Ransomware detection method and device, electronic equipment and storage medium

By analyzing the hardware data and file operation data of the detection process and detecting ransomware based on timing association relationships, the problem of poor detection effectiveness based on fixed assumptions in the prior art is solved, and the accuracy of detection is improved.

CN120012081APending Publication Date: 2025-05-16TSINGHUA UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411873543.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-18
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing ransomware detection methods are based on fixed assumptions and cannot effectively detect new ransomware, resulting in poor detection results.

Method used

By detecting the hardware data of the detection process, and combining with the quantitative analysis of file operation data, it is determined whether it is ransomware based on the timing relationship between the encryption behavior and file operation behavior.

Benefits of technology

Improve the accuracy of ransomware detection, avoid ransomware escape detection strategies, and can effectively detect new ransomware.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012081A_ABST
    Figure CN120012081A_ABST
Patent Text Reader

Abstract

The invention provides a ransomware detection method and device, electronic equipment and a storage medium, and relates to the technical field of computer software security. The method comprises the following steps: performing encryption behavior detection on hardware data of a to-be-detected process to determine a suspicious process, performing quantitative analysis on file operation data of the suspicious process in file operation data of the to-be-detected process to obtain file operation characteristics of the suspicious process, and determining whether the suspicious process is ransomware or not according to whether a time sequence association relationship exists between the hardware data of the suspicious process and the file operation characteristics of the suspicious process or not. According to the method, the ransomware can be prevented from escaping from the detection strategy, and the ransomware detection accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer software security technology, and in particular to a method, device, electronic device and storage medium for detecting ransomware. Background Art

[0002] Ransomware has become one of the main threats facing the cybersecurity field today. Its attack mode usually includes encrypting the victim's files or locking the device to restrict access to data, thereby extorting a high ransom. According to a report released in 2023, an average of 402 ransomware attacks occurred worldwide each month, an increase of 82% from 2022. In order to deal with these attacks, the average cost of recovering from a ransomware attack by enterprises is as high as US$1.82 million, excluding the ransom, causing huge economic losses. In addition, the impact of ransomware attacks is becoming more and more extensive, not only causing economic losses, but also threatening personal safety. For example, ransomware attacks against the medical and health sector may endanger the lives of patients, while attacks against education and government institutions may lead to the leakage of important information, endanger personal privacy, and pose a threat to social stability and public safety. Existing ransomware detection methods usually assume that ransomware will use the encryption API provided by the system to encrypt data, and believe that the encrypted data has a high entropy value, or assume that the ransomware is significantly different from normal programs in I / O behavior for detection.

[0003] Existing ransomware detection methods often perform ransomware detection based on some fixed assumptions, but these assumptions may fail when facing new types of ransomware, resulting in poor detection results. Summary of the invention

[0004] The present invention provides a ransomware detection method, device, electronic device and storage medium, which are used to solve the defect of poor ransomware detection effect based on some fixed assumptions in the prior art, and detect ransomware based on the temporal correlation relationship between encryption behavior and file operation behavior, thereby preventing ransomware from escaping detection strategies and improving the accuracy of ransomware detection.

[0005] The present invention provides a method for detecting ransomware, comprising the following steps: Perform encryption behavior detection on hardware data of the process to be detected to determine a suspicious process, wherein the suspicious process is at least one process including suspicious encryption behavior among the processes to be detected, and the hardware data of the process to be detected is obtained by acquiring hardware data of a processor collected by a performance counter; Performing quantitative analysis on the file operation data of the suspicious process in the file operation data of the process to be detected to obtain the file operation characteristics of the suspicious process, wherein the file operation characteristics of the suspicious process are determined according to the file operation data in the time period when the encryption behavior in the suspicious process occurs, and the file operation characteristics of the suspicious process are used to characterize the scale of the encryption behavior in the time period when the encryption behavior occurs; Whether the suspicious process is ransomware is determined according to whether there is a temporal correlation relationship between the hardware data of the suspicious process and the file operation characteristics of the suspicious process.

[0006] According to a method for detecting ransomware provided by the present invention, determining whether the suspicious process is ransomware according to whether there is a temporal correlation relationship between the hardware data of the suspicious process and the file operation characteristics of the suspicious process includes: Inputting the hardware data of the suspicious process and the file operation features of the suspicious process into the trained timing analysis model to obtain a result of whether the suspicious process is ransomware; The trained timing analysis model is obtained by training an initial timing analysis model with a process data set, and the process data set includes hardware data and file operation data collected from normal programs and ransomware respectively.

[0007] According to a method for detecting ransomware provided by the present invention, the process data set is time series data with a step length of a preset length, and the time series data is obtained by evaluating the behavior of the suspicious process every second; wherein, the evaluation of the behavior of the suspicious process every second includes dividing each second into a target number of time steps, the length of each time step is a preset duration, using the data of the hardware performance counter generated by each preset duration as the basis for the evaluation of encryption features, and using the data of the input and output request packet IRP as the basis for the evaluation of file operation features.

[0008] According to a method for detecting ransomware provided by the present invention, the encryption behavior detection of hardware data of a process to be detected and determining a suspicious process includes: Inputting the hardware data of the process to be detected into a trained K nearest neighbor classifier to obtain the suspicious process; Among them, the trained K-nearest neighbor classifier is obtained by training the initial K-nearest neighbor classifier with three types of features extracted from the hardware data set, and the three types of features include instruction execution features, memory access features and execution fluctuation features. The instruction execution features are used to characterize the instruction cycle operation status, the memory access features are used to characterize the operation status of the same memory area, and the execution fluctuation features are used to characterize the fluctuation of instruction execution features and memory access features.

