A method, system, and readable storage medium for handling intrusion by unknown users.

CN117610056BActive Publication Date: 2026-08-11SHENZHEN CHUANGZHICHENG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-12
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0004]然而,上述所列举的技术是防止未知用户入侵计算机,但是在实际应用中,依然有未知用户能够突破上述防护技术,例如未知用户可能会利用操作系统中的漏洞,通过注入恶意代码或执行未经授权的操作来获取对计算机的控制权等等,进入用户的计算机进行信息窃取,使用户的信息的安全性大大降低

Benefits of technology

1、本申请提供了一种对未知用户入侵的处理方法,通过确定未知用户采用预设方式入侵的情况下,确定目标保护对象,并获取目标保护对象的路径信息和存储位置。这样,系统可以针对目标保护对象进行有针对性的保护措施,提高系统的安全性和防护能力。同时,该方法能够有效地识别未知用户的入侵方式,及时采取相应的措施进行应对,避免潜在的风险和威胁,降低了用户信息被窃取的成功率,提高了用户信息的安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117610056B_ABST
    Figure CN117610056B_ABST
Patent Text Reader

Abstract

A method, system, and readable storage medium for handling intrusion by unknown users are disclosed. In this method, upon determining that an unknown user has intruded using a preset method, the following steps are taken: a target protected object is identified; path information of the target protected object is determined; the storage location of the target protected object is obtained based on the path information; attributes of the preset method are determined; if the attribute is determined to be a first attribute, a preset inducement object is stored in the storage location; and the target protected object is transferred from the storage location to a preset secure location. This reduces the success rate of user information theft when a computer is intruded by an unknown user, thereby improving the security of user information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of information security, and in particular relates to a method, system and readable storage medium for handling intrusion by unknown users. Background Technology

[0002] With the continuous development of information technology, from landline telephones and radios to mobile phones, computers, and global information, the globalization of the internet has brought numerous conveniences to people. It allows people to know what's happening in the world without leaving home. At the same time, in this era of booming computer development, most information is stored on computers. However, computers usually require a network connection to be used, but the network is not entirely secure; some individuals or organizations can use it to steal information. Therefore, network security has emerged.

[0003] Among related technologies, users can use firewalls, intrusion detection systems (IDS) and intrusion prevention systems (IPS), authentication and access control, encryption and data protection, security patches and updates, and security auditing and log monitoring to protect networks and systems from intrusion.

[0004] However, while the technologies listed above are designed to prevent unknown users from intruding into computers, in practice, unknown users can still bypass these protection technologies. For example, unknown users may exploit vulnerabilities in the operating system to gain control of the computer by injecting malicious code or performing unauthorized operations, thereby gaining access to the user's computer to steal information and greatly reducing the security of the user's information. Summary of the Invention

[0005] This application provides a method, system, and readable storage medium for handling intrusion by unknown users, which reduces the success rate of user information theft and improves user information security when a computer is intruded by an unknown user.

[0006] In a first aspect, this application provides a method for handling intrusion by unknown users. When it is determined that an unknown user has intruded in a preset manner, the method involves: identifying a target protected object; determining the path information of the target protected object; obtaining the storage location of the target protected object based on the path information; determining the attribute of the preset manner; if the attribute is determined to be a first attribute, storing a preset inducement object in the storage location; and transferring the target protected object from the storage location to a preset secure location.

[0007] By employing the aforementioned technical solution, the system identifies the target object for protection and obtains its path information and storage location when an unknown user attempts to intrude using a preset method. This allows the system to implement targeted protection measures for the target object, enhancing its security and defense capabilities. Furthermore, this method effectively identifies the intrusion methods of unknown users, enabling timely responses to avoid potential risks and threats, reducing the success rate of user information theft, and improving user information security.

[0008] In conjunction with some embodiments of the first aspect, in some embodiments, after transferring the target protected object from the storage location to a preset secure location, the method further includes: encrypting the target protected object using a preset encryption algorithm when the attribute is determined to be a second attribute; obtaining a key corresponding to the target protected object according to the preset encryption algorithm; displaying an authentication page when the key is determined to be accessed; verifying whether the access is from a preset user when the authentication page is determined to be completed; displaying the key when the access is from the preset user; and locking the authentication page when the access is not from the preset user.

