A method and device for dealing with ransomware, and an electronic device

By monitoring the behavioral characteristics and encryption algorithm characteristics of ransomware in the sandbox, using candidate encryption algorithms and key mark vectors to decrypt encrypted data, the problem of files that cannot be recovered after ransomware attack is solved, and efficient data recovery is achieved.

CN119720201BActive Publication Date: 2025-07-08SHANGHAI DOUXIANG INFORMATION TECH CO LTD

Patent Information

Application Number
CN202510214450.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-07-08
Estimated Expiration
2045-02-26

AI Technical Summary

Technical Problem

In the prior art, after a ransomware attack, users are unable to effectively recover encrypted files, resulting in an increase in data security threats.

Method used

By monitoring the behavioral characteristics of suspicious files in the sandbox, identifying the encryption algorithm characteristics, recording the key mark vector, and decrypting the encrypted data using the candidate encryption algorithm and the key mark vector.

Benefits of technology

Improve the recovery probability and recovery efficiency of ransomware encrypted files, ensuring data integrity and consistency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119720201B_ABST
    Figure CN119720201B_ABST
Patent Text Reader

Abstract

The present application relates to the field of network security, and discloses a method and apparatus for processing ransomware, and an electronic device. The method includes: triggering the execution of a suspicious file imported into a preset sandbox, and monitoring the first behavioral characteristics of the suspicious file; determining the running situation of an encryption algorithm according to the first behavioral characteristics and preset second behavioral characteristics; in the case where the running situation of the encryption algorithm indicates that the encryption algorithm is running, recording the encrypted data, the encryption algorithm characteristics, and the key marking vector; determining a candidate encryption algorithm according to the encryption algorithm characteristics; and decrypting the encrypted data by using the candidate encryption algorithm and the key marking vector. In this way, it is possible to facilitate the inference of the candidate encryption algorithm that the ransomware may use, and use the candidate encryption algorithm to decrypt the encrypted data, which can more easily decrypt the encrypted data successfully, thereby improving the recovery probability and recovery efficiency of the files encrypted by the ransomware.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and in particular, to a method and apparatus for dealing with ransomware, and an electronic device. Background Art

[0002] With the increasing frequency and complexity of ransomware attacks, enterprises and individuals are facing unprecedented data security threats. In related technologies, users usually can only feedback the result that the file has been encrypted by ransomware to the user after the file has been encrypted by ransomware, and cannot provide effective means to recover the file encrypted by ransomware.

[0003] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of this application, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0004] To provide a basic understanding of some aspects of the disclosed embodiments, a simple summary is given below. This summary is not an extensive review nor is it intended to identify key / critical elements or delineate the scope of protection of these embodiments. Rather, it serves as a prelude to the detailed description that follows.

[0005] Embodiments of this application provide a method and apparatus for dealing with ransomware, and an electronic device, so as to increase the probability of recovering files encrypted by ransomware.

[0006] Embodiments of this application provide a method for dealing with ransomware, including: triggering the running of a suspicious file imported into a preset sandbox, and monitoring the first behavior characteristics of the suspicious file; the first behavior characteristics represent the operation behavior of the suspicious file during the running process; the suspicious file is a file assumed to carry ransomware; determining the running situation of the encryption algorithm according to the first behavior characteristics and preset second behavior characteristics; the second behavior characteristics represent the operation behavior during the running process of the encryption algorithm; in the case where the running situation of the encryption algorithm is that there is an encryption algorithm running, recording the encrypted data, the encryption algorithm characteristics, and the key marking vector; determining a candidate encryption algorithm according to the encryption algorithm characteristics; and decrypting the encrypted data by using the candidate encryption algorithm and the key marking vector.

[0007] In the above embodiments, it is considered that the sandbox can isolate and analyze untrusted applications in a virtualized environment. By importing a suspicious file into the sandbox, the behavior of the suspicious file can be monitored, and the behavior characteristics related to encryption can be recorded, so as to facilitate the analysis of whether the suspicious file carries a ransomware. At the same time, considering that different encryption algorithms have different encryption characteristics, by recording the encryption algorithm characteristics during the running process of the suspicious file, it is possible to infer the candidate encryption algorithms that the ransomware may use. Using the candidate encryption algorithms to decrypt the encrypted data can make it easier for the encrypted data to be successfully decrypted, thereby increasing the recovery probability and recovery efficiency of the files encrypted by the ransomware.

[0008] Further, determining the running situation of the encryption algorithm according to the first behavior characteristic and a preset second behavior characteristic includes: determining a first target similarity between the first behavior characteristic and the second behavior characteristic; in the case where the first target similarity is higher than a first preset similarity, confirming that the running situation of the encryption algorithm is that there is an encryption algorithm running; otherwise, confirming that the running situation of the encryption algorithm is that there is no encryption algorithm running.

[0009] In the above embodiments, it is considered that during the running process of the encryption algorithm, there will be some specific characteristics. The similarity between the first behavior characteristic and the second behavior characteristic of the suspicious file can reflect whether the two behaviors are similar, so as to accurately infer whether an encryption algorithm is running, which is convenient for decrypting the encrypted data subsequently.

[0010] Further, the first behavior characteristic includes: a target call instruction, a target memory access pattern, a target function call chain, a target encryption duration, and a target encrypted file size; the second behavior characteristic includes: a sample call instruction, a sample memory access pattern, a sample function call chain, a sample encryption duration, and a sample encrypted file size; determining the first target similarity between the first behavior characteristic and the second behavior characteristic includes: calculating a first sample similarity between the target call instruction and the sample call instruction; calculating a second sample similarity between the target memory access pattern and the sample memory access pattern; calculating a third sample similarity between the target function call chain and the sample function call chain; calculating a fourth sample similarity between the target encryption duration and the sample encryption duration; calculating a fifth sample similarity between the target encrypted file size and the sample encrypted file size; determining the first target similarity according to the first sample similarity, the second sample similarity, the third sample similarity, the fourth sample similarity, and the fifth sample similarity.

[0011] In the above-described embodiment, considering that there are various behavioral characteristics in the encryption process, by comprehensively considering various behavioral characteristics such as target call instructions, target memory access patterns, target function call chains, target encryption duration, and target encrypted file size, and comparing the sample similarities of each behavioral characteristic to determine the target similarity, it is possible to make the speculation about whether an encryption algorithm is running according to the target similarity more accurate.