[0009] According to a method for detecting ransomware provided by the present invention, the file operation characteristics of the suspicious process include the amount of potentially encrypted data and the number of core file operations, and the file operation data of the suspicious process in the file operation data of the process to be detected is quantitatively analyzed to obtain the file operation characteristics of the suspicious process, including: Regularly counting the number of processes using a first operation mode to obtain the amount of data potentially encrypted, wherein the first operation mode includes an operation mode in which read operations and write operations are continuously performed; The number of processes using the second operation mode is regularly counted to obtain the number of core file operations, where the second operation mode includes a read operation, a write operation, a create operation, a delete operation, and a rename operation.

[0010] According to a method for detecting ransomware provided by the present invention, the performance counter includes an instruction execution counter and a memory access counter. Before performing encryption behavior detection on hardware data of a process to be detected and determining a suspicious process, the method further includes: Collecting data of the instruction execution counter and the memory access counter at preset time intervals to obtain hardware data of the process to be detected, wherein the instruction execution counter includes at least one of the number of executed instructions, the number of executed branch instructions, and the number of branch instruction prediction errors, and the memory access counter includes at least one of the number of times the lowest level cache is accessed and the number of times the lowest level cache is missed; Feature extraction is performed on input / output request packet IRP data to obtain file operation data of the process to be detected, wherein the IRP data is obtained by recording information in all IPR requests.

[0011] The present invention also provides a ransomware detection device, comprising the following modules: A behavior detection module is used to perform encryption behavior detection on the hardware data of the process to be detected, and determine a suspicious process, wherein the suspicious process is at least one process in the process to be detected that includes suspicious encryption behavior, and the hardware data of the process to be detected is obtained by acquiring the hardware data of the processor collected by the performance counter; An operation analysis module, used to perform quantitative analysis on the file operation data of the suspicious process in the file operation data of the process to be detected, and obtain the file operation characteristics of the suspicious process, wherein the file operation characteristics of the suspicious process are determined based on the file operation data in the time period when the encryption behavior in the suspicious process occurs, and the file operation characteristics of the suspicious process are used to characterize the scale of the encryption behavior in the time period when the encryption behavior occurs; The timing analysis module is used to determine whether the suspicious process is ransomware according to whether there is a timing correlation relationship between the hardware data of the suspicious process and the file operation characteristics of the suspicious process.

[0012] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein when the processor executes the computer program, the method for detecting ransomware as described in any one of the above is implemented.

[0013] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the method for detecting ransomware as described in any one of the above is implemented.

[0014] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the method for detecting ransomware as described in any one of the above is implemented.

[0015] The ransomware detection method, device, electronic device and storage medium provided by the present invention detect the ransomware based on the temporal correlation between encryption behavior and file operation behavior, thereby preventing the ransomware from escaping the detection strategy and improving the accuracy of ransomware detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0017] Figure 1 This is one of the flow charts of the method for detecting ransomware provided by the present invention.

[0018] Figure 2 It is a flow chart of the method for obtaining the file operation characteristics of a suspicious process provided by the present invention.

[0019] Figure 3 This is the second flow chart of the method for detecting ransomware provided by the present invention.

[0020] Figure 4 It is an overall process framework diagram of the ransomware detection method provided by the present invention.

[0021] Figure 5 It is a structural schematic diagram of a ransomware detection device provided by the present invention.

[0022] Figure 6It is a schematic diagram of the physical structure of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0023] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0024] Ransomware has become one of the main threats facing the field of cybersecurity today. Its attack mode usually includes encrypting the victim's files or locking the device to restrict access to data, thereby extorting a high ransom. According to a report released in 2023, an average of 402 ransomware attacks occurred worldwide each month, an increase of 82% from 2022. In order to deal with these attacks, the average cost of recovering from a ransomware attack by enterprises is as high as $1.82 million, excluding the ransom, causing huge economic losses. In addition, the impact of ransomware attacks is becoming more and more extensive, not only causing economic losses, but also threatening personal safety. For example, ransomware attacks against the medical and health sector may endanger the lives of patients, while attacks against education and government institutions may lead to the leakage of important information, endanger personal privacy, and pose a threat to social stability and public safety. Existing ransomware detection methods often perform ransomware detection based on some fixed assumptions. For example, it is usually assumed that ransomware will use the encryption API provided by the system to encrypt data and that the encrypted data has a high entropy value. However, some new ransomware successfully bypasses the monitoring of encryption APIs and entropy-based judgment mechanisms by implementing self-implemented encryption codes and mixing original data with encrypted data when writing files. For another example, suppose that the I / O behavior of ransomware is significantly different from that of normal programs. However, the latest research shows that ransomware can evade detection by imitating the I / O behavior of normal programs, thereby circumventing the defense of existing I / O detection strategies.

[0025] Therefore, existing ransomware detection methods often perform ransomware detection based on some fixed assumptions, but these assumptions may fail when facing new ransomware, resulting in poor detection results.

[0026] In view of this, an embodiment of the present invention provides a method for detecting ransomware, which detects the encryption behavior of the hardware data of the process to be detected, determines the suspicious process, performs quantitative analysis on the file operation data of the suspicious process in the file operation data of the process to be detected, obtains the file operation characteristics of the suspicious process, and determines whether the suspicious process is ransomware according to whether there is a temporal correlation between the hardware data of the suspicious process and the file operation characteristics of the suspicious process. This method can prevent ransomware from escaping detection strategies and improve the accuracy of ransomware detection.

