Method for countering encrypted ransomware attacks, solid-state drive, electronic device, and storage medium

By introducing a special flash conversion layer VAT and real-time clock chip RTC in SSD, combined with the conventional flash conversion layer FTL, the problem of early precise detection of encryption ransomware attacks in SSD is solved, and automatic detection and alarming of encryption ransomware attacks is achieved, achieving the ultimate data protection effect.

CN119918052BActive Publication Date: 2025-07-01CHENGDU XINGCHEN DIGITAL INNOVATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510396727.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-01
Publication Date
2025-07-01
Estimated Expiration
2045-04-01

AI Technical Summary

Technical Problem

The prior art is difficult to accurately detect encryption ransomware attacks in solid state drives (SSDs), and file activity detection based on the operating system kernel is difficult to resist encryption ransomware attacks with administrator privileges.

Method used

Adding a special flash conversion layer VAT in SSD, combining conventional flash conversion layer FTL and real-time clock chip RTC to realize identification and defense of encryption ransomware attacks. VAT is used to manage the mapping relationship between the logical address and the physical address to be recycled, and RTC is used to generate the time stamp of the physical address and generate an exception point-of-time queue in response to write, read and rollback commands from the host.

Benefits of technology

Automatic detection and alarming of encryption ransomware attacks is realized, which can prevent the corruption of encryption ransomware in advance, and prevent other computer viruses from being infected and privileged people from illegally tampering with data, achieving the ultimate data protection effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119918052B_ABST
    Figure CN119918052B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for countering encrypted ransom attacks, a solid-state drive, an electronic device, and a storage medium, which relate to the technical fields of data storage and data security, and include: adding a special flash translation layer for managing the mapping relationship between logical addresses and physical addresses to be recycled in the SSD, and continuing to use a conventional flash translation layer for managing the mapping relationship between logical addresses and physical addresses; equipping the SSD with a real-time clock chip to generate an RTC timestamp of the physical address, and responding to operation commands from the host based on the special flash translation layer, the conventional flash translation layer, and the real-time clock; providing a set of countermeasures and implementation technical solutions on the SSD hardware to support the production of highly secure SSD devices, which can identify and defend against all encrypted ransom attacks in advance; at the same time, it can also prevent other computer viruses from infecting and prevent internal privileged users from illegally tampering with programs, approaching the ultimate protection of the security of the data and executable programs stored in the SSD.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of data storage and data security, and more specifically, to a method for combating encrypted ransom attacks, a solid-state drive, an electronic device, and a storage medium. Background Art

[0002] An encrypted ransom attack, also known as an encrypted ransom virus, is a special type of malware. The encrypted ransomware uses various encryption algorithms to encrypt user files and demands that the victim pay a ransom to obtain the decryption key. This cryptography-based attack is extremely harmful, and there have been many malignant cases worldwide, causing huge economic losses and even social order chaos.

[0003] Currently, for the defense against encrypted ransom attacks, most are based on dynamic detection techniques for file activities. However, this dynamic behavior detection technique has a lag, resulting in some files being encrypted before being identified. Moreover, file activity detection based on the operating system kernel is difficult to resist encrypted ransom attacks with administrator privileges.

[0004] Utilizing the hardware characteristics of a solid-state drive (SSD) to achieve hardware-level defense has gradually attracted the attention of researchers. The SSD naturally has a "page replacement and update" mechanism. The encrypted data generated by an encrypted ransom attack is written into a new free physical page, while the original data remains intact as a "invalid" physical page to be recycled in the short term. This makes it possible to recover the original data. However, how to accurately detect encrypted ransom attack behaviors early under the limited computing power conditions in the SSD has become an extremely severe challenge.

