Encrypted ransomware defense system and method based on CPU system management mode (SMM mode)
By deploying the detection module in the SMM mode of the CPU and deploying the data backup module in the solid-state hard disk firmware, the problem of insufficient detection and data protection capabilities of encrypted ransomware in the prior art is solved, high-precision detection and data security backup are achieved, and the system security and hardware compatibility are improved.
Patent Information
- Application Number
- CN202510092719.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art is difficult to quickly detect and intercept after encrypted ransomware starts running, resulting in loss of user data. The existing defense mechanisms have problems such as insufficient self-protection capabilities, lack of data protection and recovery capabilities, or resulting in insufficient data backup or redundancy.
The encrypted ransomware defense system based on CPU system management mode (SMM mode) is adopted. By deploying detection modules, intercept modules and data backup and recovery modules in the motherboard firmware and SSD device firmware, the off-site update characteristics of the solid state hard disk are used to realize high-precision ransomware detection and data backup.
It realizes the acquisition of high-level semantic information inside the operating system in the SMM mode of the CPU, conducts high-precision ransomware detection, ensures secure backup of data, avoids dependence on the virtual machine management layer, and has higher security and extensive hardware compatibility.
Smart Images

Figure CN120012085A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of security encryption, and in particular relates to an encryption-type ransomware defense system and method based on a CPU system management mode (SMM mode). Background Art
[0002] For encryption-type ransomware, the mainstream defense method is dynamic detection technology based on process behavior characteristics. This research trend is determined by the characteristics of ransomware. Taking encryption-type ransomware as an example, its behavior is almost exactly the same as that of ordinary encryption software. It encrypts data without destroying system files or preventing the normal operation of the system. The only difference is that the encryption key is not in the hands of the user. If you directly perform static analysis on the code and control flow, it is difficult to find its malicious characteristics. In addition, from the perspective of user data security, once the encryption-type ransomware starts running, the user's file data has already begun to be encrypted. Therefore, how to detect and intercept ransomware as quickly as possible and reduce or even avoid user data loss is a major challenge in the research of dynamic detection technology for ransomware.
[0003] In order to protect user data from encrypted ransomware attacks, the industry has proposed three types of defense mechanisms. The first type is based on the operating system defense mechanism [Andrea Continella, Alessandro Guagnelli, Giovanni Zingaro, Giulio De Pasquale, Alessandro Barenghi, Stefano Zanero, and Federico Maggi. Shieldfs: a self-healing, ransomware-aware filesystem. In Stephen Schwab, William K. Robertson, and Davide Balzarotti, editors, Proceedings of the 32nd Annual Conference on Computer Security Applications, ACSAC 2016, Los Angeles, CA, USA, December 5-9, 2016, pages 336–347.], which is similar to traditional anti-virus software. It exists in the operating system in the form of kernel processes or user processes and identifies ransomware processes by monitoring other process behaviors or I / O data. However, this type of defense mechanism has the problem of insufficient self-protection ability: because it is deployed in the operating system kernel, it may be terminated or destroyed by malicious processes with kernel-level administrator privileges, that is, it cannot resist privilege escalation attacks. The second type is a virtualization-based defense mechanism [Fei Tang, Boyang Ma, Jinku Li, Fengwei Zhang, Jipeng Su, and Jian Feng Ma. Ransomspector: An introspection-based approach to detect crypto ransomware. Comput. Secur., 97: 101997, 2020.], that is, the defense system runs on the virtual machine management layer (Hypervisor layer) under the operating system. However, this type of defense mechanism lacks data protection and recovery capabilities.The third type is a defense mechanism based on the hardware characteristics of solid-state drives (SSDs) (i.e., off-site updates) [SungHa Baek, Youngdon Jung, Aziz Mohaisen, Sungjin Lee, and DaeHun Nyang. Ssd-insider: Internal defense of solid-state drive against ransomware with perfect data recovery. In 38th IEEE International Conference on Distributed Computing Systems, ICDCS2018, Vienna, Austria, July 2-6, 2018, pages 875–884.], which uses the hardware characteristics of solid-state drives that cannot be overwritten to achieve hardware-level data backup without data copy overhead, thereby ensuring the security of the encrypted original data. However, this type of defense mechanism lacks high-level semantic information in the operating system, and on the one hand, it cannot achieve high-precision ransomware detection, and on the other hand, it will cause insufficient or redundant data backup, resulting in data loss or excessive storage space overhead. Summary of the invention