[0027] The technical solutions in the embodiments of the present invention will be described below in conjunction with the accompanying drawings in the embodiments of the present invention.

[0028] Figure 1 This is one of the flow charts of the ransomware detection method provided by the present invention. The ransomware detection method can be applied to electronic devices, which can be various types of devices with information processing capabilities during implementation. For example, the electronic device can include a personal computer, a laptop, a PDA or a server, etc.; the electronic device can also be a mobile terminal, for example, the mobile terminal can include a mobile phone, a car computer, a tablet computer or a projector, etc. Figure 1 As shown, the method may include the following steps 101 to 103: Step 101: Perform encryption behavior detection on the hardware data of the process to be detected to determine a suspicious process, where the suspicious process is at least one process in the process to be detected that includes suspicious encryption behavior, and the hardware data of the process to be detected is obtained by acquiring the hardware data of the processor collected by the performance counter.

[0029] It should be noted that the performance counter (PMC) is used to monitor specific hardware events, and the hardware data of the process to be detected can be obtained by obtaining the hardware data of the processor collected by the performance counter. The suspicious process can be one process, two processes, or multiple processes.

[0030] Among them, there are many methods for performing encryption behavior detection on the hardware data of the process to be detected and determining suspicious processes. For example, methods such as checking the process name and path, viewing process attributes, and using network monitoring tools can be used. The present invention does not limit the method for performing encryption behavior detection on the hardware data of the process to be detected.

[0031] Step 102: Quantitatively analyze the file operation data of the suspicious process in the file operation data of the process to be detected to obtain the file operation characteristics of the suspicious process. The file operation characteristics of the suspicious process are determined based on the file operation data within the time period when the encryption behavior in the suspicious process occurs. The file operation characteristics of the suspicious process are used to characterize the scale of the encryption behavior within the time period when the encryption behavior occurs.

[0032] It should be noted that the file operation characteristics of the suspicious process are determined based on the file operation data within the time period when the encryption behavior in the suspicious process occurs. There are many methods for quantitatively analyzing the file operation data of the suspicious process in the file operation data of the process to be detected to obtain the file operation characteristics of the suspicious process, such as counting the file operation frequency, analyzing the file operation mode, or calculating the abnormality of the file operation, etc. The present invention does not limit the method of quantitatively analyzing the file operation data of the suspicious process in the file operation data of the process to be detected to obtain the file operation characteristics of the suspicious process.

[0033] Step 103: Determine whether the suspicious process is ransomware based on whether there is a temporal correlation between the hardware data of the suspicious process and the file operation characteristics of the suspicious process.

[0034] It should be noted that after obtaining the hardware data of the suspicious process and the file operation characteristics of the suspicious process, it is possible to determine whether the suspicious process is ransomware based on whether there is a time sequence correlation between the two. If there is a significant time sequence correlation between the two, it is considered that the process has performed a large number of file encryption operations, and thus the process is determined to be ransomware.

[0035] There are many methods for determining whether there is a temporal correlation relationship between the hardware data of the suspicious process and the file operation characteristics of the suspicious process, such as calculating time difference, correlation analysis, causal inference, etc. The present invention does not limit the method for determining whether there is a temporal correlation relationship between the hardware data of the suspicious process and the file operation characteristics of the suspicious process.

[0036] The ransomware detection method provided in the present application detects whether a process is ransomware based on the temporal correlation between encryption behavior and file operation behavior, which can solve the limitations of existing ransomware detection tools when facing new ransomware, prevent ransomware from escaping detection strategies, and improve the accuracy of ransomware detection.

[0037] In some embodiments, based on the characteristics of encryption behavior, which is characterized by a large number of cycles and frequent memory accesses, hardware performance counter (HPC) data may be used to construct features to detect encryption behavior.

[0038] In an embodiment of the present invention, the encryption behavior detection of the hardware data of the process to be detected and the determination of the suspicious process may include: inputting the hardware data of the process to be detected into a trained K-nearest neighbor classifier to obtain the suspicious process; wherein the trained K-nearest neighbor classifier is obtained by training an initial K-nearest neighbor classifier with three types of features extracted from a hardware data set, the three types of features including instruction execution features, memory access features and execution fluctuation features, the instruction execution features are used to characterize the instruction cycle operation, the memory access features are used to characterize the operation on the same memory area, and the execution fluctuation features are used to characterize the fluctuation of instruction execution features and memory access features.

[0039] It should be noted that the present invention has established an effective detection method based on the unique features reflected by encryption behavior on hardware data. First, three types of features are extracted from the hardware data, and then a machine learning model is trained using these features to classify encryption programs and normal programs. Then, the system will use this model to detect whether there is encryption behavior in all unknown processes.

[0040] Exemplarily, the three types of features extracted from the hardware data of the present invention are based on instruction execution, memory access, and execution fluctuation. All features can be calculated once per second, and the specific definitions are as follows: First, we represent the hardware data collected per second as: ;in, Indicates the first 100ms sub-intervals, Indicates The total number of instructions executed in the interval, Indicates the number of branch instructions, Indicates the number of branch instruction prediction errors, Indicates the number of cache accesses, Indicates the number of cache misses.