[0012] Furthermore, the first behavioral characteristic further includes: retrieving the file type; before determining the candidate encryption algorithm according to the encryption algorithm characteristics, the method further includes: determining a first hazard metric value according to the key marking vector; determining a second hazard metric value according to the retrieved file type; backing up the suspicious file according to the first hazard metric value and the second hazard metric value; stopping the running of the suspicious file, and running the backup file.

[0013] In the above-described embodiment, in the case where it is detected that a running suspicious file may be harmful, the suspicious file is backed up and the backup file is run. This can continuously monitor the running situation of the ransomware of the suspicious file while protecting the data of the suspicious file from being further damaged, providing data support for subsequent protection against ransomware.

[0014] Furthermore, the encryption algorithm characteristics include: call instructions, encryption operation mode, and key length; determining the candidate encryption algorithm according to the encryption algorithm characteristics includes: searching for the candidate encryption algorithm corresponding to the call instructions, the encryption operation mode, and the key length in a preset encryption algorithm database; the encryption algorithm database stores the corresponding relationship between call instructions, encryption operation mode, key length, and candidate encryption algorithm.

[0015] In the above-described embodiment, considering that different encryption algorithms have different encryption algorithm characteristics. By comprehensively matching multiple encryption algorithm characteristics to the candidate encryption algorithm, it is possible to facilitate narrowing down the range of encryption algorithms used by ransomware, so as to decrypt the encrypted data more quickly subsequently.

[0016] Furthermore, there are multiple candidate encryption algorithms, and decrypting the encrypted data using the candidate encryption algorithm and the key marking vector includes: determining the priority of each candidate encryption algorithm according to the call instructions, the encryption operation mode, and the key length; decrypting the encrypted data using the candidate encryption algorithm and the key marking vector according to the priority.

[0017] In the above-described embodiment, by sorting different candidate encryption algorithms and decrypting them in the order of priority, it is beneficial to more quickly match the correct candidate encryption algorithm, and thus decrypt successfully more quickly.

[0018] Further, after decrypting the encrypted data by using the candidate encryption algorithm and the key marking vector, the method for handling ransomware further includes: verifying whether the decrypted data meets a first preset condition; the first preset condition satisfies at least one of the following: the file format of the decrypted data is the same as that of the encrypted data, the file structure of the decrypted data is the same as that of the encrypted data, the content of the decrypted data is the same as the content of the encrypted data before encryption, and the decrypted data can be executed normally; if the decrypted data meets the first preset condition, it is confirmed that the decryption is successful; otherwise, it is confirmed that the decryption fails.

[0019] In the above embodiment, by verifying the decrypted data, it can be ensured that the encrypted data is correctly restored.

[0020] Further, there are multiple pieces of encrypted data; the method for handling ransomware further includes: recombining the decrypted data corresponding to each piece of encrypted data to obtain recombined data; verifying whether the recombined data meets a second preset condition; the second preset condition includes: whether the hash value of the recombined data is the same as the hash value of the suspicious file, and whether the file format of the recombined data is the same as the file format of the suspicious file; if the recombined data meets the second preset condition, it is confirmed that the recombination is successful, and the candidate encryption algorithm and the key marking vector for which the decryption is successful are recorded; otherwise, it is confirmed that the recombination fails.

[0021] In the above embodiment, considering that ransomware may encrypt multiple segments of data separately, by recombining and verifying multiple pieces of encrypted data, the accuracy and integrity of the data after restoring the suspicious file can be improved.

[0022] An embodiment of the present application provides an apparatus for handling ransomware, including: a monitoring module, configured to trigger the operation of a suspicious file imported into a preset sandbox and monitor the first behavioral characteristics of the suspicious file; the first behavioral characteristics characterize the operation behavior of the suspicious file during operation; an operation situation determination module, configured to determine the operation situation of the encryption algorithm according to the first behavioral characteristics and preset second behavioral characteristics; the second behavioral characteristics characterize the operation behavior during the operation of the encryption algorithm; a recording module, configured to record the encrypted data, the encryption algorithm characteristics, and the key marking vector when the operation situation of the encryption algorithm is that there is an encryption algorithm running; an algorithm derivation module, configured to determine a candidate encryption algorithm according to the encryption algorithm characteristics; a decryption module, configured to decrypt the encrypted data by using the candidate encryption algorithm and the key marking vector.

[0023] An embodiment of the present application provides an electronic device, including a processor and a memory. The memory stores computer-executable instructions that can be executed by the processor, and the processor executes the computer-executable instructions to implement the above method for processing ransomware.

[0024] The above general description and the following description are only exemplary and explanatory, and are not used to limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] One or more embodiments are exemplarily illustrated by corresponding drawings. These exemplary illustrations and the drawings do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are shown as similar elements. The drawings do not constitute a scale limitation, and:

[0026] Figure 1 is a schematic diagram of a method for processing ransomware provided by an embodiment of the present application;

[0027] Figure 2 is a schematic diagram of a device for processing ransomware provided by an embodiment of the present application;

[0028] Figure 3 is a schematic diagram of an electronic device provided by an embodiment of the present application.

[0029] Reference Numerals:

[0030] 1: Monitoring Module; 2: Operating Condition Determination Module; 3: Recording Module; 4: Algorithm Deduction Module; 5: Decryption Module; 6: Bus; 7: Processor; 8: Memory; 9: Communication Interface. DETAILED DESCRIPTION

[0031] In order to be able to understand the features and technical content of the embodiments of the present application in more detail, the implementation of the embodiments of the present application will be described in detail below with reference to the drawings. The attached drawings are only for reference and explanation, and are not used to limit the embodiments of the present application. In the following technical description, for the sake of explanation, numerous details are provided to give a thorough understanding of the disclosed embodiments. However, one or more embodiments may still be implemented without these details. In other cases, well-known structures and devices may be shown in a simplified manner.

[0032] The terms "first", "second", etc. in the description and claims of the embodiments of the present application and the above drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so as to implement the embodiments of the present application described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.

[0033] Unless otherwise specified, the term "a plurality of" means two or more.

[0034] The term "corresponding" may refer to an association relationship or a binding relationship. That A corresponds to B means that there is an association relationship or a binding relationship between A and B.

