- 专利标题: System and method for detection of malicious data encryption programs
-
申请号: US14951970申请日: 2015-11-25
-
公开(公告)号: US10375086B2公开(公告)日: 2019-08-06
- 发明人: Vladislav I. Ovcharik , Oleg G. Bykov
- 申请人: Kaspersky Lab AO
- 申请人地址: RU Moscow
- 专利权人: AO KASPERSKY LAB
- 当前专利权人: AO KASPERSKY LAB
- 当前专利权人地址: RU Moscow
- 代理机构: Arent Fox LLP
- 代理商 Michael Fainberg
- 优先权: RU2015141551 20150930
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L9/00 ; G06F21/56
摘要:
A method for detection of malicious encryption programs, the method comprising: intercepting, at a server, a file operation request from a client on a file stored on the server; collecting information about at least the requested file and the requested operation; determining, by a hardware processor of the server, based on the collected information, whether the file operation request came from a known malicious encryption program; when the file operation request came from an unknown program, then calculating, by the hardware processor, entropies of at least a portion of the file before and after the execution of the requested operation on the file; and calculating, by the hardware processor, a difference between the calculated entropies; when the difference is below a threshold, allowing the requested operation on the file; and when the difference is above the threshold, denying the requested operation on the file.
公开/授权文献
信息查询