Ransomware Detection Method, Device, Storage Medium, and Computer Program Product

By dynamically obtaining file type distribution information and machine learning model analysis, accurately spraying bait files and monitoring the ransomware process in real time, solving the problem of insufficient concealment of bait files and achieving efficient ransomware detection and protection.

CN119720203BActive Publication Date: 2025-07-18LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510229140.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-07-18
Estimated Expiration
2045-02-28

AI Technical Summary

Technical Problem

In the prior art, the bait file is low in concealment, which makes ransomware easy to identify and encrypt or delete bait file, reducing the accuracy and reliability of ransomware detection.

Method used

By dynamically obtaining the file type distribution information of the target file directory, accurately spraying the bait file to make it highly consistent with the real file environment, combining machine learning models to analyze file behavior patterns, and monitoring and processing ransomware processes in real time.

Benefits of technology

It improves the concealment of bait files, enhances the accuracy and reliability of ransomware detection, can promptly prevent ransomware sabotage behavior, and protects user systems and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119720203B_ABST
    Figure CN119720203B_ABST
Patent Text Reader

Abstract

The present invention discloses a ransomware detection method, device, storage medium, and computer program product, relating to the field of computer technologies. The method includes: determining a target file directory to be monitored and obtaining the file type distribution information of the target file directory; wherein the file type distribution information includes the types of files contained in the target file directory and the distribution ratios of files of various types; obtaining decoy files, and spraying the decoy files into the target file directory based on the file type distribution information to implement the detection of ransomware. By dynamically obtaining the file type distribution information of the target file directory and accurately spraying the decoy files into the target directory according to the file type distribution information, the present invention makes the types and distribution ratios of the decoy files highly consistent with the real file environment of the user system, improves the concealment of the decoy files, avoids ransomware from identifying and avoiding the decoy files, and enhances the accuracy and reliability of ransomware detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular, to a method and device for detecting ransomware, a storage medium, and a computer program product. Background Art

[0002] Ransomware is a common type of malware whose main feature is encrypting user files, making them inaccessible or modifiable by the user, and then extorting the user to pay a ransom to unlock the files. Currently, the detection technology of ransomware mainly relies on the deployment and monitoring of decoy files, and identifies the presence of ransomware by detecting whether the decoy files are encrypted or manipulated. However, in the related art, the concealment of decoy files is relatively low, resulting in a relatively high probability that ransomware can identify decoy files.

[0003] Therefore, how to improve the concealment of decoy files to reduce the probability that ransomware can identify decoy files is a technical problem that needs to be solved by those skilled in the art. Summary of the Invention

[0004] The present invention provides a method and device for detecting ransomware, a storage medium, and a computer program product, which improve the concealment of decoy files and thus reduce the probability that ransomware can identify decoy files.

[0005] The present invention provides a method for detecting ransomware, including:

[0006] Determine a target file directory to be monitored, and obtain the file type distribution information of the target file directory; wherein, the file type distribution information includes the types of files included in the target file directory and the distribution ratio of files of each type;

[0007] Obtain decoy files, and spray the decoy files into the target file directory based on the file type distribution information;

[0008] If an operation on the decoy files is detected, determine the process performing the operation as a ransomware process, and process the ransomware process according to a preset monitoring strategy.

[0009] The present invention also provides a device for detecting ransomware, including:

[0010] A first acquisition module, configured to determine a target file directory to be monitored, and obtain the file type distribution information of the target file directory; wherein, the file type distribution information includes the types of files included in the target file directory and the distribution ratio of files of each type;

[0011] A spraying module, configured to obtain decoy files, and spray the decoy files into the target file directory based on the file type distribution information;

[0012] A processing module, configured to determine that the process performing the operation is a ransomware process when an operation on a decoy file is detected, and process the ransomware process according to a preset monitoring strategy.

[0013] The present invention also provides an electronic device, including: a memory for storing a computer program; a processor for implementing the steps of any of the above ransomware detection methods when executing the computer program.

[0014] The present invention also provides a computer-readable storage medium storing a computer program, wherein the computer program implements the steps of any of the above ransomware detection methods when executed by a processor.

[0015] The present invention also provides a computer program product including a computer program that implements the steps of any of the above ransomware detection methods when executed by a processor.

[0016] The beneficial effects of the present invention are as follows: The ransomware detection method provided by the present invention dynamically obtains the file type distribution information of the target file directory, and accurately sprays decoy files into the target directory according to the file type distribution information, so that the types and distribution ratios of the decoy files are highly consistent with the real file environment of the user system. This design not only effectively improves the concealment of the decoy files, avoids ransomware from identifying and avoiding the decoy files, but also significantly enhances the accuracy and reliability of ransomware detection. At the same time, by real-time monitoring the operation behavior of the decoy files and quickly identifying the ransomware process, and combining with the preset monitoring strategy for targeted processing, the present invention can timely prevent the destructive behavior of ransomware and protect the security of the user system and data. The present invention also discloses a ransomware detection device, an electronic device, a computer-readable storage medium, and a computer program product, which can also achieve the above technical effects.

[0017] It should be understood that the above general description and the following detailed description are only exemplary and do not limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] To more clearly illustrate the embodiments of the present invention, the following will briefly introduce the drawings required for the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0019] Figure 1 It is a flowchart of a ransomware detection method shown according to an exemplary embodiment;

[0020] Figure 2Flowchart of a decoy file update method shown according to an exemplary embodiment;

[0021] Figure 3 Framework diagram of a ransomware intrusion detection system shown according to an exemplary embodiment;

[0022] Figure 4 Flowchart of a decoy file spraying shown according to an exemplary embodiment;

[0023] Figure 5 Flowchart of a whitelist determination shown according to an exemplary embodiment;

[0024] Figure 6 Flowchart of an ePBF ransomware monitoring function shown according to an exemplary embodiment;

[0025] Figure 7 Flowchart of a decoy file update shown according to an exemplary embodiment;

[0026] Figure 8 Structural diagram of a ransomware detection device shown according to an exemplary embodiment;

[0027] Figure 9 Structural diagram of an electronic device shown according to an exemplary embodiment. Detailed implementation manners

[0028] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0029] It should be noted that in the description of the present invention, the terms "include", "comprise" or any other variant thereof are intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present invention are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0030] In order to enable those skilled in the art of the present technology to better understand the solution of the present invention, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.

[0031] Embodiments of the present invention provide a method for detecting ransomware. The method will be described in detail in combination with the execution process of the ransomware detection method.

[0032] Refer to Figure 1 , a flowchart of a method for detecting ransomware shown according to an exemplary embodiment, as Figure 1 shown, includes:

[0033] S101: Determine the target file directory to be monitored, and obtain the file type distribution information of the target file directory; wherein, the file type distribution information includes the types of files included in the target file directory and the distribution ratio of each type of file.

[0034] Among them, the target file directory refers to the file storage directory in the user system where ransomware detection needs to be performed, such as / home, / opt or other custom directories. The file type distribution information refers to the statistical information of different types of files in the target file directory, including the types of files and the distribution ratio of each type of file in the directory.

