NetApp, Inc.
SYSTEMS AND METHODS FOR DETECTING MALWARE ATTACKS
Last updated:
Abstract:
A method, a computing device, and a non-transitory machine-readable medium for detecting malware attacks. In one example, an agent implemented in an operating system detects an overwrite in which an original data component is overwritten with a new data component. The agent computes a plurality of features associated with the overwrite, the plurality of features including an original entropy corresponding to the original data component, a new entropy corresponding to the new data component, an overwrite fraction, and a set of divergence features. The agent determines whether the new data component is encrypted using the plurality of features.
Status:
Application
Type:
Utility
Filling date:
5 Oct 2020
Issue date:
30 Dec 2021