A method, apparatus, device, and medium for placing a decoy file
Patent Information
- Application Number
- CN202211378171.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-04
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2042-11-04
AI Technical Summary
[0002]随着网络的普及和通信技术的发展,许多勒索病毒也是层出不穷,并快速跃升成为当前互联网安全的重点威胁之一,于是针对各种勒索病毒的检测与阻断的安全软件也应运而生,其中播散诱饵文件是大多数安全产品检测勒索病毒的关键技术之一,但对于诱饵文件的创建与放置的目录比较单一,比如生成单一的指定类型(.doc、.excel)的文件、放置目录为桌面、磁盘根目录(C盘、E盘)等等,然而,在一些功能单一的工控机中,其中存储的文件类型很少,一般只存在一种或者有限的几种类型的文件,此时若再加入诱饵文件,会导致系统中平添一些不必要出现的文件,而多出的诱饵文件会降低客户使用工控机的使用体验感
[0060]本申请所提供的一种放置诱饵文件的方法,包括:确定勒索病毒的检测开关的状态;当检测开关的状态为开启时,获取系统内全部磁盘的线程其中,各线程并行运行;在线程中,过滤系统的关键目录;在其余的普通目录中确定放置诱饵文件的位置。此时通过过滤系统的关键目录以及在其余的普通目录中确定放置诱饵文件的位置的步骤,实现了仅在功能单一的工控机中的关键目录下加入诱饵文件,避免工控机等功能单一的系统中平添一些不必要出现的文件,提升客户使用工控机的使用体验感。
Smart Images

Figure CN115688100B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, device, and medium for placing decoy files. Background Technology
[0002] With the popularization of the internet and the development of communication technology, many ransomware viruses have emerged and quickly become one of the key threats to current internet security. As a result, security software for detecting and blocking various ransomware viruses has also emerged. Among them, spreading decoy files is one of the key technologies for most security products to detect ransomware viruses. However, the creation and placement of decoy files are relatively simple. For example, they are generated as a single specified type of file (.doc, .excel) and placed in the desktop, disk root directory (C drive, E drive), etc. However, in some industrial control computers with limited functions, the types of files stored are very few. Generally, only one or a limited number of file types exist. If decoy files are added in this case, it will cause some unnecessary files to appear in the system. The extra decoy files will reduce the user experience of the industrial control computer.
[0003] Given the aforementioned problems, finding a way to target and set decoy files is a problem that those skilled in the art strive to solve. Summary of the Invention
[0004] The purpose of this application is to provide a method, apparatus, device, and medium for placing decoy files, for the purpose of directional placement of decoy files.
[0005] To address the aforementioned technical problems, this application provides a method for placing decoy files, comprising:
[0006] Determine the status of the ransomware detection switch;
[0007] When the detection switch is on, a thread is used to retrieve all disks in the system, with each thread running in parallel.
[0008] Within a thread, filter the system's critical directories;
[0009] In the remaining regular directories, determine the location to place the decoy files.
[0010] Preferably, after determining the location for placing the decoy file in the remaining ordinary directories after the critical directory of the filtering system, the method further includes:
[0011] Place a decoy file at the beginning and end of the critical directory.
[0012] Preferably, after placing a decoy file at the beginning and end of the key directory, the method further includes:
[0013] Traverse a regular directory;
[0014] Determine if a file contains data.
[0015] If so, proceed to the step of determining the location of the decoy file in the remaining ordinary directories;
[0016] If not, return to the step of traversing the normal directory.
[0017] Preferably, when determining that a file contains data content, the method further includes:
[0018] Determine if the total number of decoy files set in the system exceeds the preset number;
[0019] If not, proceed to the step of determining the location of the decoy file in the remaining ordinary directories;
[0020] If so, then the process ends.
[0021] Preferably, when it is determined that a file does not contain data content, the method further includes:
[0022] Determine whether the specified level of a normal directory has been reached;
[0023] If not, return to the step of traversing the normal directory;
[0024] If so, then the process ends.
[0025] Preferably, when it is determined that the total number of bait files set in the system does not exceed a preset number, determining the location for placing the bait files in the remaining ordinary directories includes:
[0026] Get file attributes of a file of a specified type;
[0027] Determine the search order based on file attributes;
[0028] Place a decoy file at the beginning and end of the file in the order of retrieval.
