首页> 外国专利> Automated detection and remediation of ransomware attacks involving a storage device of a computer network

Automated detection and remediation of ransomware attacks involving a storage device of a computer network

机译:自动检测和补救涉及计算机网络存储设备的勒索软件攻击

摘要

An apparatus in one embodiment comprises a security appliance having a processor coupled to a memory. The security appliance is associated with at least one storage device and comprises a ransomware detector configured to generate a detection score for one or more sets of files stored in the storage device. The ransomware detector comprises a file analyzer configured to compare characteristics relating to a current state of the files with information stored in a file history database, and a detection score generator having a weighting module for applying weights to respective comparison results from the file analyzer in generating the detection score for the one or more sets of files. The ransomware detector is further configured to generate an alert if the detection score for the one or more sets of files exceeds a specified threshold. The alert may be transmitted by the security appliance to a network security system.
机译:一个实施例中的设备包括具有耦合到存储器的处理器的安全设备。该安全设备与至少一个存储设备相关联,并且包括勒索软件检测器,该勒索软件检测器被配置为生成针对存储在该存储设备中的一组或多组文件的检测得分。勒索软件检测器包括:文件分析器,被配置为将与文件的当前状态有关的特征与文件历史数据库中存储的信息进行比较;检测得分生成器,其具有加权模块,用于在生成文件时将权重应用于来自文件分析器的各个比较结果一组或多组文件的检测得分。勒索软件检测器还配置为:如果一组或多组文件的检测得分超过指定的阈值,则生成警报。警报可以由安全设备传输到网络安全系统。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号