Harmless verification method and device for ransomware virus encryption behavior protection capability
By building a bait file in the target system and simulating ransomware encryption behavior, obtaining system response information and comprehensively analyzing it, the problem of inability to accurately judge the system's current protection capabilities in the existing technology is solved, and the accuracy of protection capabilities verification is improved.
Patent Information
- Application Number
- CN202411909029.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2044-12-24
AI Technical Summary
The prior art determines the system's protection capability through the number of successful encryption times, which cannot accurately reflect the current protection capability. The successful encryption does not necessarily mean that the system has no protection capability, resulting in a low accuracy in determining the protection capability.
By building a bait file in the target system, simulating the encryption behavior of ransomware, and obtaining the system's response information to the encryption process, including restoring the response information and intercepting the response information, comprehensively analyzing the identity verification value, encryption and restoring time of the bait file, verifying the system's protection capabilities.
It improves the accuracy of the system's protection capability verification for ransomware encryption behavior, can more truly reflect the current system's protection status, and reduces misjudgments caused by inaccurate historical data.
Smart Images

Figure CN120012098A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method and device for verifying the harmlessness of ransomware encryption behavior protection capabilities. Background Art
[0002] With the acceleration of the informatization process, the frequency and scope of ransomware attacks are expanding. Ransomware encrypts files in the target system and forces victims to pay ransom to obtain decryption keys, which may lead to permanent loss or damage of important data and other unnecessary losses. Based on this, it is necessary to detect the protection capabilities of the system to discover and repair security vulnerabilities and weaknesses in the system, thereby improving enterprise data security and avoiding other losses.
[0003] At present, the protection capability of the system is usually determined by the number of successful encryptions of files in the system by ransomware in a historical period of time. However, since the software in the system is constantly updated and upgraded, this method of determining the protection capability based on historical information cannot accurately reflect the current system's protection capability. At the same time, since successful encryption does not indicate that the system has no protection capability, the existing method of determining the system's protection capability based only on the number of successful encryptions will result in a low accuracy in determining the system's protection capability. Summary of the invention
[0004] The present invention provides a harmless verification method and device for the protection capability of ransomware encryption behavior, which mainly aims to improve the verification accuracy of the system's protection capability against ransomware encryption behavior.
[0005] According to a first aspect of the present invention, a method for verifying the harmlessness of the protection capability of ransomware encryption behavior is provided, comprising:
[0006] In response to a verification signal of the target system's ability to protect against ransomware encryption behavior, construct a bait file in the target system and determine an original identity verification value of the bait file;
[0007] Simulating the behavior of the ransomware virus, encrypting the bait file at a preset encryption start time using a preset encryption method, and obtaining response information of the target system to the encryption process during the encryption process of encrypting the bait file;
[0008] If the response information is restoration response information for the encrypted bait file, then obtaining the restoration start time and restoration completion time for the target system to restore the encrypted bait file, and obtaining the current identity verification value of the restored bait file;
[0009] Based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time, the protection capability of the target system against the ransomware encryption behavior is verified.
[0010] Optionally, after obtaining the response information of the target system to the encryption process, the method further includes:
[0011] If the response information is interception response information for the encryption process, then the target system's process identification time for the encryption process, the target system's interception start time for the encryption process, the target system's interception operation information for the encryption process (whether to isolate other files in the same path as the bait file, whether to trigger a malicious encryption alarm, the difference between the termination identity check value and the original identity check value of the bait file after encryption), and the target system's interception completion time for the encryption process are obtained;
[0012] Determining a threat detection capability coefficient of the target system for the encryption process based on the process identification time and the preset encryption start time;
[0013] Determining an interception response speed coefficient of the target system to the encryption process based on the preset encryption start time and the interception start time;
[0014] Determining an interception efficiency coefficient of the target system for the encryption process based on the interception start time and the interception completion time;
[0015] Determining, based on the interception operation information, an interception effect evaluation coefficient of the target system on the encryption process;
[0016] Based on the threat detection capability coefficient, the interception response speed coefficient, the interception efficiency coefficient, and the interception effect evaluation coefficient, the protection capability of the target system against the ransomware encryption behavior is verified.
[0017] Optionally, the step of obtaining the restoration start time and restoration completion time of the target system for restoring the encrypted bait file, and obtaining the current identity verification value of the restored bait file, includes:
[0018] Determining a method for restoring the encrypted bait file by the target system;
[0019] The restoration start time and restoration completion time of the target system for restoring the encrypted bait file according to the restoration method are obtained, and the current identity verification value of the bait file restored according to the restoration method is obtained.
[0020] Optionally, the restoration method includes a backup restoration method and a decryption restoration method;
[0021] The obtaining of the restoration start time and restoration completion time of the target system for restoring the encrypted bait file according to the restoration method, and obtaining the current identity verification value of the bait file restored according to the restoration method, includes:
[0022] In the backup and restore mode, determining the current location of the bait file, and determining the backup location after backing up the bait file at the current location;
[0023] In response to the target system's response information on the encrypted bait file's retrieval, determine the target system's retrieval start time and retrieval completion time for retrieval of the bait file at the backup location to the current location, obtain a current identity verification value of the bait file after retrieval to the current location, and determine the retrieval start time as the restore start time and the retrieval completion time as the restore completion time;
[0024] In the decryption and restoration mode, in response to the decryption response information of the target system to the encrypted bait file, the decryption start time and the decryption completion time of the target system for decrypting the encrypted bait file are determined, and the current identity verification value of the decrypted bait file is obtained, and the decryption start time is determined as the restoration start time and the decryption completion time is determined as the restoration completion time.