[0029] Preferably, determining the location of the bait files in a preset order within a general directory includes:
[0030] The location for placing the decoy files is determined by priority within the regular directory.
[0031] To address the aforementioned technical problems, this application also provides a device for placing decoy documents, comprising:
[0032] The first determining module is used to determine the state of the ransomware detection switch;
[0033] The first acquisition module is used to acquire all disks in the system when the detection switch is in the "on" state. Among them, each thread runs in parallel.
[0034] The filtering module is used to filter critical directories of the system within a thread;
[0035] The second determination module is used to determine the location where the decoy file is placed in the remaining ordinary directories.
[0036] In addition, the device also includes the following modules:
[0037] Preferably, after determining the location for placing the decoy file in the remaining ordinary directories after the critical directory of the filtering system, the method further includes:
[0038] The first placement module is used to place a decoy file at the beginning and end of the critical directory.
[0039] Preferably, it further includes:
[0040] The traversal module is used to traverse ordinary directories;
[0041] The first judgment module is used to determine whether a file contains data content;
[0042] If so, the second determination module is triggered;
[0043] If not, the traversal module is triggered.
[0044] Preferably, when determining that a file contains data content, the method further includes:
[0045] The second judgment module is used to determine whether the total number of decoy files set in the system exceeds the preset number.
[0046] If not, the second determination module is triggered; if yes, the process ends.
[0047] Preferably, when it is determined that a file does not contain data content, the method further includes:
[0048] The third judgment module is used to determine whether the specified level of a normal directory has been reached;
[0049] If not, the traversal module is triggered; if yes, the process ends.
[0050] Preferably, when it is determined that the total number of bait files set in the system does not exceed a preset number, determining the location for placing the bait files in the remaining ordinary directories includes:
[0051] The second acquisition module is used to acquire file attributes of a specified type of file;
[0052] The third determining module is used to determine the search order based on file attributes;
[0053] The second placement module is used to place a decoy file at the beginning and end of the file according to the retrieval order.
[0054] Preferably, determining the location of the bait files in a preset order within a general directory includes:
[0055] The third placement module is used to determine the location of the decoy files in a regular directory according to their priority.
[0056] To address the aforementioned technical problems, this application also provides a device for placing decoy files, comprising:
[0057] Memory, used to store computer programs;
[0058] A processor is used to direct a computer program to implement the steps of placing a decoy file.
[0059] To address the aforementioned technical problems, this application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements all the steps of the above-described method for placing decoy files.
[0060] This application provides a method for placing decoy files, comprising: determining the state of a ransomware detection switch; when the detection switch is on, acquiring threads for all disks in the system, wherein each thread runs in parallel; filtering critical directories of the system within the threads; and determining the location for placing the decoy file in the remaining ordinary directories. By filtering critical directories and determining the location for placing the decoy file in the remaining ordinary directories, the method ensures that the decoy file is only added to the critical directories of a single-function industrial control computer, avoiding the addition of unnecessary files to such systems and improving the user experience.
[0061] This application also provides a device, apparatus, and medium for placing decoy documents, with the same effect as above. Attached Figure Description
[0062] To more clearly illustrate the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0063] Figure 1 This is a flowchart illustrating a method for placing decoy files, as provided in an embodiment of this application.
[0064] Figure 2 This is a structural diagram of a device for placing decoy documents provided in an embodiment of this application;
[0065] Figure 3This is a structural diagram of a device for placing decoy files, provided as an embodiment of this application. Detailed Implementation
[0066] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.
[0067] The core of this application is to provide a method, apparatus, device, and medium for placing decoy files, which can directionally place the decoy files.
[0068] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0069] Figure 1 This is a flowchart illustrating a method for placing decoy files, as provided in an embodiment of this application. Figure 1 As shown, the method for placing the decoy file includes:
[0070] S10: Determine the status of the ransomware detection switch.