[0009] By employing the above technical solution, after transferring the target protected object from its storage location to a preset secure location, it is encrypted using a preset encryption algorithm. This encryption method effectively protects the confidentiality and privacy of the target protected object, preventing unauthorized access and theft. Furthermore, the method ensures that only authenticated users can access and obtain the key through the display and completion of an authentication page, improving the system's access control and identity verification capabilities. This reduces the success rate of user information theft and enhances user information security.

[0010] In conjunction with some embodiments of the first aspect, in some embodiments, after locking the authentication page when it is determined that the access is not the preset user, the method further includes: unlocking the authentication page after a first preset time period; verifying whether the access is the preset user when it is determined that the authentication page has been filled out; displaying the key when it is determined that the access is the preset user; and locking the authentication page for a second preset time period when it is determined that the access is not the preset user.

[0011] By adopting the above technical solution, the authentication page is unlocked after a certain period of time following its initial locking. This design can, to some extent, prevent frequent attacks on the key by unknown users, reduce frequent authentication operations, and improve system availability and convenience. Furthermore, re-verifying access after the authentication page is completed further ensures the legitimacy of the visitor's identity, preventing unauthorized access and data leakage. Additionally, if a user initially enters incorrect authentication information, this method allows the user to confirm the correct information within the first preset timeframe. This reduces the success rate of user information theft and improves user information security.

[0012] In conjunction with some embodiments of the first aspect, in some embodiments, determining the attribute of the preset method specifically includes: when it is determined that the number of accessed file paths is not greater than a preset number and the number of accesses to the accessed file paths is greater than a preset threshold, determining the attribute of the preset method as a first attribute; when it is determined that the number of accessed file paths is greater than the preset number and the number of accesses to the accessed file paths is not greater than a preset threshold, determining the attribute of the preset method as a second attribute. By employing the above technical solution, and through extracting network traffic logs and analyzing data volume and transmission destinations, the attributes of the preset method can be accurately determined. This attribute determination method can accurately determine the attributes of the preset method based on actual network traffic conditions, improving the system's adaptability and responsiveness. Furthermore, based on the attribute determination results, it is possible to better assess the existence of potential threats and risks, allowing for timely implementation of corresponding security measures, reducing the success rate of user information theft, and enhancing user information security.

[0013] In conjunction with some embodiments of the first aspect, in some embodiments, after determining the attributes of the preset method in the case that an unknown user has intruded in a preset manner, the method further includes: disconnecting from the network; and immediately updating all passwords at preset intervals.

[0014] By adopting the above technical solution and updating passwords at preset intervals, the system can ensure the timeliness and security of passwords. This timely password update measure reduces the risk of passwords being cracked or stolen, effectively protecting system data and resources. Simultaneously, regular password updates also prevent unknown users from intruding into the system through long-term monitoring and password cracking. This lowers the success rate of user information theft and improves user information security.

[0015] In conjunction with some embodiments of the first aspect, in some embodiments, after immediately updating all passwords at preset intervals, the method further includes: determining whether there is data corruption if the intrusion of the unknown user is cut off; extracting a data backup if data corruption is determined to be present; and using the data backup to restore the data corresponding to the data corruption.

[0016] By adopting the above technical solution, potential data corruption can be addressed and recovered after password updates. The system determines if data corruption exists and retrieves backup data for recovery. Using data backups for recovery avoids the impact of data corruption on normal system operation and data integrity. This reduces the success rate of user information theft and improves user information security.

[0017] In conjunction with some embodiments of the first aspect, in some embodiments, after extracting the data backup in the event of data corruption, the method further includes: determining whether the data backup is infected; if the data backup is infected, deleting the infected data in the data backup to obtain a processed data backup; and using the processed data backup to restore the data corresponding to the data corruption.

[0018] By employing the above technical solution, the data backup is checked during the data backup and recovery process to determine if it has been infected. If the data backup is infected, the infected data is deleted, resulting in a processed data backup. Deleting infected data prevents malicious code or viruses from further spreading and damaging the data. Then, the processed data backup is used to restore the data corresponding to the damaged data, ensuring data integrity and availability. This reduces the success rate of user information theft and improves user information security.

