Using entropy metrics to detect data integrity attacks in real-time

Authors:
Abstract:

Existing methods of detecting attacks on data integrity on file systems are investigated. A method of detecting such attacks based on the use of several entropy metrics is proposed. The efficiency of the proposed method is evaluated on the example of detection of existing ransomware.