[0071] Once a ransomware file enters the local machine, it runs automatically while simultaneously deleting the ransomware sample to evade detection and analysis. Next, the ransomware uses the local internet access to connect to the hacker's C&C server, uploading local information and downloading an encryption public key, which it then uses to encrypt the files. Decryption is virtually impossible for anyone other than the virus developer. After encryption, it also changes the wallpaper and generates a ransom note in a prominent location such as the desktop, instructing the user to pay the ransom. Furthermore, it mutates very rapidly and is immune to conventional antivirus software. Attack samples are primarily in the .exe, .js, .wsf, and .vbe formats, posing a significant challenge to conventional security products that rely on signature-based detection. According to Huorong monitoring, ransomware primarily spreads through three channels: vulnerabilities, emails, and advertising. Attacks launched through vulnerabilities account for 87.7% of all attacks. Because older operating systems like Windows 7 and XP have numerous vulnerabilities that cannot be patched in a timely manner, and these older systems are frequently used by government agencies, businesses, schools, hospitals, and other LAN users, they have become prime targets for virus attacks. Viruses can spread infinitely within LANs through these vulnerabilities. Conversely, Windows 10 systems, due to mandatory updates, are almost unaffected by vulnerability attacks. Attacks via email and advertising accounted for 7.4% and 3.9% respectively. Although these two methods of propagation represent a smaller percentage, they still pose a threat to businesses that rely on sending and receiving emails and browsing the web. Furthermore, for some LAN users who heavily rely on USB drives and recorders for office work, peripheral devices have become a specific avenue for ransomware attacks.
[0072] It should be noted that the ransomware detection switch generally has two states: on and off. As a preferred embodiment, there may also be a paused state, indicating that ransomware detection is paused when other files running on the system encounter errors. Furthermore, determining the ransomware detection switch state can be done in real time.
[0073] S11: When the detection switch is on, retrieve all disks in the system.
[0074] In this system, each thread runs in parallel to save time in placing the decoy file. It should be noted that the state of the detection switch can be expressed in text or data string form. When expressed in text form, the state can be "on" or "off," etc.; when expressed in data string form, the data string can be 1, 2, 4, 8, etc., and can be represented in the order mentioned above as "1," "10," "1100," "00100111," etc. It should be noted that the above-mentioned methods for representing the state of the detection switch are only a few of many embodiments and do not limit the method of representing the state of the detection switch. Furthermore, the data string can be converted to a decimal value, and it can be determined whether the value exceeds a preset value. If it exceeds the preset value, the output indicates that the state of the detection switch is on. Alternatively, the number of 0s and 1s in the data string can be counted; if the number of 1s is greater than the number of 0s, the output indicates that the state of the detection switch is on. It can also be determined whether the number of 0s or 1s in the data string exceeds a preset number; if it does, the output indicates that the state of the detection switch is on. The above-mentioned implementation methods do not limit the state of the detection switch in this application, and the implementation method can be determined according to the implementation scenario.
[0075] S12: In a thread, filter the system's critical directories.
[0076] It's important to note that each disk corresponds to one thread. Each disk stores system files, and these system files containing system data are designated as critical directories to prevent the addition of too many decoy files, which could malfunction the system files and hinder their proper operation. These critical directories can be, for example, C:\Windows\System32 on Windows or / etc / on Linux. A decoy file is placed at both the beginning and end of each critical directory.
[0077] S13: Determine the location for placing the decoy files in the remaining ordinary directories.
[0078] At this point, by filtering the critical directories of the system and determining the location of the decoy files in the remaining ordinary directories, the decoy files are added only to the critical directories of the single-function industrial control computer. This avoids adding unnecessary files to single-function systems such as industrial control computers and improves the user experience of customers using industrial control computers.
[0079] Based on the above embodiments, as a more preferred embodiment, after placing a decoy file at the beginning and end of the key directory, it further includes:
[0080] Traverse a regular directory;
[0081] Determine if a file contains data.
[0082] In this context, it can be understood that a file containing data content means a file that contains relevant configuration information for related business operations, as well as other relevant business information.
[0083] If so, proceed to the step of determining the location of the decoy file in the remaining ordinary directories;
[0084] If not, return to the step of traversing the normal directory.
[0085] When determining that a file contains data content, this also includes:
[0086] Determine if the total number of decoy files set in the system exceeds the preset number;
[0087] In general, the preset number is set to multiple, and the specific value should be determined by the number of important files divided by the technical personnel of each thread on each disk.
[0088] If not, proceed to the step of determining the location of the decoy file in the remaining ordinary directories; if yes, end.
[0089] Similarly, when a file is determined not to contain data, it also includes:
[0090] Determine whether the specified level of a normal directory has been reached;
[0091] It's understandable that a directory can have multiple levels, and the directory expands level by level. Consider a three-level directory, where it's necessary to determine whether to open the second level; the specified level is the second level.
