A ransomware early identification and blocking method based on two-stage ransom text detection
Patent Information
- Application Number
- CN202610461998.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-09
- Publication Date
- 2026-07-03
AI Technical Summary
Existing technologies struggle to achieve high-accuracy detection before ransomware is launched or before the ransom note is written, making it impossible to identify unknown ransomware and failing to balance real-time detection with timely blocking.
By extracting executable file information before process creation, performing text string extraction and semantic discrimination, using the LTCABT model for candidate text classification, and monitoring the first file write behavior and memory image during process execution, a process tree is constructed for dual discrimination and blocking.
It enables intervention before ransomware acts destructively, improves the ability to identify unknown ransomware, reduces false alarm rates, enhances the real-time nature of detection and the thoroughness of blocking, and reduces system resource consumption.
Smart Images

Figure CN122333445A_ABST