Ransomware Defense Method, System, Electronic Device, and Storage Medium

By analyzing and classifying the access relationship between subjects and objects in nodes, determining and issuing access control policies, the problems of poor universality and lag of ransomware defense in the existing technology are solved, and more effective ransomware defense is achieved.

CN113886822BActive Publication Date: 2025-06-24HANGZHOU DBAPPSECURITY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111086345.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-16
Publication Date
2025-06-24
Estimated Expiration
2041-09-16

AI Technical Summary

Technical Problem

In the prior art, ransomware defense is poor in universality and lag, and it cannot effectively prevent ransomware from encrypting user data.

Method used

By obtaining the access relationship between the subject and the object in the node, analyzing and classifying these access relationships, determining the access control policy, and issuing the policy to the corresponding node, in order to block the ransomware process and release non-ransomware process.

Benefits of technology

It improves the universality of ransomware defense, reduces lag, and can effectively defend against known and unknown ransomware threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113886822B_ABST
    Figure CN113886822B_ABST
Patent Text Reader

Abstract

The present application relates to a ransomware defense method, system, electronic device, and storage medium. By obtaining at least one pair of access relationships generated after a subject accesses an object in at least one node; analyzing the at least one pair of access relationships to determine the category to which each access relationship belongs, where the category includes a ransomware access type and a non-ransomware access type; determining an access control policy corresponding to each subject according to the category to which each access relationship belongs, and sending the access control policy to the corresponding node, where the access control policy is used to instruct the corresponding node to block the ransomware process and allow the non-ransomware process to pass through, which solves the problems of poor universality and lag in ransomware defense in the related art, improves the universality of ransomware defense, and improves the lag in ransomware defense.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security, and particularly to a method, a system, an electronic device and a storage medium for defending against ransomware. Background Art

[0002] At present, ransomware has developed into a complete black industrial chain, posing a major threat to the data and property security of enterprises. Ransomware usually spreads in the form of Trojan viruses, disguising itself as seemingly harmless files. The following two solutions for combating ransomware have been proposed in related technologies.

[0003] Solution 1: Based on the method of tainted files (bait files), by deploying tainted files (bait files) in the target system and monitoring changes to the tainted files (bait files), when a change is detected, it is considered that ransomware is running, and at this time, an alarm is given or the initiated process is terminated.

[0004] Disadvantages: The method based on tainted files (bait files) requires several prerequisites. First, it is assumed that when ransomware traverses files, it preferentially traverses the tainted files (bait files), otherwise, user files may be encrypted by ransomware before the tainted files (bait files) are rewritten. Second, this method also assumes that ransomware encrypts files in sequence. If the order is disrupted after traversing the files, user files will still be encrypted by ransomware. And this solution will generate redundant files in the user's file directory, which may cause misunderstandings to users.

[0005] Solution 2: Detection method based on a blacklist. This method essentially relies on antivirus software or an antivirus engine and adopts the idea of active defense. When a process is started (ransomware also creates a process), real-time detection is performed. If it is a malicious program, it is not allowed to start.

[0006] Disadvantages: The defect of the detection method based on a blacklist is that there is a large lag. Ransomware that has undergone anti-detection and shelling processing is very likely not to be detected by antivirus software. Once ransomware runs normally, full-disk encryption will be completed in a very short time, causing significant harm to the user's data and property.

[0007] Regarding the problems of poor universality and lag in ransomware defense in related technologies, no effective solution has been proposed yet. Summary of the Invention

[0008] In this embodiment, a method, a system, an electronic device and a storage medium for defending against ransomware are provided to solve the problems of poor universality and lag in ransomware defense in related technologies.

[0009] In a first aspect, in this embodiment, a method for defending against ransomware is provided, and the method includes:

[0010] Obtain at least one pair of access relationships generated after a subject accesses an object in at least one node;

[0011] Analyze the at least one pair of access relationships to determine the category to which each access relationship belongs, where the category includes a ransomware access type and a non-ransomware access type;

[0012] Determine an access control policy corresponding to each subject according to the category to which each access relationship belongs, and send the access control policy to the corresponding node, where the access control policy is used to instruct the corresponding node to block the ransomware process and allow the non-ransomware process to pass.