[0092] If not, return to the step of traversing the normal directory; if yes, end.
[0093] Specifically, when it is determined that the total number of bait files set in the system does not exceed the preset number, the locations for placing the bait files in the remaining ordinary directories include:
[0094] Get file attributes of a file of a specified type;
[0095] At this point, file attributes can include file type, file size, file storage location, etc.
[0096] Determine the search order based on file attributes;
[0097] Place a decoy file at the beginning and end of the file in the order of retrieval.
[0098] To protect important files, a decoy file needs to be placed at the beginning and end of each file in the search order. It's important to note that the placement of the decoy files in the regular directory is determined by priority. This priority is assigned by technical personnel based on the importance of the files. This importance can be represented by a score; for example, using a score of 1-100 as a baseline, files scoring 90-100 are given first priority, 70-90 second priority, and 60-70 third priority. Alternatively, importance can be represented by weights, with corresponding priorities determined by these weights; for example, using a weight range of 0-1.0 as a baseline, files with a weight range of 0.9-1.0 are given first priority, 0.7-0.9 second priority, and 0.6-0.7 third priority. This method can set various types of decoy files based on file types and business relevance in ordinary directories and critical directories, while avoiding critical directories in system operation. By minimizing the blindness of decoy files, it can promptly stop ransomware and encrypt critical directories, protecting the customer's business system from being damaged by ransomware.
[0099] Finally, the decoy file is described as follows: Decoy refers to data used to confuse attackers, including files, databases, flags, code, and other information, enticing them to attack the honeypot. Like a hunter setting a trap, there are certain techniques involved in creating and deploying decoys. Deploying an effective deception and camouflage system in a network typically requires considering many factors. While attackers' methods are constantly evolving, they are generally traceable. To attract and deceive attackers using decoys, one must first understand their attack strategies and psychology, determining the placement, content, and scale of the decoy along key attack paths. This often yields significantly better results with less effort.
[0100] A honeypot is a proactive security threat defense technology. It attracts attackers by simulating one or more vulnerable hosts or services, capturing attack traffic and samples, discovering network threats, and extracting threat signatures. The value of a honeypot lies in its ability to be detected and compromised. Essentially, it's a game of attack and defense between the honeypot and the attacker. The honeypot provides the service, and the attacker provides access. Attackers are drawn to the honeypot and then attack it. During the attack, experienced attackers may be able to identify a target as a honeypot. Therefore, to better attract attackers, honeypots also need to provide robust attack deception capabilities.
[0101] During the information gathering phase, the decoy's role is to confuse attackers. Disguised information, achieved through honeypot technology, is mixed into information sources frequently used by attackers, inducing them to collect incorrect information at this stage and direct their attacks towards the honeypot. Path analysis: Attackers typically utilize publicly available information platforms such as GitHub, Gitee, Baidu Cloud, and online search engines to attempt to uncover vulnerabilities.
[0102] Countermeasures generally involve two steps: First, constructing a trap: This involves building a honeypot system containing sensitive words, non-critical source code, system configuration files, etc., to lure attackers. Second, deploying bait: When deploying bait, considering the higher probability of successful tracing via browser IDs, bait can be deployed more frequently to relevant information sharing platforms. Intentionally exposing code information on software or project management platforms, and "forgetting" to anonymize it, exposes configuration information such as account settings, maintenance records, name setting methods, keyword matching, and even email usernames and passwords, which are also excellent "raw materials." Designing and deploying domain bait when attackers are performing subdomain brute-force attacks, ensuring the domain is not crawled by search engines but can be detected by dictionary-based subdomain brute-force tools. Placing documents with names and content related to a business system (honeypot) in public locations, "inadvertently" exposing some "valuable" information within the documents, can also achieve a distraction effect.
[0103] During the reconnaissance phase of a system, the attacker's goal is to analyze the collected assets as comprehensively as possible to quickly find a breakthrough. The more comprehensive the information, the greater the help for subsequent "penetration." At this stage, the key is to use honeypots as weak points, exposing them to the attacker to attract their attention and encourage analysis. Simultaneously, bait is placed within the honeypots to distract the attacker, preventing them from escaping the honeycomb network. Path analysis: After obtaining target asset or account information through information gathering, attackers will choose to conduct reconnaissance on familiar systems to find vulnerabilities.
