Abschwächung der Ransomware-Aktivität eines Host-Systems mit einem Kernel-Monitor

EP4567648 Art A1 11. Juni 2025

Anmelder: Red Hat, LLC, Red Hat, Inc. 🇺🇸

Details

Veröffentlichungs-Nr.
EP4567648
Aktenzeichen
EP24216250
Anmeldetag
28. November 2024
Veröffentlichung
11. Juni 2025
Rechtsraum
EP
IPC
G06F21/55G06F21/56G06F21/53
Offizieller Volltext

Abstract

A kernel monitor can be used to mitigate ransomware activity of a host system. In some aspects, a computing system can use the kernel monitor to monitor a set of system calls generated by the host system within a time window to perform a functionality. The kernel monitor can include a respective kernel program monitoring each system call in the set of system calls. The set of system calls can be filtered by the kernel monitor to identify a subset of system calls associated with encrypting a filesystem of the host system. The computing system can determine that the subset of system calls is indicative of ransomware activity associated with the host system based on the subset of system calls exceeding a predefined threshold. Subsequently, the computing system can perform a mitigation operation to mitigate the ransomware activity.

Anmelder

Firmen
Red Hat, LLC
Red Hat, Inc.
Land
🇺🇸 USA
🇺🇸 Red Hat

US-amerikanisches Softwareunternehmen, entwickelt Open-Source-Lösungen wie das Linux-Betriebssystem Red Hat Enterprise Linux sowie Cloud- und Middleware-Produkte.

149 Patente in unserer Datenbank

Noch Fragen?

Wir helfen Ihnen gerne weiter. Schreiben Sie uns einfach.

Kontakt aufnehmen