首页> 外国专利> SYSTEMS AND METHODS FOR PREVENTIVE RANSOMWARE DETECTION USING FILE HONEYPOTS

SYSTEMS AND METHODS FOR PREVENTIVE RANSOMWARE DETECTION USING FILE HONEYPOTS

机译:使用文件蜜点进行预防性勒索软件检测的系统和方法

摘要

A system and method is provided for detecting ransomware and malicious programs. An exemplary method comprises generating, by a hardware processor, a file honeypot in a directory in a filesystem, wherein the file honeypot is included on a file list of contents of the directory, receiving a directory enumeration request from a process executing in an operating system environment, determining whether the process is identified in a list of trusted processes based on one or more of a certificate, fingerprint, name, and process identifier, when the process is not found in the list of trusted processes, providing, by the filesystem, the file list including the file honeypot to the process responsive to receiving the directory enumeration request and otherwise, providing the file list excluding the file honeypot to the process, intercepting, by a filesystem filter driver, a file modification request for the file honeypot from the process when the file honeypot is included in the file list and identifying the process as a suspicious object responsive to intercepting the file modification request from the process.
机译:提供了一种用于检测勒索软件和恶意程序的系统和方法。一种示例性方法包括:由硬件处理器在文件系统的目录中生成文件蜜罐,其中,该文件蜜罐被包括在目录的内容的文件列表中,从操作系统中执行的进程接收目录枚举请求。在环境中,当文件系统在可信进程列表中未找到该进程时,根据证书,指纹,名称和进程标识符中的一个或多个来确定是否在可信进程列表中标识了该进程,响应于接收到目录枚举请求,向该进程包括文件蜜罐的文件列表;否则,向文件进程提供不包括该文件蜜罐的文件列表,由文件系统过滤器驱动程序拦截来自该文件蜜罐的文件修改请求。文件蜜罐包含在文件列表中时,将进程识别为可疑对象,以响应于拦截该文件来自流程的修改请求。

著录项

相似文献

  • 专利
  • 外文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号