[0019] Secondly, embodiments of this application provide a system for handling intrusion by unknown users. The system includes: an object determination module, used to determine a target protected object when it is determined that an unknown user has intruded in a preset manner; The path determination module is used to determine the path information of the target protected object; The storage determination module is used to determine the storage location of the target protected object based on the path information. The attribute determination module is used to determine the attributes of this preset method; The object storage module is used to store the preset inducement object in the storage location when it is determined that the attribute is the first attribute; The object transfer module is used to transfer the target protected object from the storage location to a preset secure location.

[0020] Thirdly, embodiments of this application provide a system for handling intrusion by unknown users. The system includes: one or more processors and a memory; the memory is coupled to the one or more processors and is used to store computer program code, the computer program code including computer instructions, and the one or more processors call the computer instructions to cause the system to perform the method described in the first aspect and any possible implementation thereof.

[0021] Fourthly, embodiments of this application provide a computer-readable storage medium including instructions that, when executed on a system, cause the system to perform the method described in the first aspect and any possible implementation thereof.

[0022] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages: 1. This application provides a method for handling intrusion by unknown users. By determining that an unknown user is intruding using a preset method, the method identifies the target object for protection and obtains its path information and storage location. This allows the system to implement targeted protection measures for the target object, improving system security and defense capabilities. Simultaneously, this method effectively identifies the intrusion methods of unknown users, enabling timely and appropriate countermeasures to avoid potential risks and threats, reduce the success rate of user information theft, and improve user information security.

[0023] 2. This application provides a method for handling intrusion by unknown users. After transferring the target protected object from its storage location to a preset secure location, the target protected object is encrypted using a preset encryption algorithm. This encryption method effectively protects the confidentiality and privacy of the target protected object, preventing unauthorized access and theft. Furthermore, the method ensures that only authenticated users can access and obtain the key through the display and completion of an authentication page, improving the system's access control and identity verification capabilities. This reduces the success rate of user information theft and enhances the security of user information.

[0024] 3. This application provides a method for handling intrusion by unknown users, unlocking the authentication page after a certain period of time. This design can, to some extent, prevent frequent attacks on the key by unknown users, reduce frequent authentication operations, and improve system availability and convenience. Furthermore, re-verifying access after the authentication page is completed further ensures the legitimacy of the visitor's identity, preventing unauthorized access and data leakage. Additionally, if a user initially enters incorrect authentication information, this method allows the user to confirm the correct authentication information within a first preset time period. This reduces the success rate of user information theft and improves user information security. Attached Figure Description

[0025] Figure 1 This is a flowchart illustrating a method for handling intrusion by unknown users in an embodiment of this application.

[0026] Figure 2 This is a flowchart illustrating another method for handling intrusion by unknown users in this application.

[0027] Figure 3 This is a schematic diagram of the functional module structure of a system for handling intrusion by unknown users, provided in an embodiment of this application.

[0028] Figure 4 This is a schematic diagram of the physical device structure of a system for handling intrusion by unknown users, provided in an embodiment of this application. Detailed Implementation

[0029] The terminology used in the following embodiments of this application is for the purpose of describing particular embodiments only and is not intended to be limiting of this application. As used in the specification and appended claims of this application, the singular expressions “a,” “an,” “the,” “the,” “the,” and “this” are intended to include the plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in this application refers to any or all possible combinations including one or more of the listed items.

[0030] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature, and in the description of the embodiments of this application, unless otherwise stated, "multiple" means two or more.

[0031] With the continuous development of information technology, from landline telephones and radios to mobile phones, computers, and global information, the globalization of the internet has brought numerous conveniences to people. It allows people to know what's happening in the world without leaving home. At the same time, in this era of booming computer development, most information is stored on computers. However, computers usually require a network connection to be used, but the network is not entirely secure; some individuals or organizations can use it to steal information. Therefore, network security has emerged.

[0032] Among related technologies, users can use firewalls, intrusion detection systems (IDS) and intrusion prevention systems (IPS), authentication and access control, encryption and data protection, security patches and updates, and security auditing and log monitoring to protect networks and systems from intrusion.

