REMEDIATING RANSOMWARE
Methods and apparatus for ransonnware remediation are disclosed. Network traffic for at least one network user is monitored. A data signature is detected, indicating that one network user has been infected by a ransonnware application. An encryption key is extracted from the detected data signature. The encryption key is stored with an identifier of the network user. The encryption key is used to decrypt one or more files of the network user.
1 . A method for remediating a ransomware infection, the method comprising:
monitoring network traffic of at least one network users;
detecting a data signature indicating that one network user of the at least one network users has been infected by a ransomware application;
extracting an encryption key from the detected data signature; and
storing the encryption key with an identifier of the network user.
2 . The method of claim 1 , further comprising:
retrieving the encryption key using the identifier of the network user; and
decrypting at least one file of the network user using the encryption key.
3 . The method of claim 1 , wherein the detected data signature comprises a request transmitted to a command and control server of the ransomware application.
4 . The method of claim 2 , wherein a request to decrypt at least one file of the network user is automatically generated in response to storing the encryption key.
5 . The method of claim 1 , further comprising automatically sending a notification to the network user in response to storing the encryption key.
6 . The method of claim 1 , wherein detecting the data signature comprises detecting one of a plurality of data signatures, each of the plurality of data signatures corresponding to a detectable ransomware application.
7 . The method of claim 3 , further comprising:
determining an address for the command and control server; and
adding the address for the command and control server to a block list.
8 . An apparatus comprising:
a ransomware signature repository;
memory storing an infection log; and
a network traffic analyzer to:
monitor network traffic of at least one network user;
analyze the network traffic using the ransomware signature repository;
detect a data signature indicating that one network user of the at least one network users has been infected by a ransomware application;
extract an encryption key from the detected data signature; and
storing the encryption key in the infection log, with an identifier of the network user.
9 . The apparatus of claim 8 , wherein the network traffic analyzer is to retrieve the encryption key from the infection log, and decrypt at least one file of the network user using the encryption key.
10 . The apparatus of claim 8 , wherein the detected data signature comprises a request transmitted to a command and control server of the ransomware application.
11 . The apparatus of claim 9 , wherein the network traffic analyzer is further to automatically generate a request to decrypt at least one file of the network user in response to storing the encryption key.
12 . The apparatus of claim 8 , wherein the network traffic analyzer is further to automatically send a notification to the network user in response to storing the encryption key.
13 . The apparatus of claim 8 , wherein detecting the data signature comprises detecting one of a plurality of data signatures, each of the plurality of data signatures corresponding to a detectable ransomware application.
14 . The apparatus of claim 10 , wherein the network traffic analyzer is further to:
determine an address for the command and control server; and
add the address for the command and control server to a block list.
15 . A non-transitory computer readable medium storing instructions, that when executed by one or more processors, cause the one or more processors to perform steps comprising:
monitoring network traffic of at least one network users;
detecting a data signature indicating that one network user of the at least one network users has been infected by a ransomware application;
extracting an encryption key from the detected data signature; and
storing the encryption key with an identifier of the network user.
16 . The non-transitory computer readable medium of claim 15 , wherein execution of the instructions further causes the one or more processors to perform steps comprising:
retrieving the encryption key using the identifier of the network user; and
decrypting at least one file of the network user using the encryption key.
17 . The non-transitory computer readable medium of claim 16 , wherein execution of the instructions further causes the one or more processors to automatically generate a request to decrypt at least one file of the network user in response to storing the encryption key.
18 . The non-transitory computer readable medium of claim 15 , wherein the data signature comprises a request transmitted to a command and control server of the ransomware application.
19 . The non-transitory computer readable medium of claim 15 , wherein execution of the instructions further causes the one or more processors to detect the data signature by detecting one of a plurality of data signatures, each of the plurality of data signatures corresponding to a detectable ransomware application.
20 . The non-transitory computer readable medium of claim 15 , wherein execution of the instructions further causes the one or more processors to automatically generate a notification to the network user in response to storing the encryption key.