[0104] The countermeasures generally involve two steps. First, honeypots can be interconnected using decoys to form a tightly linked honeycomb. For example, in an enterprise email honeypot, maintenance logs and upgrade documents from other business systems (honeypots) can be exposed, diverting the attacker's attention to other honeypots. Alternatively, honeypot database configuration files can be configured to mislead and restrain attackers through file path pointing and connection record forgery. Second, highly realistic simulation of key systems: Simulations can be built around real enterprise business systems that are of primary concern to attackers. Historically offline business systems can be re-uploaded to the honeypot system to lure attackers into staying. Third, highly realistic simulation scenarios can be created by combining manual maintenance with methods such as adding interactive pages, regularly publishing group announcements, and regularly logging in and managing the backend to construct highly realistic scenarios for these domain websites.
[0105] For lateral movement attacks on internal networks, bait needs to be pre-placed on some real assets. This could include creating historical command logs connecting to other honeypots or storing public key records from Secure Shell (SSH) connections to honeypots. Path analysis: The attacker is presumably able to gain access to the internal network through zero-day exploits. Since obtaining the path is crucial during the attack, path reconnaissance and lateral movement attacks on the internal network are often essential steps in penetration testing.
[0106] The countermeasures generally fall into four categories. First, timely attack detection: Deploy as many detection honeypots as possible within the internal network, using trunk methods to bind idle IPs, thus covering all areas of the internal network for attack detection. Second, deploy honeypots at critical points: To prevent attackers from directly accessing real hosts or maintenance terminals through host access logs, open certain ports on hosts at critical nodes and bind them to honeypots. Third, sensitive information-induced attacks: Forge login domain credentials, Remote Desktop Protocol (RDP) connection records, maintenance logs, user folders, browser browsing history, and related sensitive information to lure attackers into attacks. Fourth, honeypots need to be used with decoys: Open valuable ports on the honeypots targeted by the decoys. When attackers are sniffing assets, this can attract them to intrude and enter the honeypot. For example, attackers prefer systems with large user volumes such as OA and email systems; deploy such honeypots in key areas and forge fake connection records on real servers to lure attackers into the trap.
[0107] For real-time attack analysis: When attackers launch real-time attacks, defenders need to block the attacks, record attack information, analyze attack paths, and trace the adversary's information. This cannot be accomplished by simple data information alone; it must rely on the attack detection and recording capabilities of their own products, and also expand their collaborative defense capabilities with security products, combine security big data for attribution and countermeasures, and create user profiles.
[0108] The typical countermeasure is attack redirection. Attack redirection can be further divided into the following types: First, network attack detection: the honeypot monitors the network environment in real time for any attack traffic. Second, attack flow redirection: the attack flow is redirected and introduced into the deployed honeypot system, achieving secure isolation between attack activities and the customer's network environment, thus ensuring the security of the customer's network environment.
[0109] Application analysis for attacks: After obtaining information about the attackers, it is necessary to further analyze the attackers' tools, paths, and intentions in order to find vulnerabilities in your own system and defenses, and then address these vulnerabilities in a targeted manner.
[0110] Their response strategy typically involves vulnerability simulation. Vulnerability prevention generally falls into the following categories: Simulation scenario upgrades: Based on Seebug, the largest and most comprehensive vulnerability knowledge base in China, the simulation scenarios in the honeypot device are regularly upgraded through Proof of Concept (POC) testing. Simulation vulnerability settings: The honeypot system can inject simulation scenarios with newer vulnerabilities that fit business services and application needs, enticing intruders to probe the honeypot and prolong their stay, accurately capturing high-risk hacker attacks, and protecting the customer's business systems.
[0111] Application Analysis for Attack Tracing: The biggest advantage of honeypots in security defense is their offensive-defense approach, tracing the source of attacks. Their countermeasures involve real-time attack forensics. First, obtaining virtual identities: Attack behavior data is collected, categorized, and processed for in-depth tracing and anti-penetration, allowing the acquisition of more personal information about attackers, including social media IP addresses, IM communication tool IDs, etc. Second, correlating threat intelligence: Attackers often use VPNs / proxies to initiate access requests. Honeypots can obtain the attacker's real IP address through their integrated rich tracing plugins. Honeypots create a unique fingerprint for each attack source IP, allowing effective correlation analysis of attack behavior even if the attacker tampers with the IP. The information obtained at this stage is synchronized to big data platforms such as Microstep Online and Tencent Threat Intelligence to construct accurate and comprehensive threat intelligence.