[0033] However, while the technologies listed above are designed to prevent unknown users from intruding into computers, in practice, there are still some unknown users who can bypass these protection technologies. For example, unknown users may exploit vulnerabilities in the operating system to gain control of the computer by injecting malicious code or performing unauthorized operations, thereby gaining access to the user's computer to steal information and greatly reducing the security of the user's information.

[0034] This application provides a method, system, and readable storage medium for handling intrusion by unknown users, used to reduce the success rate of user information theft and improve user information security when a computer is invaded by an unknown user. The following is in conjunction with... Figure 1 This application describes a method for handling intrusion by unknown users: Please see Figure 1 This is a flowchart illustrating a method for handling intrusion by unknown users in an embodiment of this application.

[0035] S101. If it is determined that an unknown user has intruded in a preset manner, determine the target protected object; When monitoring computer systems and networks reveals signs of abnormal activity, such as an increase in unauthorized access, it can be determined that an unknown user has infiltrated the computer. The method of intrusion can be determined by detecting whether default accounts and passwords, weak passwords, default configurations, and outdated updates and patches have been tampered with. If it is determined that an unknown user has infiltrated using a preset method, the target protected object should be identified. This target protected object can be a file with a high level of confidentiality preset by the user, possessing a corresponding identifier. This identifier identifies the target protected object as something that cannot be stolen, while other files on the computer are of lower importance and can be stolen. For example, suppose there is an e-commerce platform system; the target protected object could be a database storing users' personal information. In this case, an unknown user might attempt to infiltrate the database through various means, such as password cracking or SQL (Structured Query Language) injection. To prevent this, the target protected object, i.e., the database, needs to be identified as the focus and target of system defense.

[0036] S102. Determine the path information of the target protected object; Path information refers to the location or access path of the target protected object within the system. In the example above, the path information refers to the storage path of the database on the server. For example, the database path information could be " / var / www / html / database / user_info.db". By determining the path information of the target protected object, the system can accurately locate the target protected object, providing the necessary basis for subsequent processing steps.

[0037] S103. Obtain the storage location of the target protected object based on the path information; Based on the path information, the system can accurately locate the storage location of the target protected object within the file system. In the example above, the storage location of the target protected object could be a specific directory on the server's hard drive. For example, the storage location of the target protected object could be " / var / www / html / database / ". By determining the storage location of the target protected object, the system can perform operations on it as needed, such as storing the decoy object or moving it to a secure location.

[0038] S104. Determine the attributes of the preset mode; Specifically: if the number of accessed file paths is not greater than a preset number and the number of accesses to the accessed file path is greater than a preset threshold, the attribute of the preset method is determined as the first attribute; if the number of accessed file paths is greater than a preset number and the number of accesses to the accessed file path is not greater than a preset threshold, the attribute of the preset method is determined as the second attribute.

[0039] The default method has two attributes: a first attribute and a second attribute. The attributes of the default method refer to whether, after infiltrating the computer, the target is one or several specific files, or whether it searches through all files. The first attribute indicates that the target is one or several specific files, while the second attribute indicates that it searches through all files. Different attributes will be handled differently.

[0040] S105. If the attribute is determined to be the first attribute, the preset inducement object is stored in the storage location; If the attribute is determined to be the first attribute, a pre-defined inducement object is stored in the storage location. This means the target protected object needs to be protected from theft. These inducement objects can be specially crafted files, tags, or indicators. For example, in the above example, when the attribute of the pre-defined method is the first attribute, the system will store a file named "password_cracker.txt" in the database storage location. This file can serve as an inducement for attackers, attracting them to compromise the target protected object, and can also serve as evidence for the system to monitor and identify intrusion behavior.

[0041] S106. Transfer the target protected object from the storage location to the preset safe location; To protect the security of the target data, the system will move it from its original storage location to a preset secure location. This secure location can be an encrypted area within the system, offline backup media, etc. For example, in the above example, the system can move the database from the server's hard drive to an encrypted storage device, such as a USB encrypted drive. This prevents unknown users from obtaining sensitive data by directly accessing the database's storage location.

