首页> 外国专利> RANSOMWARE DETECTION METHOD AND RANSOMWARE DETECTION SYSTEM

RANSOMWARE DETECTION METHOD AND RANSOMWARE DETECTION SYSTEM

机译:勒索软件检测方法和勒索软件检测系统

摘要

The present invention relates to a ransomware detection method and a ransomware detection system which are capable of preventing ransomware by detecting ransomware activity inside a NAND flash memory-based solid state drive (SSD), and, more particularly, to a ransomware detection method and a ransomware detection system, the ransomware detection method comprising the steps of: classifying files that are infected with ransomware and periodically monitoring, at each predefined monitoring time, an IO request with respect to files having the same magic number as the classified files in order to detect the ransomware; identifying whether overwriting has occurred on a memory block having the same logic block address (LBA) as a read-requested block, on the basis of distribution of a monitored IO request header; counting the number of overwriting times according to a plurality of predefined features in order to specify operation characteristics of the ransomware, on the basis of the identifying whether overwriting has occurred; and detecting ransomware activity, on the basis of the counted number of overwriting times.
机译:勒索软件检测方法和勒索软件检测系统技术领域本发明涉及能够通过检测基于NAND闪存的固态驱动器(SSD)内部的勒索软件活动来防止勒索软件的勒索软件检测方法和勒索软件检测系统,更具体地,涉及一种勒索软件检测方法和方法。勒索软件检测系统,该勒索软件检测方法包括以下步骤:对感染了勒索软件的文件进行分类,并在每个预定义的监视时间定期监视对与已分类文件具有相同魔术数的文件的IO请求,以进行检测勒索软件;基于监视的IO请求头的分配,识别在与读取请求的块具有相同逻辑块地址(LBA)的存储块上是否发生了覆盖;基于识别是否已经发生重写,根据多个预定特征对重写次数进行计数,以指定勒索软件的操作特性;并根据计算出的覆盖次数检测勒索软件活动。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号