[0041] The first part of the features is the instruction execution features about instruction execution. In order to encrypt a large amount of data, the encryption algorithm usually needs to execute a large number of loop operations. In this case, the compiler usually optimizes the program performance by unrolling the loop, so there are fewer branch instructions during the execution process. Therefore, the present invention determines the branch instruction ratio and the branch instruction prediction error ratio through two features.

[0042] Branch instruction ratio characteristics , represents the number of subintervals, It means to find the average value of n subintervals; Branch instruction prediction error ratio characteristics ; The second part of the features is the memory access features about memory access. Since encryption behavior usually frequently operates on the same memory area, it significantly affects the cache access situation. Therefore, the present invention determines it through two features: cache access frequency and cache miss frequency.

[0043] Cache access frequency characteristics ; Cache miss frequency .

[0044] The third feature is the execution fluctuation feature. A large number of encryption operations usually repeatedly execute similar instruction fragments, which will lead to the small volatility of the instruction execution feature and memory access feature mentioned above. Therefore, the present invention proposes four features: branch instruction ratio volatility, branch prediction error ratio volatility, cache access ratio volatility, and cache miss ratio volatility to measure the fluctuation of the above features during the process running.

[0045] Branch instruction ratio fluctuation characteristics ; Branch misprediction rate volatility ; Cache access ratio fluctuation ; Cache miss ratio volatility .

[0046] After obtaining these features, the present invention trains a K-nearest neighbor (KNN) classifier to distinguish the behavior of encrypted programs from normal programs. After training, the system monitors all running processes, extracts hardware data and calculates the above features, and uses the trained KNN model to detect encryption behavior. If a process is detected to contain encryption operations, the system marks it as a suspicious process, thus entering the next stage of I / O association, that is, file operation feature analysis.

[0047] It can be understood that the present invention uses HPC data to construct features to detect encryption behavior based on the characteristics of encryption behavior such as a large number of cycles and frequent memory accesses, thereby improving the accuracy of encryption behavior detection.

[0048] In some embodiments, I / O behavior features, namely, file operation features, may be extracted using IRP data based on the ransomware file destruction mode.

[0049] Figure 2 FIG. 1 is a flow chart of a method for obtaining file operation characteristics of a suspicious process provided by the present invention. Figure 2As shown, the file operation characteristics of the suspicious process include the amount of potentially encrypted data and the number of core file operations, and the file operation data of the suspicious process in the file operation data of the process to be detected is quantitatively analyzed to obtain the file operation characteristics of the suspicious process, which may include: Step 201: regularly counting the number of processes using a first operation mode to obtain the amount of data potentially encrypted, wherein the first operation mode includes an operation mode in which read operations and write operations are continuously performed; Step 202: regularly counting the number of processes using the second operation mode to obtain the number of core file operations, where the second operation mode includes the operation modes of read operation, write operation, create operation, delete operation and rename operation.

[0050] It should be noted that the statistics of file operation features, i.e., I / O behavior features, can include the amount of data potentially encrypted and the number of core I / O operations, i.e., the number of core file operations. Since ransomware encrypts a large number of files during an attack, its encryption behavior is highly correlated with I / O operations in terms of time. I / O behavior features can be used to measure the scale of these encryption operations and used as quantitative features in the timing analysis module.

[0051] First, the present invention calculates the total size of files operated in the "read-write" mode as an estimate of the potential size of encrypted data. Ransomware usually follows the "read-encrypt-write" operation mode when attacking, so the file size counted in this way can effectively reflect the scale of encryption operations. At the same time, considering that different basic I / O operations require specific instructions to implement, we also include the following operations in the statistical scope, including the number of read, write, create, delete and rename operations, that is, the number of core I / O operations. For all processes marked as suspicious, the I / O behavior characteristics are calculated every 100ms. In summary, the complete definition of the I / O behavior characteristics is shown in Table 1 below.

[0052] Table 1 I / O behavior characteristics definition

[0053] It can be understood that based on the ransomware file destruction mode, the method of extracting I / O behavior characteristics using IRP data improves the accuracy of detecting file operation characteristics of suspicious processes.

[0054] In some embodiments, a trained timing analysis model may be used to determine whether there is a timing correlation relationship between the hardware data of a suspicious process and the file operation characteristics of the suspicious process.

[0055] In an embodiment of the present invention, determining whether the suspicious process is ransomware based on whether there is a temporal correlation between the hardware data of the suspicious process and the file operation characteristics of the suspicious process may include: inputting the hardware data of the suspicious process and the file operation characteristics of the suspicious process into a trained timing analysis model to obtain a result of whether the suspicious process is ransomware; wherein the trained timing analysis model is obtained by training an initial timing analysis model through a process data set, and the process data set includes hardware data and file operation data collected from normal programs and ransomware, respectively.

[0056] It should be noted that the trained timing analysis model can use deep learning methods to capture the timing correlation between encryption behavior and I / O behavior. The present invention can use a long short-term memory neural network (Long Short-Term Memory, LSTM), which is a recurrent neural network variant suitable for processing time series data and can effectively capture the timing dependency between data.

[0057] Furthermore, the process data set is time series data with a step size of a preset length, and the time series data is obtained by evaluating the behavior of the suspicious process every second; wherein, the evaluation of the behavior of the suspicious process every second includes dividing each second into a target number of time steps, the length of each time step is a preset duration, and the encryption features are based on the evaluation of the data of the hardware performance counter generated at each preset duration, and the file operation features are based on the evaluation of the input and output request packet IRP data.