[0035] Embodiment 1

[0036] In an embodiment of the present application, a method for dealing with ransomware is provided. Refer to Figure 1 as shown Figure 1 which is a schematic diagram of the basic process of the method for dealing with ransomware provided in the embodiment of the present application, including:

[0037] Step S101, trigger the running of a suspicious file imported into a preset sandbox, and monitor the first behavioral characteristics of the suspicious file.

[0038] Among them, the first behavioral characteristic characterizes the operation behavior of the suspicious file during the running process. That is, the operation behavior generated when the suspicious file runs in the sandbox.

[0039] Among them, the suspicious file is a file assumed to carry ransomware. Suspicious files, for example: executable files, script files. Suspicious files, for another example: application programs.

[0040] Among them, the sandbox can be deployed on a local device or in the cloud.

[0041] Exemplarily, as an effective dynamic analysis tool, the sandbox can isolate and analyze untrusted applications in a virtualized environment, providing functions such as behavior analysis, encryption identification, and data recovery. Use the sandbox to build an isolated execution environment, import the suspicious file into the sandbox, and trigger the running of the suspicious file. At this time, through the system hooks and virtual machine monitor (VMM) built into the sandbox, the running status of the suspicious file can be monitored in real time, and the monitoring content includes but is not limited to operation behaviors such as process calls, system resource access, memory usage, network communication, and registry operations. Subsequently, it can be speculated whether the suspicious file is encrypted and how to decrypt and recover the encrypted data by analyzing the monitoring content, so as to improve the response speed and processing ability to ransomware attacks.

[0042] Step S102, determine the running situation of the encryption algorithm according to the first behavioral characteristic and the preset second behavioral characteristic.

[0043] Among them, the second behavioral characteristic characterizes the operation behavior during the running process of the encryption algorithm. Exemplarily, the operation behaviors generated by different encryption algorithms during the encryption process can be observed and statistically analyzed by engineers in advance to obtain the second behavioral characteristic.

[0044] In some embodiments, step S102 may include: determining a first target similarity between a first behavior feature and a second behavior feature; in the case where the first target similarity is higher than a first preset similarity, confirming that there is an encryption algorithm running; otherwise, confirming that there is no encryption algorithm running.

[0045] In an alternative manner of the above embodiments, the first behavior feature includes one or more of the following behavior features: a target call instruction, a target memory access pattern, a target function call chain, a target encryption duration, and a target encrypted file size. The types of behaviors of the second behavior feature are the same as those of the first behavior feature, and the sample similarity between the corresponding behavior types in the first behavior feature and the second behavior feature is calculated to determine the first target similarity.

[0046] Exemplarily, the first behavior feature includes: a target call instruction, a target memory access pattern, a target function call chain, a target encryption duration, and a target encrypted file size. The second behavior feature includes: a sample call instruction, a sample memory access pattern, a sample function call chain, a sample encryption duration, and a sample encrypted file size. Determining the first target similarity between the first behavior feature and the second behavior feature includes: calculating a first sample similarity between the target call instruction and the sample call instruction; calculating a second sample similarity between the target memory access pattern and the sample memory access pattern; calculating a third sample similarity between the target function call chain and the sample function call chain; calculating a fourth sample similarity between the target encryption duration and the sample encryption duration; calculating a fifth sample similarity between the target encrypted file size and the sample encrypted file size; and determining the first target similarity based on the first sample similarity, the second sample similarity, the third sample similarity, the fourth sample similarity, and the fifth sample similarity.

[0047] Among them, different encryption algorithms will call a specific instruction set during execution, and the call instructions include instructions unique to the encryption algorithm. The instructions unique to the encryption algorithm are the function calls related to the executed encryption algorithm, specific encryption operators, etc. For example: the S-Box (Substitution Box) operation, round function operation, etc. of AES (Advanced Encryption Standard), and for another example: the large integer calculation instruction of RSA (a non-symmetric encryption algorithm).

[0048] Among them, the function call chain can be the call function sequence and parameters of the encryption algorithm.

[0049] Among them, the target encryption duration can be the execution duration of the encryption process of the encryption algorithm.

[0050] Among them, the target encrypted file size can be the file size processed during the encryption process of the encryption algorithm.

[0051] Among them, considering that encryption algorithms usually involve a large amount of memory reads and writes. The target memory access pattern can be the memory pattern during data encryption. Exemplarily, since some encryption algorithms encrypt data in fixed-size data blocks, the target memory access pattern can be the memory pattern during the encryption of block data.

[0052] In the above example, calculating the first sample similarity between the target call instruction and the sample call instruction can be: calculating the similarity between the first feature vector representing the target call instruction and the second feature vector representing the sample call instruction as the first sample similarity.

[0053] In the above example, calculating the second sample similarity between the target memory access pattern and the sample memory access pattern can be: calculating the similarity between the third feature vector representing the target memory access pattern and the fourth feature vector representing the sample memory access pattern as the second sample similarity.

[0054] In the above example, calculating the third sample similarity between the target function call chain and the sample function call chain can be: calculating the similarity between the fifth feature vector representing the target function call chain and the sixth feature vector representing the sample function call chain as the third sample similarity.

[0055] In the above example, calculating the fourth sample similarity between the target encryption duration and the sample encryption duration can be: calculating the similarity between the seventh feature vector representing the target encryption duration and the eighth feature vector representing the sample encryption duration as the fourth sample similarity.

[0056] In the above example, calculating the fifth sample similarity between the target encrypted file size and the sample encrypted file size can be: calculating the similarity between the ninth feature vector representing the target encrypted file size and the tenth feature vector representing the sample encrypted file size as the fifth sample similarity.

[0057] In the above example, determining the first target similarity according to the first sample similarity, the second sample similarity, the third sample similarity, the fourth sample similarity, and the fifth sample similarity can be: taking the average similarity of the first sample similarity, the second sample similarity, the third sample similarity, the fourth sample similarity, and the fifth sample similarity as the first target similarity.

[0058] In the above example, determining the first target similarity based on the first sample similarity, the second sample similarity, the third sample similarity, the fourth sample similarity, and the fifth sample similarity may be: obtaining the first weights corresponding to the first sample similarity, the second sample similarity, the third sample similarity, the fourth sample similarity, and the fifth sample similarity respectively, and weighting the first sample similarity, the second sample similarity, the third sample similarity, the fourth sample similarity, and the fifth sample similarity according to the first weights to obtain the first target similarity.

