- 专利标题: SYSTEM AND METHOD FOR PROTECTING AGAINST DATA STORAGE ATTACKS
-
申请号: US17703210申请日: 2022-03-24
-
公开(公告)号: US20230325503A1公开(公告)日: 2023-10-12
- 发明人: Liran Orevi , Haggai David
- 申请人: Check Point Software Technologies Ltd.
- 申请人地址: IL Tel Aviv
- 专利权人: Check Point Software Technologies Ltd.
- 当前专利权人: Check Point Software Technologies Ltd.
- 当前专利权人地址: IL Tel Aviv
- 主分类号: G06F21/56
- IPC分类号: G06F21/56
摘要:
A system, method, and device are provided for detecting and mitigating a storage attack at the block level by generating canary blocks by marking blocks of data (referred to as memory blocks) such that other programs do not modify these canary blocks that are monitored to detect data storage attacks that attempt to modify the canary blocks and/or by monitoring statistical and behavioral features of activities over blocks, whether they can be modified by other programs or not. The system and method also backup the memory blocks by backing up memory blocks as they are modified. When a data storage attack is detected, the attack is stopped, and the files are remediated using the backup of the affected memory blocks.
公开/授权文献
信息查询