DETECTION OF RANSOMWARE ATTACK USING ENTROPY VALUES

    公开(公告)号:US20240143761A1

    公开(公告)日:2024-05-02

    申请号:US18051110

    申请日:2022-10-31

    CPC classification number: G06F21/566 G06F17/18 G06F2221/033

    Abstract: Example implementations relate to storing data in a storage system. An example includes accessing a first portion of a data stream to be stored in a storage system; selecting sample data blocks included in the first portion; determining entropy values based on the sample data blocks; selecting, based on the sample data blocks, a entropy threshold from multiple precalculated entropy thresholds; determining whether the generated set of entropy values matches the selected entropy threshold within a probability level; and in response to a determination that the generated set of entropy values matches the selected entropy threshold within the probability level, identifying the first portion of the data stream as potentially including encrypted data affected by a ransomware attack.

Patent Agency Ranking