发明申请
- 专利标题: RANSOMWARE DETECTION
-
申请号: US16129609申请日: 2018-09-12
-
公开(公告)号: US20190108340A1公开(公告)日: 2019-04-11
- 发明人: PurnaChandra Sekhar BEDHAPUDI , Sri Karthik BHAGI , Deepak Raghunath ATTARDE , Arun Prasad AMARENDRAN , Amit Bhaskar AUSARKAR , Mrityunjay UPADHYAY
- 申请人: Commvault Systems, Inc.
- 主分类号: G06F21/56
- IPC分类号: G06F21/56 ; G06F16/17
摘要:
This application relates to ransomware detection. Ransomware typically involves an I/O heavy process of encrypting data files and/or deleting or renaming the original files. Thus, ransomware attacks may be detected by analyzing the I/O activity in a given file system. In some embodiments, a software module running on a client machine monitors the I/O activity in a file system. The software module records the number of times the files in the file system are modified, created, deleted, and renamed. The recorded number is compared against a threshold. If the number exceeds the threshold, the software module provides an alert to the user of the client machine that the client machine may be under a ransomware attack. In some embodiments, index data gathered as part of backup operations is utilized, either alone or in combination with the continuously monitored I/O activity data, to detect ransomware attacks.
信息查询