Abschwächung der Ransomware-Aktivität eines Host-Systems mit einem Kernel-Monitor
Anmelder: Red Hat, LLC, Red Hat, Inc. 🇺🇸
Details
- Veröffentlichungs-Nr.
- EP4567648
- Aktenzeichen
- EP24216250
- Anmeldetag
- 28. November 2024
- Veröffentlichung
- 11. Juni 2025
- Rechtsraum
- EP
- IPC
- G06F21/55G06F21/56G06F21/53
Abstract
A kernel monitor can be used to mitigate ransomware activity of a host system. In some aspects, a computing system can use the kernel monitor to monitor a set of system calls generated by the host system within a time window to perform a functionality. The kernel monitor can include a respective kernel program monitoring each system call in the set of system calls. The set of system calls can be filtered by the kernel monitor to identify a subset of system calls associated with encrypting a filesystem of the host system. The computing system can determine that the subset of system calls is indicative of ransomware activity associated with the host system based on the subset of system calls exceeding a predefined threshold. Subsequently, the computing system can perform a mitigation operation to mitigate the ransomware activity.
Anmelder
- Firmen
- Red Hat, LLC
Red Hat, Inc. - Land
- 🇺🇸 USA
US-amerikanisches Softwareunternehmen, entwickelt Open-Source-Lösungen wie das Linux-Betriebssystem Red Hat Enterprise Linux sowie Cloud- und Middleware-Produkte.
149 Patente in unserer Datenbank
Fachgebiete
Vertreten von
-
Murgitroyd & Company
Murgitroyd & Company · Glasgow