Ransom
Keeper
OVERVIEW
Malicious programs which ask money
by locking system or encrypting data to make
it unusable and making it as a hostage.
Blocking new variants
Through situational and content-aware
profiling and machine learning technology,
we block new variants that are generated
thousands of times a day, and share
information collected from various companies
and customers to provide more effective
services.
Minimizing cost burden
We provides the most efficient and final
endpoint Ransomware blocking function by
minimizing the burden of additional
complicated management tasks and
additional costs through optimal interlocking
with the established security infrastructure.
Backup solution
Backup solution installation/operation/Beyond
the limitations of backup processing of
management costs burden and gaps due to
the backup cycle, we provide powerful backup
by selecting damaged files in real time.
(No separate storage required)
Do you still respond to the
threat of intelligent Ransomware
with the existing solution?
RansomKeeper can prevent damages by blocking
new variants and complex variants not through
blacklist (signature) method, but through situation
and content recognition profiling engine.
Real-time
variant blocking
ABC-P
engine
Machine
learning
Trust
DB
FUNCTION
in the case of vaccine, even if a
Ransomware variant occurs, it is
impossible to immediately respond
by detecting data deformation
Behavior and content-based
profiling ABC-P engine
RansomKeeper can respond
immediately by detecting data
modification even when
Ransomware variant occurs
In the case of existing security
such as DLP, if the file is encrypted
and blocked, information security
is impossible
3-step verification and blocking
RansomKeeper creates the optimal
environment implementation
through simultaneous use with
information security solution (option)
In the case of backup solution,
due to continuous HDD increase,
management and high cost occur
Real-time exception handling and
powerful backup
RansomKeeper prevents damage
from Ransomware with low
resources and low cost
ABC-P
Through Ransomware behavior and based on situational awareness, it blocks variants that occur in real time in advance/
We applied cumulative behavioral situation detection profiling technology that detects Ransomware behavior in advance by recognizing
and learning the processor’s behavior that occurs cumulatively and the situation of the timing, and creating the profiles by process.
Existing behavioral
profile A, B…
Reflecting feedback from users and the
entire network (machine learning beta)
Overview 1 of ABC-P Engine operation
1st execution warning
In case of certain programs, exception handling is possible
without additional measures
(blocking again in case of
malicious code action)
2nd execution warning
In case of certain programs,
exception handling is possible
without additional measures
Blocking and isolating when
file corruption is detected
Cleanup recovery process
operation in case of infection
Blocking and isolating mostly
at the previous steps
Overview 2 of ABC-P Engine operation
Intrusion
detection
Ransomware suspicious
behavior detection
Malware blocking
and isolation
Warning message
and blocking
Backup
File recovery process
operation
GLOBAL
New York Connecticut
Joint R&D consultation with
Sacred Heart Univ.
Washington
Consultation on marketing in
overseas markets
France
Global security company
RALF-Kairos
Australia
Global security company cloudyBoss
CERTIFICATE
It uses a cumulative behavioral situation detection profiling engine
to block Ransomware which is strengthened and sophisticated
through AI technology and blocks Ransomware through comprehensive
judgment rather than a simple file change detection method.
Partner