Eastsoft announced that its security subsidiary, East Security, has integrated a 'behavioral ransomware detection feature' into its antivirus software for Linux servers to strengthen ransomware defenses in corporate server environments.
This feature combines file damage detection with analysis of abnormal file system behavior, allowing effective responses to the Linux server environment, which has recently become a target for ransomware attacks due to its concentration of critical data and services, including web servers, databases, and internal business systems.
By applying technology that analyzes and responds to abnormal behaviors in real time, the new feature enhances the ability to counter new ransomware or variant threats that bypass pattern-based detection. This overcomes the limitations of existing antivirus solutions that were primarily focused on Windows environments or only provided limited protection along specified paths.
Recent ransomware attacks have evolved beyond using known malware patterns, increasingly employing new and variant forms that evade detection. Given that Linux servers house essential corporate data and services, the risk of data damage and service disruption necessitates technology capable of capturing abnormal behaviors in the file system in real time.
The new feature comprehensively analyzes multiple signals of abnormal behavior, including: 'decoy damage detection' using bait files, continuous changes to multiple files, changes in names and extensions, abnormal deletions, and file changes across multiple directories.
A 'monitoring mode' is also provided to ensure stable server operations. This safety mechanism helps prevent false positives and service disruptions that may occur when implementing security solutions. In this mode, suspicious processes are not immediately blocked, allowing administrators to assess the impact of detection results on operations.
As a result, administrators can monitor for a set period, confirm normal operations, and then fine-tune protection paths, exceptions, and response methods. Since application and file access patterns differ across corporate servers, this allows for the safe application of optimized security policies tailored to each system environment.
Lee Ji-han, head of product development at East Security, stated, "To effectively respond to evolving cyber threats, it is essential to not only adopt the latest security technologies but also to continuously update operating system (OS) and security patches, and to integrate security policies optimized for actual operating environments. We will continue to enhance security technologies that respond immediately to changing threats, ensuring our customers can maintain a stable business environment."
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.
