Skip to main content

Ransomware Detection - Entropy with Machine Learning and AI


leduardoserrano
Forum|alt.badge.img+6

Hi! In this post, I describe some aspects of the analysis of entropy analysis associated with Machine Learning and Artificial Intelligence techniques aimed at detecting Ransomware.

This is an exciting topic. As announced in VeeamON 2023, Veeam is working to improve the VDP´s ransomware detection capabilities with AI/ML to perform an in-line entropy analysis of the data stream on backup proxies to detect previously unencrypted data becoming encrypted.

It can undoubtedly be another powerful tool in the battle against ransomware.

Ransomware Detection: Entropy with Machine Learning and AI – Cloud and Roll (cloudnroll.com)

 

 

5 comments

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8395 comments
  • October 8, 2023

This is definitely going to be a great addition to Veeam for sure. Great blog post. 👍


leduardoserrano
Forum|alt.badge.img+6

 

Thanks, Chris! This approach makes much sense for backup systems because files must be processed in each backup job.


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8395 comments
  • October 9, 2023
leduardoserrano wrote:

 

Thanks, Chris! This approach makes much sense for backup systems because files must be processed in each backup job.

Absolutely agree and having the inline scanner is going to help.  Already testing the Beta myself.


leduardoserrano
Forum|alt.badge.img+6

Great to know, Chris! If you can share some impressions and screens with us asap, it should be greeeeat! :-)

Best Of Lumbergh - YouTube


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8395 comments
  • October 9, 2023
leduardoserrano wrote:

Great to know, Chris! If you can share some impressions and screens with us asap, it should be greeeeat! :-)

Best Of Lumbergh - YouTube

Off today for Thanksgiving in Canada but will get some tomorrow if I am not too busy with work. 😜


Comment