[0004] In order to overcome the problems existing in the above-mentioned prior art, the purpose of the present invention is to disclose an encrypted ransomware defense system and method based on the CPU system management mode (SMM mode). Based on the hardware characteristics of the solid-state drive "off-site update", the detection module is deployed in the mainboard firmware, and the data input and output (I / O) interception module and the data backup and recovery module are deployed in the SSD solid-state drive firmware; in this way, the detection module can obtain the context information (such as process, file activity, etc.) inside the operating system in the system management mode of the CPU, and realize high-precision ransomware detection based on this information; at the same time, in order to ensure that the detection module accurately obtains the context information closely related to the intercepted I / O in the SMM mode; the present invention also proposes a method for initiating an interrupt signal by the solid-state drive to make the CPU enter the system management mode; the method uses a message signal interrupt (MSI-X interrupt) to send a special mode (SMI mode) MSI-X interrupt to the host, so that the CPU recognizes the interrupt signal as an SMI interrupt, and the SMI interrupt is the only way to enter the SMM mode, thereby finally making the CPU enter the SMM mode.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] An encrypted ransomware defense system based on a CPU system management mode (SMM mode) comprises a mainboard firmware and an SSD device firmware, wherein the mainboard firmware is embedded with an information collection module, a detection module and a first communication module, and the information collection module, the detection module and the first communication module are encapsulated as an SMI interrupt processing subroutine, and the SMI interrupt processing subroutine is registered in the SMI interrupt processing program list of the mainboard firmware; the SSD device firmware is embedded with an interception module, an arbitration module, a second communication module and a data backup and recovery module; the mainboard firmware detects the ransomware and outputs the detection result; the SSD device firmware identifies and processes each I / O command passed into the SSD device firmware according to the detection result, and retains all data attacked by the ransomware.
[0007] The signal input end of the interception module in the SSD device firmware is connected to the NVMe driver in the operating system to intercept all I / O commands sent to the SSD device by the NVMe driver. The signal output end of the interception module is respectively connected to the signal input end of the arbitration module and the information collection module in the mainboard firmware. The signal output end of the arbitration module is connected to the signal input end of the data backup and recovery module. The output end of the data backup and recovery module is connected to the NAND flash memory. The signal output end of the information collection module is connected to the signal input end of the detection module. The signal output end of the detection module is connected to the signal input end of the first communication module. The first communication module communicates and interacts with the second communication module in the SSD device firmware, and the second communication module communicates and interacts with the arbitration module.
[0008] The defense methods based on the above defense system specifically include:
[0009] First, the interception module intercepts all I / O commands sent by the NVMe driver to the SSD device, and sends a special mode MSI-X interrupt to the CPU, so that the CPU recognizes it as an SMI interrupt and enters the CPU's SMM mode;
[0010] Secondly, the information collection module in the motherboard firmware collects contextual information related to the intercepted I / O commands and sends this information to the detection module;
[0011] Then, the detection module analyzes the received context information based on the context information inside the operating system and determines whether the received information matches the ransomware behavior;
[0012] Next, the first communication module in the mainboard firmware sends the detection result to the SSD device firmware, and the second communication module in the SSD device firmware receives the detection result;
[0013] Finally, the arbitration module in the SSD device firmware executes different processes based on the detection results.
[0014] The delivery mode field of the MSI-X interrupt message of the special mode, ie, the MSI-X interrupt message, is set to the SMI mode.
[0015] The arbitration module in the SSD device firmware executes different processes according to the detection results, specifically: when the intercepted I / O command comes from the ransomware process and is a write request, the data backup and recovery module executes the operation of retaining the original data; when the intercepted I / O command does not come from the ransomware process, it is further determined whether the intercepted I / O command comes from the data recovery program in the data backup and recovery module. If so, and it is a read request, the data backup and recovery module executes the operation of restoring the original data; if the intercepted I / O command does not come from the data recovery program, normal data read and write operations are performed.
[0016] Compared with the prior art, the present invention has the following beneficial effects:
[0017] 1. The present invention uses a hardware-level defense system, and its detection system runs in the SMM mode of the CPU. Compared with the existing detection system based on the operating system kernel and virtualization technology, it has higher security permissions, so it has stronger isolation and security.
[0018] 2. The present invention detects ransomware behavior outside the operating system. Compared with the existing detection system based on virtualization technology that implements this function, the present invention obtains high-level semantic information (such as processes, file objects, etc.) within the operating system in SMM mode, and implements high-precision ransomware detection based on this rich context information; it avoids dependence on the virtual machine management layer (Hypervisor), has wider hardware compatibility and applicability, higher performance, and higher security.
