首页> 外国专利> System and method for protection against ransomware attacks

System and method for protection against ransomware attacks

机译:保护赎金软件攻击的系统和方法

摘要

A method is provided for protecting a file server from a ransomware attack. An exemplary method comprises assigning a session identifier to a remote session initiated with the file server, monitoring operations associated with the session identifier, determining whether the operations are suspicious according to a policy, creating a volume-level snapshot of files on the file server, determining that encryption of the data is occurring when entropy of the monitored data is growing faster than the predetermined threshold rate, classifying the remote session as having a calculated degree of danger when the operations match operations contained in previously observed suspicious behavior patterns, interrupting the remote session when a combination of the degree of danger and the entropy is greater than a predetermined threshold value and restoring the data on the file server using the volume-level snapshot to a state prior to the encryption and dangerous activity.
机译:提供了一种用于保护文件服务器免受勒索软件攻击保护文件。示例性方法包括将会话标识符分配给与文件服务器发起的远程会话,监视与会话标识符相关联的操作,确定操作是否根据策略可疑,在文件服务器上创建文件级快照,确定当被监视数据的熵增长的速度比预定阈值速率增长的熵时,确定数据的加密,当在先前观察到的可疑行为模式中包含的操作匹配的操作时,将远程会话分类为具有计算的危险程度,中断遥控器会话当危险程度和熵的组合大于预定阈值并使用卷级快照在加密和危险活动之前将数据服务器上的数据恢复到文件服务器上。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号