首页> 外国专利> SSD INTERNAL DEFENSE METHOD INCURRING NO DATA LOSS DUE TO RANSOMWARE, AND RANSOMWARE DETECTION SYSTEM

SSD INTERNAL DEFENSE METHOD INCURRING NO DATA LOSS DUE TO RANSOMWARE, AND RANSOMWARE DETECTION SYSTEM

机译:不会因RANSOMWARE而导致数据丢失的SSD内部防御方法以及RANSOMWARE检测系统

摘要

An SSD internal defense method incurring no data loss due to ransomware, and a ransomware detection system are disclosed. A method for detecting ransomware operating in a NAND flash memory can comprise the steps of: periodically monitoring IO requests at every pre-defined monitoring period for ransomware detection; checking, on the basis of distribution of the header of the monitored IO requests, whether an overwrite occurred on a memory block having the same logical block address (LBA) as a read-requested block; counting, on the basis of the checking of whether overwriting occurred, the number of overwrites for each of a plurality of pre-defined features in order to specify operational features of the ransomware; and detecting activity of the ransomware on the basis of the counted number of overwrites.
机译:公开了一种不会因勒索软件而导致数据丢失的SSD内部防御方法,以及勒索软件检测系统。一种用于检测在NAND闪存中运行的勒索软件的方法,可以包括以下步骤:在每个预定义的监视时段定期监视IO请求以进行勒索软件检测;以及根据被监视的IO请求的报头的分布,检查在与读取请求的块具有相同逻辑块地址(LBA)的存储块上是否发生了覆盖;基于检查是否发生覆盖,对多个预定特征中的每个特征的覆盖次数进行计数,以指定勒索软件的操作特征;并根据计数的覆盖次数检测勒索软件的活动。

著录项

  • 公开/公告号WO2019107609A1

    专利类型

  • 公开/公告日2019-06-06

    原文格式PDF

  • 申请/专利权人 THEVAULTERS INC.;

    申请/专利号WO2017KR13905

  • 发明设计人 BAEK SUNG HA;NYANG DAE HUN;

    申请日2017-11-30

  • 分类号G06F21/56;G06F21/55;

  • 国家 WO

  • 入库时间 2022-08-21 11:54:30

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号