[0025] Optionally, the verifying the protection capability of the target system against ransomware encryption behavior based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time includes:
[0026] Determining a restoration integrity coefficient of the target system for the decoy file based on the original identity verification value and the current identity verification value;
[0027] Determining a restoration speed coefficient of the target system for the decoy file based on the restoration start time and the restoration completion time;
[0028] Determining a recovery speed coefficient of the target system for the ransomware encryption behavior based on the preset encryption start time and the restoration completion time;
[0029] Based on the restoration completeness coefficient, the restoration speed coefficient, and the recovery speed coefficient, the protection capability of the target system against the encryption behavior of the ransomware virus is verified.
[0030] Optionally, constructing a bait file in the target system includes:
[0031] Obtaining encryption tendency information of the ransomware virus and obtaining predicted demand information for protection capabilities of the target system;
[0032] Determining the type of bait file and the content of the bait file based on the encryption tendency information and the predicted demand information;
[0033] The bait file is constructed in the target system based on the bait file type and the bait file content.
[0034] Optionally, before encrypting the decoy file at a preset encryption start time by using a preset encryption method in simulating the behavior of the ransomware virus, the method further includes:
[0035] Determine the anti-attack capability information, encryption speed information, and occupied resource information of the encryption method to be selected based on the predicted demand information of the protection capability of the target system and the available memory resource information of the target system;
[0036] The preset encryption method is determined among different encryption methods based on the anti-attack capability information, the encryption speed information, and the occupied resource information.
[0037] According to a second aspect of the present invention, a harmless verification device for protecting against ransomware encryption behavior is provided, comprising:
[0038] A construction unit, configured to construct a bait file in the target system in response to a verification signal of the target system's ability to protect against ransomware encryption behavior, and determine an original identity verification value of the bait file;
[0039] An encryption simulation unit, used for simulating the behavior of the ransomware virus to encrypt the bait file at a preset encryption start time using a preset encryption method, and in the encryption process of encrypting the bait file, obtaining the response information of the target system to the encryption process;
[0040] an acquiring unit, configured to acquire, if the response information is restoration response information for the encrypted bait file, a restoration start time and a restoration completion time for the target system to restore the encrypted bait file, and acquire a current identity verification value of the restored bait file;
[0041] A determination unit is used to verify the protection capability of the target system against the encryption behavior of the ransomware virus based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time.
[0042] According to a third aspect of the present invention, there is provided a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements harmless verification of the above-mentioned ransomware encryption behavior protection capability.
[0043] According to a fourth aspect of the present invention, there is provided a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, harmless verification of the above-mentioned ransomware encryption behavior protection capability is achieved.
[0044] According to a harmless verification method and device for ransomware encryption behavior protection capability provided by the present invention, compared with the current method of determining the system's protection capability by the number of successful and failed encryptions of files in the system by the ransomware in a historical time period, the present invention responds to a verification signal of the target system's protection capability against ransomware encryption behavior, constructs a bait file in the target system, and determines the original identity verification value of the bait file; and simulates the behavior of the ransomware to encrypt the bait file at a preset encryption start time using a preset encryption method, and in the encryption process of encrypting the bait file, obtains the target system's response information to the encryption process; then, if the response information is restoration response information for the encrypted bait file, then obtains the restoration start time and restoration completion time for the target system to restore the encrypted bait file, and obtains the current identity verification value of the restored bait file; and finally verifies the target system's protection capability against ransomware encryption behavior based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time. Therefore, when receiving the prediction signal of the target system's protection capability, the protection capability of the target system is verified by encrypting the bait file through on-site simulation of the ransomware behavior, which can reflect the real protection capability of the target system in the current state. At the same time, the protection capability of the target system against the ransomware encryption behavior is verified by comprehensively analyzing various factors such as the original identity verification value and the current identity verification value of the bait file, the preset encryption start time, the restoration start time, and the restoration completion time, which can improve the verification accuracy of the system's protection capability. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0046] Figure 1 A flow chart of a method for verifying the harmlessness of ransomware encryption behavior protection capability provided by an embodiment of the present invention is shown;
[0047] Figure 2 A flowchart of another method for verifying the harmlessness of the ransomware encryption behavior protection capability provided by an embodiment of the present invention is shown;
[0048] Figure 3 A schematic diagram of the structure of a harmless verification device for protecting against encryption behavior of ransomware provided by an embodiment of the present invention is shown;
[0049] Figure 4 A schematic diagram of the structure of another harmlessness verification device for protecting against encryption behavior of ransomware provided by an embodiment of the present invention is shown;
[0050] Figure 5 A schematic diagram of the physical structure of a computer device provided by an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0051] The present invention will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that the embodiments and features in the embodiments of the present application can be combined with each other without conflict.
[0052] At present, determining the system's protection capability by the number of successful encryptions of files in the system by ransomware within a historical period cannot accurately reflect the current system's protection capability. At the same time, since successful encryption does not indicate that the system has no protection capability, the existing method of determining the system's protection capability based only on the number of successful encryptions will result in a low accuracy in determining the system's protection capability.
[0053] In order to solve the above problems, an embodiment of the present invention provides a harmless verification method for the protection capability of ransomware encryption behavior, such as Figure 1 As shown, the method includes:
[0054] 101. In response to a verification signal of the target system's ability to protect against ransomware encryption behavior, a bait file is constructed in the target system, and an original identity verification value of the bait file is determined.
[0055] The target system is a specific computer system or network that needs to be evaluated for protection capabilities. The target system can be any type of computer system, including but not limited to servers, personal computers, mobile devices, IoT devices, etc. Ransomware is a type of malware whose main purpose is to illegally gain benefits by encrypting the victim's files. The original identity verification value of the bait file can be a hash value, digital signature, message authentication code, or other verification value that uniquely identifies the bait file identity.