[0035] In this step, through a system scanning tool or a file analysis module, the target file directory is traversed, the types and quantities of all files in the directory are counted, and then the distribution ratio of each type of file is calculated. For example, use the Linux system command or script tool to scan the / home directory, count that there are 100.txt files and 300.db files, and the total number of files is 400, so as to obtain that the.txt files account for 25% and the.db files account for 75%.

[0036] This step provides an accurate basis for the subsequent generation and placement of decoy files, enabling the decoy files to highly match the true file type distribution of the target directory, thereby effectively reducing the possibility of ransomware identifying the decoy files and improving the concealment and accuracy of detection.

[0037] S102: Obtain decoy files, and spray the decoy files into the target file directory based on the file type distribution information;

[0038] Among them, the decoy file refers to a false file used to lure ransomware to perform operations, and its purpose is to identify the existence of ransomware by detecting the operation behavior of the decoy file. Spraying means placing the decoy files into the target file directory according to specific distribution rules, mixing them with real files, and increasing the probability of triggering ransomware detection.

[0039] In this step, according to the file type distribution information obtained in the previous step, generate or obtain decoy files that are consistent with the file type distribution of the target file directory. For example, if.db files account for 75% and.txt files account for 25% in the target directory, then generate or obtain the corresponding number of.db and.txt decoy files according to this ratio, and place them randomly or according to rules in the target file directory.

[0040] By precisely matching the file type distribution of the target directory, the decoy files can better disguise themselves as real files and reduce the risk of being recognized by ransomware. At the same time, the dynamic spraying mechanism makes the distribution of decoy files more natural, further improving the concealment and effectiveness of detection.

[0041] As a feasible implementation method, after determining the target file directory to be monitored, it also includes: obtaining the overall file type distribution information; where the overall file type distribution information includes the total number of files, file types, and the overall distribution ratio of each type of file included in all target file directories; correspondingly, obtaining decoy files and spraying the decoy files into the target file directory based on the file type distribution information includes: obtaining the target number of decoy files based on the overall file type distribution information; where the target number is the product of the total number and the preset ratio, and the distribution ratio of each type of file in the obtained target number of decoy files conforms to the overall distribution ratio; spraying the decoy files into each target file directory based on the file type distribution information of each target file directory.

[0042] Among them, the overall file type distribution information refers to the comprehensive statistical information of files in all target file directories, including the total number of files, file types, and the distribution ratio of each file type in the entire system. For example, there are a total of 1000 files in all target file directories, among which.txt files account for 30%,.db files account for 50%, and.py files account for 20%. The target number refers to the total number of decoy files calculated according to the overall file type distribution information, usually the product of the total number of files in all target file directories and the preset ratio. For example, if the total number of files in all target file directories is 1000 and the preset ratio is 10%, then the target number is 100. The preset ratio refers to the ratio of decoy files to real files preset by the system, used to control the placement density of decoy files. For example, a preset ratio of 10% means that the number of decoy files is 10% of the number of real files. The overall distribution ratio refers to the distribution ratio of each file type in the entire system. For example,.txt files account for 30%,.db files account for 50%, and.py files account for 20%.

[0043] In a specific implementation, first, all target file directories are scanned to count the number and types of files in each directory, and this information is aggregated to calculate the overall file type distribution ratio. For example, the system scans the / home, / opt, and / var directories, and the total number of files is counted as 1000, among which there are 300.txt files, 500.db files, and 200.py files. The overall distribution ratio is 30% for.txt, 50% for.db, and 20% for.py. Second, the total number of decoy files is calculated according to a preset ratio (e.g., 10%). If the total number of files is 1000 and the preset ratio is 10%, then the target number is 100. Then, the target number of decoy files is generated or obtained according to the overall distribution ratio. For example, 30.txt decoy files, 50.db decoy files, and 20.py decoy files are generated to conform to the overall distribution ratio. Finally, according to the file type distribution information of each target file directory, the decoy files are allocated to each directory in proportion. For example, if the.txt files account for a relatively high proportion in the / home directory, more.txt decoy files are allocated to the / home directory; if the.db files dominate in the / opt directory, more.db decoy files are allocated to the / opt directory.

[0044] For example, assume that an enterprise server system contains multiple target file directories to be monitored, such as / home (user documents), / opt (database files), and / var (log files). The system discovers through scanning that: the / home directory has 400 files, among which.txt accounts for 70% and.docx accounts for 30%; the / opt directory has 300 files, among which.db accounts for 80% and.log accounts for 20%; the / var directory has 300 files, among which.log accounts for 60% and.conf accounts for 40%. The overall file type distribution is:.txt accounts for 28%,.docx accounts for 12%,.db accounts for 24%,.log accounts for 24%, and.conf accounts for 12%. The total number of files is 1000, the preset ratio is 10%, and the target number is 100. According to the overall distribution ratio, 28.txt decoy files, 12.docx decoy files, 24.db decoy files, 24.log decoy files, and 12.conf decoy files are generated. Then, according to the file type distribution of each target file directory, these decoy files are allocated to each directory to ensure that the types and ratios of decoy files in each target file directory highly match the real files.

[0045] By generating and spraying decoy files based on the overall file type distribution information, it is ensured that the types and proportions of decoy files are highly consistent with the real files in the system, reducing the possibility of ransomware identifying decoy files. By calculating the target quantity based on the overall distribution ratio and the preset ratio, precise control over the decoy file placement density is achieved, which can not only effectively cover the file types in the system but also not affect the system performance due to excessive decoy files. The decoy file placement strategy not only considers the file type distribution of a single directory but also takes into account the file type distribution of the entire system, making it easier for ransomware to trigger detection globally and improving the comprehensiveness and accuracy of detection.

[0046] It should be noted that this embodiment does not limit the method of obtaining decoy files. They can be obtained from the local library or dynamically generated and distributed from a remote server.

[0047] As a feasible implementation method, obtaining decoy files includes: obtaining decoy files from the local decoy file library.

[0048] Among them, the local decoy file library refers to the set of decoy files stored in the local system. These files are pre-generated and saved locally for ransomware detection. In specific implementation, the required decoy files are directly selected and obtained from the locally stored decoy file library. The types and quantities of these files can be dynamically adjusted according to the file type distribution information of the target file directory.

[0049] Obtaining decoy files directly from the local area without interacting with the remote server reduces the acquisition time and improves the detection efficiency. It is applicable to situations without network connection or with unstable network, ensuring that the system can still perform ransomware detection in an offline state. It reduces the system complexity and dependence on the network and remote server, and is suitable for scenarios with high real-time requirements.

[0050] As another feasible implementation method, obtaining decoy files includes: the ransomware detection module sending a request for obtaining decoy files to the remote server; receiving the remote attestation challenge sent by the remote server and generating remote attestation information based on the remote attestation challenge; sending the remote attestation information to the remote server so that the remote server can verify that the ransomware detection module runs in a trusted execution environment; establishing a secure channel with the remote server and obtaining decoy files from the remote server through the secure channel.

