Solved

Kaspersky Anti-Ransomware Tool for Business

Posted on 2016-08-11
10
99 Views
Last Modified: 2016-09-22
hello,

is anyone familiar with this tool: 'Kaspersky Anti-Ransomware Tool for Business'.
what is your opinion on it ?
is it free ?

thank u
0
Comment
Question by:David Dotan Sofer
  • 3
  • 2
  • 2
  • +2
10 Comments
 
LVL 4

Expert Comment

by:Laroy Shtotland
ID: 41751999
Yes, it's free. As a complementary anti-ransomware solution, Kaspersky Anti-Ransomware Tool for Business provides corporate users with protection from ransomware and can serve as second opinion software.
For organizations that demand protection for each network level, including security technologies to protect workstations, file servers and mobile devices from all types of malware and today’s sophisticated attacks, use specialized business solutions.
0
 
LVL 23

Expert Comment

by:Eirman
ID: 41752011
Looking at the issue sideways .....
Veeam backup Protects USB-based storage targets from CryptoLocker threats
by automatically ejecting them after a successful run.

https://www.veeam.com/endpoint-backup-free.html
0
 
LVL 2

Expert Comment

by:furuno
ID: 41752019
As a matter of interest, anyone know does the Kaspersky Anti-Ransomware Tool work - heuristic analysis?
0
 
LVL 4

Expert Comment

by:Laroy Shtotland
ID: 41752039
It uses 2 technologies: Kaspersky Security Network (KSN) and Kaspersky System Watcher.

Kaspersky Security Network, a cloud-based service dedicated to processing depersonalized cybersecurity-related data streams from millions of voluntary participants all over the world. With Kaspersky Security Network, delivery of Kaspersky Lab security intelligence happens in a matter of seconds, ensuring fast reaction times and maintaining high levels of protection. http://ksn.kaspersky.com/

System Watcher is an advanced proactive security technology that scans all important system events, including the creation and modification of operating system files and configurations, program execution and data exchange over the network. Events are recorded and analyzed, and if there is evidence that a program is performing malicious operations, those actions can be blocked and reversed, preventing further infection.
http://support.kaspersky.com/6270
http://www.kaspersky.com/images/Kaspersky_Lab_Whitepaper_System_Watcher_ENG.pdf
0
 
LVL 23

Expert Comment

by:Eirman
ID: 41752064
If you have a computer with files that have encrypted with Ransomware,
it is very unlikely that you can decrypt them yourself without paying a ransom.
This is not to be recommended as you are giving money to/dealing with criminals who may not decrypt your files anyway.
0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 
LVL 4

Expert Comment

by:Laroy Shtotland
ID: 41752081
It was not part of the initial question, but if your files are already encrypted, you can try free decryptors like https://noransom.kaspersky.com/
0
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 41752119
Will it stop all versions of ransom-ware highly unlikely so it isn't a magic bullet.  What one has to look for are typical behaviour of a ransom-ware attack. modification of a significant number of files in a short period of time. deletion of shadow copies, change of file sizes of multiple files in a short period of time.  Execution of executable from the users appdata directory.

The creation of software that performs the same as ransom-ware is trivial to code, getting a spam bot to include the code or a launcher that retrieves the executable code and getting paid without being caught are the only stumbling blocks.

There are a few solutions created by the white hat community and they want to sell their ideas to the anti-virus vendors but no vendors have taken up the offer as of yet.
0
 
LVL 2

Expert Comment

by:furuno
ID: 41752140
>>There are a few solutions created by the white hat community and they want to sell their ideas to the anti-virus vendors >>but no vendors have taken up the offer as of yet.

any particular reason(s) David?
0
 

Author Comment

by:David Dotan Sofer
ID: 41752176
looking for a good and simple solution for Ransomware
0
 
LVL 78

Accepted Solution

by:
David Johnson, CD, MVP earned 500 total points
ID: 41754336
There is no real solution at this time.. Checkpoint.com has some good ideas on how to limit the damage. It is a cat and mouse game and the mice are winning.

AV is a post 0 day at best solution, the problem being that in many cases the exact launcher is only being seen 1 time.  The malware authors are creating individual launchers and the payloads are also being customized so any signature based AV will fail.  All one can do is monitor user activity and if a user changes 100+ files in a minute then you can have an appliance lockout that machine or process. The # of uniques is growing by about 100% per month in the last 6 months.
1

Featured Post

Get up to 2TB FREE CLOUD per backup license!

An exclusive Black Friday offer just for Expert Exchange audience! Buy any of our top-rated backup solutions & get up to 2TB free cloud per system! Perform local & cloud backup in the same step, and restore instantly—anytime, anywhere. Grab this deal now before it disappears!

Join & Write a Comment

SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now