[0059] Optionally, the first weights corresponding to the respective sample similarities may be pre-recorded in the similarity weight database.

[0060] Optionally, existing algorithms for calculating the similarity between two feature vectors may be used, such as: cosine similarity, Euclidean distance, etc., which will not be elaborated here.

[0061] Exemplarily, the features of the first line include: target call instruction, target memory access pattern. The features of the second line include: sample call instruction, sample memory access pattern. Determining the first target similarity between the features of the first line and the features of the second line includes: calculating the first sample similarity between the target call instruction and the sample call instruction; calculating the second sample similarity between the target memory access pattern and the sample memory access pattern; calculating the average similarity between the first sample similarity and the second sample similarity as the first target similarity.

[0062] Step S103, in the case where there is an encryption algorithm running, record the data to be encrypted, the encryption algorithm features, and the key marker vector.

[0063] Among them, the key marker vector may include encryption algorithm features and / or key features. Exemplarily, the key marker vector may be a vector formed by splicing encryption algorithm features and / or key features. Among them, the encryption algorithm features, such as: algorithm type, call instruction, encryption operation mode, key length, etc. The key features, such as: certain bit patterns of the key, transformation methods, etc.

[0064] Exemplarily, splice the encryption algorithm features and the key features according to the set feature types and feature orders to form the key marker vector. The key marker vector is used to characterize the encryption algorithm features and the key features in the encryption process. In this way, by recording the key marker vector, the key marker vector can provide a basis for subsequent data recovery and decryption processes.

[0065] In some embodiments, the first-line features further include: retrieving the file type; before determining the candidate encryption algorithm according to the encryption algorithm features, further including: determining the first hazard metric value according to the key marking vector; determining the second hazard metric value according to the retrieved file type; backing up the suspicious file according to the first hazard metric value and the second hazard metric value; stopping the operation of the suspicious file and running the backup file.

[0066] Among them, retrieving the file type, for example: documents, pictures, databases, etc. The sandbox can determine whether a specific file type is retrieved and which file type is retrieved by monitoring whether specific file extensions, such as.doc,.xls,.pdf, etc. are called.

[0067] In an alternative of the above embodiment, determining the first hazard metric value according to the key marking vector may be: calculating the key similarity between the key marking vector and the sample marking vector in the preset first metric value database, and taking the sample hazard metric value corresponding to the highest key similarity as the first hazard metric value.

[0068] Among them, the first metric value database records the corresponding relationship between the sample marking vector and the sample hazard metric value.

[0069] In another alternative of the above embodiment, determining the first hazard metric value according to the key marking vector may be: inputting the key marking vector into the first hazard degree prediction model to obtain the first hazard metric value corresponding to the key marking vector.

[0070] Optionally, a sample key marking vector with a first hazard metric value label can be obtained, and the sample key marking vector with a first hazard metric value label is input into a preset first training model for training to obtain the first hazard degree prediction model.

[0071] Among them, the first training model, for example: a neural network model, etc.

[0072] In an alternative of the above embodiment, determining the second hazard metric value according to the retrieved file type may be: looking up the second hazard metric value corresponding to the retrieved file type in the preset second metric value database. The second metric value database stores the corresponding relationship between the retrieved file type and the second hazard metric value.

[0073] In another alternative of the above embodiment, determining the second hazard metric value according to the retrieved file type may be: inputting the retrieved file type into the second hazard degree prediction model to obtain the second hazard metric value corresponding to the retrieved file type.

[0074] Optionally, a sample retrieval file type with a second hazard metric value label can be obtained, and the sample retrieval file type with the second hazard metric value label is input into a preset second training model for training to obtain a second hazard degree prediction model.

[0075] Among them, the second training model, for example: a neural network model, etc.

[0076] In an optional manner of the above embodiment, backing up the suspicious file according to the first hazard metric value and the second hazard metric value can be: determining a target metric value according to the first hazard metric value and the second hazard metric value. When the target metric value is greater than the preset metric value, the suspicious file is backed up. When the target metric value is less than or equal to the preset metric value, it is determined that the suspicious file has no ransomware threat.

[0077] Optionally, the sum of the first hazard metric value and the second hazard metric value is used as the target metric value.

[0078] Alternatively, second weights corresponding to the first hazard metric value and the second hazard metric value are obtained, and the first hazard metric value and the second hazard metric value are weighted according to the second weights to obtain a target hazard metric value.

[0079] Optionally, the second weights corresponding to each hazard metric value can be pre-recorded in a hazard metric weight database. For example: the second weight of the first hazard metric value is 0.6, and the second weight of the second hazard metric value is 0.4.

[0080] In some embodiments, before determining the candidate encryption algorithm according to the encryption algorithm feature, it further includes: sending the first behavior feature and the encryption algorithm feature to a preset decision client, and the decision client responds to the user's first decision instruction to feedback whether to back up the suspicious file. Among them, the first decision instruction is used to indicate whether to back up the suspicious file.

[0081] In this way, after backing up the suspicious file, the suspicious file is stopped from running, and the backup file is run, which can continuously monitor the running situation of the ransomware of the suspicious file while protecting the data of the suspicious file from being further damaged, providing data support for the subsequent protection of the ransomware.

[0082] Optionally, when the ransomware attempts to delete or encrypt the backup file, the sandbox can abort the operation or create an instant running snapshot to save the state to prevent further data damage.

[0083] Step S104, determining a candidate encryption algorithm according to the encryption algorithm feature.

[0084] In some embodiments, the encryption algorithm feature may include: one or more of a call instruction, an encryption operation mode, and a key length.

[0085] Among them, the encryption operation modes include, for example: symmetric encryption, asymmetric encryption, block modes, etc.

[0086] Exemplarily, if the encryption operation mode is symmetric encryption, AES, DES (a symmetric encryption algorithm) may be candidate encryption algorithms. If asymmetric encryption is used, RSA may be a candidate encryption algorithm.

[0087] Also exemplarily, if the sandbox captures a block-level encryption mode, such as: CBC (Cipher Block Chaining mode) or ECB (Electronic Codebook mode), then encryption algorithms such as AES and DES that use this encryption operation mode may be candidate encryption algorithms.