[0005] Currently, under the existing computer technology conditions, it is very difficult and costly to manufacture a comprehensive and general-purpose data storage device and storage system for defending against encrypted ransom attacks. However, in application fields such as trusted data resources and data assets, the common characteristic of their data is that once the data is generated, it is permanently unchangeable (such as the monthly financial reports of enterprises, transaction vouchers, government affairs personnel files). In particular, most of this type of data is related to economic activities. Once damaged by an encrypted ransom virus, it directly causes the enterprise operation to come to a standstill. In view of the actual needs of such data security storage, there is an urgent need for a dedicated storage device that can combat encrypted ransom attacks, detect and prevent illegal data rewriting in advance. Summary of the Invention

[0006] The purpose of the present invention is to provide a method for combating encrypted ransom attacks and a solid-state drive (SSD) for specific purposes. In view of the basic nature of the static data in the fields of trusted data resources and data assets and the characteristics of encrypted ransom attacks, a complete set of countermeasures and implementation technical solutions are provided on the SSD hardware to support the production of a highly secure SSD device that can effectively identify and defend against various encrypted ransom attacks and protect data security.

[0007] The above object of the present invention is achieved by the following technical solutions:

[0008] In a first aspect, the present application provides a method for countering encrypted ransom attacks, including the following specific steps:

[0009] Add a special flash translation layer VAT in the SSD for managing the mapping relationship between logical addresses and physical addresses to be recycled;

[0010] Continue to use the conventional flash translation layer FTL in the SSD for managing the mapping relationship between logical addresses and physical addresses;

[0011] Equip the SSD with a real-time clock chip RTC for generating the RTC timestamp of the physical address and generating an exception time point queue TQ;

[0012] Based on the special flash translation layer VAT, the conventional flash translation layer FTL, and the real-time clock RTC, respond to operation commands from the host, where the operation commands include write commands, read commands, and rollback commands.

[0013] On the basis of the above technical solutions, the present invention can also be improved as follows.

[0014] Further, the above-mentioned special flash translation layer VAT includes a VAT bitmap and a VAT mapping table. The VAT bitmap is used to record the working status of each logical address, and the VAT mapping table is used to record the physical address to be recycled corresponding to each logical address. When the physical address to be recycled does not exist, it is also used to record the RTC timestamp of the physical address corresponding to the logical address in the conventional flash translation layer FTL.

[0015] Further, the above response to the write command from the host is specifically as follows:

[0016] Obtain the working status of the peer logical address in the VAT bitmap according to the logical address of the write command. If the working status is the occupied state, calculate and save the attack rate AR of the encrypted ransom attack, then perform a null operation, and return write success to the host; the attack rate AR is the cumulative number of occurrences of the above-mentioned encrypted ransom attack within N seconds, N >= 1;

[0017] If the working status is the idle state, then use the conventional flash translation layer FTL to perform a conventional write operation, then record the RTC timestamp of this write operation in the entry of the peer logical address in the VAT mapping table, and at the same time update the working status of the peer logical address in the VAT bitmap to the occupied state, and return write success to the host.

[0018] Further, the above response to the read command from the host is specifically as follows:

[0019] Obtain the working status of the VAT bitmap peer logical address according to the logical address of the read command. If the working status is the occupied state, perform a normal read operation using the conventional flash translation layer (FTL) and return a read success to the host.

[0020] If the working status is the idle state, the current RTC time exceeds the time point of the first item in the exception time point queue (TQ), and the exceeded time reaches more than one hour, then push the current RTC time into the exception time point queue (TQ); the exception time point queue (TQ) is a first-in-first-out queue.

[0021] If the working status is the idle state and the current attack rate (AR) value is greater than or equal to the threshold, generate an alarm signal, perform a normal read operation using the conventional flash translation layer (FTL) at the same time, and return a read success to the host.

[0022] Further, the above response to the rollback command from the host is specifically as follows:

[0023] Judge whether the time point is out of limit according to the specified time point of the rollback command or the time point in the exception time point queue (TQ). If the time point is out of limit, return a rollback failure to the host. Otherwise, obtain each entry within the time point range from the VAT mapping table and the conventional flash translation layer (FTL), swap the entry content of the VAT mapping table with the corresponding entry content in the conventional flash translation layer (FTL) one by one, and update the VAT bitmap according to the entry content in the conventional flash translation layer (FTL) after the swap: that is, if the entry content is the RTC timestamp, update the VAT bitmap to the idle state and update the PBA of the corresponding logical address in the FTL to "invalid", otherwise update the VAT bitmap to the occupied state and update the PBA of the corresponding logical address in the FTL to "valid", and return a rollback success to the host.