[0056] For the embodiment of the present invention, when receiving the harmless verification signal of the protection capability of ransomware encryption behavior, a bait file is created in the commonly used storage path of the data file of the target system to be predicted (such as desktop, ~\documents (documents) ~\downloads (downloads), \tmp (temporary files), etc.), and the type of the bait file can be selected according to the prediction requirements, including but not limited to image files, text files, audio files, etc., and the content of the bait file can also be set according to the prediction requirements. The content of the bait file will not cause direct damage to the system or user, and it should also avoid containing any sensitive information, etc., such as the bait file can be a randomly generated password book, the type is txt, and after the bait file is created, the original identity verification value of the bait file is determined, such as a hash value, etc. After the bait file is constructed in the preset folder of the target system, the bait file and other files in the same folder can be backed up to other file storage locations of the target system, such as backing up to a new directory at the same level as the parent directory of the bait file, and the original identity verification values of other files are determined and recorded. So that it can be used in the subsequent process of detecting the protection capability of the target system. When receiving a prediction signal of the protection capability of the target system, the embodiment of the present invention verifies the protection capability of the target system by encrypting and testing the bait file through on-site simulation of the ransomware behavior, which can reflect the real protection capability of the target system in the current state and avoid the problem that the use of historical data cannot accurately reflect the protection capability of the system in the current state. At the same time, the embodiment of the present invention predicts the protection capability of the target system by creating a bait file, and by monitoring the state changes of the bait file, it can be understood whether the system can timely identify and intercept the attack behavior of the ransomware virus, reducing the risk of real data being damaged during the test process, thereby ensuring the harmless verification of the embodiment of the present invention.
[0057] In another embodiment of the present invention, it is also possible to determine whether the target system meets the preset conditions for protection capability detection according to the construction process of the bait file. Based on this, the method includes: determining whether there is an abnormality in the construction process of the bait file. If there is an abnormality, it is determined that the target system does not meet the preset conditions for protection capability prediction, and the protection capability prediction of the target system is prohibited. Otherwise, it is determined whether there is an abnormality in the backup process of the bait file. If there is an abnormality, it is determined that the target system does not meet the preset conditions for protection capability prediction, and the protection capability prediction of the target system is prohibited. Specifically, the bait file generation is abnormal. When generating a bait file for encryption testing, the task fails to successfully create the bait file, or the file content generation does not meet expectations. This abnormality will cause subsequent tasks (such as backup, encryption) to fail to proceed normally. Backup failure. During the execution of the task, when the bait file and other files in the target directory are copied or moved to the backup directory, one of the following problems occurs, resulting in backup abnormality: due to path problems, disk space, file access conflicts, concurrency problems, hardware abnormalities, etc., the bait file creation process or backup process will be intercepted by the security device as a potential danger and intercepted, resulting in the bait file creation task and backup task being interrupted or failed. When the above exceptions occur, it means that it is not suitable to perform a protection capability test on the target system at this time. If the test is forced, it will cause damage to the target system or inaccurate testing will occur. Therefore, the embodiment of the present invention determines whether the target system meets the preset conditions for protection capability detection. If it meets the preset conditions, it will perform a protection capability test on it, which can avoid system failures or inaccurate testing problems.
[0058] 102. The behavior of simulating the ransomware virus is to encrypt the bait file at the preset encryption start time using the preset encryption method, and in the encryption process of encrypting the bait file, obtain the target system's response information to the encryption process.
[0059] Among them, the preset encryption method can be an encryption method commonly used by ransomware viruses, and can also be selected according to the predicted demand for the protection capability of the target system. For example, if the predicted demand for the protection capability of the target system is high, the preset encryption method can select an encryption method that is more difficult to crack; if the predicted demand for the protection capability of the target system is low, the preset encryption method can select an encryption method that is relatively easy to crack; the preset encryption start time can be set according to actual needs; the response information includes restoration response information and interception response information. The restoration response information refers to the operation signal for restoring the encrypted bait file, and the interception response information refers to the operation signal for intercepting the encryption process of the bait file to avoid encrypting the bait file.
[0060] For the embodiment of the present invention, the behavior of the ransomware virus is simulated. When the preset encryption start time is reached, the bait file is encrypted using the preset encryption method. When the encryption starts, the response information of the target system to the encryption process is obtained in real time to determine whether the target system adopts the method of intercepting the encryption process or the method of restoring the encrypted bait file for this encryption process. That is, whether it is the method of intercepting the encryption process or restoring the encrypted bait file, it can reflect the target system's protection ability against the encryption behavior of the ransomware virus. If it can be determined through the response information of the target system that the protection measure of the target system against the ransomware encryption behavior is: intercepting the encryption process of the bait file, then under this protection measure, in order to verify the protection capability of the target system, the method includes: if the response information is interception response information for the encryption process, then obtaining the process identification time of the encryption process by the target system, the interception start time of the encryption process by the target system, the interception operation information of the encryption process by the target system, and the interception completion time of the encryption process by the target system; based on the process identification time and the preset encryption start time, determining the threat detection capability coefficient of the encryption process by the target system; based on the preset encryption start time and the interception start time, determining the interception response speed coefficient of the encryption process by the target system; based on the interception start time and the interception completion time, determining the interception efficiency coefficient of the encryption process by the target system; based on the interception operation information, determining the interception effect evaluation coefficient of the encryption process by the target system; based on the threat detection capability coefficient, the interception response speed coefficient, the interception efficiency coefficient, and the interception effect evaluation coefficient, verifying the protection capability of the target system against the ransomware encryption behavior.
[0061] The interception operation information includes: whether to isolate other files in the same path as the bait file, whether to trigger a malicious encryption alarm, the difference between the termination identity verification value of the encrypted bait file and the original identity verification value, etc.