[0088] Among them, the key lengths used by different encryption algorithms are different, but the key length of the same encryption algorithm is usually fixed. For example, AES uses 128-bit, 192-bit or 256-bit keys, while RSA usually uses 1024-bit or 2048-bit keys.

[0089] Exemplarily, the encryption algorithm features include: call instructions, encryption operation modes, and key lengths. Determining candidate encryption algorithms based on the encryption algorithm features may include: looking up the candidate encryption algorithms corresponding to the call instructions, encryption operation modes, and key lengths in a preset encryption algorithm database; the encryption algorithm database stores the corresponding relationships between the call instructions, encryption operation modes, key lengths, and candidate encryption algorithms.

[0090] Also exemplarily, the encryption operation mode can first be compared with the sample encryption operation modes in a preset encryption operation mode database to screen out the first sample encryption algorithm. The key length is compared with the sample key lengths in a preset key length database to screen out the second sample encryption algorithm. The call instructions are compared with the sample call instructions in a preset call instruction database to screen out the third sample encryption algorithm, and the same encryption algorithms among the first sample encryption algorithm, the second sample encryption algorithm, and the third sample encryption algorithm are determined as candidate encryption algorithms.

[0091] Among them, the encryption operation mode database stores the corresponding relationships between the sample encryption operation modes and encryption algorithms. The key length database stores the corresponding relationships between the sample key lengths and encryption algorithms. The call instruction database stores the corresponding relationships between the sample call instructions and encryption algorithms.

[0092] Exemplarily, based on the encryption operation mode observed in the sandbox, the electronic device first filters possible encryption algorithms. For example, if the sandbox captures a block-level encryption mode such as CBC or ECB, the candidate encryption algorithms will be narrowed down to those using this mode, such as AES, DES, etc. Then, based on the key length extracted by the sandbox, the encryption algorithms are further screened as candidate encryption algorithms. For example, if the key length used by the virus is 256 bits, AES and other symmetric encryption algorithms such as Blowfish may be candidate encryption algorithms. Then, the call instructions recorded by the sandbox are compared with the preset sample call instructions in the encryption algorithm database. If S-Box lookups, round function operations, etc. exist in the call instructions, AES can be used as a candidate encryption algorithm. Through the above comparison, a set of candidate encryption algorithms can be derived.

[0093] Also exemplarily, the encryption algorithm features include: call instructions, encryption operation mode, and key length. Determining candidate encryption algorithms based on the encryption algorithm features may include: inputting the call instructions, encryption operation mode, and key length into an encryption algorithm prediction model to obtain the candidate encryption algorithms jointly corresponding to the call instructions, encryption operation mode, and key length.

[0094] Optionally, obtain sample encryption algorithm features with candidate encryption algorithm labels, and input the sample encryption algorithm features with candidate encryption algorithm labels into a preset third training model for training to obtain an encryption algorithm prediction model.

[0095] Among them, the third training model is, for example: a neural network model, etc.

[0096] Step S105, decrypt the encrypted data using the candidate encryption algorithm and the key marking vector.

[0097] In some embodiments, there are multiple candidate encryption algorithms. Step S105 may include: sending the candidate encryption algorithms to a preset decision client, and the decision client selects a candidate encryption algorithm for decryption in response to the user's second decision instruction, and decrypt the encrypted data using the candidate encryption algorithm and the key marking vector fed back by the decision client.

[0098] In some embodiments, there are multiple candidate encryption algorithms. Step S105 may include: determining the priority of each candidate encryption algorithm according to the call instructions, encryption operation mode, and key length; decrypt the encrypted data using the candidate encryption algorithm and the key marking vector according to the priority.

[0099] In an alternative of the above embodiment, determining the priorities of the candidate encryption algorithms according to the call instruction, the encryption operation mode, and the key length may be: searching for the priorities corresponding to the call instruction, the encryption operation mode, and the key length in a preset priority database; the priority database stores the corresponding relationships between the call instruction, the encryption operation mode, the key length, and the priorities.

[0100] In some embodiments, after decrypting the data to be encrypted using the candidate encryption algorithm and the key tag vector, the method further includes: verifying whether the decrypted data meets a first preset condition; the first preset condition satisfies at least one of the following: the file format of the decrypted data is the same as that of the data to be encrypted, the file structure of the decrypted data is the same as that of the data to be encrypted, the content of the decrypted data is the same as the content of the data to be encrypted before encryption, the decrypted data can be executed normally; if the decrypted data meets the first preset condition, it is confirmed that the decryption is successful; otherwise, it is confirmed that the decryption fails.

[0101] Among them, the file format, for example: text, picture, compressed package, etc.

[0102] Among them, the file structure refers to the organization and arrangement of the internal data of the file, describing the composition of each part in the file and the relationship between each part, for example: sequential file, indexed file, etc.

[0103] Among them, it can be verified whether the content of the decrypted data is the same as the content of the data to be encrypted before encryption by hash comparison.

[0104] Among them, it can be judged whether the decrypted data can be executed normally by starting the executable file. If the executable file can be started normally, the decrypted data can be executed normally; otherwise, the decrypted data cannot be executed normally.

[0105] In some embodiments, there are multiple data to be encrypted; the method further includes: reorganizing the decrypted data corresponding to each data to be encrypted respectively to obtain reorganized data; verifying whether the reorganized data meets a second preset condition. If the reorganized data meets the second preset condition, it is confirmed that the reorganization is successful, and the candidate encryption algorithm and the key tag vector with successful decryption are recorded; otherwise, it is confirmed that the reorganization fails.

[0106] Among them, the second preset condition includes: whether the hash value of the reorganized data is consistent with the hash value of the suspicious file, and whether the file format of the reorganized data is the same as the file format of the suspicious file.

[0107] Exemplarily, for different types of files such as image files, compressed packages, text files, etc., the file format can be verified to meet the expectations in the following ways. For example: If it is an image file, detect the header identifier and pixel data of the image file. If it is a database file, detect the table structure and field data of the database.

[0108] In this way, calculate the hash value of the decrypted data and compare it with the hash value of the original data. Through hash verification, the integrity and consistency of the data before and after decryption can be ensured, and data loss or damage during decryption and recombination can be avoided. Further ensuring the integrity and consistency of the data can be achieved through the judgment of the file format.