[0051] Among them, the remote server refers to an external server that provides decoy files and usually has the ability to dynamically generate and distribute decoy files. The remote attestation challenge refers to a verification request initiated by the remote server to verify whether the ransomware detection module is running in a trusted execution environment. The trusted execution environment (TEE) is a secure execution environment that ensures that code and data are not tampered with or leaked during operation. The secure channel refers to an encrypted communication link established through an encrypted communication protocol to ensure the security of data transmission.

[0052] In a specific implementation, the ransomware detection module sends a decoy file acquisition request to the remote server. The remote server sends a remote attestation challenge containing a random number. The ransomware detection module obtains the measurement value of the trusted execution environment based on the random number and signs the measurement value using a private key to generate remote attestation information. The remote attestation information is sent to the remote server, and the server verifies the signature and compares the measurement value with a reference value. After the verification passes, the ransomware detection module establishes a secure channel with the remote server and obtains the decoy file through this channel.

[0053] As a feasible implementation, receiving the remote attestation challenge sent by the remote server and generating remote attestation information based on the remote attestation challenge includes: receiving the remote attestation challenge sent by the remote server; where the remote attestation challenge includes a random number; obtaining the measurement value of the trusted execution environment based on the random number, signing the measurement value using the private key generated by the trusted execution environment, and generating remote attestation information based on the signed measurement value; correspondingly, the remote server verifies the signature of the measurement value in the remote attestation information and compares whether the measurement value in the remote attestation information is consistent with the pre-stored reference value. If the signature verification passes and the measurement value is consistent with the reference value, it is confirmed that the ransomware detection module is running in the trusted execution environment.

[0054] Among them, the measurement value is generated by the trusted execution environment and can describe the current running state of the trusted execution environment, and is used to verify the integrity and security of the trusted execution environment. The signature refers to encrypting data using a private key and is used to verify the integrity and source of the data.

[0055] In a specific implementation, the ransomware detection module receives the remote attestation challenge containing a random number sent by the remote server. Obtains the measurement value of the trusted execution environment based on the random number. Signs the measurement value using the private key generated by the trusted execution environment. Generates remote attestation information from the signed measurement value and sends it to the remote server. The remote server verifies the signature and compares the measurement value with the pre-stored reference value. If the verification passes, it is confirmed that the ransomware detection module is running in the trusted execution environment.

[0056] Through the remote attestation mechanism, ensure that the ransomware detection module runs in a trusted execution environment to prevent the ransomware detection module from being maliciously tampered with or attacked. Establish a trust relationship between the remote server and the ransomware detection module to ensure the security of subsequent communication and file transfer.

[0057] As a feasible implementation, after the remote server verifies that the ransomware detection module runs in a trusted execution environment, it further includes: negotiating a key based on the remote attestation information with the remote server; correspondingly, after obtaining the decoy file from the remote server through a secure channel, it further includes: verifying the signature of the obtained decoy file using the public key generated by the remote server to verify the legitimacy of the decoy file.

[0058] Among them, the public key refers to the key used to verify the signature, which is used in pair with the private key. Signature verification refers to verifying the integrity and source of the signature data through the public key to ensure that the data has not been tampered with.

[0059] In a specific implementation, after the remote server verifies that the ransomware detection module runs in a trusted execution environment, it negotiates a key with the detection module based on the remote attestation information. The ransomware detection module obtains the decoy file from the remote server through a secure channel. The ransomware detection module uses the public key generated by the remote server to verify the signature of the obtained decoy file to ensure the legitimacy of the decoy file.

[0060] Through the signature verification mechanism, ensure that the decoy file has not been tampered with and has a reliable source to prevent malicious file injection. Use public key encryption technology to ensure the security and integrity of the file transfer process.

[0061] As a preferred implementation, after spraying the decoy file to the target file directory, it further includes: modifying the attributes of the decoy file sprayed to the target file directory according to the attribute information of the non-decoy files in the target file directory.

[0062] Among them, the attribute information refers to the metadata of the file, including file permissions, owner, group, last access time (atime), last modification time (mtime), last change time (ctime), etc.

[0063] In a specific implementation, after placing the decoy file in the target file directory, the system scans the non-decoy files (real files) in the target directory. Obtain the attribute information of the non-decoy files, including file permissions, owner, group, access time, etc. According to the attribute information of the non-decoy files, modify the corresponding attributes of the decoy file to make it highly consistent with the attributes of the real files.

[0064] For example, the update of the most recently accessed time is achieved through the cat process, the update of the most recently changed time and the most recently modified time is achieved through the vi process, and at the same time, the update of some content values of the decoy file is achieved. The update of the permissions, file owner, and file group of the decoy file is achieved through the chmod, chown, and chgrp processes.

[0065] By modifying the attributes of the decoy file to be highly consistent with those of the real file, the possibility of the ransomware identifying the decoy file is reduced. The consistency of the attributes of the decoy file with those of the real file makes it more difficult for the ransomware to distinguish which files are decoy files, thereby improving the reliability of the detection system. The attributes of the files in the target file directory may change over time, and dynamically modifying the attributes of the decoy file can ensure that the detection system is always effective.

[0066] As a feasible implementation, after detecting an operation on the decoy file, it further includes: determining whether the process executing the operation is a whitelist process; where the whitelist process includes processes for modifying file attributes; if not, then proceed to the step of determining that the process executing the operation is a ransomware process.

[0067] Among them, the whitelist process refers to a pre-defined process that is allowed to operate on files, and these processes are usually used for normal file management or maintenance tasks, such as file editing, backup, etc. The ransomware process refers to a process detected to operate on the decoy file. If this process is not in the whitelist, it is considered a ransomware process.

[0068] In a specific implementation, after detecting an operation on the decoy file, the system records the process information of the operation. The system checks whether this process is in the whitelist, and the whitelist usually includes processes allowed to modify file attributes, such as the cat, vi, chmod, chown, chgrp processes, etc. If the process executing the operation is not in the whitelist, the system marks it as a ransomware process and proceeds to the subsequent processing flow.

[0069] Through the whitelist mechanism, the misjudgment of processes performing normal operations as ransomware processes is avoided, improving the accuracy of the detection system. The whitelist can be dynamically adjusted according to actual needs to adapt to different system environments and operation requirements. For processes not in the whitelist, the system can quickly identify and take measures to prevent further damage by the ransomware.

[0070] As a feasible implementation, after spraying the decoy file to the target file directory based on the file type distribution information, it further includes: mounting a process monitoring event at the mount point to monitor the operations of processes on the files in the target file directory through the process monitoring event.

[0071] Among them, the mount point refers to a specific location in the system for monitoring the behavior of processes, usually related to file system operations such as file opening, deletion, renaming, etc. The process monitoring event refers to the monitoring mechanism of the system for the behavior of processes, which is used to record and analyze the operations of processes on files.

[0072] In a specific implementation, after spraying the decoy files into the target file directory, the process monitoring event is mounted at the mount point, and the operation behavior of the process on the files in the target file directory is monitored in real time through these mount points. When an operation on the decoy file is detected, the relevant process information is recorded and the subsequent detection process is entered.