[0058] Exemplarily, the analysis of the trained timing analysis model evaluates the behavior of the suspicious process every second. Each second is divided into 10 time steps, and the length of each time step is 100ms. Every 100ms, encryption features based on HPC data and I / O behavior features based on IRP data are generated, forming time series data with a step length of 10, and then LSTM is trained for binary classification.

[0059] Among them, in order to train the initial timing analysis model to obtain a trained timing analysis model, the present invention collects hardware data and I / O behavior data from normal programs and ransomware respectively. The ransomware data is collected from a unified virtual experimental environment. In the experiment, the present invention creates a folder containing 1,000 randomly generated normal files on the user's desktop to simulate a real file system and induce the occurrence of a ransomware attack. Subsequently, the present invention only extracts data marked as encryption behavior. The screened hardware data and I / O behavior features are merged to form a complete data set for training the initial timing analysis model. The model detects the ransomware by learning the timing correlation between the encryption behavior and the I / O behavior in the ransomware, thereby achieving a defensive effect.

[0060] It can be understood that by analyzing the trained timing analysis model to evaluate the behavior of suspicious processes every second, the accuracy of detecting timing correlations is improved, thereby improving the accuracy of ransomware detection.

[0061] Figure 3 This is the second flow chart of the method for detecting ransomware provided by the present invention. Figure 3 As shown, the performance counter includes an instruction execution counter and a memory access counter, and the ransomware detection method may include: Step 301: collecting data of the instruction execution counter and the memory access counter at a preset time interval to obtain hardware data of the process to be detected, wherein the instruction execution counter includes at least one of the number of executed instructions, the number of executed branch instructions, and the number of branch instruction prediction errors, and the memory access counter includes at least one of the number of times the lowest level cache is accessed and the last level cache miss counter; It should be noted that the embodiment of the present invention can collect processor hardware data using a performance monitoring unit (PMU) based on Windows system event tracing (Event Tracing for Windows, ETW). PMU provides a variety of performance counters (Performance Monitor Counter, PMC) for monitoring specific hardware events.

[0062] Exemplarily, the present invention can select five counters that are most relevant to process instruction execution and memory access for analysis. These counters are shown in Table 2 below. Among them, the number of instructions executed InstructionRetiredFixed, the number of branch instructions executed BranchInsructionRetired, and the number of branch instruction prediction errors BranchMispredictsRetired are related to the execution of instructions, and the number of times the lowest level cache is accessed LLCReferences and the number of misses in accessing the lowest level cache LLCMises are related to memory access. The hardware monitor summarizes the data of these counters every 100ms through a sampling mode, and these data can reflect the cyclic characteristics and memory access of the process execution. When a process performs a large number of encryption operations, these characteristics will show abnormalities, thus becoming an important basis for detecting encryption behavior.

[0063] Table 2 PMC list

[0064] Step 302: Extract features from input / output request packet IRP data to obtain file operation data of the process to be detected. The IRP data is obtained by recording information in all IPR requests.

[0065] It should be noted that the present invention designs a system driver running in kernel mode, which records relevant information by adding a callback function to all input and output request packets (I / O Request Packet, IRP) requests. The IRP request is an interface for device I / O in the Windows system, which contains all key information of the I / O request, such as operation type, data buffer pointer, type of operated file or device, completion status, etc. Since the IRP request is located at the bottom layer of the interaction between the operating system and the storage device, the disk operation of any process cannot bypass the monitoring mechanism. Finally, the data format of the monitoring record is (time, process name, process number, operation type, operated file name, operated file size). These data will provide a basis for subsequent I / O behavior analysis.

[0066] Step 303: Perform encryption behavior detection on the hardware data of the process to be detected to determine a suspicious process, where the suspicious process is at least one process in the process to be detected that includes suspicious encryption behavior, and the hardware data of the process to be detected is obtained by acquiring the hardware data of the processor collected by the performance counter.

[0067] The description of step 303 may refer to the description of step 101 in the above embodiment.

[0068] Step 304: Quantitatively analyze the file operation data of the suspicious process in the file operation data of the process to be detected to obtain the file operation characteristics of the suspicious process. The file operation characteristics of the suspicious process are determined based on the file operation data within the time period when the encryption behavior in the suspicious process occurs. The file operation characteristics of the suspicious process are used to characterize the scale of the encryption behavior within the time period when the encryption behavior occurs.

[0069] The description of step 304 may refer to the description of step 102 in the above embodiment.

[0070] Step 305: Determine whether the suspicious process is ransomware based on whether there is a temporal correlation between the hardware data of the suspicious process and the file operation characteristics of the suspicious process.

[0071] The description of step 305 may refer to the description of step 103 in the above embodiment.

[0072] It can be understood that by collecting the data of the instruction execution counter and the memory access counter, the hardware data of the process to be detected is obtained, and the feature extraction of the input and output request packet IRP data is performed to obtain the file operation data of the process to be detected. The hardware data and file operation data of all processes can be accurately obtained in real time, which lays a good foundation for ransomware detection and further improves the accuracy of ransomware detection.

[0073] The following describes an exemplary application of an embodiment of the present invention in a practical application scenario.

