Invention Grant
- Patent Title: Ransomware key extractor and recovery system
-
Application No.: US15334311Application Date: 2016-10-26
-
Publication No.: US10387648B2Publication Date: 2019-08-20
- Inventor: Benyamin Hirschberg , Moshe Kravchik , Arie Haenel , Hillel Solow
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Main IPC: G06F21/56
- IPC: G06F21/56

Abstract:
In one embodiment, a system includes a central processing unit (CPU) to identify a ransomware process which encrypted a plurality of files yielding a plurality of encrypted files, in response to identifying the ransomware process, dump a memory space and a state of the CPU yielding a memory dump, and search the memory dump for a plurality of candidate encryption keys, and a decryption engine to attempt to decrypt at least one encrypted file of the plurality of encrypted files with different candidate encryption keys of the plurality of candidate encryption keys until the at least one encrypted file is successfully decrypted with one candidate encryption key of the different candidate encryption keys, and decrypt the plurality of encrypted files using the one candidate encryption key. Related apparatus and methods are also described.
Public/Granted literature
- US20180114020A1 RANSOMWARE KEY EXTRACTOR AND RECOVERY SYSTEM Public/Granted day:2018-04-26
Information query