[0073] For example, assume that several.db decoy files are sprayed in the target file directory / opt / database. Monitor events are mounted at the mount points of file system operations (such as lsm / file_open, lsm / inode_unlink, lsm / inode_rename). When a certain process attempts to open or delete a decoy file, the operation behavior is captured through these mount points, and the process information of the executing operation is recorded.

[0074] S103: If an operation on the decoy file is detected, determine that the process performing the operation is a ransomware process, and process the ransomware process according to the preset monitoring strategy.

[0075] Among them, the operation refers to behaviors such as reading, writing, encrypting, deleting, and renaming files. Ransomware usually encrypts or deletes files. The preset monitoring strategy refers to the strategy predefined for dealing with ransomware behaviors, such as recording logs, issuing alerts, terminating suspicious processes, etc.

[0076] In this step, the file operation behavior in the target file directory is monitored in real time through the file monitoring module. Once an encryption, deletion, or other suspicious operation on the decoy file is detected, the system immediately determines that the process performing the operation is a ransomware process and processes it according to the preset monitoring strategy. For example, record the operation log, issue an alert to notify the administrator, terminate the suspicious process, or isolate the infected file. That is, as a feasible implementation method, processing the ransomware process according to the preset monitoring strategy includes: ending the ransomware process and / or reporting the ransomware process according to the preset monitoring strategy.

[0077] For example, in the / home directory, the system detects that a process attempts to encrypt a.txt decoy file. The system immediately identifies the process as a ransomware process and terminates the process according to the preset policy. At the same time, a detailed operation log is recorded and the system administrator is notified. In this way, the system can detect and prevent the ransomware from further damaging other files in the system at the initial stage of the ransomware behavior.

[0078] This step realizes the rapid response and precise handling of ransomware behavior, can detect and prevent its behavior in time before the ransomware encrypts real files, and minimizes data loss to the greatest extent. At the same time, by recording operation logs and notifying the administrator, it provides an important basis for subsequent security analysis and system recovery.

[0079] The ransomware detection method provided by the embodiments of the present invention dynamically obtains the file type distribution information of the target file directory, and precisely sprays the decoy files into the target directory according to the file type distribution information, so that the types and distribution ratios of the decoy files are highly consistent with the real file environment of the user system. This design not only effectively improves the concealment of the decoy files, avoids the ransomware from identifying and avoiding the decoy files, but also significantly enhances the accuracy and reliability of ransomware detection. At the same time, by real-time monitoring the operation behavior of the decoy files and quickly identifying the ransomware process, and performing targeted processing in combination with the preset monitoring strategy, the embodiments of the present invention can timely prevent the destructive behavior of the ransomware and protect the security of the user system and data.

[0080] The embodiments of the present invention disclose a method for updating decoy files. Specifically:

[0081] See Figure 2 , a flowchart of a method for updating decoy files shown according to an exemplary embodiment, as Figure 2 shown, includes:

[0082] S201: When the update time of the decoy file arrives, determine whether the proportion of non-decoy files with attribute updates in the target file directory during the current update period to all non-decoy files in the target file directory is greater than a first preset value; if so, enter S202; if not, enter S203;

[0083] Among them, attribute update means that the metadata of the file (such as permissions, owners, access times, etc.) changes. The first preset value is a preset ratio threshold used to determine whether the frequency of file attribute updates is high enough to trigger the update of the decoy file attributes.

[0084] In this step, when the update time of the decoy file arrives, the system counts the number of non-decoy files with attribute changes in the target file directory during the current update period and calculates its proportion to all non-decoy files. If this proportion is greater than the first preset value, enter S202; otherwise enter S203.

[0085] This step dynamically determines whether to update the attributes of the decoy files by judging the proportion of file attribute updates. This not only reduces unnecessary operations, but also ensures that the attributes of the decoy files can be kept consistent with the real file environment in time, improving the concealment of the decoy files and the reliability of the detection system.

[0086] S202: Update the attributes of the decoy files in the target file directory according to the current attribute information of the non-decoy files in the target file directory, and proceed to S203;

[0087] The current attribute information refers to the metadata of the non-decoy files at the current moment, including permissions, owners, access times, etc.

[0088] In this step, obtain the current attribute information of the non-decoy files in the target file directory, and modify the attributes of the decoy files to be the same as those of the non-decoy files. After completion, proceed to S203.

[0089] S203: Determine whether the number of newly added non-decoy files in the current update period is greater than a second preset value; if so, proceed to S204;

[0090] The second preset value is a preset quantity threshold used to determine whether the number of newly added files is large enough to trigger an update of the file type distribution information.

[0091] In this step, count the number of newly added non-decoy files in the target file directory during the current update period. If the newly added quantity is greater than the second preset value, proceed to S204; otherwise, the process ends.

[0092] In this step, by judging the number of newly added files, it is dynamically determined whether it is necessary to update the file type distribution information. This ensures that the system can promptly adapt to changes in the file directory, maintain the dynamic consistency of the decoy file distribution, and improve the adaptability and reliability of the detection system.

[0093] S204: Update the file type distribution information of the target file directory;

[0094] In this step, rescan the target file directory, count the quantity and proportion of each file type, and update the file type distribution information. By dynamically updating the file type distribution information, the system can promptly reflect changes in the target file directory, provide an accurate basis for the subsequent generation and spraying of decoy files, and ensure that the types and distributions of decoy files are consistent with the real file environment.

[0095] S205: Obtain decoy files, and spray the decoy files into the target file directory based on the file type distribution information;

[0096] In this step, according to the updated file type distribution information, the system obtains or generates decoy files of corresponding types and places these decoy files into the target file directory.

[0097] S206: Modify the attributes of the decoy files sprayed into the target file directory according to the attribute information of the non-decoy files in the target file directory.

[0098] In this step, obtain the current attribute information of non-bait files in the target file directory, and modify the attributes of the sprayed bait files to be the same as those of the non-bait files. By dynamically updating the attributes of the bait files to make them consistent with the attributes of real files, further confuse the ransomware, reduce the possibility of it identifying the bait files, and improve the concealment and effectiveness of the detection system.

[0099] It can be seen that this embodiment provides a mechanism for dynamically updating bait files to improve the adaptability and effectiveness of the ransomware detection system. By periodically checking the attribute changes and newly added files in the target file directory, dynamically adjust the attributes and distribution of the bait files to ensure that the bait files are highly consistent with the real file environment. This mechanism can not only effectively confuse the ransomware, but also adapt to the dynamic changes of system files, improving the reliability and concealment of the detection system.

[0100] Based on the above embodiment, introduce a machine learning model to analyze the file behavior patterns and attribute changes in the target file directory, so as to implement a more intelligent bait file update strategy and ransomware behavior prediction. Specifically, it includes the following steps: Collect the attribute information and file operation behaviors of files in the target file directory, and use these data as features to input into the machine learning model. Train the machine learning model with historical data so that it can identify the differences between normal file behavior patterns and ransomware behavior patterns. The model can be based on supervised learning (such as classification algorithms) or unsupervised learning (such as anomaly detection algorithms). Use the machine learning model to predict the change trend of file attributes in the target file directory. According to the prediction results, adjust the attributes and distribution of the bait files in advance to make them more in line with the dynamic changes of real files in the system. When an operation on a bait file is detected, use the machine learning model to analyze the characteristics of the operation behavior and predict whether the behavior is a ransomware behavior. If the model predicts a high-risk behavior, immediately take corresponding handling measures. Feed back the detected ransomware behaviors and false alarm situations into the model to continuously optimize the accuracy and reliability of the model.