[0112] In the above embodiments, the method for placing decoy files has been described in detail. This application also provides embodiments corresponding to the apparatus for placing decoy files. It should be noted that this application describes the embodiments of the apparatus from two perspectives: one is based on functional modules, and the other is based on hardware.
[0113] Figure 2 This is a structural diagram of a device for placing decoy documents, provided in an embodiment of this application. Figure 2 As shown, this application also provides a device for placing decoy documents, comprising:
[0114] The first determining module 20 is used to determine the state of the ransomware detection switch;
[0115] The first acquisition module 21 is used to acquire all disks in the system when the detection switch is in the open state. The threads run in parallel.
[0116] Filtering module 22 is used to filter critical directories of the system within a thread;
[0117] The second determining module 23 is used to determine the location where the decoy file is placed in the remaining ordinary directories.
[0118] In addition, the device also includes the following modules:
[0119] Preferably, after the critical directory of the filtering system and before determining the location for placing the decoy files in the remaining general directories, the method further includes:
[0120] The first placement module is used to place a decoy file at the beginning and end of the critical directory.
[0121] Preferably, it further includes:
[0122] The traversal module is used to traverse ordinary directories;
[0123] The first judgment module is used to determine whether a file contains data content;
[0124] If so, the second determination module is triggered;
[0125] If not, the traversal module is triggered.
[0126] Preferably, when determining that a file contains data content, the method further includes:
[0127] The second judgment module is used to determine whether the total number of decoy files set in the system exceeds the preset number.
[0128] If not, the second determination module is triggered; if yes, the process ends.
[0129] Preferably, when it is determined that a file does not contain data content, the method further includes:
[0130] The third judgment module is used to determine whether the specified level of a normal directory has been reached;
[0131] If not, the traversal module is triggered; if yes, the process ends.
[0132] Preferably, when it is determined that the total number of bait files set in the system does not exceed a preset number, determining the location for placing the bait files in the remaining ordinary directories includes:
[0133] The second acquisition module is used to acquire file attributes of a specified type of file;
[0134] The third determining module is used to determine the search order based on file attributes;
[0135] The second placement module is used to place a decoy file at the beginning and end of the file according to the retrieval order.
[0136] Preferably, determining the location of the bait files in a preset order within a general directory includes:
[0137] The third placement module is used to determine the location of the decoy files in a regular directory according to their priority.
[0138] Since the embodiments of the apparatus and the embodiments of the method correspond to each other, please refer to the description of the embodiments of the method for the embodiments of the apparatus, which will not be repeated here.
[0139] Figure 3 This application provides a structural diagram of a device for placing decoy documents, as shown in the embodiment of the present application. Figure 3 As shown, the device for placing the decoy file includes:
[0140] Memory 30 is used to store computer programs;
[0141] The processor 31 is configured to execute a computer program to implement the steps of the method for placing a decoy file as described in the above embodiments.
[0142] The device for placing the bait file provided in this embodiment may include, but is not limited to, smartphones, tablets, laptops, or desktop computers.
[0143] The processor 31 may include one or more processing cores, such as a quad-core processor or an octa-core processor. The processor 31 may be implemented using at least one hardware form selected from Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), and Programmable Logic Array (PLA). The processor 31 may also include a main processor and a coprocessor. The main processor, also known as the Central Processing Unit (CPU), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor 31 may integrate a Graphics Processing Unit (GPU), which is responsible for rendering and drawing the content to be displayed on the screen. In some embodiments, the processor 31 may also include an Artificial Intelligence (AI) processor, which is used to handle computational operations related to machine learning.
[0144] The memory 30 may include one or more computer-readable storage media, which may be non-transitory. The memory 30 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In this embodiment, the memory 30 is used to store at least the following computer program, which, after being loaded and executed by the processor 31, is capable of implementing the relevant steps of the method for placing decoy files disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory 30 may also include an operating system and data, and the storage method may be temporary or permanent. The operating system may include Windows, Unix, Linux, etc. The data may include, but is not limited to, the method for placing decoy files.