[0024] In a second aspect, the present application provides a solid-state drive, which uses the method for combating encrypted ransomware attacks in any one of the first aspects to achieve defense against encrypted ransomware viruses and protect the data in the solid-state drive from being rewritten by the viruses.

[0025] In a third aspect, the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it uses the method in any one of the first aspects to achieve defense against encrypted ransomware viruses and protect the data in the electronic device from being rewritten by the viruses.

[0026] In a fourth aspect, the present application provides a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium stores computer instructions. When the computer executes the instructions, it uses the method in any one of the first aspects to achieve defense against encrypted ransomware viruses and protect the data in the computer from being rewritten by the viruses.

[0027] Compared with the prior art, the present invention has at least the following beneficial effects:

[0028] In this application, the real-time clock chip equipped in the SSD is used to generate the RTC timestamp, and based on the special flash translation layer VAT and the conventional flash translation layer FTL, in response to write commands, read commands, and rollback commands from the host, it can automatically detect encrypted ransom attacks and give an alarm, can prevent all damages of encrypted ransom viruses in advance, and at the same time can also prevent other computer virus infections and unauthorized tampering of executable programs by privileged users, approaching extreme protection of the data and executable programs stored in the SSD. At the same time, this method can protect program codes, key parameters, and business rules from being arbitrarily changed by humans, so it supports unmanned trusted application systems; when this method is used to save data resources or data assets (such as account books, transaction contracts or vouchers, property rights certificates, etc.), it can meet the basic accounting code (that is, prohibit late modification and adding hedging records when correcting errors) and the permanent immutability of data, converting ordinary data into high-quality, high-value data that meets "judicial trust"; in particular, it can also strictly limit the data manipulation power of system privileged users and eliminate data security threats from internal users (such as preventing embezzlement, under-the-table operations, etc.). BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The drawings described herein are used to provide a further understanding of the embodiments of the present invention, form a part of this application, and do not constitute a limitation to the embodiments of the present invention. In the drawings:

[0030] Figure 1 is a schematic diagram of the special flash translation layer and the conventional flash translation layer in the embodiment of the present invention;

[0031] Figure 2 is a schematic diagram of the process of the write command in the embodiment of the present invention;

[0032] Figure 3 is a schematic diagram of the process of the read command in the embodiment of the present invention;

[0033] Figure 4 is a schematic diagram of the process of the rollback command in the embodiment of the present invention;

[0034] Figure 5 is a schematic diagram of the solid-state drive device in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0035] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. The components of the embodiments of the present invention usually described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.

[0036] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0037] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0038] In the description of the embodiments of the present invention, "a plurality of" represents at least two.

[0039] Embodiment 1: This embodiment provides a method for combating encrypted ransom attacks, including the following specific steps:

[0040] S1. Add a special flash translation layer VAT in the SSD for managing the mapping relationship between logical addresses and physical addresses to be recycled.

[0041] S11. Continue to use the conventional flash translation layer FTL in the SSD for managing the mapping relationship between logical addresses and physical addresses.

[0042] S12. Equip the SSD with a real-time clock chip RTC for generating the RTC timestamp of the physical address and generating the exception time point queue TQ.

[0043] Among them, the FTL (conventional flash translation layer) is the core metadata of a conventional SSD (solid-state drive). The main controller of the SSD depends on the FTL to manage its large number of NAND storage units. Usually, a conventional SSD only has one layer of FTL, which completes management tasks such as the translation and conversion of host logical addresses vs SSD physical addresses, PBA (physical address) page allocation, waste block recovery, bad block replacement, wear leveling, etc. However, in order to combat encrypted ransom attacks, new functions need to be added. In order to keep the conventional working tasks of the FTL basically unchanged and not increase its complexity, a dedicated layer of FTL called VAT (special flash translation layer) can be added. The VAT also works under the control of the SSD main control CPU, and its main task is to combat encrypted ransom attacks.