[0019] 3. The present invention utilizes the hardware characteristics of the solid-state drive and can be deployed in any motherboard firmware and SSD device firmware in the form of an independent functional module. It does not rely on the operating system kernel or the specific technology of the device manufacturer, and realizes efficient hardware-level data backup to ensure the security of the original data.
[0020] In summary, the design of the present invention based on the motherboard firmware not only gets rid of the dependence on the virtual machine management layer (Hypervisor), but also effectively overcomes the limitations of insufficient computing power and semantic information in solutions based purely on SSD device firmware, thereby maintaining high-precision detection capabilities while also greatly improving its own security. Secondly, the detection module of this technology runs in the SMM mode of the CPU, and can safely and transparently obtain contextual information inside the operating system to achieve high-precision ransomware detection based on advanced semantics. Third, this technology is a real-time defense system that can accurately identify and process each I / O command passed into the SSD based on the detection results, and retain all data attacked by ransomware through backup technology based on the hardware characteristics of the SSD. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is the overall structural diagram of the present invention.
[0022] Figure 2 The present invention is a flow chart of detecting encrypted ransomware and data backup and recovery. DETAILED DESCRIPTION
[0023] The present invention will be further described in detail below in conjunction with the accompanying drawings.
[0024] See also Figure 1 , an encrypted ransomware defense system based on CPU system management mode (SMM mode), including a mainboard firmware and an SSD device firmware, wherein the mainboard firmware is embedded with an information collection module, a detection module and a first communication module, and the information collection module, the detection module and the first communication module are encapsulated as an SMI interrupt processing subroutine, and the SMI interrupt processing subroutine is registered in the SMI interrupt processing program list of the mainboard firmware to ensure that when the SMI interrupt is triggered, the information collection module, the detection module and the first communication module can be called normally; the SSD device firmware is embedded with an interception module, an arbitration module, a second communication module and a data backup and recovery module; the mainboard firmware detects the ransomware and outputs the detection result; the SSD device firmware identifies and processes each I / O command passed into the SSD device firmware according to the detection result, and retains all data attacked by the ransomware.
[0025] The signal input end of the interception module in the SSD device firmware is connected to the NVMe driver in the operating system to intercept all I / O commands sent to the SSD device by the NVMe driver. The signal output end of the interception module is respectively connected to the signal input end of the arbitration module and the information collection module in the mainboard firmware. The signal output end of the arbitration module is connected to the signal input end of the data backup and recovery module. The output end of the data backup and recovery module is connected to the NAND flash memory. The signal output end of the information collection module is connected to the signal input end of the detection module. The signal output end of the detection module is connected to the signal input end of the first communication module. The first communication module communicates and interacts with the second communication module in the SSD device firmware, and the second communication module communicates and interacts with the arbitration module.
[0026] See also Figure 2 The defense method based on the above defense system specifically includes:
[0027] First, the interception module intercepts all I / O commands sent by the NVMe driver to the SSD device, and sends a special mode of MSI-X interrupt to the CPU, that is, the delivery mode field of the MSI-X interrupt message is set to SMI mode, so that the CPU recognizes it as an SMI interrupt and enters the SMM mode of the CPU;
[0028] Secondly, the information collection module in the motherboard firmware collects contextual information related to the intercepted I / O commands and sends this information to the detection module;
[0029] Then, the detection module analyzes the received context information based on the context information inside the operating system and determines whether the received information matches the ransomware behavior;
[0030] Next, the first communication module in the mainboard firmware sends the detection result to the SSD device firmware, and the second communication module in the SSD device firmware receives the detection result;
[0031] Finally, the arbitration module in the SSD device firmware executes different processes based on the detection results: when the intercepted I / O command comes from the ransomware process and is a write request, the data backup and recovery module executes the operation of retaining the original data; when the intercepted I / O command does not come from the ransomware process, it is further determined whether the intercepted I / O command comes from the data recovery program in the data backup and recovery module. If so, and it is a read request, the data backup and recovery module executes the operation of restoring the original data; if the intercepted I / O command does not come from the data recovery program, normal read and write data operations are performed.
[0032] The effect of the present invention can be further verified by the following experiments:
[0033] 1. Experimental conditions
[0034] A test computer with the following configurations: x64 processor, MSI Z690A motherboard;
[0035] One status monitoring computer, with any configuration;
[0036] An AMD UltraScale (XCKU060) FPGA development board as an SSD device for testing;
[0037] 3,359 ransomware samples;
[0038] 300 user files in various file formats.