[0042] S107. If the attribute is determined to be the second attribute, the target protected object is encrypted using a preset encryption algorithm. When the default method's attribute is the second attribute, the system will encrypt the target protected object. This means the default method will iterate through all files. Encryption uses a specific algorithm to transform the target protected object into an unreadable form, thus protecting its confidentiality and integrity. For example, in the above example, when the default method's attribute is the second attribute, the system can encrypt sensitive data in the database to prevent attackers from obtaining data by injecting malicious SQL statements.

[0043] The encryption algorithm can be a symmetric encryption algorithm (such as AES), an asymmetric encryption algorithm (such as RSA), etc. For example, in the example above, when the preset method attribute is the second attribute, the system will encrypt the database with AES.

[0044] S108. Obtain the key corresponding to the target protected object according to the preset encryption algorithm; Based on a preset encryption algorithm, the system can generate a key for decrypting the target protected object. This key can be a symmetric key or an asymmetric key. For example, in the example above, the system generates a symmetric key for decrypting the database based on the AES encryption algorithm.

[0045] S109. If it is determined that the key has been accessed, display the authentication page; By analyzing system and application logs, any unusual activity related to the key can be identified, such as key usage records and unauthorized access attempts. Key access logs may include login logs and key management system logs to determine if the key has been accessed. When the system detects key access, it displays an authentication page requiring the user to authenticate to ensure that only authorized users can access the key. For example, in the above example, when the system detects that someone has accessed the database decryption key, it displays an authentication page requiring the user to enter the correct username and password.

[0046] It should be noted that the verification information on the identity verification page can be other verification information, such as security questions, fingerprints, iris scans, and palm prints, etc., and there are no restrictions here.

[0047] S110. After confirming that the identity verification page has been filled out, verify whether the access is to the preset user; The system verifies whether the information entered by the user on the authentication page matches the information of a pre-defined user. Only if the verification is successful will the system confirm that the visitor is a pre-defined user. For example, in the example above, the system checks whether the username and password entered by the user on the authentication page match the pre-defined user information stored in the database.

[0048] S111. If it is determined that the access is to a preset user, display the key; If the information entered on the authentication page matches the information of the default user, it can be confirmed that the accessed user is indeed the default user. If the system confirms that the visitor is the default user, it will display the database decryption key. The user can then use this key to decrypt the database and perform operations. For example, in the above example, if the system verification is successful, it will display the database decryption key, which the user can use to decrypt the database and perform related operations.

[0049] S112. If it is determined that the access is not to a default user, lock the authentication page.

[0050] If the information entered on the authentication page does not match the information of the default user, it can be determined that the accessing user is not the default user. If the system confirms that the visitor is not the default user, it will lock the authentication page, preventing further access attempts. This protects the database security and prevents unauthorized users from accessing sensitive data. For example, in the above example, if the system verification fails, it will lock the authentication page, preventing the visitor from continuing to attempt to access the database.

[0051] The above embodiments have the following beneficial effects: By identifying unauthorized users who intrude using pre-defined methods, the system determines the target object for protection and obtains its path information and storage location. This allows the system to implement targeted protection measures for the target object, improving overall system security and defense capabilities. Simultaneously, this method effectively identifies the intrusion methods of unauthorized users, enabling timely responses to avoid potential risks and threats, reducing the success rate of user information theft, and enhancing user information security.

[0052] After transferring the target protected object from its storage location to a preset secure location, it is encrypted using a preset encryption algorithm. This encryption method effectively protects the confidentiality and privacy of the target protected object, preventing unauthorized access and theft. Furthermore, the method ensures that only authenticated users can access and obtain the key through the display and completion of an authentication page, improving the system's access control and identity verification capabilities. This reduces the success rate of user information theft and enhances user information security.

[0053] By extracting network traffic logs and analyzing data volume and transmission destinations, the attributes of preset methods can be accurately determined. This attribute determination method can accurately determine the attributes of preset methods based on actual network traffic conditions, improving the system's adaptability and responsiveness. Furthermore, based on the attribute determination results, it is possible to better assess the existence of potential threats and risks, allowing for timely implementation of corresponding security measures, reducing the success rate of user information theft, and improving user information security.