[0101] It can be seen that the machine learning model can predict the change trend of file attributes, adjust the attributes and distribution of the bait files in advance, so that it always maintains a high degree of consistency with the real file environment, further reducing the possibility of the ransomware identifying the bait files. Using the machine learning model to analyze and predict operation behaviors can more accurately identify ransomware behaviors, reduce the false alarm rate, and improve the reliability of the detection system. By predicting ransomware behaviors, the system can detect and prevent the further destruction of other files in the system by the ransomware at the initial stage of the ransomware behavior, achieving active defense and minimizing data loss to the greatest extent. By feeding back the detection results into the model, the system can continuously optimize the performance of the model, adapt to the changing ransomware attack methods and system environment, and ensure the long-term effectiveness of the detection system.

[0102] The following introduces an application embodiment provided by the present invention. The framework diagram of the ransomware intrusion detection system is as Figure 3 shown. The ransomware detection and control module is in the user state and runs in a trusted execution environment. The code and data within the module are protected by the trusted execution environment, which can effectively resist attacks from malicious adversaries on the ransomware monitoring module. The decoy file remote server exists independently of the user business system. By invoking the decoy file generation function, a large number of various types of decoy files are dynamically and real-time generated and stored in the decoy file remote library. The ransomware monitoring module runs in the kernel state and performs real-time detection of ransomware.

[0103] Among them, the ransomware monitoring module mainly includes a local decoy file library, a process whitelist function, a decoy file acquisition function, a decoy file spraying function, a log management function, a decoy file verification function, a system file analysis function, and a decoy file update function.

[0104] Local decoy file library: Stores decoy files and is located on the user's Linux system. There are two cases for decoy files, namely those pre-set when installing the ransomware intrusion detection system, those obtained from the decoy file remote server, and those saved in the local decoy file library during local decoy file updates.

[0105] Process whitelist function: Sets the user processes of specific users in the user system to be in the whitelist. Multiple specific users can be set, and these whitelisted processes will not trigger an alarm even if they operate on decoy files. For example, in order to achieve periodic updates of decoy files, processes such as cat, vi, chmod, chown, and chgrp need to be saved in the process whitelist.

[0106] Decoy file acquisition function: When the ransomware intrusion detection system is initialized, it needs to acquire a specified type and quantity of decoy files. There are two ways to acquire decoy files: The first is to directly obtain them from the local decoy file library, but the decoy files stored in the local decoy file library are all pre-set and cannot be updated in real time. The second is to perform real-time updates from the decoy file remote server. The decoy file remote server dynamically and real-time generates a large number of various types of decoy files by invoking the decoy file generation function and stores them in the decoy file remote library.

[0107] Decoy file spraying function: Sprays decoy files in the file monitoring directory, and at the same time, it is necessary to take into account the file type distribution ratio of different decoy file directories. The file type distribution includes two types of distribution data. The first is the distribution ratio of file types in the overall file monitoring directory, and the second is the file type distribution ratio under different file monitoring directories.

[0108] Log management function: Manage the alarm logs of ransomware reported in the kernel state, and perform corresponding display and storage operations.

[0109] Bait file verification function: The bait files generated by the bait file remote server may be tampered with by a third party when sent to the user system. Therefore, the bait file verification function uses the certificate of the bait file remote server to perform signature verification operations on all bait files from the bait file remote server to prove the legitimacy and integrity of the bait files.

[0110] System file analysis function: Different user systems have different file types due to different deployed business systems. When ransomware knows that there is a detection system based on bait files in the user business system, it may identify the bait files and then only encrypt the files of the user business system without encrypting the bait files, thus bypassing the detection system. To prevent ransomware from being able to identify bait files, it is necessary to ensure that the bait files can conform to the distribution ratio of the file types in the monitored directory. Use the system file analysis function to analyze the file type distribution of the user system. The file type distribution includes two types of distribution data. The first is the distribution ratio of the file types in the overall file monitored directory, and the second is the file type distribution ratio under different file monitored directories. The first type of data is used to determine the type and quantity of bait files to be obtained, which belongs to the macroscopic distribution of bait files; the second type of data is used to determine how the obtained bait files are sprayed into different file monitored directories according to the corresponding ratio, which belongs to the fine-grained control of bait spraying.

[0111] Bait file update function: As the user system runs, the permissions, file owners, user groups the files belong to, the most recent access time, the most recent change time, and the most recent modification time of the files in the file monitoring directory will also change. At the same time, many new normal files will be generated in the system. To make the bait files and normal files have the same distribution pattern in terms of attributes, it is necessary to perform update operations on the bait files. The bait file update function in the user state realizes the periodic update of the bait files. Specific users in the system update the permissions, file owners, user groups the files belong to, the most recent access time, the most recent change time, and the most recent modification time of the existing bait files in the system. Before the system initialization, the processes of specific users of cat, vi, chmod, chown, and chgrp need to be added to the process whitelist function. The most recent access time is updated through the cat command, the most recent change time and the most recent modification time are updated through vi, and at the same time, the partial content values of the bait files are updated. The permissions, file owners, and user groups the files belong to of the bait files are updated through chmod, chown, and chgrp, and the updated bait files are saved in the local bait file library. In the case of newly added normal files in the system, at this time, the bait files no longer conform to the file type distribution of the file monitoring directory, and the bait files need to be updated. The corresponding bait files are obtained by using the bait file acquisition function, and the distribution ratio of the bait files conforms to the distribution ratio of the file types in the overall file monitoring directory. The bait files can be obtained from the local bait file library or from the remote bait file server. At the same time, bait file spraying is performed, and the bait files that do not conform to the system state are deleted. The bait file update policy is sent to the monitoring policy function in the kernel state, and the latest bait detection policy is enabled.

[0112] The remote bait file server provides functions such as bait file generation, remote bait file library, bait file distribution, and remote proof verification for the user's ransomware detection system.

[0113] Bait file generation function: It can periodically generate new bait files of various types and then store them in the remote bait file library. The bait file generation function can read and write the existing bait files in the remote bait file library, so as to ensure that the bait files have been dynamically and real-time operated on, rather than zombie files. At the same time, the remote bait file server has a legal certificate for signing the bait files.

[0114] Remote bait file library: It is used to store the bait files generated by the bait file generation function. The remote bait file library contains a large number of real-time bait files, which can meet the needs of various user systems.

[0115] Bait file distribution function: It is used to process the bait file acquisition requests sent by users, and thus distribute corresponding bait files according to users' requirements. At the same time, it can also call the remote attestation verification function to verify that the ransomware detection and control module of the user runs in a trusted execution environment, and then establish a secure communication channel to ensure the security of bait file distribution.