[0074] Figure 4 This is the overall process framework diagram of the ransomware detection method provided by the present invention. Figure 4As shown in Figure 1, the ransomware defense process of the framework includes the following four main steps: First, a system monitoring module is deployed in the operating system kernel to collect hardware data and I / O behavior data of all processes. These data will be used in the subsequent analysis process to provide a basis for detecting and identifying ransomware. Second, the encryption detection module extracts instruction execution features, memory access features, and execution fluctuation features from the collected hardware data to determine whether the process has performed encryption operations. Based on these features, if the process is determined to have suspicious encryption behavior, it will be marked as a suspicious process. Next, for the marked suspicious process, the I / O calculation module performs quantitative analysis of its file operation behavior, calculates the file size where the "read-encrypt-write" operation may occur, and analyzes the type and number of related file operations. This step is used to evaluate the potential amount of data involved in the process encryption operation and its impact on the file system. Finally, the timing analysis module performs timing correlation analysis on the hardware data and I / O behavior data of the suspicious process to detect the correlation between encryption behavior and I / O behavior. If it is confirmed that there is a significant timing correlation, it is considered that the process has performed a large number of file encryption operations, and thus the process is determined to be ransomware.

[0075] Among them, the main function of the system monitoring module is to monitor and collect the behavior data of processes in the system to provide a basis for subsequent analysis. This module consists of two sub-modules: hardware monitor and I / O monitor. The hardware monitor is responsible for collecting key hardware data in the system for the detection and quantification of encryption behavior. It runs continuously in a way that the user process is not aware of, ensuring that the data collection process does not affect the normal operation of the system. The I / O monitor is responsible for monitoring the I / O operations of all processes and providing data support for the I / O behavior analysis in subsequent steps. The monitor monitors at the bottom layer of the operating system and the disk to ensure that the I / O behavior of all suspicious processes can be fully recorded.

[0076] Encryption detection based on hardware performance counters. This module is the first stage of ransomware detection. It is mainly used to detect potential encryption behaviors in the system and mark the corresponding processes as suspicious processes.

[0077] I / O behavior calculation based on key I / O operations, which corresponds to the I / O calculation module in the framework. For processes marked as suspicious by the encryption detection module, the I / O behavior calculation module will calculate their I / O behavior characteristics according to the predefined quantification method, providing data support for the subsequent encryption behavior and I / O behavior timing correlation analysis.

[0078] Ransomware analysis based on the temporal correlation between encryption behavior and I / O behavior. This part corresponds to the timing analysis module in the framework. With the processing of the first two modules, it is possible to identify the suspicious process that performs encryption operations and the time when the encryption behavior occurs, and calculate the I / O behavior characteristics of the process during this time period. The timing analysis module will then determine whether there is a temporal correlation between encryption behavior and I / O behavior based on these hardware data and I / O behavior characteristics. If the correlation is confirmed, we will believe that these encryption operations are likely to target file objects in the I / O behavior, and then determine the process as ransomware.

[0079] The present invention proposes a ransomware detection framework based on the temporal correlation between encryption behavior and file operation behavior, aiming to solve the limitations of existing ransomware detection tools when facing new ransomware. The framework collects hardware performance counter data and I / O behavior data through the system monitoring module, first detects suspicious encryption behavior, and then quantitatively analyzes the I / O behavior of related processes. Then, deep learning technology is used to analyze the correlation between encryption behavior and I / O behavior to determine whether the suspicious process is ransomware. It can prevent ransomware from escaping detection strategies and improve the accuracy of ransomware detection.

[0080] Based on the foregoing embodiments, an embodiment of the present invention provides a ransomware detection device, wherein each module included in the device and each unit included in each module may be implemented by a processor; of course, they may also be implemented by a specific logic circuit; during implementation, the processor may be a central processing unit (CPU), a microprocessor (MPU), a digital signal processor (DSP) or a field programmable gate array (FPGA), etc.

[0081] The ransomware detection device provided by the present invention is described below. The ransomware detection device described below and the ransomware detection method described above can be referred to each other.

[0082] Figure 5 Schematic diagram of the structure of the ransomware detection device provided by the present invention. Figure 5 As shown, the device 500 includes a behavior detection module 501, an operation analysis module 502 and a timing analysis module 503, wherein: The behavior detection module 501 is used to perform encryption behavior detection on the hardware data of the process to be detected, and determine a suspicious process, wherein the suspicious process is at least one process including suspicious encryption behavior in the process to be detected, and the hardware data of the process to be detected is obtained by acquiring the hardware data of the processor collected by the performance counter; The operation analysis module 502 is used to perform quantitative analysis on the file operation data of the suspicious process in the file operation data of the process to be detected, and obtain the file operation characteristics of the suspicious process, wherein the file operation characteristics of the suspicious process are determined according to the file operation data in the time period when the encryption behavior of the suspicious process occurs, and the file operation characteristics of the suspicious process are used to characterize the scale of the encryption behavior in the time period when the encryption behavior occurs; The timing analysis module 503 is used to determine whether the suspicious process is ransomware according to whether there is a timing correlation relationship between the hardware data of the suspicious process and the file operation characteristics of the suspicious process.

[0083] In some embodiments, the timing analysis module 503 is specifically used to: input the hardware data of the suspicious process and the file operation characteristics of the suspicious process into a trained timing analysis model to obtain a result of whether the suspicious process is ransomware; wherein the trained timing analysis model is obtained by training an initial timing analysis model through a process data set, and the process data set includes hardware data and file operation data collected from normal programs and ransomware respectively.

[0084] In some embodiments, the process data set is time series data with a step size of a preset length, and the time series data is obtained by evaluating the behavior of the suspicious process every second; wherein, the evaluation of the behavior of the suspicious process every second includes dividing each second into a target number of time steps, the length of each time step is a preset duration, encryption features based on the evaluation of the data of the hardware performance counter generated at each preset duration, and file operation features based on the evaluation of the input and output request packet IRP data.

