Patent · US Active

Systems and methods for detecting a suspicious process in an operating system environment using a file honeypots

US11611586B2 · kind B2 · utility

5Cited by
3References
19Claims
0Family size

Assignee

Inventors

Key dates

Filing dateFeb 2, 2021
Grant dateMar 21, 2023
Priority date
Expiry dateAug 8, 2041

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L67/1097
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A system and method is provided for detecting a suspicious process in an operating system environment. In an exemplary aspect, a method comprises generating, by a hardware processor, a file honeypot in a directory in a file system and receiving a directory enumeration request from a process executing in the operating system environment. The method comprises determining whether the process is identified in a list of trusted processes and in response to determining that the process is not in the list of trusted processes, providing, to the process by the file system, a file list including the file honeypot responsive to the directory enumeration request. The method further comprises intercepting, by a file system filter driver, a file modification request for the file honeypot from the process, and identifying the process as a suspicious object responsive to intercepting the file modification request from the process.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.