• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 330
  • Last Modified:

Kaspersky Anti-Ransomware Tool for Business

hello,

is anyone familiar with this tool: 'Kaspersky Anti-Ransomware Tool for Business'.
what is your opinion on it ?
is it free ?

thank u
0
David Dotan Sofer
Asked:
David Dotan Sofer
  • 3
  • 2
  • 2
  • +2
1 Solution
 
Laroy ShtotlandIT Security ConsultantCommented:
Yes, it's free. As a complementary anti-ransomware solution, Kaspersky Anti-Ransomware Tool for Business provides corporate users with protection from ransomware and can serve as second opinion software.
For organizations that demand protection for each network level, including security technologies to protect workstations, file servers and mobile devices from all types of malware and today’s sophisticated attacks, use specialized business solutions.
0
 
EirmanCommented:
Looking at the issue sideways .....
Veeam backup Protects USB-based storage targets from CryptoLocker threats
by automatically ejecting them after a successful run.

https://www.veeam.com/endpoint-backup-free.html
0
 
furunoCommented:
As a matter of interest, anyone know does the Kaspersky Anti-Ransomware Tool work - heuristic analysis?
0
Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

 
Laroy ShtotlandIT Security ConsultantCommented:
It uses 2 technologies: Kaspersky Security Network (KSN) and Kaspersky System Watcher.

Kaspersky Security Network, a cloud-based service dedicated to processing depersonalized cybersecurity-related data streams from millions of voluntary participants all over the world. With Kaspersky Security Network, delivery of Kaspersky Lab security intelligence happens in a matter of seconds, ensuring fast reaction times and maintaining high levels of protection. http://ksn.kaspersky.com/

System Watcher is an advanced proactive security technology that scans all important system events, including the creation and modification of operating system files and configurations, program execution and data exchange over the network. Events are recorded and analyzed, and if there is evidence that a program is performing malicious operations, those actions can be blocked and reversed, preventing further infection.
http://support.kaspersky.com/6270
http://www.kaspersky.com/images/Kaspersky_Lab_Whitepaper_System_Watcher_ENG.pdf
0
 
EirmanCommented:
If you have a computer with files that have encrypted with Ransomware,
it is very unlikely that you can decrypt them yourself without paying a ransom.
This is not to be recommended as you are giving money to/dealing with criminals who may not decrypt your files anyway.
0
 
Laroy ShtotlandIT Security ConsultantCommented:
It was not part of the initial question, but if your files are already encrypted, you can try free decryptors like https://noransom.kaspersky.com/
0
 
David Johnson, CD, MVPOwnerCommented:
Will it stop all versions of ransom-ware highly unlikely so it isn't a magic bullet.  What one has to look for are typical behaviour of a ransom-ware attack. modification of a significant number of files in a short period of time. deletion of shadow copies, change of file sizes of multiple files in a short period of time.  Execution of executable from the users appdata directory.

The creation of software that performs the same as ransom-ware is trivial to code, getting a spam bot to include the code or a launcher that retrieves the executable code and getting paid without being caught are the only stumbling blocks.

There are a few solutions created by the white hat community and they want to sell their ideas to the anti-virus vendors but no vendors have taken up the offer as of yet.
0
 
furunoCommented:
>>There are a few solutions created by the white hat community and they want to sell their ideas to the anti-virus vendors >>but no vendors have taken up the offer as of yet.

any particular reason(s) David?
0
 
David Dotan SoferAuthor Commented:
looking for a good and simple solution for Ransomware
0
 
David Johnson, CD, MVPOwnerCommented:
There is no real solution at this time.. Checkpoint.com has some good ideas on how to limit the damage. It is a cat and mouse game and the mice are winning.

AV is a post 0 day at best solution, the problem being that in many cases the exact launcher is only being seen 1 time.  The malware authors are creating individual launchers and the payloads are also being customized so any signature based AV will fail.  All one can do is monitor user activity and if a user changes 100+ files in a minute then you can have an appliance lockout that machine or process. The # of uniques is growing by about 100% per month in the last 6 months.
1

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

  • 3
  • 2
  • 2
  • +2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now