Cato’s Ransomware Lab Births Network-based Ransomware Prevention
ID: 91e80b7b-5aa7-5434-b1ab-7b958337c2a3
STIX ID: report--91e80b7b-5aa7-5434-b1ab-7b958337c2a3
Feed Name: Cato Networks
Cato Networks announces a network-based ransomware protection feature that uses machine-learning heuristics to inspect SMB traffic for file properties, shared-volume access patterns, network behavior and rapid encryption intervals; when ransomware-like activity is detected the system blocks SMB traffic from the source device and isolates it for remediation. The capability was developed in a ransomware lab where Cato reproduced infections from multiple families (e.g., Black Basta, Conti, Avos Locker) and is presented as an addition to their existing antimalware and IPS defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