[0054] In step S112 of the above embodiment, if it is determined that the access is not by a preset user, the authentication page is locked. There are two reasons for authentication failure: one is that the access is by a non-preset user, and the other is that the access is by a preset user but the authentication information is entered incorrectly, causing the authentication page to be locked. The following describes... Figure 2 This application describes another method for handling intrusion by unknown users: Please see Figure 2 This is a flowchart illustrating another method for handling intrusion by unknown users in this application.

[0055] S201. After the first preset time has elapsed, unlock the identity verification page; The first preset timeout refers to the pre-defined period during which the system waits to verify the user's identity after the user accesses the system. During this time, the system is locked and authentication is not possible. After the first preset timeout has elapsed, the system unlocks the authentication page, allowing the user to fill in authentication information.

[0056] For example, a preset 10-second wait is required for the system to unlock the authentication page. During these 10 seconds, the user cannot enter authentication information. After the 10 seconds have elapsed, the system unlocks the authentication page, and the user can then begin entering their username and password to authenticate.

[0057] S202. After confirming that the identity verification page has been filled out, verify whether the access is to the preset user; After the user completes the identity verification page, the system needs to verify whether the user's identity is that of a preset user. The system will compare the identity verification information entered by the user with the preset user information to determine the user's identity.

[0058] Continuing the previous example, after the user enters their username and password, the system compares this information with preset usernames and passwords. If the username and password entered by the user match the preset ones, the system confirms that the user is a preset user and can proceed to the next step. If the username and password entered by the user do not match the preset ones, the system confirms that the user is not a preset user and needs to take appropriate measures.

[0059] S203. If it is determined that the access is to a preset user, display the key; Once the system confirms that the user is the preset user, the system will display the key.

[0060] Continuing with the previous example, when the user's account and password match the preset ones, the system generates an encrypted communication key and displays it to the user. The user can use this key for subsequent secure communication and operations, ensuring the confidentiality and integrity of the data.

[0061] S204. If it is determined that the access is not to a preset user, lock the authentication page and continue for a second preset duration.

[0062] Once the system confirms that the user is not the preset user, it will lock the authentication page for a second preset duration. During this time, the user will be unable to enter authentication information again.

[0063] Continuing the previous example, when a user's username and password do not match the preset ones, the system will lock the authentication page and wait for a second preset duration. During this time, the user cannot enter their username and password again for authentication. Only after the second preset duration has elapsed will the system unlock the authentication page, allowing the user to try entering authentication information again. In some embodiments, the second preset duration may be longer than the first preset duration. This is to remind users to carefully enter authentication information or to prevent repeated attacks from unknown users.

[0064] In the above embodiments, after locking the authentication page, it is unlocked after a certain period of time. This design can, to some extent, prevent frequent attacks on the key by unknown users, reduce frequent authentication operations, and improve the system's availability and convenience. Furthermore, re-verifying access after the authentication page is completed further ensures the legitimacy of the visitor's identity, preventing unauthorized access and data leakage. Also, if a user enters incorrect authentication information the first time, this method allows the user to confirm the correct authentication information within a first preset time period. This reduces the success rate of user information theft and improves user information security.

[0065] In step S112: If it is determined that the access is not from a preset user, after locking the authentication page, it is necessary to prevent the unknown user from continuing to intrude, and it is also necessary to determine whether any data has been corrupted. Specifically: disconnect from the network; immediately update all passwords at preset intervals; if the intrusion of the unknown user is prevented, determine whether any data has been corrupted; if data corruption is determined, extract a data backup; use the data backup to restore the data corresponding to the data corruption; determine whether the data backup is infected; if the data backup is infected, delete the infected data in the data backup to obtain a processed data backup; use the processed data backup to restore the data corresponding to the data corruption.

[0066] The above embodiments have the following beneficial effects: By updating passwords at preset intervals, the system ensures both the timeliness and security of passwords. This timely password update reduces the risk of passwords being cracked or stolen, effectively protecting system data and resources. Furthermore, regular password updates prevent unknown users from infiltrating the system through long-term monitoring and password cracking. This lowers the success rate of user information theft and improves user information security.

