Agentless ransomware detection and recovery
A network security apparatus includes an interface and a processor. The interface is configured to communicate at least with an endpoint computer over a network. The processor is configured to create a trap resource that is shared between the network security apparatus and an operating system of the endpoint computer, to detect ransomware activity in the shared resource, and to initiate a responsive action in response to the detected ransomware activity.
1 . A network security apparatus, comprising:
an interface, configured to communicate at least with an endpoint computer over a network; and
a processor, which is configured to create a trap resource that is shared between the network security apparatus and an operating system of the endpoint computer, to detect ransomware activity in the shared resource, and to initiate a responsive action in response to the detected ransomware activity.
2 . The apparatus according to claim 1 , wherein the processor is configured to create the trap resource in the network security apparatus and to share the trap resource with the operating system of the endpoint computer.
3 . The apparatus according to claim 1 , wherein the processor is configured to create the trap resource in the operating system of the endpoint computer and to share the trap resource with the network security apparatus.
4 . The apparatus according to claim 1 , wherein the processor is configured to detect the ransomware activity without adding any agent to the endpoint computer.
5 . The apparatus according to claim 1 , wherein the shared resource comprises a directory that is shared between the network security apparatus and the operating system of the endpoint computer.
6 . The apparatus according to claim 1 , wherein the shared resource comprises a file that is shared between the network security apparatus and the operating system of the endpoint computer.
7 . The apparatus according to claim 1 , wherein the processor is configured to create the trap resource by running a command-line in the endpoint computer.
8 . The apparatus according to claim 1 , wherein the processor is configured to create the trap resource in the network security apparatus on-the-fly, in response to an access attempt by the endpoint computer.
9 . The apparatus according to claim 1 , wherein the processor is configured to assign first and second clones of the trap resource, having identical names but addressed by different IP addresses, to the endpoint computer and to another endpoint computer.
10 . A method for network security, comprising:
creating a trap resource that is shared between a network security system and an operating system of an endpoint computer;
using the network security system, detecting ransomware activity in the shared resource; and
initiating a responsive action in response to the detected ransomware activity.
11 . The method according to claim 10 , wherein creating the trap resource comprises creating the trap resource in the network security system and sharing the trap resource with the operating system of the endpoint computer.
12 . The method according to claim 10 , wherein creating the trap resource comprises creating the trap resource in the operating system of the endpoint computer and sharing the trap resource with the network security system.
13 . The method according to claim 10 , wherein detecting the ransomware activity is performed without adding any agent to the endpoint computer.
14 . The method according to claim 10 , wherein the shared resource comprises a directory that is shared between the network security system and the operating system of the endpoint computer.
15 . The method according to claim 10 , wherein the shared resource comprises a file that is shared between the network security system and the operating system of the endpoint computer.
16 . The method according to claim 10 , wherein creating the trap resource comprises running a command-line in the endpoint computer.
17 . The method according to claim 10 , wherein creating the trap resource comprises creating the trap resource on-the-fly in the network security system, in response to an access attempt by the endpoint computer.
18 . The method according to claim 10 , wherein creating the trap resource comprises assigning first and second clones of the trap resource, having identical names but addressed by different IP addresses, to the endpoint computer and to another endpoint computer.
19 . A computer software product, the product comprising a tangible non-transitory computer-readable medium in which program instructions are stored, which instructions, when read by a processor of a network security system, cause the processor to communicate at least with an endpoint computer over a network, to create a trap resource that is shared between the network security system and an operating system of the endpoint computer, to detect ransomware activity in the shared resource, and to initiate a responsive action in response to the detected ransomware activity.
20 . The product according to claim 19 , wherein the instructions cause the processor to detect the ransomware activity without adding any agent to the endpoint computer.