[0062] Specifically, the time interval between the process identification time and the preset encryption start time is determined, and based on the time interval, the threat detection capability coefficient corresponding to the time interval is determined in the preset detection capability coefficient configuration table (the preset detection capability coefficient configuration table records the threat capability detection coefficients corresponding to different time intervals). If the time interval is long, the corresponding threat capability detection coefficient is small, and if the time interval is short, the corresponding threat capability detection coefficient is large. The larger threat capability detection coefficient reflects that the target system has a stronger threat detection capability for the encryption process. At the same time, the time interval between the preset encryption start time and the interception start time is determined, and based on the time interval, the interception response speed coefficient corresponding to the time interval is determined in the preset interception response speed coefficient configuration table (the preset interception response speed coefficient configuration table records the interception response speed coefficients corresponding to different time intervals). If the time interval is long, the corresponding interception response speed coefficient is small, and if the time interval is short, the corresponding interception response speed coefficient is large. The larger interception response speed coefficient reflects that the target system has a faster interception response speed for the encryption process. At the same time, the time interval between the interception start time and the interception completion time is determined, and based on the time interval, the interception efficiency coefficient corresponding to the time interval is determined in the preset interception efficiency coefficient configuration table (the preset interception efficiency coefficient configuration table records the interception efficiency coefficients corresponding to different time intervals). If the time interval is longer, the corresponding interception efficiency coefficient is smaller, and if the time interval is shorter, the corresponding interception efficiency coefficient is larger. A larger interception efficiency coefficient reflects that the target system has a higher interception efficiency for the encryption process. At the same time, it is determined whether the target system has isolated other files with the same path as the bait file when intercepting encryption, whether a malicious encryption alarm is triggered, and at the same time, the difference between the termination identity verification value and the original identity verification value of the bait file after the encryption is terminated is determined. If the target system has not isolated other files with the same path as the bait file, has not triggered a malicious encryption alarm, and the difference between the termination identity verification value and the original identity verification value of the bait file after the encryption is terminated is large (indicating that the interception effect is poor), then it is determined that the target system has a small interception effect evaluation coefficient for the encryption process. If the target system has isolated other files with the same path as the bait file, triggered a malicious encryption alarm, and the difference between the termination identity verification value and the original identity verification value of the bait file after the encryption is terminated is small or there is no difference, then it is determined that the target system has a large interception effect evaluation coefficient for the encryption process (indicating that the interception effect is good). The specific value of the interception effect evaluation coefficient can be determined according to the completion status of each item of information in the interception operation information. For example, in the above three items (item 1: whether to isolate other files in the same path as the bait file, item 2: whether to trigger a malicious encryption alarm, item 3: the difference between the termination identity verification value and the original identity verification value of the encrypted bait file), the interception effect evaluation coefficient is set by the number of items that are met and which specific item is met.Further, after determining the threat detection capability coefficient, interception response speed coefficient, interception efficiency coefficient, and interception effect evaluation coefficient of the target system to the encryption process, the weight coefficients corresponding to the threat detection capability coefficient, interception response speed coefficient, interception efficiency coefficient, and interception effect evaluation coefficient are determined respectively, and then the threat detection capability coefficient, interception response speed coefficient, interception efficiency coefficient, and interception effect evaluation coefficient are added according to the weight coefficient to obtain the comprehensive interception effect coefficient of the target system to the encryption process, and finally the protection capability of the target system is determined according to the comprehensive interception effect coefficient, such as the larger the comprehensive interception effect coefficient, the stronger the protection capability of the target system, and the smaller the comprehensive interception effect coefficient, the weaker the protection capability of the target system. The implementation of the present invention determines its protection capability by comprehensively analyzing the threat detection capability, interception response speed, interception efficiency, and interception effect of the target system to the encryption process, which can avoid the problem of inaccurate judgment caused by judging the system protection capability only according to the number of successful encryptions.
[0063] 103. If the response information is restoration response information for the encrypted bait file, then the restoration start time and restoration completion time of the target system for restoring the encrypted bait file are obtained, as well as the current identity verification value of the restored bait file.
[0064] Specifically, if it can be determined through the response information of the target system that the protection measure of the target system against the encryption behavior of the ransomware virus is: restore the encrypted bait file, that is, restore the encrypted bait file to the state before encryption. Under this protection measure, in order to verify the protection capability of the target system, it is first necessary to record the restoration start time and restoration completion time of the target system to restore the encrypted bait file, and at the same time, it is also necessary to determine the current identity verification value of the restored bait file, the form of which should be the same as the original identity verification value of the bait file before encryption, and then comprehensively analyze the original identity verification value, current identity verification value, restoration start time, and restoration completion time of the bait file to determine the protection capability of the target system. By evaluating the restoration capability of the encrypted bait file, the embodiment of the present invention can more comprehensively understand the recovery capability of the target system after being attacked. The interception capability mainly stays at the surface protection level, that is, preventing the attacker from encrypting the file or executing malicious code, while the restoration capability involves a deeper level of protection, that is, after the file is encrypted, the system can quickly take measures to restore it, that is, the restoration capability provides a lasting protection effect, even if the system is attacked, the system state can be restored by restoring the file. Therefore, the present invention determines its protection capability in real time through the target system's ability to restore the encrypted file, which can improve the comprehensiveness and accuracy of the determination of the system's protection capability.
[0065] 104. Verify the target system's protection against ransomware encryption behavior based on the original identity verification value, current identity verification value, preset encryption start time, restore start time, and restore completion time.
