CONTAP-355948:検出されたファイル数が20未満のランサムウェアアクティビティの可能性が報告される
問題
- EMSレポートarw.activity.seen:[callhome.arw.activity.seen:alert]: Call home message for POSSIBLE RANSOMWARE ACTIVITY DETECTED, Volume: vol1 (UUID: xxxx) in Vserver: svm1 (UUID: xxxx)
- System Managerで検出されたファイルは6個(デフォルトの20個未満)だけです。
- デフォルト値の20は使用中です。cluster::> security anti-ransomware volume attack-detection-parameters show -vserver svm1 -volume vol1
 Vserver Name : svm1
 Volume Name : vol1
 Is Detection Based on High Entropy Data Rate? : true
 Is Detection Based on Never Seen before File Extension? : false
 Is Detection Based on File Create Rate? : true
 Is Detection Based on File Rename Rate? : true
 Is Detection Based on File Delete Rate? : true
 Is Detection Relaxing Popular File Extensions? : true
 High Entropy Data Surge Notify Percentage : 100
 File Create Rate Surge Notify Percentage : 100
 File Rename Rate Surge Notify Percentage : 100
 File Delete Rate Surge Notify Percentage : 100
 Never Seen before File Extensions Count Notify Threshold : 20
 Never Seen before File Extensions Duration in Hour : 24