[0013] In some embodiments, before analyzing the at least one pair of access relationships to determine the category to which each access relationship belongs, the method further includes:

[0014] Filter out the access relationships generated after a system process accesses a system file.

[0015] In some embodiments, before analyzing the at least one pair of access relationships to determine the category to which each access relationship belongs, the method further includes:

[0016] Filter out the access relationships generated after a desktop process accesses a user file.

[0017] In some embodiments, analyzing the at least one pair of access relationships to determine the category to which each access relationship belongs includes:

[0018] Determine the access relationships with the same subject among multiple pairs of access relationships, merge the access relationships with the same subject, and obtain an access relationship set;

[0019] Analyze the access relationship set, and determine the category to which each access relationship in the access relationship set belongs according to the subject in the access relationship set.

[0020] In some embodiments, the object includes a file and / or a directory. Determining an access control policy corresponding to each subject according to the category to which each access relationship belongs and sending the access control policy to the corresponding node includes:

[0021] Determine the target file and / or target directory listed as protected objects;

[0022] Configure the target processes allowed to access according to the target file and / or the target directory to obtain the access control policy.

[0023] In some embodiments, the access control policy is a mandatory access control policy.

[0024] In some of these embodiments, obtaining at least one pair of access relationships generated after a subject accesses an object in at least one node includes:

[0025] Monitoring file access events of the operating system in each of the nodes to obtain context information, operation modes, and operation objects in the file access events;

[0026] Determining the access relationship between the subject and the object according to the context information, operation modes, and operation objects in the file access events.

[0027] In a second aspect, a ransomware defense system is provided in this embodiment. The ransomware defense system includes a cloud control center and multiple nodes, and the cloud control center is communicatively connected to the multiple nodes; the cloud control center is configured to execute the ransomware defense method described in the first aspect above.

[0028] In a third aspect, an electronic device is provided in this embodiment, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the ransomware defense method described in the first aspect above is implemented.

[0029] In a fourth aspect, a storage medium is provided in this embodiment, on which a computer program is stored. When the program is executed by a processor, the ransomware defense method described in the first aspect above is implemented.

[0030] Compared with the related art, the ransomware defense method, system, electronic device, and storage medium provided in this embodiment obtain at least one pair of access relationships generated after a subject accesses an object in at least one node; analyze the at least one pair of access relationships to determine the category to which each access relationship belongs, where the category includes a ransomware access type and a non-ransomware access type; determine an access control policy corresponding to each subject according to the category to which each access relationship belongs, and send the access control policy to the corresponding node, where the access control policy is used to instruct the corresponding node to block the ransomware process and allow the non-ransomware process to pass, solving the problems of poor universality and lag in ransomware defense in the related art, and improving the universality and lag of ransomware defense.

[0031] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more concise and understandable. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] The accompanying drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0033] Figure 1 is a hardware structure block diagram of the terminal of the ransomware defense method in this embodiment;

[0034] Figure 2 is a flowchart of the ransomware defense method in this embodiment;

[0035] Figure 3 is an operation flowchart of the ransomware defense system in this embodiment. Detailed implementation manners

[0036] For a clearer understanding of the purpose, technical solution, and advantages of the present application, the present application will be described and explained below in conjunction with the accompanying drawings and embodiments.

[0037] Unless otherwise defined, the technical terms or scientific terms involved in the present application should have the general meaning understood by those with ordinary skills in the technical field to which the present application belongs. In the present application, words such as "a", "an", "one kind", "the", "these", etc. do not indicate a limitation in quantity, and they can be singular or plural. The terms "including", "containing", "having" and any variants thereof involved in the present application are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device including a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent in these processes, methods, products, or devices. The terms "connected", "coupled", etc. involved in the present application do not limit to physical or mechanical connections, but may include electrical connections, whether directly or indirectly. The "multiple" involved in the present application refers to two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships can exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, and B exists alone. Usually, the character " / " represents an "or" relationship between the associated objects before and after. The terms "first", "second", "third", etc. involved in the present application are only used to distinguish similar objects and do not represent a specific order for the objects.