[0085] In some embodiments, the behavior detection module 501 is specifically used to: input the hardware data of the process to be detected into a trained K-nearest neighbor classifier to obtain the suspicious process; wherein the trained K-nearest neighbor classifier is obtained by training the initial K-nearest neighbor classifier with three types of features extracted from the hardware data set, the three types of features include instruction execution features, memory access features and execution fluctuation features, the instruction execution features are used to characterize the instruction cycle operation status, the memory access features are used to characterize the operation status of the same memory area, and the execution fluctuation features are used to characterize the fluctuation of instruction execution features and memory access features.

[0086] In some embodiments, the file operation characteristics of the suspicious process include the amount of potentially encrypted data and the number of core file operations.

[0087] In some embodiments, the operation analysis module 502 is specifically used to: regularly count the number of processes using a first operation mode to obtain the amount of data potentially encrypted, wherein the first operation mode includes an operation mode that continuously executes read operations and write operations; regularly count the number of processes using a second operation mode to obtain the number of core file operations, wherein the second operation mode includes an operation mode for read operations, write operations, create operations, delete operations, and rename operations.

[0088] In some embodiments, the performance counter includes an instruction execution counter and a memory access counter, and the device also includes a data acquisition module, wherein the data acquisition module is used to collect data of the instruction execution counter and the memory access counter at a preset time interval to obtain hardware data of the process to be detected, the instruction execution counter includes at least one of the number of instructions executed, the number of branch instructions executed, and the number of branch instruction prediction errors, and the memory access counter includes at least one of the number of times the lowest level cache is accessed and the number of times the lowest level cache is missed; feature extraction is performed on input and output request packet IRP data to obtain file operation data of the process to be detected, and the IRP data is obtained by recording information in all IPR requests.

[0089] In the embodiment of the present invention, ransomware can be detected based on the temporal correlation between encryption behavior and file operation behavior, thereby preventing the ransomware from escaping the detection strategy and improving the accuracy of ransomware detection.

[0090] Figure 6 Schematic diagram of the physical structure of the electronic device provided by the present invention. Figure 6As shown, the electronic device 600 may include: a processor 610 , a communications interface 620 , a memory 630 and a communication bus 640 , wherein the processor 610 , the communications interface 620 , and the memory 630 communicate with each other via the communication bus 640 . The processor 610 can call the logic instructions in the memory 630 to execute the ransomware detection method, which includes: performing encryption behavior detection on the hardware data of the process to be detected to determine a suspicious process, wherein the suspicious process is at least one process including suspicious encryption behavior in the process to be detected, and the hardware data of the process to be detected is obtained by obtaining the hardware data of the processor collected by the performance counter; performing quantitative analysis on the file operation data of the suspicious process in the file operation data of the process to be detected to obtain the file operation characteristics of the suspicious process, wherein the file operation characteristics of the suspicious process are determined based on the file operation data within the time period when the encryption behavior occurs in the suspicious process, and the file operation characteristics of the suspicious process are used to characterize the scale of the encryption behavior within the time period when the encryption behavior occurs; and determining whether the suspicious process is ransomware based on whether there is a temporal correlation between the hardware data of the suspicious process and the file operation characteristics of the suspicious process.

[0091] In addition, the logic instructions in the above-mentioned memory 630 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0092] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the ransomware detection method provided by the above methods, which includes: performing encryption behavior detection on hardware data of a process to be detected to determine a suspicious process, wherein the suspicious process is at least one process in the process to be detected that includes suspicious encryption behavior, and the hardware data of the process to be detected is obtained by obtaining hardware data of a processor collected by a performance counter; performing quantitative analysis on file operation data of the suspicious process in file operation data of the process to be detected to obtain file operation features of the suspicious process, wherein the file operation features of the suspicious process are determined based on file operation data within a time period in which the encryption behavior occurs in the suspicious process, and the file operation features of the suspicious process are used to characterize the scale of the encryption behavior within the time period in which the encryption behavior occurs; and determining whether the suspicious process is ransomware based on whether there is a temporal correlation between the hardware data of the suspicious process and the file operation features of the suspicious process.

[0093] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present invention is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive Solid State Disk (SSD)), etc.

[0094] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the ransomware detection method provided by the above methods, the method comprising: performing encryption behavior detection on hardware data of a process to be detected, and determining a suspicious process, wherein the suspicious process is at least one process including suspicious encryption behavior in the process to be detected, and the hardware data of the process to be detected is obtained by acquiring hardware data of a processor collected by a performance counter; performing quantitative analysis on file operation data of the suspicious process in file operation data of the process to be detected, and obtaining file operation characteristics of the suspicious process, wherein the file operation characteristics of the suspicious process are determined based on file operation data within a time period in which the encryption behavior occurs in the suspicious process, and the file operation characteristics of the suspicious process are used to characterize the scale of the encryption behavior within the time period in which the encryption behavior occurs; and determining whether the suspicious process is ransomware based on whether there is a temporal correlation between the hardware data of the suspicious process and the file operation characteristics of the suspicious process.

[0095] The above-mentioned computer-readable storage medium can adopt any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium can be, for example, - but not limited to - an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples (non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM) or flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, a computer-readable storage medium can be any tangible medium containing or storing a program, which can be used by an instruction execution system, device or device or used in combination with it.

