検索に戻る
案件記録

VIRTUAL FILE HONEY POTS FOR COMPUTING SYSTEMS BEHAVIOR-BASED PROTECTION AGAINST RANSOMWARE ATTACKS

発明審査中
3閲覧数
21請求項 · 4 独立
§ Ⅰ

案件概要

発明者

Vladimir Strogov; Aliaksei Dodz; Oleg Ishanov; Serg Bell; Stanislav Protasov

IPC分類

G6F 21/53G6F 21/55G6F 21/56

CPC分類

G6F21/53G6F21/552G6F21/566G6F2221/34

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.

原文(中国語)

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.

外部リソース