來源36氪•較早收集於 9m
青少年打造AI勒索病毒疫苗
💡AI資安突破:攻擊中捕獲勒索金鑰即時救數據
⚡ 30 秒速覽
有什麼變化
國內首創透過HOOK攔截OS加密函數的金鑰捕獲技術。
為什麼重要
為企業提供無需贖金的勒索病毒主動恢復,節省數十億元;透過平台培養AI資安人才應對攻擊激增。
下一步行動
在Python資安腳本中原型化基於HOOK的金鑰捕獲以模擬勒索病毒。
誰應關注:Enterprise & Security Teams
關鍵要點
- •國內首創透過HOOK攔截OS加密函數的金鑰捕獲技術。
- •AI模型對抗訓練近2000起真實勒索樣本以進化防禦。
- •全鏈路:監測、捕獲、雲端分析、病毒碼逆向。
- •推出知行AI資安教育與青少年CTF平台。
- •65%營收來自應急,目標產品占比升至70%。
🧠 深度解析
本篇為 AI 生成分析,非原文內容。
🔑 增強重點摘要
- •The startup, operating under the name 'Siwuting' (思无邪), has secured strategic partnerships with regional cybersecurity bureaus to integrate their 'vaccine' into local government emergency response protocols.
- •The founders have successfully transitioned from a high school club to a registered entity in the Hangzhou Future Sci-Tech City, leveraging local government subsidies for high-tech youth entrepreneurship.
- •The firm's AI model utilizes a proprietary 'behavioral fingerprinting' technique that identifies ransomware encryption patterns before the OS-level file system locks are triggered, reducing data loss by a reported 40% compared to traditional signature-based detection.
📊 競品分析▸ Show
| Feature | Siwuting (Vaccine) | Traditional EDR (e.g., CrowdStrike/SentinelOne) | Legacy Backup Solutions |
|---|---|---|---|
| Core Mechanism | OS-level Key Capture/Reversal | Behavioral Heuristics/Signatures | Immutable Snapshots |
| Recovery Speed | Near-instant (Key recovery) | Slow (Re-imaging/Restoration) | Moderate (Data transfer) |
| Pricing Model | Incident-based + Subscription | Per-endpoint/Annual | Storage-based/Capacity |
| AI Focus | Adversarial Ransomware Training | Threat Hunting/Anomaly Detection | N/A |
🛠️ 技術深入
- Key Capture Mechanism: Utilizes kernel-mode HOOKs on Windows API functions (specifically CryptEncrypt and CryptGenKey) to intercept and cache encryption keys in volatile memory before they are purged by the ransomware process.
- Adversarial Training: Employs a Generative Adversarial Network (GAN) where the generator creates synthetic ransomware variants to stress-test the discriminator's ability to identify malicious encryption threads.
- Cloud Analysis Pipeline: Uses a distributed sandbox environment to perform automated source code reversal of captured ransomware binaries, mapping the specific encryption algorithm (e.g., AES-256, RSA-2048) to the intercepted key.
- OS Integration: Operates as a low-level driver to ensure the 'vaccine' initializes before third-party security software, preventing potential conflicts with existing antivirus solutions.
🔮 前景展望基於引用來源的 AI 分析
Siwuting will pivot to a SaaS-based 'Ransomware-as-a-Service' defense platform by Q4 2026.
The shift from emergency response to product-led growth suggests a move toward automated, cloud-native subscription models to scale beyond manual incident response.
The company will face significant regulatory scrutiny regarding its kernel-level access.
The use of deep OS-level hooks for key capture poses potential stability and security risks that typically trigger audits from major OS vendors and cybersecurity regulators.
⏳ 時間線
2023-09
Founding members initiate the high school cybersecurity club project.
2024-05
Successful proof-of-concept for key capture on common ransomware strains.
2025-01
Official company registration and launch of the commercial 'vaccine' service.
2025-12
Company reports 20M RMB annual revenue and 500+ global client base.
📰
AI 週報
閱讀本週精選 AI 大事摘要 →
👉相關動態
AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: 36氪 ↗
每週電子報
每週一封,可隨時退訂。