Cyber recovery forensics kit configured to maintain communication and send return malware

US12505213B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12505213-B2
Application numberUS-202217937887-A
CountryUS
Kind codeB2
Filing dateOct 4, 2022
Priority dateOct 4, 2022
Publication dateDec 23, 2025
Grant dateDec 23, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Data protection including malware response operations are disclosed. When a production system is attacked, the malware is allowed to run in a forensic environment in order to learn its operational characteristics. The forensic environment includes a working scenario that may be prepared in advance with false data that allows the malware to communicate with a malware host system. Once the operational characteristics are learned, a return malware can be placed in the data. The return malware is transmitted to a malware host system by the malware itself and executed.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising: detecting malware in a production system; generating a backup of the production system by a forensic engine that includes the malware; recovering the backup that includes the malware to a forensic infrastructure that includes a recovered system; while operating the recovered system that includes the malware in the forensic infrastructure, learning operational characteristics of the malware while allowing the malware to transmit communications to and/or receive communications from a malware host system; placing return malware into the data of the recovered system as new data based on the operational characteristics, wherein the return malware is configured to cause the malware to be transmitted to the malware host system, wherein the return malware is executed in the malware host system. 2 . The method of claim 1 , wherein the malware views the return malware as data of the recovered system. 3 . The method of claim 1 , wherein the operational characteristics include functions performed by the malware, timing of the functions, communications performed by the malware, data affected by the malware, evasion functions, or combination thereof. 4 . The method of claim 1 , further comprising configuring the return malware such that the malware transmits the return malware back to the malware host system. 5 . The method of claim 1 , wherein the recovered system comprises a working scenario that is prepared with false data. 6 . The method of claim 1 , wherein the return malware is configured to mitigate or reverse damage caused by the malware. 7 . The method of claim 1 , further comprising replacing data in the recovered system with false data and allowing the recovered system to operate in a live and connected manner. 8 . The method of claim 7 , wherein the recovered system is configured to operate normally. 9 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising: detecting malware in a production system; generating a backup of the production system by a forensic engine that includes the malware; recovering the backup that includes the malware to a forensic infrastructure that includes a recovered system; while operating the recovered system that includes the malware in the forensic infrastructure, learning operational characteristics of the malware while allowing the malware to transmit communications to and/or receive communications from a malware host system; placing return malware into the data of the recovered system as new data based on the operational characteristics, wherein the return malware is configured to cause the malware to be transmitted to the malware host system, wherein the return malware is executed in the malware host system. 10 . The non-transitory storage medium of claim 9 , wherein the malware views the return malware as data of the recovered system. 11 . The non-transitory storage medium of claim 9 , wherein the operational characteristics include functions performed by the malware, timing of the functions, communications performed by the malware, data affected by the malware, evasion functions, or combination thereof. 12 . The non-transitory storage medium of claim 9 , further comprising configuring the return malware such that the malware transmits the return malware back to the malware host system. 13 . The non-transitory storage medium of claim 9 , wherein the recovered system comprises a working scenario that is prepared with false data. 14 . The non-transitory storage medium of claim 9 , wherein the return malware is configured to mitigate or reverse damage caused by the malware. 15 . The non-transitory storage medium of claim 9 , further comprising replacing data in the recovered system with false data and allowing the recovered system to operate in a live and connected manner. 16 . The non-transitory storage medium of claim 15 , wherein the recovered system is configured to operate normally. 17 . A method comprising: learning operational characteristics of multiple malware while allowing the multiple malware to communicate with corresponding malware host systems; and placing a return malware in a production system based on the operational characteristics of the multiple malware to cause, in the event of an attack by malware on the production system, the malware to transmit the return malware to a malware host system, wherein the return malware is executed at the malware host system and is placed in the production system prior to the attack. 18 . The method of claim 17 , wherein the return malware is transmitted prior to detecting the malware at the production system. 19 . The method of claim 17 , further comprising altering the return malware and/or a manner in which the return malware is placed as additional operational characteristics become available. 20 . The method of claim 17 , further comprising detecting the malware and generating a snapshot of a production system that includes the malware, wherein the snapshot is recovered and run in a working scenario to learn the operational characteristics of the malware.

Assignees

Inventors

Classifications

  • G06F21/554Primary

    involving event detection and direct action · CPC title

  • Test or assess software · CPC title

  • eliminating virus, restoring damaged files · CPC title

  • G06F21/566Primary

    Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12505213B2 cover?
Data protection including malware response operations are disclosed. When a production system is attacked, the malware is allowed to run in a forensic environment in order to learn its operational characteristics. The forensic environment includes a working scenario that may be prepared in advance with false data that allows the malware to communicate with a malware host system. Once the operat…
Who is the assignee on this patent?
Dell Products Lp
What technology area does this patent fall under?
Primary CPC classification G06F21/554. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Dec 23 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).