CNIPA.AI
검색으로 돌아가기
기록

VIRTUAL FILE HONEY POTS FOR COMPUTING SYSTEMS BEHAVIOR-BASED PROTECTION AGAINST RANSOMWARE ATTACKS

발명심사 중
21청구항 · 4 독립항
§ Ⅰ

개요

발명자

Vladimir Strogov; Aliaksei Dodz; Oleg Ishanov; Serg Bell; Stanislav Protasov

IPC 분류

G6F 21/53G6F 21/55G6F 21/56

CPC 분류

G6F21/53G6F21/552G6F21/566G6F2221/34

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.

원문 (중국어)

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.