[0066] Among them, the preset encryption start time refers to the time point when the simulated ransomware behavior begins to encrypt the bait file; the restore start time refers to the time point when the target system starts to perform the file restore operation after detecting the ransomware encryption behavior; the restore completion time refers to the time point when the system completes the file restore operation.
[0067] For an embodiment of the present invention, when the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time are obtained, it is necessary to conduct a comprehensive analysis of the above information to determine the protection capability of the target system. Based on this, the method includes: determining the restoration completeness coefficient of the target system for the bait file based on the original identity verification value and the current identity verification value; determining the restoration speed coefficient of the target system for the bait file based on the restoration start time and the restoration completion time; determining the recovery speed coefficient of the target system for the ransomware encryption behavior based on the preset encryption start time and the restoration completion time; and verifying the protection capability of the target system against the ransomware encryption behavior based on the restoration completeness coefficient, the restoration speed coefficient, and the recovery speed coefficient.
[0068] Specifically, the difference between the original identity verification value and the current identity verification value is determined, and based on the size of the difference, a corresponding restoration integrity coefficient is set for it. If the difference is large, it indicates that the ransomware has destroyed the system's files, or the attacker has obtained legitimate files, then the corresponding restoration integrity coefficient is small; if the difference is small, it means that the system can still maintain the validity of the files after the ransomware incident occurs, then the corresponding restoration integrity coefficient is large. By restoring the time interval between the start time and the restoration completion time, the restoration speed coefficient corresponding to the time interval is determined in the preset restoration speed coefficient configuration table (the restoration speed coefficient configuration table records the restoration speed coefficients corresponding to different time periods). If the time interval is small, the corresponding restoration speed coefficient is large, and if the time interval is large, the corresponding restoration speed coefficient is small. By presetting the time interval between the encryption start time and the restoration completion time, the restoration speed coefficient corresponding to the time interval is determined in the preset restoration speed coefficient configuration table (the restoration speed coefficient configuration table records the restoration speed coefficients corresponding to different time periods). If the time interval is small, the corresponding restoration speed coefficient is large, and if the time interval is large, the corresponding restoration speed coefficient is small. Finally, the weight coefficients corresponding to the restoration integrity coefficient, restoration speed coefficient, and recovery speed coefficient are determined respectively, and based on the weight coefficients, the restoration integrity coefficient, restoration speed coefficient, and recovery speed coefficient are added together to obtain the restoration effect coefficient of the target to restore the encrypted bait file. Finally, according to the restoration effect coefficient, the protection capability of the target system against the encryption behavior of the ransomware virus is determined, that is, the larger the restoration effect coefficient, the stronger the corresponding protection capability, and the smaller the restoration effect coefficient, the weaker the corresponding protection capability.
[0069] In summary, when the embodiment of the present invention receives the prediction signal of the protection capability of the target system, the protection capability of the target system is verified by encrypting the bait file through on-site simulation of the ransomware behavior, which can reflect the real protection capability of the target system in the current state. At the same time, by simulating the ransomware encryption behavior on-site, the attack scenario and attack means of the real world can be more accurately simulated, which makes the evaluation result closer to the actual situation and can more accurately reflect the protection capability of the system. By comprehensively analyzing the original identity verification value and the current identity verification value of the bait file, the preset encryption start time, the restoration start time, the restoration completion time and other factors, these data can more accurately reflect the actual performance of the system under the ransomware encryption behavior, thereby improving the accuracy of the evaluation and avoiding the problem of determining the system protection capability based on the historical encryption success and failure times alone. The system protection capability is too simple and one-sided. In addition, when the embodiment of the present invention tests the system protection capability, there is no need to re-establish a new environment, cut off the network, have no impact on other components in the system network, and do not require full disk encryption. It only needs to encrypt specific files and folders, so the target system can be verified harmlessly. The embodiment of the present invention can also configure multiple encryption algorithms, execution time, bait file types, bait file paths, etc. to comprehensively evaluate the target system's detection, protection and recovery capabilities against ransomware encryption behavior.
[0070] According to a harmless verification method for protection capability against ransomware encryption provided by the present invention, compared with the current method of determining the protection capability of a system by the number of successful and failed encryptions of files in a system by a ransomware in a historical time period, the present invention constructs a bait file in the target system in response to a verification signal of the target system's protection capability against ransomware encryption, and determines the original identity verification value of the bait file; and encrypts the bait file at a preset encryption start time using a preset encryption method to simulate the behavior of the ransomware, and in the encryption process of encrypting the bait file, obtains the response information of the target system to the encryption process; thereafter, if the response information is restoration response information for the encrypted bait file, then obtains the restoration start time and restoration completion time of the target system for restoring the encrypted bait file, and obtains the current identity verification value of the restored bait file; and finally verifies the protection capability of the target system against ransomware encryption based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time. Therefore, when it is necessary to detect the protection capability of the target system, after receiving the prediction signal, a bait file is constructed in the target system, and the bait file is encrypted by simulating the behavior of the ransomware virus. The protection capability of the target system is judged by the response information of the target system to the ransomware virus. That is, the present invention can perform protection capability detection on the target system after receiving the protection capability prediction signal, and can accurately reflect the protection capability of the target system at the current moment. At the same time, the protection capability of the target system against the encryption behavior of the ransomware virus is verified by comprehensively analyzing various factors such as the original identity verification value and the current identity verification value of the bait file, the preset encryption start time, the restoration start time, and the restoration completion time, so as to improve the verification accuracy of the system protection capability.
[0071] Further, in order to better illustrate the above process of classifying data, as a refinement and extension of the above embodiment, the embodiment of the present invention provides another harmless verification method for the protection capability of ransomware encryption behavior, such as Figure 2 As shown, the method includes:
[0072] 201. In response to a verification signal of the target system's ability to protect against ransomware encryption behavior, a bait file is constructed in the target system, and an original identity verification value of the bait file is determined.
