首页> 外国专利> SYSTEM AND METHOD TO PREVENT, DETECT, THWART, AND RECOVER AUTOMATICALLY FROM RANSOMWARE CYBER ATTACKS, USING BEHAVIORAL ANALYSIS AND MACHINE LEARNING

SYSTEM AND METHOD TO PREVENT, DETECT, THWART, AND RECOVER AUTOMATICALLY FROM RANSOMWARE CYBER ATTACKS, USING BEHAVIORAL ANALYSIS AND MACHINE LEARNING

机译:利用行为分析和机器学习自动预防,检测,破坏和恢复勒索软件网络攻击的系统和方法

摘要

An anti-ransomware system for a computer system has a deception component comprising a decoy module configured to place decoy segments within one or more file systems, a detection component comprising a behavioral analysis module configured to analyze the behavior of a suspected ransomware, and a response component. The response component has a suspend/kill module configured to suspend the suspected ransomware, a restore files module configured to restore files from an on-demand backup system, a capture encryption key module configured to retrieve the encryption used by the suspected ransomware, and a quarantine module configured to quarantine the suspected ransomware on the device and to quarantine the device off the network, to prevent spread of infection. In an embodiment, the detection and/or response components operate within a kernel-level access. The system's detection component may further comprise a machine-learning module, and the decoy segments may be on-demand and dynamic.
机译:一种用于计算机系统的反勒索软件系统,包括:欺骗组件,包括:诱饵模块,配置为将诱饵段放置在一个或多个文件系统中;检测组件,包括行为分析模块,配置为分析可疑勒索软件的行为;以及响应零件。响应组件具有配置为暂停可疑勒索软件的暂停/杀死模块,配置为从按需备份系统还原文件的还原文件模块,配置为检索可疑勒索软件使用的加密的捕获加密密钥模块以及隔离模块,配置为隔离设备上的可疑勒索软件并隔离网络之外的设备,以防止感染扩散。在一个实施例中,检测和/或响应组件在内核级访问内操作。系统的检测组件可以进一步包括机器学习模块,并且诱饵段可以是按需的并且是动态的。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号