New Google Drive Desktop Feature adds AI-powered Ransomware Detection to Prevent Cyberattacks
Google has introduced an AI-powered ransomware detection feature for Google Drive for desktop, which aims to protect user files by automatically blocking cyberattacks.
Google has introduced an AI-powered ransomware detection feature for Google Drive for desktop, which aims to protect user files by automatically blocking cyberattacks.
This enhancement provides enhanced security for users on Windows and macOS, addressing the ongoing threat of ransomware, which poses significant risks to various sectors including healthcare, retail, and government, often resulting in financial losses and data breaches.
While Google's Workspace files, such as Docs and Sheets, are not susceptible to ransomware, other file types like PDFs and Microsoft Office documents remain vulnerable on desktop operating systems.
Traditional antivirus software has become insufficient against evolving ransomware tactics. Google's new feature in Drive for desktop detects ransomware activity through AI, focusing on the mass encryption or corruption of files.
When such activity is detected, the system intervenes by pausing file syncing to the cloud, containing the attack and preventing file corruption within Drive and across the network.
Traditional antivirus software has become insufficient against evolving ransomware tactics.
Google Drive for desktop now employs a specialized AI model trained on millions of ransomware samples to identify malicious file modifications. The detection engine continuously adapts by analyzing file changes and incorporating new threat intelligence from VirusTotal.
Upon detecting suspicious activity, Drive for desktop automatically takes the following actions:
Pauses Syncing: Immediately stops syncing affected files to the cloud to prevent encryption spread. Alerts the User: Notifies the user via desktop and email about the detected threat and provides recovery guidance. Facilitates Restoration: Allows users to restore files to a previous state via an intuitive web interface in Drive, minimizing data loss without complex IT intervention.
The feature provides IT administrators with management tools and oversight. An alert is generated in the Admin console upon detecting a ransomware event on a user's device, allowing administrators to review detailed audit logs in the security center.
This capability is enabled by default for eligible customers, but administrators can disable detection and restoration features based on organizational policies.
This ransomware detection and file restoration feature is currently in open beta and is included at no additional cost in most Google Workspace commercial plans. The file restoration capability is also available to consumer users for free.
Based on reporting by Cyber Security News.
