首页> 外国专利> Using recognized backup images for recovery after a ransomware attack

Using recognized backup images for recovery after a ransomware attack

机译:在勒索软件攻击后使用公认的备份映像进行恢复

摘要

The content of each specific image file in a user's backup set (or other type of file set on an endpoint) is analyzed, for example during a backup of the endpoint. Each analyzed image file is categorized based on the results of analyzing its content. The analysis can be in the form identifying one or more objects graphically represented in given image files, and the categorization of image files can be based on these identified graphically represented object(s). Subsequently (for example during a subsequent backup of the endpoint), modifications made to specific ones of the image files in the file set are detected. In response to a quantification of the detected modifications exceeding a specific threshold level, it is adjudicated that a file corruption event has occurred on the endpoint, such as a cryptographic ransomware attack. In response to the adjudication, one or more security actions are taken.
机译:例如在端点备份期间,分析用户备份集中(或端点上其他类型的文件集)中每个特定映像文件的内容。根据分析其内容的结果对每个分析的图像文件进行分类。该分析可以以识别在给定图像文件中以图形方式表示的一个或多个对象的形式,并且图像文件的分类可以基于这些识别出的以图形方式表示的对象。随后(例如,在端点的后续备份期间),将检测到对文件集中特定的图像文件所做的修改。响应于对检测到的修改的量化超过特定阈值水平,可以判定端点上已发生文件损坏事件,例如加密勒索软件攻击。响应于该裁决,采取了一项或多项安全措施。

著录项

  • 公开/公告号US10438000B1

    专利类型

  • 公开/公告日2019-10-08

    原文格式PDF

  • 申请/专利权人 SYMANTEC CORPORATION;

    申请/专利号US201715712940

  • 发明设计人 LEI GU;ILYA SOKOLOV;

    申请日2017-09-22

  • 分类号G06F21/56;H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 12:14:50

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号