[0096] Computer-readable signal media may include a data signal propagated in baseband or as part of a carrier wave, which carries a computer-readable program code. Such propagated data signals may take a variety of forms, including, but not limited to, electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0097] The program code embodied on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wire, optical cable, radio frequency (RF), etc., or any suitable combination of the foregoing.

[0098] Computer program code for performing the operations of the present specification may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0099] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0100] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0101] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for detecting ransomware, characterized in that: include: Perform encryption behavior detection on hardware data of the process to be detected to determine a suspicious process, wherein the suspicious process is at least one process including suspicious encryption behavior among the processes to be detected, and the hardware data of the process to be detected is obtained by acquiring hardware data of a processor collected by a performance counter; Performing quantitative analysis on the file operation data of the suspicious process in the file operation data of the process to be detected to obtain the file operation characteristics of the suspicious process, wherein the file operation characteristics of the suspicious process are determined according to the file operation data in the time period when the encryption behavior in the suspicious process occurs, and the file operation characteristics of the suspicious process are used to characterize the scale of the encryption behavior in the time period when the encryption behavior occurs; Whether the suspicious process is ransomware is determined according to whether there is a temporal correlation relationship between the hardware data of the suspicious process and the file operation characteristics of the suspicious process.

2. The method for detecting ransomware according to claim 1, characterized in that: The determining whether the suspicious process is ransomware according to whether there is a temporal correlation relationship between the hardware data of the suspicious process and the file operation characteristics of the suspicious process includes: Inputting the hardware data of the suspicious process and the file operation features of the suspicious process into the trained timing analysis model to obtain a result of whether the suspicious process is ransomware; The trained timing analysis model is obtained by training an initial timing analysis model with a process data set, and the process data set includes hardware data and file operation data collected from normal programs and ransomware respectively.

3. The method for detecting ransomware according to claim 2, characterized in that: The process data set is time series data with a step size of a preset length, and the time series data is obtained by evaluating the behavior of the suspicious process every second; wherein, the evaluation of the behavior of the suspicious process every second includes dividing each second into a target number of time steps, the length of each time step is a preset duration, the data of the hardware performance counter generated at each preset duration is evaluated as the encryption feature based on the encryption feature, and the data of the input and output request packet IRP is evaluated as the file operation feature based on the file operation feature.

4. The method for detecting ransomware according to claim 1, characterized in that: The encryption behavior detection of the hardware data of the process to be detected to determine the suspicious process includes: Inputting the hardware data of the process to be detected into a trained K nearest neighbor classifier to obtain the suspicious process; Among them, the trained K-nearest neighbor classifier is obtained by training the initial K-nearest neighbor classifier with three types of features extracted from the hardware data set, and the three types of features include instruction execution features, memory access features and execution fluctuation features. The instruction execution features are used to characterize the instruction cycle operation status, the memory access features are used to characterize the operation status of the same memory area, and the execution fluctuation features are used to characterize the fluctuation of instruction execution features and memory access features.

5. The method for detecting ransomware according to claim 1, characterized in that: The file operation characteristics of the suspicious process include the amount of potentially encrypted data and the number of core file operations. The file operation data of the suspicious process in the file operation data of the process to be detected is quantitatively analyzed to obtain the file operation characteristics of the suspicious process, including: Regularly counting the number of processes using a first operation mode to obtain the amount of data potentially encrypted, wherein the first operation mode includes an operation mode in which read operations and write operations are continuously performed; The number of processes using the second operation mode is regularly counted to obtain the number of core file operations, where the second operation mode includes a read operation, a write operation, a create operation, a delete operation, and a rename operation.

6. The method for detecting ransomware according to claim 1, characterized in that: The performance counter includes an instruction execution counter and a memory access counter. Before performing encryption behavior detection on the hardware data of the process to be detected and determining the suspicious process, the method further includes: Collecting data of the instruction execution counter and the memory access counter at preset time intervals to obtain hardware data of the process to be detected, wherein the instruction execution counter includes at least one of the number of executed instructions, the number of executed branch instructions, and the number of branch instruction prediction errors, and the memory access counter includes at least one of the number of times the lowest level cache is accessed and the number of times the lowest level cache is missed; Feature extraction is performed on input / output request packet IRP data to obtain file operation data of the process to be detected, wherein the IRP data is obtained by recording information in all IPR requests.

7. A ransomware detection device, characterized in that: include: A behavior detection module is used to perform encryption behavior detection on the hardware data of the process to be detected, and determine a suspicious process, wherein the suspicious process is at least one process in the process to be detected that includes suspicious encryption behavior, and the hardware data of the process to be detected is obtained by acquiring the hardware data of the processor collected by the performance counter; An operation analysis module, used to perform quantitative analysis on the file operation data of the suspicious process in the file operation data of the process to be detected, and obtain the file operation characteristics of the suspicious process, wherein the file operation characteristics of the suspicious process are determined based on the file operation data in the time period when the encryption behavior in the suspicious process occurs, and the file operation characteristics of the suspicious process are used to characterize the scale of the encryption behavior in the time period when the encryption behavior occurs; The timing analysis module is used to determine whether the suspicious process is ransomware according to whether there is a timing correlation relationship between the hardware data of the suspicious process and the file operation characteristics of the suspicious process.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the method for detecting ransomware according to any one of claims 1 to 6 is implemented.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for detecting ransomware according to any one of claims 1 to 6 is implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method for detecting ransomware according to any one of claims 1 to 6 is implemented.