[0038] The method embodiments provided in this embodiment can be executed on a terminal, a computer, or a similar computing device. For example, running on a terminal, Figure 1 is a hardware structure block diagram of the terminal of the ransomware defense method in this embodiment. As Figure 1As shown, the terminal may include one or more ( Figure 1 only one is shown in the figure) processors 102 and a memory 104 for storing data. Among them, the processor 102 may include, but is not limited to, processing devices such as a microprocessor MCU or a field-programmable gate array FPGA. The above terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above terminal. For example, the terminal may further include more or fewer components than Figure 1 shown in the figure, or have a different configuration from Figure 1 shown in the figure.

[0039] The memory 104 can be used to store computer programs. For example, software programs and modules of application software, such as the computer program corresponding to the ransomware defense method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories can be connected to the terminal through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0040] The transmission device 106 is used to receive or send data via a network. The above network includes a wireless network provided by the communication provider of the terminal. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0041] In this embodiment, a ransomware defense method is provided. Figure 2 is a flowchart of the ransomware defense method in this embodiment. As Figure 2 shown, the process includes the following steps:

[0042] Step S201, obtain at least one pair of access relationships generated after a subject accesses an object in at least one node.

[0043] The cloud control center obtains the data uploaded by each node and generates the access relationship between the subject and the object based on this data. Among them, the subject refers to the operator of the resource, which can be the software program itself in this embodiment. The object refers to the resource to be operated, which can be a file or a directory accessed and operated by certain programs in this embodiment. In some embodiments, when obtaining at least one pair of access relationships generated after the subject in at least one node accesses the object, by monitoring the file access events of the operating system in each node, the context information, operation mode, and operation object in the file access events are obtained; based on the context information, operation mode, and operation object in the file access events, the access relationship between the subject and the object is determined.

[0044] For example, the node monitors all file accesses of the operating system through the Minifilter file filtering driver provided by the Windows system, can obtain the context information, operation mode, and operation object, and upload such data to the cloud control center for analysis after statistics in a cycle.

[0045] Step S202, analyze at least one pair of access relationships to determine the category to which each access relationship belongs, where the category includes the ransomware access type and the non-ransomware access type.

[0046] The cloud control center conducts a distributed summary analysis of the access relationships generated by each node to determine the category of the access relationships. The category of the access relationships includes the ransomware access type and the non-ransomware access type. Among them, the ransomware access type represents the access relationship formed after using the process of the ransomware as the subject to access the object of the node, and the non-ransomware access type represents the access relationship formed after using the process of the non-ransomware as the subject to access the object of the node.

[0047] Step S203, determine the access control policy corresponding to each subject according to the category to which each access relationship belongs, and send the access control policy to the corresponding node, where the access control policy is used to instruct the corresponding node to block the ransomware process and allow the non-ransomware process to pass.

[0048] After comprehensively analyzing the access relationships uploaded by multiple nodes, the cloud control center determines the access control policy corresponding to each subject according to the category to which each access relationship belongs, and sends the access control policy to the corresponding node. After receiving the access control policy, the node will control the access of the corresponding subject to the object according to the access control policy, that is, block the ransomware process and allow the non-ransomware process to pass.

[0049] During specific implementation, after the kernel module of the node receives the file access control policy, when there are operations such as writing, overwriting, renaming, and deleting files, it will perform policy matching, allow the legitimate process to pass, and block the illegal operation on the file.

[0050] In the above steps S201 to S203, the cloud control center continuously collects the subject-object access relationships of the nodes, conducts distributed analysis, and finally forms a compliant access control policy. The nodes reject non-compliant access through the access control policy analyzed and issued by the cloud control center to defend against ransomware. The ransomware defense method of this embodiment avoids the disadvantages of setting tainted files in related technologies and has general applicability. Moreover, the access control policy is generated by the cloud control center continuously collecting the subject-object access relationships of the nodes and conducting distributed analysis, which has real-time performance and avoids the defects of the detection method based on the blacklist in related technologies and has no lag.

