首页> 外国专利> Advanced ransomware detection

Advanced ransomware detection

机译:高级赎金软件检测

摘要

Methods, apparatuses and computer program products implement embodiments of the present invention that include protecting a computer system coupled to a storage device by storing, to the storage device, a set of protected files and one or more decoy files, wherein any modification to the decoy file indicates a cyber-attack on the computer system. Upon receiving a request from a process executing on the computing device to enumerate files stored on the storage device, the process is analyzed so as to classify the process as benign or suspicious. The protected files are enumerated to the process whether the process was classified as benign or suspicious. However, the one or more decoy files are enumerated to the process only upon process being classified as suspicious.
机译:方法,装置和计算机程序产品实现本发明的实施例,其包括通过将耦合到存储设备耦合到存储设备的计算机系统,通过存储到存储设备,一组受保护的文件和一个或多个诱饵文件,其中对诱饵的任何修改 文件表示计算机系统上的网络攻击。 在从计算设备上执行的过程接收到要枚举存储在存储设备上的文件时,分析该过程以便将过程分类为良性或可疑。 受保护的文件枚举到过程中的过程是否被归类为良性或可疑。 但是,只有在归类为可疑的过程时才会枚举一个或多个诱饵文件。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号