[0116] Remote attestation verification function: It can verify that the ransomware detection and control module of the user runs in a trusted execution environment. The remote attestation verification function first sends remote attestation challenge information to the ransomware detection and control module. Then the ransomware detection and control module obtains the measurement value of the trusted execution environment based on the challenge value, and signs it based on the hardware private key produced by the trusted execution environment to produce a remote attestation report. The ransomware detection and control module sends the remote attestation report to the remote attestation verification function of the bait file remote server to verify the signature of the remote attestation report of the ransomware detection and control module, and compare whether the reference value in it is consistent with the pre-stored reference value. If all verifications pass, the ransomware detection and control module runs in a trusted execution environment. Then key negotiation can be carried out based on the remote attestation report to establish a secure communication channel.

[0117] The ransomware monitoring module includes modules such as the ePBF (Extended Berkeley Packet Filter) ransomware monitoring function, the monitoring policy function, and the log reporting function.

[0118] ePBF ransomware monitoring function: Based on the ePBF function, it realizes hooking (hooking) of corresponding file operation functions in the LSM (Linux Security Module), and scans for ransomware in real time according to the monitoring policy function. When a virus is detected, corresponding processing is carried out according to the settings of the policy file, including log reporting, process warning, process killing and other operations.

[0119] Monitoring policy function: It stores the process whitelist of specific users set in the user state, as well as the corresponding bait file paths. It provides a policy basis for the ePBF ransomware monitoring function.

[0120] Log reporting function: When the ePBF ransomware monitoring function detects an intrusion behavior of ransomware, it performs a log reporting operation to the user.

[0121] The bait file spraying process is as Figure 4As shown, the file monitoring directory of the ransomware detection and control module is determined using the system file analysis function. The decoy directory is determined based on the file monitoring directory. Furthermore, the file type distribution of the user system is analyzed according to the file monitoring directory. The corresponding decoy files are obtained using the decoy file acquisition function, and the distribution ratio of the decoy files conforms to the distribution ratio of the file types in the overall file monitoring directory, making it impossible for ransomware to distinguish between normal files and decoy files. There are two ways to obtain decoy files: the first is to directly obtain them from the local decoy file library, and the second is to perform real-time updates from the remote decoy file server. Users can freely choose between the two methods. When the second method is selected, the remote attestation verification function of the decoy file remote server verifies that the ransomware detection and control module of the user runs in a trusted execution environment. The remote attestation verification function issues a remote attestation challenge to the user, which contains a random number. Then the ransomware detection and control module obtains the measurement value of the trusted execution environment based on the challenge value, and signs it based on the hardware private key generated by the trusted execution environment to generate a remote attestation report. The ransomware detection and control module sends the remote attestation report to the remote attestation verification function of the decoy file remote server to verify the signature of the remote attestation information of the ransomware detection and control module, and compares whether the reference value in it is the same as the pre-stored reference value. If all verifications pass, the ransomware detection and control module runs in a trusted execution environment. Then the ransomware detection and control module and the decoy file remote server can perform key negotiation based on the remote attestation information, establish a secure communication channel, and request decoy files that conform to the file type distribution ratio from the decoy file remote server. The decoy file distribution function obtains the latest decoy files from the decoy file remote library according to the request and sends them to the ransomware detection and control module. The signature public key of the decoy file remote server is pre-stored in the ransomware detection and control module, and the decoy file verification function uses the public key to verify the signature of the obtained decoy files to confirm the legitimacy of the decoy files. The decoy files are saved to the local decoy file library. The decoy file spraying function first determines the decoy file type and quantity according to the distribution ratio of the file types in the overall file monitoring directory, which is the macroscopic quantity of decoy files. Then, according to the file type distribution ratio under different file monitoring directories, the decoy files are placed in the decoy directory according to the corresponding file type ratio. According to the attributes of other normal files in the directory where the decoy files are located, the permissions, file owners, and file user groups of the decoy files for specific users are set to make the attribute information of the decoy files more similar to that of normal files. The distribution situation of the decoy files is sent to the mapping space of ePBF in the detection policy function in the kernel state and saved in the ePBFmap format.

[0122] The white list determination process is as Figure 5As shown in the figure, a specific user can set which user processes of specific users belong to the process whitelist through the process whitelist function. Even if the processes of specific users in these whitelists operate on the decoy files, no alarm will be triggered. For example, in order to achieve periodic updates of the decoy files, processes such as cat, vi, chmod, chown, and chgrp need to be saved in the process whitelist. The process whitelist is sent to the mapping space of ePBF in the monitoring policy function in the kernel state and saved in the ePBF map format.

[0123] The ePBF ransomware monitoring function process is as Figure 6 shown in the figure. Start the ePBF ransomware monitoring function: Mount process monitoring events at the mount points of LSM through ePBF technology. The mount points include lsm / file_open, lsm / inode_unlink, and lsm / inode_rename, which are used to track the file editing, deletion, and renaming operations of the system. The ePBF ransomware monitoring function obtains all events at the mount points and queries them in the monitoring policy. If the object of the current operation queried is the decoy file in the monitoring policy, it makes a whitelist function judgment on it. If it is not a whitelist process, this process is considered a ransomware, and the log is reported. The log reporting function in the kernel state reports the intrusion detection event to the log management function in the user state, and the user state displays and stores the intrusion detection log. Decide whether to kill the ransomware process according to the matching monitoring policy.

[0124] The decoy file update process is as Figure 7As shown, to determine whether the update time of the decoy file update function in user mode has been reached, the update time can be set to once a day or once every few hours. If the periodic update time is reached, the decoy file update function determines whether there is an attribute update operation for normal files. If there is an update operation, it further determines whether the attribute update operation exceeds the threshold. If the update operation exceeds the threshold, the attribute distribution rule of the updated file is obtained, and the attribute information of the decoy file is changed according to the attribute distribution rule of the updated file. The updated decoy file is saved in the local decoy file library. It is determined whether there are new normal files. If there are, it further determines whether the new normal files exceed the threshold. When the new normal files exceed the threshold, it indicates that the current decoy file no longer conforms to the distribution ratio of the file types in the overall file monitoring directory, and the decoy file needs to be updated. The system file analysis function is used to determine the file type distribution of the file monitoring directory. According to the file type distribution ratio, the corresponding decoy file is obtained by using the decoy file acquisition function, and the distribution ratio of the decoy file conforms to the distribution ratio of different file types in the system. There are also two acquisition methods for decoy files, which will not be elaborated here. The decoy file spraying function distributes the decoy files to the decoy directory according to the file type distribution ratio under different file monitoring directories, and deletes the decoy files that do not conform to the system state. According to the attributes of other normal files in the directory where the decoy file is located, the permissions, file owners, and file user groups of specific users for the decoy file are set to make the attribute information of the decoy file more similar to that of normal files. The update policy of the decoy file (the decoy files currently existing in the target file directory) is sent to the detection policy function in the kernel state, and the latest decoy detection policy is enabled.

[0125] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.

[0126] Next, a ransomware detection device provided by an embodiment of the present invention will be introduced. The ransomware detection device described below can be referred to each other with the ransomware detection method described above.

