首页> 外国专利> SYSTEM AND METHOD FOR DETECTING AND MITIGATING RANSOMWARE THREATS

SYSTEM AND METHOD FOR DETECTING AND MITIGATING RANSOMWARE THREATS

机译:检测和缓解勒索威胁的系统和方法

摘要

This disclosure relates generally to malware detection, and more particularly to system and method for detecting and mitigating ransomware threats. For a User Equipment being monitored, the system performs a behavior analysis of corresponding file system to determine whether any anomalous behavior that would amount to a ransomware threat is associated with flies associated with the file system change, if present, then the system virtualizes the file system on the fly. If information pertaining to the identified anomalous behavior is present in any of the reference databases in the system, then all the I/O calls are terminated or the file system is virtualized for rest of the session. If data pertaining to the identified anomalous behavior is not found in any of the associated databases, then new behavioral features and structural patterns of the identified anomalous behavior and the associated processes are extracted, and the reference databases are updated accordingly.
机译:本公开总体上涉及恶意软件检测,并且更具体地涉及用于检测和减轻勒索软件威胁的系统和方法。对于正在监视的用户设备,系统执行相应文件系统的行为分析,以确定是否可能构成勒索软件威胁的任何异常行为与与文件系统更改相关联的果蝇(如果存在)相关联,然后系统将文件虚拟化系统运行中。如果系统中的任何参考数据库中都存在与所标识的异常行为有关的信息,则将终止所有I / O调用,或者将文件系统虚拟化以用于会话的其余部分。如果在任何关联的数据库中都找不到与所识别的异常行为有关的数据,则将提取所识别的异常行为以及关联过程的新行为特征和结构模式,并相应地更新参考数据库。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号