US2018204000A1PendingUtilityA1

Protecting backup files from malware

Assignee: IBMPriority: Jan 19, 2017Filed: Feb 6, 2018Published: Jul 19, 2018
Est. expiryJan 19, 2037(~10.5 yrs left)· nominal 20-yr term from priority
G06F 21/565G06F 21/568G06F 2221/034
59
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for safeguarding a stored file from malware. In one embodiment, the method includes at least one computer processor receiving, to a storage system, a first file from a first computing device. The method further includes analyzing the received first file to determine whether the received first file is suspected of encryption by malware. The method further includes responding to determining that the received first file is suspected of encryption by malware, initiating one or more actions, including suspending replacement of an instance of the first file backed up to the storage system with the received first file. The method further includes storing the received first file to a portion of the storage system designated for file isolation.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for safeguarding a stored file from malware, the method comprising:
 determining, by one or more computer processors, that a storage system supports version control of files backed up to the storage system and that the storage system supports user profiles for backing up files to the storage system, a user profile including:
 identities of one or more computing devices associated with the user; 
 one or more methods for notifying the user of a result of an analysis indicating that malware is suspected of affecting a file of the user; and 
 a list of files that the user backs up to the storage system, the list of files further including: 
 version control information corresponding to the files that the user backs up to the storage system; and 
 an indication, corresponding to each file the user backs up to the storage system, identifying that the file is shared and respective identities corresponding to other computing devices that utilize the shared file; 
   receiving, by one or more computer processors, to a storage system, a version of a first file from a first computing device associated with a first user; and   analyzing, by one or more computer processors, the received version of the first file to determine whether the received first file is suspected of encryption by malware, wherein analyzing the received version of the first file to determine whether the received version of the first file is suspected of encryption by malware further comprises:
 determining, by one or more computer processors, one or more attributes associated with the received version of the first file; 
 comparing, by one or more computer processors, the one or more attributes of the received version of first file to one or more corresponding items related to the received version of the first file, wherein the items related to the received version of first file are selected from a group consisting of a structure of the received first file, a portion of content of the received version of the first file, one or more file attributes of other versions of the first file, a structure of another version of the first file, a portion of content of another version of the first file; and 
   in response to the comparison of the one or more attributes associated with the received version of the first file and the one or more corresponding items related to the received version of the first file identifying one or more differences and determining, by one or more computer processors, that the received first file is suspected of encryption by malware;   responsive to determining that the received version of the first file is suspected of encryption by malware, initiating, by one or more computer processors, one or more actions, including:
 suspending replacement of another version of the first file backed up to the storage system with the received version of the first file; 
 storing the received version of the first file to a portion of the storage system designated for file isolation; 
 transmitting a notification to the first user indicating that the received version of the first file is suspected of encryption by malware; and 
 determining whether the first file is shared based on information within the profile associated with the first user; 
   in response to determining that the first file is shared, identifying, by one or more computer processors, respective identities for other computing devices that utilize the shared first file; and   transmitting, by one or more computer processors, another notification to the respective identities for other computing devices that utilize the shared first file, the other notification indicating that the received version of the first file is suspected of encryption by malware.

Join the waitlist — get patent alerts

Track US2018204000A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.