 17. The non-transitory storage medium of claim 10 , wherein the access attempt comprises accessing the bait file by any process other than the bait process or interfering with the bait process. 18. The non-transitory storage medium of claim 10 , further comprising configuring the bait file or attributes of the bait file such that the bait file appears valuable in the computing system to cause the process to perform the access attempt.

Assignees

Inventors

Classifications

  • the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

  • G06F21/562Primary

    Static detection · CPC title

  • eliminating virus, restoring damaged files · CPC title

  • G06F21/566Primary

    Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12437070B2 cover?
A bait file owned by a bait process is created and locked in a computing system. Attempts or access the bait file or kill the bait process are detected. The process attempting to access the bait file or kill the bait process is viewed as malicious and protective operations are performed in the computing system.
Who is the assignee on this patent?
Dell Products Lp
What technology area does this patent fall under?
Primary CPC classification G06F21/562. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Oct 07 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).