[0145] In some embodiments, the device for placing the decoy file may further include a display screen, an input / output interface, a communication interface, a power supply, and a communication bus.
[0146] Those skilled in the art will understand that Figure 3 The structure shown does not constitute a limitation on the device for placing the decoy file and may include more or fewer components than illustrated.
[0147] The device for placing decoy files provided in this application includes a memory 30 and a processor 31. When the processor 31 executes the program stored in the memory 30, it can implement the method for placing decoy files.
[0148] Finally, this application also provides an embodiment corresponding to a computer-readable storage medium. The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps described in the above method embodiments.
[0149] It is understood that if the methods in the above embodiments are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and executes all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0150] The foregoing has provided a detailed description of a method, apparatus, device, and medium for placing decoy documents. The various embodiments in the specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section. It should be noted that those skilled in the art can make various improvements and modifications to this application without departing from the principles of this application, and these improvements and modifications also fall within the protection scope of the claims of this application.
[0151] It should also be noted that, in this specification, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
Claims
1. A method for placing decoy files, characterized in that, include: Determine the status of the ransomware detection switch; When the detection switch is in the ON state, the system acquires all disk threads, where each thread runs in parallel. In the thread, the key directories of the system are filtered; each disk stores system files, and the system files containing system data are used as the key directories; In the remaining regular directories, determine the location to place the bait files; After filtering the critical directories of the system, and before determining the location for placing the decoy files in the remaining general directories, the process further includes: Place one of the aforementioned decoy files at the beginning and one at the end of the key directory; After placing one of the decoy files at the beginning and one at the end of the key directory, the method further includes: Traverse the aforementioned ordinary directories; Determine if a file contains data. If so, proceed to the step of determining the location of the decoy file in the remaining ordinary directories; If not, return to the step of traversing the ordinary directory; When it is determined that the file does not contain the data content, the method further includes: Determine whether the specified level of the ordinary directory has been reached; If not, return to the step of traversing the ordinary directory; If so, then the process ends.
2. The method for placing decoy files according to claim 1, characterized in that, When the file containing the data content is determined, the method further includes: Determine whether the total number of decoy files set in the system exceeds a preset number; If not, proceed to the step of determining the location of the decoy file in the remaining ordinary directories; If so, then the process ends.
3. The method for placing decoy files according to claim 2, characterized in that, When it is determined that the total number of decoy files set in the system does not exceed the preset number, determining the location for placing the decoy files in the remaining ordinary directories includes: Retrieve the file attributes of the specified file type; Determine the search order based on the file attributes; The decoy file is placed at the beginning and end of the file according to the search order.
4. The method for placing bait documents according to claim 1, characterized in that, Determining the location of the bait files in the general directory according to a preset order includes: The location for placing the decoy files is determined according to priority within the general directory.
5. A device for placing decoy documents, characterized in that, include: The first determining module is used to determine the state of the ransomware detection switch; The first acquisition module is used to acquire all disk threads in the system when the detection switch is in the on state, wherein each thread runs in parallel; A filtering module is used to filter the key directories of the system within the thread; each disk stores system files, and the system files containing system data are used as the key directories. The second determining module is used to determine the location where the decoy file is placed in the remaining ordinary directories; After filtering the critical directories of the system, and before determining the location for placing the decoy files in the remaining general directories, the process further includes: Place one of the aforementioned decoy files at the beginning and one at the end of the key directory; After placing one of the decoy files at the beginning and one at the end of the key directory, the method further includes: Traverse the aforementioned ordinary directories; Determine if a file contains data. If so, proceed to the step of determining the location of the decoy file in the remaining ordinary directories; If not, return to the step of traversing the ordinary directory; When it is determined that the file does not contain the data content, the method further includes: Determine whether the specified level of the ordinary directory has been reached; If not, return to the step of traversing the ordinary directory; If so, then the process ends.
6. A device for placing decoy documents, characterized in that, include: Memory, used to store computer programs; A processor, configured to implement the steps of the method for placing a decoy file as described in any one of claims 1 to 4 when executing the computer program.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method for placing a decoy file as described in any one of claims 1 to 4.
Citation Information
Patent Citations
High-power secret information stealing malicious code detection method and system based on backward tracing
CN103294950A
Method for Detecting and Defeating Ransomware
US20210182392A1