[0044] Optionally, the above-mentioned special flash translation layer VAT includes a VAT bitmap and a VAT mapping table. The VAT bitmap is used to record the working state of each logical address, and the VAT mapping table is used to record the physical address to be recycled corresponding to each logical address. When the physical address to be recycled does not exist, it is also used to record the RTC timestamp of the physical address corresponding to the logical address in the FTL.

[0045] Among them, the VAT mapping table is a mapping table with special functions. It is used to record the physical address to be recycled, which is generated by the "page update" feature naturally possessed by the SSD and temporarily stores the original data of the logical address. This is to utilize the "page update" feature of the SSD to achieve data "rollback" to eliminate the damage caused by viruses. When there is no physical address to be recycled, the VAT mapping table is used to record the RTC timestamp of the PBA corresponding to the logical address in the FTL; the VAT bitmap stores the working states of all logical addresses of the SSD, and its initial value is "idle". Once a logical address is used, it is immediately updated to "occupied". The VAT bitmap is inside the SSD and cannot be accessed by encrypted ransomware. There are two types of entry points for the virus to launch an attack: one is to directly attack the storage device through the host's underlying driver. At this time, since it cannot know the current working state of its target address, illogical read and write operations will inevitably occur; the other is to launch an attack through the host OS's file system, and at this time it will encounter a strong resistance described in the following.

[0046] S2. Based on the special flash translation layer VAT, the conventional flash translation layer FTL, and the real-time clock RTC, respond to the operation commands from the host. The operation commands include write commands, read commands, and rollback commands.

[0047] Among them, the RTC (real-time clock) is a hardware integrated circuit chip used to generate the internal time of the SSD. The internal time of the SSD can form its own timing system or be synchronized with the actual time (such as Beijing time); when host data is written to the PBA, the current RTC time is used as the timestamp of the PBA.

[0048] Optionally, the above-mentioned response to the write command from the host, as Figure 2 shown, specifically:

[0049] S21. Obtain the working state of the VAT bitmap peer logical address according to the logical address of the write command. If the working state is the occupied state, calculate and save the attack rate AR of the encrypted ransomware attack, then perform a null operation, and return write success to the host; if the working state is the idle state, perform a conventional write operation using the conventional flash translation layer FTL, then record the RTC timestamp of this write operation in the table entry of the VAT mapping table corresponding to the logical address, and at the same time update the working state of the VAT bitmap corresponding to the logical address to the occupied state, and return write success to the host.

[0050] Among them, the main target of the encrypted ransom attack is the data already existing in the SSD (data files or executable programs seen at the host OS layer). Therefore, strong blocking measures are taken here: that is, any existing data in the logical address space of the SSD is prohibited from being rewritten; this prevents the encrypted ransom virus from causing "fatal" damage to user data; further, in order to prevent encrypted ransom or other viruses from adopting the "depleting storage" tactic (such as creating a large number of hidden junk files) and maliciously blocking the user host, the VAT mapping table is also used here to save the RTC timestamp of the "write" operation, so that when needed, the rollback command extended by the present invention can be used to eliminate the damage caused by the virus; through these two steps, the encrypted ransomware cannot achieve its purpose of extorting money, nor can it cause any damage to the data in the SSD.

[0051] Optionally, the above response is from a read command of the host, as Figure 3 shown, specifically:

[0052] S22, obtain the working state of the peer logical address of the VAT bitmap according to the logical address of the read command. If the working state is the occupied state, perform a conventional read operation using the conventional flash translation layer FTL and return a read success to the host;

[0053] If the working state is the idle state and the current RTC time exceeds the time point of the first item in the abnormal time point queue TQ, and the exceeded time reaches more than one hour, then push the current RTC time into the abnormal time point queue TQ. The abnormal time point queue TQ is a first-in-first-out queue (FIFO);

[0054] If the working state is the idle state and the current attack rate AR value is greater than or equal to the threshold, generate an alarm signal, and at the same time perform a conventional read operation using the conventional flash translation layer FTL and return a read success to the host.