[0073] For the embodiment of the present invention, in order to simulate the encryption behavior of the ransomware virus and avoid using real data in the system to cause data corruption and other problems, it is necessary to create a bait file. Based on this, the method includes: obtaining the encryption tendency information of the ransomware virus, and obtaining the predicted demand information for the protection capability of the target system; based on the encryption tendency information and the predicted demand information, determining the bait file type and the bait file content; based on the bait file type and the bait file content, constructing the bait file in the target system.
[0074] Among them, encryption tendency information includes information such as file types that ransomware likes to encrypt, file contents, file locations that it likes to attack, and encryption methods it usually uses; predicted demand information refers to: system type, system architecture, system purpose, existing protection mechanisms of the target system, backup and restore mechanisms, system performance, resource usage, important file types in the system, and protection information expected for the system.
[0075] Specifically, the type and content of the bait file to be constructed can be determined based on the file type and content of the ransomware tendency, or based on the file type of important files that need to be protected in the target system, or based on the ransomware tendency information and the predicted demand information of the target system. At the same time, by analyzing the type, architecture and purpose of the target system, as well as the attack path of the ransomware tendency, it is helpful to determine the deployment location and method of the bait file in the target system. In another embodiment of the present invention, a preset file prediction model can be used to determine the file type and file content of the bait file to be constructed. In order to improve the prediction accuracy of the preset file prediction model, it is first necessary to train and construct the preset file prediction model. Based on this, the method includes: constructing an initial model and obtaining a sample data set, wherein the sample data set includes encryption tendency information of a sample ransomware virus with label information and predicted demand information of a sample system, and the label information is the file type and file content of the sample bait file for accurately detecting the system's protection capabilities; dividing the sample data set into training data and test data, using the training data to train the initial model, and using the test data to test the trained initial model; and finally determining the initial model that meets the test conditions as the preset file prediction model. Furthermore, after constructing the preset file prediction model, it is necessary to use the model to predict the file type and file content of the bait file to be constructed. Based on this, the method includes: determining the tendency feature vector corresponding to the encrypted tendency information and the demand feature vector corresponding to the predicted demand information; cross-processing the tendency feature vector and the demand feature vector to obtain a file cross-feature vector; inputting the file cross-feature vector into the preset file prediction model to predict the file type and file content, and obtaining the file type and file content of the bait file to be constructed. Among them, the process of cross-processing the tendency feature vector and the demand feature vector includes: performing feature-level cross-processing on the tendency feature vector and the demand feature vector to obtain a feature cross-vector; performing element-level cross-processing on the tendency feature vector and the demand feature vector to obtain an element cross-vector; performing low-level cross-processing on the tendency feature vector and the demand feature vector to obtain a low-level cross-vector; using a preset transformation function to transform the feature cross-vector, the element cross-vector, and the low-level cross-vector to obtain a file cross-feature vector.
[0076] Specifically, in order to make full use of the relationship between data, extract more implicit features, and take into account both high-order and low-order processing, so that data utilization is more sufficient, the prediction results obtained later are more accurate, and meet the needs of actual application scenarios, it is necessary to cross-process the tendency feature vector and the demand feature vector. The specific cross-processing method is as follows: if the tendency feature vector is (a1, a2) and the demand feature vector is (b1, b2), the specific cross-processing method includes: cross-feature-level cross-processing between different feature vectors, that is, after performing Hadamard product on all elements between vectors, convolution transformation is performed under certain weights to obtain a feature cross-vector f(w*(a1*b1, a2*b2)); at the same time, for all feature vectors The data is crossed at the element level, that is, after making the Hadamard product for each element between the vectors, different weight values are assigned to the results of each product, and then a linear transformation is performed, and the obtained element cross vector is f(w1*a1*b1,w2*a2*b2); in addition, all feature vectors are subjected to low-order cross processing, and weight coefficients are assigned to the results after the cross processing, and then a linear transformation is performed, and the obtained low-order cross vector is f(w2(a1,a2,b1,b2)); finally, the preset transformation function (the preset transformation function can be set according to the actual situation, and this embodiment does not limit this) is used to transform the above feature cross vectors, element cross vectors, and low-order cross vectors, such as horizontal splicing, to obtain a file cross feature vector. It should be noted that the above examples are only illustrative and do not limit the embodiments of the present application. Therefore, by cross-processing the tendency feature vector and the demand feature vector, different features can be automatically or explicitly combined to generate new feature combinations. These combined features may contain complex nonlinear relationships between the original features, so that the model can capture more detailed and rich information in the data, that is, it can make full use of the relationship between various data, extract more implicit features, and take into account both high-order and low-order processing, so that data utilization is more complete, and the subsequent file type and file content prediction are more accurate, meeting the needs of actual application scenarios.
[0077] Furthermore, after determining the file type and file content of the bait file to be constructed, a bait file is constructed based on the file type and file content. The bait file is stored in a corresponding location in the target system. The embodiment of the present invention detects the protection capability of the system by constructing a bait file, which can avoid the risk of file damage caused by using real files in the system for testing.
[0078] 202. Simulate the behavior of the ransomware virus to encrypt the bait file at a preset encryption start time using a preset encryption method, and in the encryption process of encrypting the bait file, obtain response information of the target system to the encryption process.
[0079] For the embodiments of the present invention, in order to ensure the predicted effect of the protection capability of the target system, it is first necessary to select a suitable preset encryption method. Based on this, the method includes: determining the anti-attack capability information, encryption speed information, and occupied resource information of the encryption method to be selected based on the predicted demand information of the protection capability of the target system and the available memory resource information of the target system; based on the anti-attack capability information, the encryption speed information, and the occupied resource information, determining the preset encryption method among different encryption methods.