[0067] After password updates, potential data corruption is addressed and recovered. This involves determining if data corruption exists and retrieving backups for recovery. Using backups for recovery avoids the impact of data corruption on normal system operation and data integrity. This reduces the success rate of user information theft and improves user information security.

[0068] During the data backup and recovery process, the data backup is checked to determine if it has been infected. If the backup is infected, the infected data is deleted, resulting in a processed backup. Deleting infected data prevents malicious code or viruses from further spreading and damaging the data. The processed backup is then used to restore the data corresponding to the damaged data, ensuring data integrity and availability. This reduces the success rate of user information theft and improves user information security.

[0069] The system in this application embodiment is described below from a module perspective: Please see Figure 3 This is a schematic diagram of the functional module structure of a system for handling intrusion by unknown users, provided in an embodiment of this application.

[0070] The system includes: The object determination module 301 is used to determine the target protected object when it is determined that an unknown user has intruded in a preset manner; The path determination module 302 is used to determine the path information of the target protected object; The storage determination module 303 is used to determine the storage location of the target protected object based on the path information. The attribute determination module 304 is used to determine the attributes of the preset method; The object storage module 305 is used to store a preset inducement object in the storage location when it is determined that the attribute is the first attribute; The object transfer module 306 is used to transfer the target protected object from the storage location to a preset safe location.

[0071] The system in the embodiments of this application has been described above from the perspective of modular functional entities. The system in the embodiments of this application will now be described below from the perspective of hardware processing. Please refer to [link / reference needed]. Figure 4 This is a schematic diagram of the physical device structure of a system for handling intrusion by unknown users, provided in an embodiment of this application.

[0072] It should be noted that, Figure 4 The structure of the system shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.

[0073] like Figure 4 As shown, the server includes a Central Processing Unit (CPU) 401, which can perform various appropriate actions and processes based on a program stored in Read-Only Memory (ROM) 402 or a program loaded from storage portion 408 into Random Access Memory (RAM) 403, such as performing the method described in the above embodiment. The RAM 403 also stores various programs and data required for system operation. The CPU 401, ROM 402, and RAM 403 are interconnected via a bus 404. An Input / Output (I / O) interface 405 is also connected to the bus 404.

[0074] The following components are connected to I / O interface 405: input section 406 including a camera, infrared sensor, etc.; output section 407 including a liquid crystal display (LCD) and speakers, etc.; storage section 408 including a hard disk, etc.; and communication section 409 including a network interface card such as a LAN (Local Area Network) card and a modem, etc. Communication section 409 performs communication processing via a network such as the Internet. Drive 410 is also connected to I / O interface 405 as needed. Removable media 411, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 410 as needed so that computer programs read from it can be installed into storage section 408 as needed.

[0075] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing computer programs for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 409, and / or installed from removable medium 411. When the computer program is executed by central processing unit (CPU) 401, it performs the various functions defined in the present invention.

[0076] It should be noted that the computer-readable medium shown in the embodiments of the present invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In the present invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, wherein a computer-readable computer program is carried. The transmitted data signal can take many forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof.

[0077] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0078] In another aspect, the present invention also provides a computer-readable storage medium, which may be included in the system described in the above embodiments; or it may exist independently and not assembled into the system. The storage medium carries one or more computer programs that, when executed by a processor of a system, cause the system to implement the methods provided in the above embodiments.

[0079] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

[0080] As used in the above embodiments, depending on the context, the term "when..." can be interpreted as meaning "if...", "after...", "in response to determining...", or "in response to detecting...". Similarly, depending on the context, the phrase "when determining..." or "if (the stated condition or event) is interpreted as meaning "if determining...", "in response to determining...", "when (the stated condition or event) is detected", or "in response to detecting (the stated condition or event)".

[0081] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. This computer program product includes one or more computer instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc.

[0082] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.