[0109] In an alternative way of the above embodiment, the sandbox can record the position and order of each encrypted data. Recombining the decrypted data corresponding to each encrypted data to obtain the recombined data can be: recombining the decrypted data according to the recorded position and order of the encrypted data to obtain the recombined data.

[0110] In another alternative way of the above embodiment, recombining the decrypted data corresponding to each encrypted data to obtain the recombined data can be: reading the file header information of each encrypted data and recombining the decrypted data according to the file header information to obtain the recombined data. Among them, the file header information includes the order of the encrypted data.

[0111] Exemplarily, some file formats, such as images, videos, databases, etc., have file header information. The file header information contains information such as the structure of the file, the order of data blocks, and the data type. The correct order of data blocks can be identified by reading this header information.

[0112] In this way, once the order of different encrypted data is correctly determined, each decrypted data block can be merged into a complete file or data. For example, if an image file is encrypted in multiple data blocks, the system will splice them according to the width and length of the image and the order of each data block to restore the complete image.

[0113] In some embodiments, for certain file types, such as compressed packages, database files, etc., it is also necessary to parse the file format and restore the file content according to the format requirements of the file. For example, each data block in a compressed file may be a compressed part, and the decrypted data blocks will be decompressed and merged to ensure the correctness of the data.

[0114] Exemplarily, considering that each encryption algorithm has a specific instruction sequence. At runtime, the program will call the specific instructions of these encryption algorithms, such as using the encryption instructions of the CPU (processor) or calling encryption functions through libraries. And these instructions will exhibit a series of behavioral characteristics, such as specific opcodes, memory access patterns, data processing methods, etc. A set of behavioral characteristics can be preset in the sandbox. When the ransomware executes in the sandbox, monitor its code execution, capture behavioral characteristics such as the instructions called, data operations, and memory changes during the actual execution process, and match these characteristics with the instruction set of the known encryption algorithms preset in the sandbox and the code behavioral characteristics when running the encryption algorithms. Determine whether there is sufficient evidence indicating that a certain encryption algorithm is running through algorithm matching and feature similarity measurement. After identifying the encryption behavior, the sandbox derives the possible type of encryption algorithm, that is, derives the candidate encryption algorithms, by analyzing the encryption mode and key length used in the application. In the process of deriving the candidate encryption algorithms, a pre-constructed encryption algorithm database is used. The encryption algorithm database contains encryption algorithm characteristics such as call instructions, encryption operation modes, and key lengths of common encryption algorithms. The sandbox compares these characteristics with the behavior of the ransomware to form a series of candidate encryption algorithms.

[0115] After deriving the candidate encryption algorithms, the sandbox administrator can manually select from the derived candidate encryption algorithms or select the most suitable candidate encryption algorithm according to the priority. Then, the sandbox accesses and reads the encrypted data in the saved snapshot and calls the candidate encryption algorithm to decrypt the encrypted data. During the decryption process, a block-level data decryption verification mechanism is adopted. After decrypting each piece of encrypted data one by one using the candidate encryption algorithm with the recorded key marking vector, it is also necessary to confirm whether the decrypted data conforms to the expected format or content to determine the correctness of the decryption algorithm. After determining that the decryption algorithm is correct, the sandbox will recover the damaged data through segmented decryption and recombination technology. Since the ransomware may use different encryption algorithms or keys for different files or data blocks, the encrypted data blocks can be processed segment by segment and each segment of encrypted data can be decrypted. The decrypted data is reorganized to restore the original data structure. At the same time, verify the reorganized data to ensure the integrity and consistency after data reorganization. After the data reorganization is successful, the sandbox can also record the key and candidate encryption algorithm used for decryption and generate a key-algorithm mapping table. This mapping table will be used for the prevention of future similar attacks and data recovery work. At the same time, the sandbox can also encrypt and store the recorded key to prevent its leakage.

[0116] After completing data decryption and recovery, the sandbox can also allow the ransomware to continue executing until all its encryption actions are completed. At this time, the sandbox can record the complete attack process of the ransomware, including but not limited to information such as encryption methods, network communications, and attack targets, and store this data in the threat intelligence database to provide a basis for subsequent threat intelligence analysis and defense strategies.

[0117] Embodiment 2

[0118] Based on the same inventive concept, an embodiment of the present application provides a device for processing ransomware, as Figure 2 shown. The device for processing ransomware includes: a monitoring module 1, an operation situation determination module 2, a recording module 3, an algorithm derivation module 4, and a decryption module 5. Among them, the monitoring module 1 is used to trigger the operation of a suspicious file imported into a preset sandbox and monitor the first behavior characteristics of the suspicious file; the first behavior characteristics characterize the operation behavior of the suspicious file during operation; the operation situation determination module 2 is used to determine the running situation of the encryption algorithm according to the first behavior characteristics and preset second behavior characteristics; the second behavior characteristics characterize the operation behavior during the running of the encryption algorithm; the recording module 3 is used to record the encrypted data, encryption algorithm characteristics, and key marker vector when the running situation of the encryption algorithm is that there is an encryption algorithm running; the algorithm derivation module 4 is used to determine a candidate encryption algorithm according to the encryption algorithm characteristics; the decryption module 5 is used to decrypt the encrypted data by using the candidate encryption algorithm and the key marker vector.

[0119] In some embodiments, the operation situation determination module 2 is used to determine the running situation of the encryption algorithm according to the first behavior characteristics and the preset second behavior characteristics in the following manner: determining a first target similarity between the first behavior characteristics and the second behavior characteristics; when the first target similarity is higher than a first preset similarity, confirming that the running situation of the encryption algorithm is that there is an encryption algorithm running; otherwise, confirming that the running situation of the encryption algorithm is that there is no encryption algorithm running.