[0055] Among them, when an encrypted ransom attack occurs, it needs to "first" read its target data for encryption. If the logical address of its target data is in the "occupied" state, the SSD main control CPU cannot detect an abnormality; but if the logical address is in the "idle" state, it is obviously abnormal because almost no application reads undefined data (except for some OS infrequently used functions and disk utility programs, but in the SSD application scenario of the present invention, the user (operator) knows the impact of their operations, and exceptions are okay). At this time, the SSD main control CPU combines the AR value to determine that an encrypted ransom attack is occurring and alarms through a flashing light.

[0056] The abnormal time point queue TQ is used to record the time list when encrypted ransom behavior is detected for use when executing the rollback command.

[0057] Optionally, the above response is from a rollback command of the host, asFigure 4 As shown in the figure, specifically:

[0058] S23. According to the specified time point of the rollback command or the time points in the abnormal time point queue TQ, determine whether the time point is exceeded. If the time point is exceeded, return a rollback failure to the host. Otherwise, obtain each entry falling within the time point range from the VAT mapping table and the conventional flash translation layer FTL, swap the entry content of the VAT mapping table and the corresponding entry content in the conventional flash translation layer FTL one by one, and update the VAT bitmap according to the entry content in the conventional flash translation layer FTL after the swap: that is, if the entry content is the RTC timestamp, update the VAT bitmap to the idle state and update the PBA of the corresponding logical address in the FTL to "invalid"; otherwise, update the VAT bitmap to the occupied state and update the PBA of the corresponding logical address in the FTL to "valid". Finally, return a rollback success to the host.

[0059] Among them, the rollback command is a professional maintenance tool for the SSD of the present invention. The rollback command can be operated and executed within a limited time after a virus attack occurs, and is used to eliminate the garbage data generated by the virus; the time point range of the rollback command refers to the time span from the present to a certain time point in the past (for example, 12 hours).

[0060] Embodiment 2: The purpose of this embodiment is to support the production of an SSD device that resists encrypted ransomware attacks, such as Figure 5 As shown; this SSD device includes three components: a motherboard part, a main controller part, and a NAND storage array part; among them:

[0061] The motherboard part is a PCB circuit board, which carries an encrypted ransomware attack alarm light ALARM, a main controller, a NAND array, and other necessary auxiliary electronic components;

[0062] The main controller includes a CPU, an OTP (one-time programmable memory), a DRAM, an RTC, a VAT bitmap, a VAT mapping table, and an FTL (flash translation layer); the CPU is responsible for overall scheduling and uses the metadata provided by the VAT and the FTL to complete various calculation and processing tasks; the OTP is solidified to store the key parameters of the SSD and the algorithms for various work tasks; the DRAM provides the high-speed cache required when the CPU works; the RTC is a hardware real-time clock chip, which is used to generate the local time of the SSD. The local time of the SSD can form its own timing system or be synchronized with the actual time (for example, Beijing time); when user data is written to the PBA, the specific RTC value is used as the timestamp of the PBA; the FTL is the core metadata of a conventional SSD, which completes the translation and conversion of the host logical address vs the SSD physical address, PBA page allocation, bad block recovery, bad block replacement, wear leveling, and other management tasks under the scheduling of the CPU. The SSD in this embodiment has two flash translation layers, which are called VAT and FTL respectively.

[0063] Specifically, the VAT includes a VAT bitmap and a VAT mapping table.

[0064] The VAT bitmap is a data structure added by the present invention. It stores the working states of all logical addresses accessible by the SSD host, and its initial values are all "idle". Once a logical address is used, it is immediately updated to "occupied". The VAT mapping table is also a data structure added by the present invention, which is used to record the physical addresses to be recycled corresponding to each logical address, and is also used to record the RTC timestamp of the physical address corresponding to the logical address when the physical address to be recycled does not exist.

