首页> 外国专利> DETECTION SYSTEM OF RANSOMEWARE USING PATTERN RECOGNITION OF RANSOMEWARE AND MAGIC NUMBER OF FILES

DETECTION SYSTEM OF RANSOMEWARE USING PATTERN RECOGNITION OF RANSOMEWARE AND MAGIC NUMBER OF FILES

机译:基于文件识别和文件数量的文件识别检测系统

摘要

The present invention relates to a system for detecting a ransomware using pattern recognition of the ransomware and a magic number, which can detect an activity of the ransomware in a NAND flash memory-based solid-state drive (SSD), and defend from the ransomware. More specifically, the present invention relates to a system for detecting a ransomware using pattern recognition of the ransomware and a magic number, which can define a file format infected by the ransomware, identify whether only the files with the same magic number as that of the defined file format are infected by the ransomware or not, monitor the files having the same magic number on a regular basis, and detect whether the ransomware is in an activity state or not based on the number of times of overwriting by the monitored files.
机译:本发明涉及一种利用勒索软件和幻数的模式识别来检测勒索软件的系统,该系统可以检测基于NAND闪存的固态驱动器(SSD)中勒索软件的活动,并防御勒索软件。 。更具体地,本发明涉及一种用于使用勒索软件的模式识别和魔术数来检测勒索软件的系统,该系统可以定义被勒索软件感染的文件格式,仅识别具有与该勒索软件相同的魔术数的文件。定义的文件格式是否被勒索软件感染,定期监视具有相同幻数的文件,并根据被监视文件覆盖的次数检测勒索软件是否处于活动状态。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号