Claims

1. A method for handling intrusion by unknown users, characterized in that, include: In cases where it is determined that an unknown user has intruded using a preset method, the target object for protection must be identified. Determine the path information of the target protected object; The storage location of the target protected object is obtained based on the path information; Determining the attributes of the preset method specifically includes: Get the accessed file path and the number of accesses; If it is determined that the number of accessed file paths is not greater than a preset number and the number of accesses to the accessed file paths is greater than a preset threshold, the attribute of the preset method is determined as the first attribute. If it is determined that the number of accessed file paths is greater than a preset number and the number of accesses to the accessed file paths is not greater than a preset threshold, the attribute of the preset method is determined as the second attribute. If the attribute is determined to be the first attribute, the preset inducement object is stored in the storage location; Transfer the target protected object from the storage location to a preset secure location; If the attribute is determined to be the second attribute, the target protected object is encrypted using a preset encryption algorithm; The key corresponding to the target protected object is obtained according to the preset encryption algorithm; If it is determined that the key has been accessed, an authentication page is displayed; If the identity verification page is found to be filled out, verify whether the access belongs to a preset user; If it is determined that the access belongs to the preset user, the key is displayed; If it is determined that the access is not to the preset user, the authentication page is locked.

2. The method according to claim 1, characterized in that, After locking the authentication page when it is determined that the access is not to the preset user, the method further includes: After a first preset time period, the authentication page is unlocked; If the identity verification page is found to be completed, verify whether the access belongs to the preset user; If it is determined that the access belongs to the preset user, the key is displayed; If it is determined that the access is not to the preset user, the authentication page is locked and remains locked for a second preset duration.

3. The method according to claim 1, characterized in that, After determining the attributes of the preset method in the case of determining that an unknown user has intruded in a preset manner, the method further includes: Disconnect from the network; All passwords are updated immediately at preset intervals.

4. The method according to claim 3, characterized in that, After updating all passwords immediately at preset intervals, the method further includes: If the intrusion by the unknown user is successfully blocked, determine whether there is any data corruption. If data corruption is confirmed, extract and back up the data. Use the data backup to restore the data corresponding to the data corruption.

5. The method according to claim 4, characterized in that, After retrieving the data backup in the event of data corruption, the method further includes: Determine whether the data backup has been infected; If the data backup is infected, the infected data in the data backup is deleted to obtain the processed data backup; Use the processed data backup to restore the data corresponding to the data corruption.

6. A system for handling intrusion by unknown users, characterized in that, include: The object determination module is used to determine the target protected object when it is determined that an unknown user has intruded in a preset manner; The path determination module is used to determine the path information of the target protected object; A storage determination module is used to determine the storage location of the target protected object based on the path information; An attribute determination module is used to determine the attributes of the preset method; It is also used to obtain the accessed file path and the number of accesses; It is also used to determine the attribute of the preset method as the first attribute when it is determined that the number of accessed file paths is not greater than a preset number and the number of accesses to the accessed file paths is greater than a preset threshold. It is also used to determine the attribute of the preset method as a second attribute when it is determined that the number of accessed file paths is greater than a preset number and the number of accesses to the accessed file paths is not greater than a preset threshold. The object storage module is used to store a preset inducement object in the storage location when the attribute is determined to be the first attribute. The object transfer module is used to transfer the target protected object from the storage location to a preset safe location; It is also used to encrypt the target protected object using a preset encryption algorithm when the attribute is determined to be the second attribute; it is also used to obtain the key corresponding to the target protected object according to the preset encryption algorithm; it is also used to display an authentication page when the key is determined to be accessed; it is also used to verify whether the access is a preset user when the authentication page is determined to be filled in; it is also used to display the key when the access is determined to be the preset user. It is also used to lock the authentication page if it is determined that the access is not to the preset user.

7. A system for handling intrusion by unknown users, characterized in that, include: One or more processors and memory; The memory is coupled to the one or more processors, the memory being used to store computer program code, the computer program code including computer instructions, the one or more processors invoking the computer instructions to cause the system to perform the method as described in any one of claims 1-5.

8. A computer-readable storage medium comprising instructions, characterized in that, When the instructions are executed on the system, the system performs the method as described in any one of claims 1-5.

Citation Information

Patent Citations

  • High-interaction traceability method, equipment and hardware of honeypot system

    CN114095264A

  • Attack transfer method and device, electronic equipment and storage medium

    CN115499195A