Inventors:
- Palo Alto CA, US
Sumeet Bharatbhai Varma - Sunnyvale CA, US
Guilherme Vale Ferreira Menezes - San Jose CA, US
Stephen Chu - San Francisco CA, US
Mohit Gupta - Palo Alto CA, US
International Classification:
H04L 29/06
G06F 9/455
G06N 20/00
G06K 9/62
G06F 16/953
Abstract:
Techniques for implementing a scalable automated training framework for anomaly and ransomware detection are disclosed. In some embodiments, a computer system performs operations comprising: instantiating a plurality of virtual machines, each one of the virtual machines being loaded with a corresponding file system; simulating user actions and ransomware on the virtual machines, the simulating of user actions and ransomware on the virtual machines causing changes to the corresponding file systems of the virtual machines; for each one of the plurality of virtual machines, generating a corresponding metadata file based on one or more corresponding snapshots of the virtual machine, the one or more corresponding snapshots indicating the changes to the corresponding file system of the virtual machine; and training a ransomware detection model using a machine learning algorithm and training data, the training data being based on the corresponding metadata files of the virtual machines.