[0065] The FTL, VAT mapping table, and VAT bitmap are stored in the reserved storage space in the NAND array when static, and are loaded into the DRAM or SRAM high-speed dynamic memory on the motherboard during the initialization of the SSD power-on. The addressing space sizes of the FTL, VAT mapping table, and VAT bitmap are the same, all being the logical address LBA space of the SSD.

[0066] The above-mentioned NAND storage array is the storage medium of the SSD. A part of its storage space is reserved for storing the metadata of the SSD or as a bad block backup, and another part of the storage space can be allocated as the physical address PBA for the host to store data. Obviously, the PBA addressing space is larger than the LBA.

[0067] Furthermore, the ALARM warning light is used to emit an alarm and flash when the CPU detects a suspected attack behavior of encrypted ransomware. However, the alarm flashing does not mean that the virus attack has caused data damage, but only reminds the user to pay attention to the occurrence of a suspected virus attack behavior. In fact, the stored data of the SSD in this embodiment cannot be damaged online by encrypted ransomware or other viruses (unless the NAND medium is disassembled on-site).

[0068] Optionally, attached Figure 1The two - layer FTL architecture of the present invention is shown. By applying the system design concept of hierarchical processing, the processing tasks of each layer are clear and the operations are simple. The inter - layer crossover is minimized as much as possible, making the SSD device more robust. At the same time, the mature technology of the second - layer conventional FTL is inherited. Among them, the first - layer VAT (special flash translation layer) of this embodiment includes a VAT bitmap and a VAT mapping table. It can be seen that the VAT bitmap is a very important component of the present invention. Utilizing the characteristic that it is difficult for encrypted ransomware to know the current working state of the SSD logical address, its blind attack will inevitably result in unreasonable operations of accessing undefined data, thus enabling the CPU to discover its attack. At the same time, taking advantage of the characteristic that the virus will inevitably forcefully rewrite the existing data, its trace is caught again. This embodiment uses the method of prohibiting the rewriting of existing data to strongly block it. Of course, in other embodiments, the method of temporarily diverting the attack target PBA data of the virus can also be adopted, and then the user uses the rollback command of the present invention to make its attack fail.

[0069] Further, the flowcharts of writing data, reading data, and rolling back data in this embodiment are shown in Appendix Figure 2 Appendix Figure 3 Appendix Figure 4 ; Traditional SSDs also support full - disk reset, delete commands, and erase commands. Obviously, they are not applicable to the SSD products of the present invention, and implementers must remove these commands. It should be clear that this embodiment introduces a "rollback" command implemented in the SSD and sets an operable time - point limit for this command. On the one hand, this limit avoids the disaster of accidentally or maliciously rolling back all data (the bad - block recovery mechanism of the SSD also does not allow long - term rollback). On the other hand, this limit reflects the characteristic of "chronological" sealing of trusted data resources or data assets. (Chronological means periodically compiling data at fixed times and prohibiting later modification, such as a company's monthly financial report). Thus, it can be seen that the real - time clock RTC in this embodiment is an essential and important component.

[0070] The design of this embodiment aims to protect ordinary user files or programs, and can also protect user data assets or data resources (whose characteristic is that once the data is generated, it is permanently unchangeable). However, this embodiment does not include the "disk - encryption" function and cannot be used to store any classified files. If needed, this embodiment supports implementers to add a disk - encryption function or component in the main controller. This embodiment does not support partitioning protection (or no protection) of the storage space of the SSD to avoid complications and vulnerabilities and ensure data security.

[0071] Embodiment 3: The embodiment of the present application provides a solid - state drive, which realizes the defense against encrypted ransom attacks and protects data security through the method for countering encrypted ransom attacks in any one of the first aspects.

[0072] An embodiment of the present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the method according to any one of the first aspects is used to implement defense against encrypted ransomware and protection of data security.

[0073] An embodiment of the present application further provides a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium stores computer instructions. When the computer executes the instructions, the method according to any one of the first aspects is used to implement defense against encrypted ransomware and protection of data security.