[0120] In some embodiments, the first behavioral features include: a target call instruction, a target memory access pattern, a target function call chain, a target encryption duration, and a target encrypted file size; the second behavioral features include: a sample call instruction, a sample memory access pattern, a sample function call chain, a sample encryption duration, and a sample encrypted file size; the operation condition determination module 2 is configured to determine a first target similarity between the first behavioral features and the second behavioral features in the following manner: calculating a first sample similarity between the target call instruction and the sample call instruction; calculating a second sample similarity between the target memory access pattern and the sample memory access pattern; calculating a third sample similarity between the target function call chain and the sample function call chain; calculating a fourth sample similarity between the target encryption duration and the sample encryption duration; calculating a fifth sample similarity between the target encrypted file size and the sample encrypted file size; and determining the first target similarity according to the first sample similarity, the second sample similarity, the third sample similarity, the fourth sample similarity, and the fifth sample similarity.

[0121] In some embodiments, the first behavioral features further include: a retrieved file type; the device for dealing with the ransomware further includes: a backup module, configured to determine a first hazard metric value according to a key marking vector before determining a candidate encryption algorithm according to the encryption algorithm features; determining a second hazard metric value according to the retrieved file type; backing up the suspicious file according to the first hazard metric value and the second hazard metric value; stopping the operation of the suspicious file, and running the backup file.

[0122] In some embodiments, the encryption algorithm features include: a call instruction, an encryption operation mode, and a key length; the algorithm derivation module 4 is configured to determine a candidate encryption algorithm according to the encryption algorithm features in the following manner: looking up a candidate encryption algorithm corresponding to the call instruction, the encryption operation mode, and the key length in a preset encryption algorithm database; the encryption algorithm database stores the corresponding relationships between the call instruction, the encryption operation mode, the key length, and the candidate encryption algorithm.

[0123] In some embodiments, there are multiple candidate encryption algorithms, and the decryption module 5 is configured to decrypt the encrypted data by using the candidate encryption algorithms and the key marking vector in the following manner: determining the priorities of the candidate encryption algorithms according to the call instruction, the encryption operation mode, and the key length; decrypting the encrypted data by using the candidate encryption algorithms and the key marking vector according to the priorities.

[0124] In some embodiments, the device for dealing with ransomware further includes: a verification module, configured to decrypt the encrypted data by using a candidate encryption algorithm and a key tag vector, and then verify whether the decrypted data meets a first preset condition; the first preset condition satisfies at least one of the following: the file format of the decrypted data is the same as that of the encrypted data, the file structure of the decrypted data is the same as that of the encrypted data, the content of the decrypted data is the same as the content of the encrypted data before encryption, and the decrypted data can be executed normally; if the decrypted data meets the first preset condition, it is confirmed that the decryption is successful; otherwise, it is confirmed that the decryption fails.

[0125] In some embodiments, there are multiple pieces of encrypted data; the device for dealing with ransomware further includes: a recombination module, configured to recombine the decrypted data respectively corresponding to each piece of encrypted data to obtain recombined data; verify whether the recombined data meets a second preset condition; the second preset condition includes: whether the hash value of the recombined data is consistent with the hash value of the suspicious file; whether the file format of the recombined data is the same as the file format of the suspicious file; if the recombined data meets the second preset condition, it is confirmed that the recombination is successful, and the candidate encryption algorithm and the key tag vector for successful decryption are recorded; otherwise, it is confirmed that the recombination fails.

[0126] It can be understood that the embodiments described in Embodiment 1 are also applicable to Embodiment 2 without conflict. For the sake of brevity, they will not be elaborated here.

[0127] Embodiment 3

[0128] Combined with Figure 3 As shown, an embodiment of the present application provides an electronic device, including a processor 7 and a memory 8. Optionally, the device may further include a communication interface 9 and a bus 6. Among them, the processor 7, the communication interface 9, and the memory 8 can complete mutual communication through the bus 6. The communication interface 9 can be used for information transmission. The processor 7 can call the logical instructions in the memory 8 to execute the method for dealing with ransomware in the above embodiments.

[0129] In addition, when the logical instructions in the above-mentioned memory 8 are implemented in the form of a software functional unit and sold or used as an independent product, they can be stored in a computer-readable storage medium.

[0130] The memory 8, as a computer-readable storage medium, can be used to store software programs and computer-executable programs, such as the program instructions / modules corresponding to the method in the embodiments of the present application. The processor 7 executes functional applications and data processing by running the program instructions / modules stored in the memory 8, that is, implements the method for dealing with ransomware in the above embodiments.

[0131] The memory 8 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created according to the use of the terminal device, etc. In addition, the memory 8 may include a high-speed random access memory and may also include a non-volatile memory.

[0132] An embodiment of the present application provides a storage medium storing computer-executable instructions, and the computer-executable instructions are configured to execute the above method for handling ransomware.

[0133] An embodiment of the present application provides a computer program product. The computer program product includes a computer program stored on a storage medium. The computer program includes program instructions, and when the program instructions are executed by a computer, the computer is caused to execute the above method for handling ransomware.

[0134] The above computer-readable storage medium may be a transient computer-readable storage medium or a non-transient computer-readable storage medium.

[0135] The technical solution of the embodiment of the present application may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes one or more instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method of the embodiment of the present application. The foregoing storage medium may be a non-transient storage medium, including: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc that can store program codes, or may also be a transient storage medium.

[0136] In the embodiments provided by the present application, it should be understood that the disclosed devices and methods may be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.

[0137] The above are only embodiments of the present application and are not used to limit the protection scope of the present application. For those skilled in the art, the present application may have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. At the same time, the above embodiments may be combined with each other without conflict to form new embodiments.