[0127] See Figure 8 , a structural diagram of a ransomware detection device shown according to an exemplary embodiment, as Figure 8 shown, includes:

[0128] The first acquisition module 100 is used to determine the target file directory to be monitored and obtain the file type distribution information of the target file directory; wherein, the file type distribution information includes the types of files included in the target file directory and the distribution ratio of each type of file;

[0129] The spraying module 200 is configured to obtain decoy files and spray the decoy files into the target file directory based on the file type distribution information.

[0130] The processing module 300 is configured to, when an operation on a decoy file is detected, determine that the process performing the operation is a ransomware process, and process the ransomware process according to a preset monitoring policy.

[0131] The ransomware detection device provided by the embodiment of the present invention dynamically obtains the file type distribution information of the target file directory, and accurately sprays the decoy files into the target directory according to the file type distribution information, so that the types and distribution ratios of the decoy files are highly consistent with the real file environment of the user system. This design not only effectively improves the concealment of the decoy files, avoids the ransomware from identifying and avoiding the decoy files, but also significantly enhances the accuracy and reliability of ransomware detection. At the same time, by real-time monitoring the operation behavior of the decoy files and quickly identifying the ransomware process, and performing targeted processing in combination with the preset monitoring policy, the embodiment of the present invention can timely prevent the destructive behavior of the ransomware and protect the security of the user system and data.

[0132] Based on the above embodiment, as a preferred embodiment, it further includes:

[0133] The second obtaining module is configured to obtain the overall file type distribution information; wherein, the overall file type distribution information includes the total number of files contained in all target file directories, file types, and the overall distribution ratios of files of each type.

[0134] Correspondingly, the spraying module 200 is specifically configured to: obtain a target number of decoy files based on the overall file type distribution information; wherein, the target number is the product of the total number and a preset ratio, and the distribution ratios of files of each type in the obtained target number of decoy files conform to the overall distribution ratio; spray the decoy files into each target file directory based on the file type distribution information of each target file directory.

[0135] Based on the above embodiment, as a preferred embodiment, the spraying module 200 includes:

[0136] The first obtaining unit is configured to obtain decoy files from the local decoy file library.

[0137] Based on the above embodiment, as a preferred embodiment, the spraying module 200 includes:

[0138] The first sending unit is configured to send a request for obtaining decoy files from the ransomware detection module to the remote server.

[0139] A generation unit, configured to receive a remote attestation challenge sent by a remote server and generate remote attestation information based on the remote attestation challenge;

[0140] A second sending unit, configured to send the remote attestation information to the remote server so that the remote server can verify that the ransomware detection module runs in a trusted execution environment;

[0141] A second obtaining unit, configured to establish a secure channel with the remote server and obtain a decoy file from the remote server through the secure channel.

[0142] Based on the above embodiments, as a preferred embodiment, the generation unit is specifically configured to: receive a remote attestation challenge sent by a remote server; wherein the remote attestation challenge includes a random number; obtain a measurement value of the trusted execution environment based on the random number, sign the measurement value using a private key generated by the trusted execution environment, and generate remote attestation information based on the signed measurement value;

[0143] Correspondingly, the remote server verifies the signature of the measurement value in the remote attestation information and compares whether the measurement value in the remote attestation information is consistent with a pre-stored reference value. If the signature verification passes and the measurement value is consistent with the reference value, it means that the ransomware detection module runs in a trusted execution environment.

[0144] Based on the above embodiments, as a preferred embodiment, the spraying module 200 further includes:

[0145] A negotiation unit, configured to negotiate a key with the remote server based on the remote attestation information;

[0146] A verification unit, configured to verify the signature of the obtained decoy file using a public key generated by the remote server to verify the legality of the decoy file.

[0147] Based on the above embodiments, as a preferred embodiment, it further includes:

[0148] A modification module, configured to modify the attributes of the decoy files sprayed to the target file directory according to the attribute information of the non-decoy files in the target file directory.

[0149] Based on the above embodiments, as a preferred embodiment, it further includes:

[0150] A judgment module, configured to judge whether the process performing the operation is a whitelist process; wherein the whitelist process includes a process for modifying file attributes; if not, it is determined that the process performing the operation is a ransomware process.

[0151] Based on the above embodiments, as a preferred embodiment, it further includes:

[0152] A first update module, configured to, when the update time of the decoy file arrives, determine whether the ratio of the non-decoy files with attribute updates in the target file directory during the current update period to all non-decoy files in the target file directory is greater than a first preset value; if so, update the attributes of the decoy files in the target file directory according to the current attribute information of the non-decoy files in the target file directory.

[0153] Based on the above embodiments, as a preferred embodiment, it further includes:

[0154] A second update module, configured to, when the update time of the decoy file arrives, determine whether the number of newly added non-decoy files during the current update period is greater than a second preset value; if so, update the file type distribution information of the target file directory and restart the workflow of the spraying module 200.

[0155] Based on the above embodiments, as a preferred embodiment, it further includes:

[0156] A monitoring module, configured to mount a process monitoring event at the mount point, so as to monitor the operations of the process on the files in the target file directory through the process monitoring event.

[0157] Based on the above embodiments, as a preferred embodiment, the processing module 300 is specifically configured to: end the ransomware process and / or report the ransomware process according to a preset monitoring strategy.

[0158] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated here.

[0159] An embodiment of the present invention further provides an electronic device, Figure 9 which is a structural diagram of an electronic device shown according to an exemplary embodiment, as Figure 9 shown, the electronic device includes:

[0160] A communication interface 1, capable of interacting with other devices such as network devices for information.

[0161] A processor 2, connected to the communication interface 1 to achieve information interaction with other devices, and is used to execute the ransomware detection method provided by the above one or more technical solutions when running a computer program. The computer program is stored on the memory 3.

[0162] Of course, in actual application, the various components in the electronic device are coupled together through a bus system 4. It can be understood that the bus system 4 is used to realize the connection and communication between these components. The bus system 4 includes not only a data bus, but also a power bus, a control bus, and a status signal bus. However, for the sake of clear illustration, in Figure 9All kinds of buses are labeled as bus system 4.

[0163] The memory 3 in the embodiments of the present invention is used to store various types of data to support the operation of the electronic device. Examples of such data include: any computer program for operating on the electronic device.

[0164] It can be understood that the memory 3 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM, Read Only Memory), a programmable read-only memory (PROM, Programmable Read-Only Memory), an erasable programmable read-only memory (EPROM, Erasable Programmable Read-Only Memory), an electrically erasable programmable read-only memory (EEPROM, Electrically Erasable Programmable Read-Only Memory), a ferromagnetic random access memory (FRAM, ferromagnetic random access memory), a flash memory (Flash Memory), a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM, Compact Disc Read-Only Memory); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM, Random Access Memory), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as a static random access memory (SRAM, Static Random Access Memory), a synchronous static random access memory (SSRAM, Synchronous Static Random Access Memory), a dynamic random access memory (DRAM, Dynamic Random Access Memory), a synchronous dynamic random access memory (SDRAM, Synchronous Dynamic Random Access Memory), a double data rate synchronous dynamic random access memory (DDR SDRAM, Double Data Rate Synchronous Dynamic Random Access Memory), an enhanced synchronous dynamic random access memory (ESDRAM, Enhanced Synchronous Dynamic Random Access Memory), a sync link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and a direct rambus random access memory (DRRAM, Direct Rambus Random Access Memory).The memory 3 described in the embodiments of the present invention is intended to include but not limited to these and any other suitable types of memories.