[0080] Specifically, if the predicted demand for the protection capability of the target system is high, an encryption method with strong anti-attack capability and fast encryption speed can be selected. If the predicted demand for the protection capability of the target system is low, an encryption method with weak anti-attack capability and slow encryption speed can be selected. At the same time, according to the structure, type and other information of the target system, select an encryption method that matches it, and according to the available resource space of the target system, that is, the available storage space, select an encryption method that can run smoothly, that is, the resource occupancy information of the selected encryption method can match the available resource space of the system. Finally, according to the anti-attack capability, encryption speed, occupied resources and other information of the encryption method to be selected, a preset encryption method is selected from multiple known encryption methods. In another embodiment of the present invention, the preset encryption method can also be determined according to the encryption method tending to be used by the ransomware virus, or the preset encryption method can be determined by comprehensively analyzing the encryption method tending to be used by the ransomware virus and the predicted demand information of the target system. The embodiment of the present invention encrypts the bait file by selecting a suitable encryption method to simulate the behavior of the ransomware virus. The suitable encryption method can verify the actual effect of the system protection technology. At the same time, the suitable encryption method can truly simulate the encryption behavior of the ransomware virus, including its encryption mechanism, encryption strength, and encrypted file status, etc. This helps to ensure the prediction accuracy and prediction effectiveness of the system protection capability, making the evaluation results closer to the actual ransomware attack situation.
[0081] 203. If the response information is restoration response information for the encrypted bait file, determine a restoration method for the encrypted bait file in the target system.
[0082] Specifically, the restoration method includes a backup restoration method and a decryption restoration method. The backup restoration method refers to restoring the bait file that was previously backed up to another location in the system (backup location) to the starting location of the bait file (current location). The decryption restoration method refers to decrypting the encrypted bait file to restore the encrypted bait file.
[0083] 204. Obtain the restoration start time and restoration completion time of the target system for the encrypted bait file according to the restoration method, and obtain the current identity verification value of the bait file after restoration according to the restoration method.
[0084] For an embodiment of the present invention, if the restoration method is a backup restoration method, the method for obtaining the restoration start time, the restoration completion time, and the current identity verification value includes: in the backup restoration method, determining the current location of the bait file, and determining the backup location after backing up the bait file at the current location; in response to the target system's migration response information for the encrypted bait file, determining the migration start time and migration completion time for the target system to migrate the bait file at the backup location to the current location, and obtaining the current identity verification value of the bait file after migrating to the current location, and determining the migration start time as the restoration start time and the migration completion time as the restoration completion time.
[0085] Specifically, if the backup and restore method is adopted, after receiving the migration response information, the migration start time and migration completion time of migrating the bait file at the backup location to the current location through copy and paste operations are determined, the migration start time is determined as the restore start time of the encrypted bait file, and the migration completion time is determined as the restore completion time of the encrypted bait file. At the same time, after the backup bait file is migrated back to the current location, the bait file before the backup needs to be deleted. At the same time, the current identity verification value of the bait file after migration is determined, and finally the protection capability of the target system against the encryption behavior of the ransomware virus is verified based on the original identity verification value of the bait file, the current identity verification value of the bait file after backup and restoration, the preset encryption start time, the migration start time, and the migration completion time.
[0086] In another embodiment of the present invention, if a decryption and restoration method is used, after receiving the decryption response information, the interpretation start time and decryption completion time of the target system for decrypting the encrypted bait file are determined, the decryption start time is determined as the restoration start time, and the decryption completion time is determined as the restoration completion time. After the decryption is completed, the current identity verification value of the decrypted bait file is determined. Finally, the protection capability of the target system against the encryption behavior of the ransomware virus is verified based on the original identity verification value of the bait file, the current identity verification value of the decrypted bait file, the preset encryption start time, the decryption start time, and the decryption completion time.
[0087] 205. Based on the original identity verification value, the current identity verification value, the preset encryption start time, the restore start time, and the restore completion time, verify the protection capability of the target system against the encryption behavior of the ransomware virus.
[0088] For the embodiment of the present invention, in the backup and restore mode, the protection capability of the target system against the encryption behavior of the ransomware virus is verified based on the original identity verification value of the bait file, the current identity verification value of the bait file after the backup and restoration, the preset encryption start time, the migration start time, and the migration completion time. For example, based on the original identity verification value and the current identity verification value, the restoration integrity coefficient of the target system for the bait file is determined; based on the migration start time and the migration completion time, the migration restoration speed coefficient of the target system for the bait file is determined; based on the preset encryption start time and the migration completion time, the migration recovery speed coefficient of the target system for the encryption behavior of the ransomware virus is determined; based on the restoration integrity coefficient, the migration speed coefficient, and the migration recovery speed coefficient, the protection capability of the target system against the encryption behavior of the ransomware virus is verified.
[0089] In the decryption and restoration mode, the protection capability of the target system against ransomware encryption behavior is verified based on the original identity verification value of the bait file, the current identity verification value of the decrypted bait file, the preset encryption start time, the decryption start time, and the decryption completion time. For example, based on the original identity verification value and the current identity verification value, the restoration integrity coefficient of the target system for the bait file is determined; based on the decryption start time and the decryption completion time, the decryption restoration speed coefficient of the target system for the bait file is determined; based on the preset encryption start time and the decryption completion time, the decryption recovery speed coefficient of the target system for ransomware encryption behavior is determined; based on the restoration integrity coefficient, the decryption speed coefficient, and the decryption recovery speed coefficient, the protection capability of the target system against ransomware encryption behavior is verified.