[0051] Through the above steps, this embodiment avoids the deficiencies in the current common ransomware protection methods and has a good user experience. The user does not need to participate throughout the process after configuring the policy, achieving the effect of defending against known and unknown ransomware. It solves the problems of poor universality and lag in ransomware defense in related technologies, improves the universality of ransomware defense, and improves the lag in ransomware defense.

[0052] In some embodiments, before analyzing at least one pair of access relationships to determine the category to which each access relationship belongs, some access relationships that do not belong to the analysis object are also filtered out. Including but not limited to:

[0053] Filter out the access relationships generated after the system process accesses the system files, that is, filter out the operations of the operating system itself.

[0054] Filter out the access relationships generated after the desktop process accesses the user files, such as the traversal and reading operations during refreshing.

[0055] In some of these embodiments, when analyzing at least one pair of access relationships to determine the category to which each access relationship belongs, determine the access relationships with the same subject among multiple pairs of access relationships, merge the access relationships with the same subject, and obtain an access relationship set; analyze the access relationship set, and determine the category to which each access relationship in the access relationship set belongs according to the subject in the access relationship set.

[0056] With such a setting, for the data submitted by each node, it is merged from the perspectives of the subject and the object and then processed secondly. For example, the data submitted by user A is the information of creating an Excel file by WPS or Office software, and the data submitted by user B is the information of creating a Word file by WPS or Office software. Those with the same subject can be intelligently merged, making the access control policy have general applicability.

[0057] In some embodiments, the objects include files and / or directories. During the process of determining the access control policies corresponding to each subject according to the categories to which the access relationships belong and distributing the access control policies to the corresponding nodes, the cloud management center determines the target files and / or target directories listed as protected objects; configures the target processes allowed to access according to the target files and / or target directories to obtain the access control policies.

[0058] Specifically, the cloud management center sets the file access control policy through the policy configuration page. For example, it sets files with *doc and *.xls extensions or a certain key directory as the protected objects, and then configures the legal processes that can write, such as word and wps processes.

[0059] In some embodiments, the access control policy is a mandatory access control policy. The mandatory access control policy can rely on the mandatory access control technology, insert a driver module into the system kernel of the node, and develop it using the standard file filtering interface provided by the operating system to achieve the mandatory permission control of the target files.

[0060] In this embodiment, a ransomware defense system is provided. The ransomware defense system includes a cloud management center and multiple nodes, and the cloud management center is communicatively connected to the multiple nodes; the cloud management center is used to execute the ransomware defense method of any of the above embodiments.

[0061] Figure 3 is the operation flowchart of the ransomware defense system in this embodiment, as Figure 3 shown, this process includes the following steps:

[0062] Step S31, the node continuously monitors the access relationship between the main and object and uploads it to the cloud management center;

[0063] Step S32, the cloud management center performs distributed analysis to generate the access control policy;

[0064] Step S33, the node configures the mandatory access control policy according to the access control policy;

[0065] Step S34, the node receives an access request initiated by a process to a file;

[0066] Step S35, determine whether it is a legal process; if so, execute Step S36; if not, execute Step S37;

[0067] Step S36, allow access;

[0068] Step S37, prohibit access.

[0069] In this embodiment, an electronic device is further provided, which includes a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any of the above method embodiments.

[0070] Optionally, the above electronic device may further include a transmission device and an input / output device. Among them, the transmission device is connected to the above processor, and the input / output device is connected to the above processor.

[0071] Optionally, in this embodiment, the above processor may be configured to execute the following steps through a computer program:

[0072] S1, obtain at least one pair of access relationships generated after a subject accesses an object in at least one node.

[0073] S2, analyze at least one pair of access relationships to determine the category to which each access relationship belongs. Among them, the categories include ransomware access types and non-ransomware access types.

[0074] S3, determine an access control policy corresponding to each subject according to the category to which each access relationship belongs, and send the access control policy to the corresponding node. Among them, the access control policy is used to instruct the corresponding node to block the ransomware process and allow the non-ransomware process to pass.