[0039] 2. Experimental Setup
[0040] Install Windows 10 operating system on the test computer and status monitoring computer respectively;
[0041] Flash the mainboard firmware that has integrated the information collection module, the detection module and the first communication module of the present invention into the mainboard BIOS chip of the test computer, and flash the SSD device firmware that has integrated the interception module, the arbitration module, the second communication module and the data backup and recovery module of the present invention into the FPGA development board as the test SSD device, and connect the test SSD device to the test computer;
[0042] The serial port (COM port) signal of the test computer is connected to the USB port of the status monitoring computer through an adapter cable, so that the status information of the system of the present invention is received and monitored in the status monitoring computer.
[0043] 3. Experimental process
[0044] First, start two computers respectively, and confirm that each functional module of the present invention starts normally from the information displayed on the status monitoring computer;
[0045] Secondly, import 300 user files into the test SSD device;
[0046] Next, import the first ransomware sample into the test computer and run it, and observe the log information of the status monitoring computer to confirm whether the encryption ransomware is successfully detected;
[0047] Then, based on the log information, confirm whether the data backup and recovery module in the test SSD device successfully backs up the attacked data;
[0048] After that, run a data recovery program on the test computer and restore all the attacked files;
[0049] Finally, verify the integrity of the recovered files;
[0050] After completing the above experimental process, reset the operating system and SSD device of the test computer and restart the next round of experiments until all ransomware sample tests are completed. The experimental results are shown in Table 1:
[0051] Table 1 Experimental results
[0052]
[0053]
[0054] As can be seen from Table 1, the present invention can effectively detect encrypted ransomware samples without false positives or false negatives. At the same time, the present invention can completely restore all user files encrypted by the ransomware.
Claims
1. An encrypted ransomware defense system based on CPU system management mode, including motherboard firmware and SSD device firmware, characterized in that: The mainboard firmware is embedded with an information collection module, a detection module and a first communication module, and the information collection module, the detection module and the first communication module are encapsulated as an SMI interrupt processing subroutine, and the SMI interrupt processing subroutine is registered in the SMI interrupt processing subroutine list of the mainboard firmware; The SSD device firmware is embedded with an interception module, an arbitration module, a second communication module and a data backup and recovery module; The motherboard firmware detects ransomware and outputs the detection results; The SSD device firmware identifies and processes each I / O command passed into the SSD device firmware based on the detection result, and retains all data attacked by the ransomware.
2. The encrypted ransomware defense system based on CPU system management mode according to claim 1, characterized in that: The signal input end of the interception module in the SSD device firmware is connected to the NVMe driver in the operating system to intercept all I / O commands sent to the SSD device by the NVMe driver. The signal output end of the interception module is respectively connected to the signal input end of the arbitration module and the information collection module in the mainboard firmware. The signal output end of the arbitration module is connected to the signal input end of the data backup and recovery module. The output end of the data backup and recovery module is connected to the NAND flash memory. The signal output end of the information collection module is connected to the signal input end of the detection module. The signal output end of the detection module is connected to the signal input end of the first communication module. The first communication module communicates and interacts with the second communication module in the SSD device firmware, and the second communication module communicates and interacts with the arbitration module.
3. A defense method for an encrypted ransomware defense system based on a CPU system management mode, characterized in that: The specific steps include: First, the interception module intercepts all I / O commands sent by the NVMe driver to the SSD device, and sends a special mode MSI-X interrupt to the CPU, so that the CPU recognizes it as an SMI interrupt and enters the CPU's SMM mode; Secondly, the information collection module in the motherboard firmware collects contextual information related to the intercepted I / O commands and sends this information to the detection module; Then, the detection module analyzes the received context information based on the context information inside the operating system and determines whether the received information matches the ransomware behavior; Next, the first communication module in the mainboard firmware sends the detection result to the SSD device firmware, and the second communication module in the SSD device firmware receives the detection result; Finally, the arbitration module in the SSD device firmware executes different processes based on the detection results.
4. The defense method of the encrypted ransomware defense system based on the CPU system management mode according to claim 3 is characterized in that: The delivery mode (DeliveryMode) field of the MSI-X interrupt message of the special mode, ie, the MSI-X interrupt message, is set to the SMI mode.
5. The defense method of the encrypted ransomware defense system based on CPU system management mode according to claim 3 is characterized in that: The arbitration module in the SSD device firmware executes different processes according to the detection results, specifically: when the intercepted I / O command comes from the ransomware process and is a write request, the data backup and recovery module executes the operation of retaining the original data; when the intercepted I / O command does not come from the ransomware process, it is further determined whether the intercepted I / O command comes from the data recovery program in the data backup and recovery module. If so, and it is a read request, the data backup and recovery module executes the operation of restoring the original data; If the intercepted I / O command does not come from the data recovery program, normal data read and write operations are performed.