Invention Grant
- Patent Title: System and method for detection of malicious data encryption programs
-
Application No.: US14951970Application Date: 2015-11-25
-
Publication No.: US10375086B2Publication Date: 2019-08-06
- Inventor: Vladislav I. Ovcharik , Oleg G. Bykov
- Applicant: Kaspersky Lab AO
- Applicant Address: RU Moscow
- Assignee: AO KASPERSKY LAB
- Current Assignee: AO KASPERSKY LAB
- Current Assignee Address: RU Moscow
- Agency: Arent Fox LLP
- Agent Michael Fainberg
- Priority: RU2015141551 20150930
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/00 ; G06F21/56

Abstract:
A method for detection of malicious encryption programs, the method comprising: intercepting, at a server, a file operation request from a client on a file stored on the server; collecting information about at least the requested file and the requested operation; determining, by a hardware processor of the server, based on the collected information, whether the file operation request came from a known malicious encryption program; when the file operation request came from an unknown program, then calculating, by the hardware processor, entropies of at least a portion of the file before and after the execution of the requested operation on the file; and calculating, by the hardware processor, a difference between the calculated entropies; when the difference is below a threshold, allowing the requested operation on the file; and when the difference is above the threshold, denying the requested operation on the file.
Public/Granted literature
- US20170093886A1 SYSTEM AND METHOD FOR DETECTION OF MALICIOUS DATA ENCRYPTION PROGRAMS Public/Granted day:2017-03-30
Information query