[0075] It should be noted that specific examples in this embodiment may refer to the examples described in the above embodiments and optional implementation manners, and will not be elaborated in this embodiment.

[0076] In addition, in combination with the ransomware defense method provided in the above embodiment, a storage medium may also be provided to implement it in this embodiment. A computer program is stored on the storage medium; when the computer program is executed by a processor, any of the ransomware defense methods in the above embodiments is implemented.

[0077] It should be understood that the specific embodiments described here are only used to explain this application, rather than to limit it. According to the embodiments provided in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0078] Obviously, the drawings are only some examples or embodiments of this application. For those of ordinary skill in the art, this application can also be applied to other similar situations based on these drawings without creative efforts. In addition, it can be understood that although the work done during the development process here may be complex and time-consuming, for those of ordinary skill in the art, certain design, manufacturing, or production changes based on the technical content disclosed in this application are only conventional technical means and should not be regarded as insufficient disclosure of this application.

[0079] As used in this application, the term "embodiment" means that the specific features, structures or characteristics described in connection with the embodiments may be included in at least one embodiment of this application. The phrase appears at various positions in the specification and does not necessarily mean the same embodiment, nor does it mean being independent or alternative to other embodiments and mutually exclusive. Those of ordinary skill in the art can clearly or implicitly understand that the embodiments described in this application can be combined with other embodiments without conflict.

[0080] The above-described embodiments merely represent several implementation manners of this application. The description thereof is relatively specific and detailed, but should not be construed as a limitation on the scope of patent protection. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application shall be subject to the appended claims.

Claims

1. A ransomware defense method, characterized in that, Applied to a cloud control center, the method includes: Obtaining at least one pair of access relationships generated after a subject accesses an object in at least one node; Analyzing the at least one pair of access relationships to determine the category to which each access relationship belongs, where the category includes a ransomware access type and a non-ransomware access type; Determining an access control policy corresponding to each subject according to the category to which each access relationship belongs, and sending the access control policy to the corresponding node, where the access control policy is used to instruct the corresponding node to block the ransomware process and allow the non-ransomware process to pass; Among them, obtaining at least one pair of access relationships generated after a subject accesses an object in at least one node includes: monitoring file access events of the operating system in each node to obtain context information, operation methods, and operation objects in the file access events; determining the access relationship between the subject and the object according to the context information, operation methods, and operation objects in the file access events.

2. The ransomware defense method according to claim 1, wherein Before analyzing the at least one pair of access relationships to determine the category to which each access relationship belongs, the method further includes: Filtering out the access relationships generated after a system process accesses a system file.

3. The ransomware defense method according to claim 1, characterized in that, Before analyzing the at least one pair of access relationships to determine the category to which each access relationship belongs, the method further includes: Filtering out the access relationships generated after a desktop process accesses a user file.

4. The ransomware defense method according to any one of claims 1 to 3, characterized in that Analyzing the at least one pair of access relationships to determine the category to which each access relationship belongs includes: Determining the access relationships with the same subject among multiple pairs of access relationships, merging the access relationships with the same subject, and obtaining an access relationship set; Analyzing the access relationship set and determining the category to which each access relationship in the access relationship set belongs according to the subject in the access relationship set.

5. The ransomware defense method according to claim 1, characterized in that The object includes a file and / or a directory. Determining an access control policy corresponding to each subject according to the category to which each access relationship belongs, and sending the access control policy to the corresponding node includes: Determining the target file and / or target directory listed as protected objects; Configuring the target process allowed to access according to the target file and / or the target directory to obtain the access control policy.

6. The ransomware defense method according to claim 5, wherein, The access control policy is a mandatory access control policy.

7. A ransomware defense system, characterized in that, The ransomware defense system includes a cloud control center and multiple nodes, and the cloud control center is communicatively connected to the multiple nodes; the cloud control center is used to execute the ransomware defense method according to any one of claims 1 to 6.

8. An electronic device, comprising a memory and a processor, characterized in that, A computer program is stored in the memory, and the processor is configured to run the computer program to execute the ransomware defense method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the ransomware defense method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Information processing method and device, electronic equipment and storage medium

    CN110879884A