Claims

1. A method for dealing with ransomware, characterized in that, Including: Trigger the running of a suspicious file that imports a preset sandbox, and monitor the first behavioral characteristics of the suspicious file; The first behavioral characteristics characterize the operation behavior of the suspicious file during running; The suspicious file is a file assumed to carry a ransomware virus; Determine the running situation of the encryption algorithm according to the first behavioral characteristics and the preset second behavioral characteristics; the second behavioral characteristics characterize the operation behavior during the running of the encryption algorithm; When the running situation of the encryption algorithm is that there is an encryption algorithm running, record the encrypted data, the encryption algorithm characteristics, and the key marking vector; Determine the candidate encryption algorithm according to the encryption algorithm characteristics; Decrypt the encrypted data by using the candidate encryption algorithm and the key marking vector; Determining the running situation of the encryption algorithm according to the first behavioral characteristics and the preset second behavioral characteristics includes: determining the first target similarity between the first behavioral characteristics and the second behavioral characteristics; when the first target similarity is higher than the first preset similarity, confirm that the running situation of the encryption algorithm is that there is an encryption algorithm running; otherwise, confirm that the running situation of the encryption algorithm is that there is no encryption algorithm running; The first behavioral characteristics include: target call instruction, target memory access pattern, target function call chain, target encryption duration, and target encrypted file size; the second behavioral characteristics include: sample call instruction, sample memory access pattern, sample function call chain, sample encryption duration, and sample encrypted file size. Determining the first target similarity between the first behavioral characteristics and the second behavioral characteristics includes: calculating the first sample similarity between the target call instruction and the sample call instruction; calculating the second sample similarity between the target memory access pattern and the sample memory access pattern; calculating the third sample similarity between the target function call chain and the sample function call chain; calculating the fourth sample similarity between the target encryption duration and the sample encryption duration; calculating the fifth sample similarity between the target encrypted file size and the sample encrypted file size; determining the first target similarity according to the first sample similarity, the second sample similarity, the third sample similarity, the fourth sample similarity, and the fifth sample similarity; Among them, the call instruction includes the function call of the encryption algorithm and the encryption operator; the function call chain is the call function sequence and parameters of the encryption algorithm; the memory access pattern is the memory pattern when encrypting data.

2. The method according to claim 1, characterized in that The first behavioral characteristics further include: retrieving the file type; before determining the candidate encryption algorithm according to the encryption algorithm characteristics, the method further includes: Determine the first hazard metric value according to the key marking vector; Determine the second hazard metric value according to the retrieved file type; Back up the suspicious file according to the first hazard metric value and the second hazard metric value; Stop running the suspicious file and run the backup file.

3. The method according to claim 1, characterized in that, The encryption algorithm characteristics include: call instruction, encryption operation mode, and key length. Determining the candidate encryption algorithm according to the encryption algorithm characteristics includes: Search for a candidate encryption algorithm corresponding to the call instruction, the encryption operation mode, and the key length in a preset encryption algorithm database; the corresponding relationship between the call instruction, the encryption operation mode, the key length, and the candidate encryption algorithm is stored in the encryption algorithm database.

4. The method according to claim 3, wherein There are multiple candidate encryption algorithms. Using the candidate encryption algorithms and the key marking vector to decrypt the data to be encrypted includes: Determine the priority of each candidate encryption algorithm according to the call instruction, the encryption operation mode, and the key length; Decrypt the data to be encrypted using the candidate encryption algorithms and the key marking vector according to the priority.

5. The method according to any one of claims 1 to 4, characterized in that After decrypting the data to be encrypted using the candidate encryption algorithms and the key marking vector, the method further includes: Verify whether the decrypted data meets a first preset condition; the first preset condition satisfies at least one of the following: the file format of the decrypted data is the same as that of the data to be encrypted, the file structure of the decrypted data is the same as that of the data to be encrypted, the content of the decrypted data is the same as the content before encryption of the data to be encrypted, and the decrypted data can be executed normally; If the decrypted data meets the first preset condition, confirm that the decryption is successful; otherwise, confirm that the decryption is failed.

6. The method according to claim 5, characterized in that There are multiple pieces of data to be encrypted; the method further includes: Recombine the decrypted data corresponding to each piece of data to be encrypted to obtain recombined data; Verify whether the recombined data meets a second preset condition; the second preset condition includes: whether the hash value of the recombined data is the same as the hash value of the suspicious file, and whether the file format of the recombined data is the same as the file format of the suspicious file; If the recombined data meets the second preset condition, confirm that the recombination is successful, and record the candidate encryption algorithm and the key marking vector for which the decryption is successful; otherwise, confirm that the recombination is failed.

7. A device for dealing with ransomware, characterized in that, Includes: A monitoring module for triggering the execution of a suspicious file imported into a preset sandbox and monitoring the first behavior characteristics of the suspicious file; The first behavior characteristic characterizes the operation behavior of the suspicious file during operation; An operation situation determination module for determining the operation situation of the encryption algorithm according to the first behavior characteristic and a preset second behavior characteristic; the second behavior characteristic characterizes the operation behavior during the operation of the encryption algorithm; A recording module for recording the data to be encrypted, the encryption algorithm characteristics, and the key marking vector when the operation situation of the encryption algorithm is that there is an encryption algorithm running; An algorithm derivation module for determining a candidate encryption algorithm according to the encryption algorithm characteristics; A decryption module for decrypting the data to be encrypted using the candidate encryption algorithm and the key marking vector; Among them, the running situation determination module is used to determine the running situation of the encryption algorithm according to the first behavior feature and the preset second behavior feature in the following way: determine the first target similarity between the first behavior feature and the second behavior feature; in the case where the first target similarity is higher than the first preset similarity, confirm that the running situation of the encryption algorithm is that there is an encryption algorithm running; otherwise, confirm that the running situation of the encryption algorithm is that there is no encryption algorithm running; The first behavior feature includes: target call instruction, target memory access pattern, target function call chain, target encryption duration, and target encrypted file size; the second behavior feature includes: sample call instruction, sample memory access pattern, sample function call chain, sample encryption duration, and sample encrypted file size; the running situation determination module is used to determine the first target similarity between the first behavior feature and the second behavior feature in the following way: calculate the first sample similarity between the target call instruction and the sample call instruction; calculate the second sample similarity between the target memory access pattern and the sample memory access pattern; calculate the third sample similarity between the target function call chain and the sample function call chain; calculate the fourth sample similarity between the target encryption duration and the sample encryption duration; calculate the fifth sample similarity between the target encrypted file size and the sample encrypted file size; determine the first target similarity according to the first sample similarity, the second sample similarity, the third sample similarity, the fourth sample similarity, and the fifth sample similarity; Among them, the call instruction includes function calls and encryption operators of the encryption algorithm; the function call chain is the call function sequence and parameters of the encryption algorithm; the memory access pattern is the memory pattern when encrypting data.

8. An electronic device, characterized in that, It includes a processor and a memory, and the memory stores computer-executable instructions that can be executed by the processor, and the processor executes the computer-executable instructions to implement the method for dealing with ransomware according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Ransomware protection method and system

    CN114186222A

  • Ransomware encryption analysis method and device, electronic equipment and storage medium

    CN118264431A

Cited By

  • Recovering from ransomware attacks

    US12430438B1