[0165] The method disclosed in the above embodiments of the present invention can be applied to or implemented by the processor 2. The processor 2 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor 2 or the instructions in the form of software. The above processor 2 may be a general-purpose processor, DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 2 can implement or execute each method, step, and logic block diagram disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or any conventional processor, etc. Combining the steps of the method disclosed in the embodiments of the present invention, it can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by the combination of the hardware and software modules in the decoding processor. The software module may be located in the storage medium, which is located in the memory 3. The processor 2 reads the program in the memory 3 and combines its hardware to complete the steps of the foregoing method.

[0166] When the processor 2 executes the program, it implements the corresponding processes in each method of the embodiments of the present invention. For the sake of brevity, it will not be elaborated here.

[0167] The embodiments of the present invention also provide a computer-readable storage medium, in which a computer program is stored. Wherein, the computer program is configured to execute the steps in any of the embodiments of the above ransomware detection methods when running.

[0168] In an exemplary embodiment, the above computer-readable storage medium may include but not limited to: USB flash drive, read-only memory (ROM for short), random access memory (RAM for short), mobile hard disk, magnetic disk, or optical disc, etc., various media that can store computer programs.

[0169] The embodiments of the present invention also provide a computer program product. The above computer program product includes a computer program, and when the computer program is executed by the processor 2, it implements the steps in any of the embodiments of the above ransomware detection methods.

[0170] The embodiments of the present invention also provide another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by the processor 2, it implements the steps in any of the embodiments of the above ransomware detection methods.

[0171] Those skilled in the art may further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0172] The above has introduced in detail a ransomware detection method, device, storage medium, and computer program product provided by the present invention. Specific examples are used herein to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the present invention.

Claims

1. A ransomware detection method, characterized in that, Including: Determine the target file directory to be monitored, and obtain the file type distribution information of the target file directory; wherein, the file type distribution information includes the types of files contained in the target file directory and the distribution ratio of each type of file; Obtain decoy files, and spray the decoy files into the target file directory based on the file type distribution information; If an operation on the decoy file is detected, determine the process that executes the operation as a ransomware process, and process the ransomware process according to a preset monitoring strategy; Wherein, after determining the target file directory to be monitored, it further includes: Obtain the overall file type distribution information; wherein, the overall file type distribution information includes the total number of files, file types, and the overall distribution ratio of each type of file contained in all the target file directories; Correspondingly, the step of obtaining decoy files and spraying the decoy files into the target file directory based on the file type distribution information includes: Obtain a target number of decoy files based on the overall file type distribution information; wherein, the target number is the product of the total number and a preset ratio, and the distribution ratio of each type of file in the obtained target number of decoy files conforms to the overall distribution ratio; Spray decoy files into each target file directory based on the file type distribution information of each target file directory.

2. The ransomware detection method according to claim 1, wherein The step of obtaining decoy files includes: Obtain decoy files from the local decoy file library.

3. The ransomware detection method according to claim 1, wherein The step of obtaining decoy files includes: The ransomware detection module sends a request for obtaining decoy files to the remote server; Receive the remote attestation challenge sent by the remote server, and generate remote attestation information based on the remote attestation challenge; Send the remote attestation information to the remote server so that the remote server can verify that the ransomware detection module runs in a trusted execution environment; Establish a secure channel with the remote server, and obtain decoy files from the remote server through the secure channel.

4. The ransomware detection method according to claim 3, wherein, The step of receiving the remote attestation challenge sent by the remote server and generating remote attestation information based on the remote attestation challenge includes: Receive the remote attestation challenge sent by the remote server; wherein, the remote attestation challenge includes a random number; Obtain the measurement value of the trusted execution environment based on the random number, sign the measurement value using the private key generated by the trusted execution environment, and generate remote attestation information based on the signed measurement value; Correspondingly, the remote server verifies the signature of the measurement value in the remote attestation information, and compares the measurement value in the remote attestation information with a pre-stored reference value. If the signature verification is passed and the measurement value is consistent with the reference value, the ransomware detection module runs in a trusted execution environment.

5. The ransomware detection method according to claim 3, wherein, After the remote server verifies that the ransomware detection module runs in a trusted execution environment, it further includes: Negotiate a key with the remote server based on the remote attestation information; Correspondingly, after obtaining decoy files from the remote server through the secure channel, it further includes: Verify the signature of the decoy file obtained based on the public key pair generated by the remote server to verify the legitimacy of the decoy file.

6. The ransomware detection method according to claim 1, wherein After spraying the decoy file to the target file directory, it further includes: Modify the attributes of the decoy file sprayed to the target file directory according to the attribute information of the non-decoy files in the target file directory.

7. The ransomware detection method according to claim 6, wherein After detecting an operation on the decoy file, it further includes: Determine whether the process executing the operation is a whitelist process; wherein, the whitelist process includes a process for modifying file attributes; If not, then enter the step of determining that the process executing the operation is a ransomware process.

8. The ransomware detection method according to claim 6, wherein After modifying the attributes of the decoy file sprayed to the target file directory according to the attribute information of the non-decoy files in the target file directory, it further includes: When the update time of the decoy file arrives, determine whether the proportion of non-decoy files with attribute updates in the target file directory during the current update period to all non-decoy files in the target file directory is greater than a first preset value; If so, update the attributes of the decoy files in the target file directory according to the current attribute information of the non-decoy files in the target file directory.

9. The ransomware detection method according to claim 1, wherein After spraying the decoy file to the target file directory based on the file type distribution information, it further includes: When the update time of the decoy file arrives, determine whether the number of newly added non-decoy files during the current update period is greater than a second preset value; If so, update the file type distribution information of the target file directory and re-enter the step of obtaining the decoy file and spraying the decoy file to the target file directory based on the file type distribution information.

10. The ransomware detection method according to claim 1, wherein, After spraying the decoy file to the target file directory based on the file type distribution information, it further includes: Mount a process monitoring event at the mount point to monitor the operations of processes on the files in the target file directory through the process monitoring event.

11. The ransomware detection method according to claim 1, wherein Processing the ransomware process according to a preset monitoring strategy includes: End the ransomware process and / or report the ransomware process according to a preset monitoring strategy.

12. An electronic device, characterized in that, It includes: A memory for storing a computer program; A processor for implementing the steps executed by the ransomware detection method according to any one of claims 1 to 11 when executing the computer program.

13. A computer-readable storage medium, characterized in that, A computer program is stored on a computer-readable storage medium, and when the computer program is executed, it implements the steps executed by the ransomware detection method according to any one of claims 1 to 11.

14. A computer program product, characterized in that, It includes a computer program, and when the computer program is executed, it implements the steps executed by the ransomware detection method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Ransomware early detection method and system based on a bait file

    CN113626811A

  • Bait file putting method, device and equipment

    CN117633792A