[0074] The specific embodiments described above further elaborate on the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for resisting crypto-ransomware attacks, characterized in that: The specific steps include: Add a special flash translation layer VAT in the SSD to manage the mapping relationship between logical addresses and physical addresses to be reclaimed; The conventional flash translation layer FTL for managing the mapping relationship between logical addresses and physical addresses is used in the SSD; The SSD is equipped with a real-time clock chip RTC, which is used to generate the RTC timestamp of the physical address and the abnormal time point queue TQ; Based on the special flash translation layer VAT, the conventional flash translation layer FTL and the real-time clock chip RTC, responding to an operation command from a host, the operation command including a write command, a read command and a rollback command; The special flash translation layer VAT includes a VAT bitmap and a VAT mapping table. The VAT bitmap is used to record the working status of each logical address, and the VAT mapping table is used to record the physical address to be reclaimed corresponding to each logical address. When the physical address to be reclaimed does not exist, it is also used to record the RTC timestamp of the physical address corresponding to the logical address in the conventional flash translation layer FTL.

2. A method for resisting encryption ransomware attacks according to claim 1, characterized in that: Respond to the write command from the host, specifically: Obtain the working state of the VAT bitmap equivalent logical address according to the logical address of the write command. If the working state is occupied, calculate and save the attack rate AR of the encryption ransomware attack, then perform a no-op, and return a write success to the host. The attack rate AR is the cumulative number of times the above encryption ransomware attack occurs within N seconds, where N>=1. If the working state is an idle state, a regular write operation is performed using the conventional flash translation layer FTL, and then the RTC timestamp of this write operation is recorded in the table entry of the peer logical address in the VAT mapping table. At the same time, the working state of the peer logical address in the VAT bitmap is updated to an occupied state, and a write success is returned to the host.

3. A method for resisting encryption ransomware attacks according to claim 1, characterized in that: Respond to the read command from the host, specifically: Obtaining the working state of the VAT bitmap equivalent logical address according to the logical address of the read command, and if the working state is an occupied state, performing a conventional read operation using the conventional flash translation layer FTL, and returning a read success to the host; If the working state is idle and the current RTC time exceeds the first time point in the abnormal time point queue TQ, and the exceeding time reaches more than one hour, the current RTC time is pushed into the abnormal time point queue TQ; the abnormal time point queue TQ is a first-in-first-out queue; If the working state is an idle state and the current attack rate AR value is greater than or equal to a threshold, an alarm signal is generated, and a conventional read operation is performed using the conventional flash translation layer FTL, and a read success is returned to the host.

4. The method for resisting encryption ransomware attack according to claim 1, characterized in that: Respond to the rollback command from the host, specifically: According to the specified time point of the rollback command or the time point in the abnormal time point queue TQ, it is determined whether the time point is out of limit. If the time point is out of limit, the rollback failure is returned to the host. Otherwise, each table entry falling into the time point range is obtained from the VAT mapping table and the conventional flash translation layer FTL, and the table entry content of the VAT mapping table is exchanged with the corresponding table entry content in the conventional flash translation layer FTL one by one, and the VAT bitmap is updated according to the table entry content in the conventional flash translation layer FTL after the exchange: that is, if the table entry content is an RTC timestamp, the VAT bitmap is updated to an idle state and the PBA of the equivalent logical address in the FTL is updated to "invalid"; otherwise, the VAT bitmap is updated to an occupied state and the PBA of the equivalent logical address in the FTL is updated to "valid", and the rollback success is returned to the host.

5. A solid state hard disk, characterized in that: Using the method described in any one of claims 1-4, defense against encryption ransomware viruses is achieved, and data in the solid-state hard disk is protected from being rewritten by viruses.

6. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method described in any one of claims 1 to 4 is used to defend against encryption ransomware viruses and protect data in electronic devices from being rewritten by viruses.

7. A non-transitory computer-readable storage medium, characterized in that: The non-transitory computer-readable storage medium stores computer instructions, and when the computer executes the instructions, the method described in any one of claims 1-4 is used to defend against encryption ransomware viruses and protect data in the computer from being rewritten by viruses.