Invention Grant
- Patent Title: Systems and methods for automatic detection of malicious activity via common files
-
Application No.: US14971828Application Date: 2015-12-16
-
Publication No.: US09935973B2Publication Date: 2018-04-03
- Inventor: Teo Winton Crofton , Clark Marshall Baker
- Applicant: Carbonite, Inc.
- Applicant Address: US MA Boston
- Assignee: Carbonite, Inc.
- Current Assignee: Carbonite, Inc.
- Current Assignee Address: US MA Boston
- Agency: Foley & Lardner LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/64 ; G06F21/60

Abstract:
The present disclosure describes systems and methods for detection and mitigation of malicious activity regarding user data by a network backup system. In a first aspect, a backup system receiving and deduplicating backup data from a plurality of computing devices may detect, based on changes in uniqueness or shared rates for files, atypical modifications to common files, and may take steps to mitigate any potential attack by maintaining versions of the common files prior to the modifications or locking backup snapshots. In a second aspect, the backup system may monitor file modification behaviors on a single device, relative to practices of an aggregated plurality of devices. Upon detection of potentially malicious modification activity, a previously backed up or synchronized store of data may be locked and/or duplicated, preventing any of the malicious modifications from being transferred to the backup system.
Public/Granted literature
- US20170180394A1 SYSTEMS AND METHODS FOR AUTOMATIC DETECTION OF MALICIOUS ACTIVITY VIA COMMON FILES Public/Granted day:2017-06-22
Information query