[0090] According to another harmless verification method of the protection capability of ransomware encryption behavior provided by the present invention, compared with the current method of determining the protection capability of the system by the number of successful encryptions and the number of failed encryptions of files in the system by the ransomware in a historical time period, the present invention constructs a bait file in the target system in response to a verification signal of the target system's protection capability against ransomware encryption behavior, and determines the original identity verification value of the bait file; and encrypts the bait file at a preset encryption start time using a preset encryption method to simulate the behavior of the ransomware, and in the encryption process of encrypting the bait file, obtains the response information of the target system to the encryption process; then, if the response information is the restoration response information of the encrypted bait file, the restoration start time and the restoration completion time of the target system for restoring the encrypted bait file are obtained, and the current identity verification value of the restored bait file is obtained; and finally, based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time, the protection capability of the target system against ransomware encryption behavior is verified. Therefore, when it is necessary to detect the protection capability of the target system, after receiving the prediction signal, a bait file is constructed in the target system, and the bait file is encrypted by simulating the behavior of the ransomware virus. The protection capability of the target system is judged by the response information of the target system to the ransomware virus. That is, the present invention can perform protection capability detection on the target system after receiving the protection capability prediction signal, and can accurately reflect the protection capability of the target system at the current moment. At the same time, the protection capability of the target system against the encryption behavior of the ransomware virus is verified by comprehensively analyzing various factors such as the original identity verification value and the current identity verification value of the bait file, the preset encryption start time, the restoration start time, and the restoration completion time, so as to improve the verification accuracy of the system protection capability.
[0091] Further, as Figure 1 The specific implementation of the present invention provides a harmless verification device for the protection capability of ransomware encryption behavior, such as Figure 3 As shown, the device includes: a construction unit 31, an encryption simulation unit 32, an acquisition unit 33, and a determination unit 34.
[0092] The construction unit 31 may be configured to construct a bait file in the target system in response to a verification signal of the target system's ability to protect against ransomware encryption behavior, and determine an original identity verification value of the bait file.
[0093] The encryption simulation unit 32 can be used to simulate the behavior of the ransomware virus to encrypt the bait file at a preset encryption start time using a preset encryption method, and in the encryption process of encrypting the bait file, obtain the response information of the target system to the encryption process.
[0094] The acquisition unit 33 can be used to obtain the restoration start time and restoration completion time of the target system for the encrypted bait file if the response information is the restoration response information of the encrypted bait file, and obtain the current identity verification value of the restored bait file.
[0095] The determination unit 34 may be configured to verify the protection capability of the target system against ransomware encryption behavior based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time.
[0096] In a specific application scenario, when the response information is interception response information to the encryption process, in order to determine the system protection capability, the acquisition unit 33 can also be used to obtain the process identification time of the target system for the encryption process, the interception start time of the target system for the encryption process, the interception operation information of the target system for the encryption process, and the interception completion time of the target system for the encryption process if the response information is interception response information to the encryption process.
[0097] The determination unit 34 may also be configured to determine a threat detection capability coefficient of the target system for the encryption process based on the process identification time and the preset encryption start time.
[0098] The determination unit 34 may also be configured to determine an interception response speed coefficient of the target system to the encryption process based on the preset encryption start time and the interception start time.
[0099] The determination unit 34 may also be configured to determine an interception efficiency coefficient of the target system for the encryption process based on the interception start time and the interception completion time.
[0100] The determination unit 34 may also be configured to determine an interception effect evaluation coefficient of the target system on the encryption process based on the interception operation information.
[0101] The determination unit 34 may also be used to verify the protection capability of the target system against ransomware encryption behavior based on the threat detection capability coefficient, the interception response speed coefficient, the interception efficiency coefficient, and the interception effect evaluation coefficient.
[0102] In a specific application scenario, in order to obtain the restoration start time and restoration completion time of the target system for the encrypted bait file, and obtain the current identity verification value of the restored bait file, such as Figure 4 As shown, the acquisition unit 33 includes a first determination module 331 and a first acquisition module 332 .
[0103] The first determination module 331 may be used to determine a restoration method of the target system for the encrypted bait file.
[0104] The first acquisition module 332 can be used to obtain the restoration start time and restoration completion time of the target system for the encrypted bait file according to the restoration method, and obtain the current identity verification value of the bait file after restoration according to the restoration method.
[0105] In a specific application scenario, in a backup and restore mode, in order to obtain information, the first acquisition module 332 can be specifically used to determine the current location of the bait file in the backup and restore mode, and determine the backup location after backing up the bait file at the current location; in response to the target system's migration response information to the encrypted bait file, determine the migration start time and migration completion time for the target system to migrate the bait file at the backup location to the current location, and obtain the current identity verification value of the bait file after migrating to the current location, and determine the migration start time as the restore start time and the migration completion time as the restore completion time.
[0106] In the decryption and restoration mode, in order to obtain information, the first acquisition module 332 can be specifically used to determine the decryption start time and decryption completion time of the target system for decrypting the encrypted bait file in response to the decryption response information of the target system for the encrypted bait file in the decryption and restoration mode, and obtain the current identity verification value of the decrypted bait file, and determine the decryption start time as the restoration start time and the decryption completion time as the restoration completion time.
[0107] In a specific application scenario, in order to determine the protection capability of the target system, the determination unit 34 can be specifically used to determine the restoration completeness coefficient of the target system for the bait file based on the original identity verification value and the current identity verification value; determine the restoration speed coefficient of the target system for the bait file based on the restoration start time and the restoration completion time; determine the recovery speed coefficient of the target system for the ransomware encryption behavior based on the preset encryption start time and the restoration completion time; and verify the protection capability of the target system against the ransomware encryption behavior based on the restoration completeness coefficient, the restoration speed coefficient, and the recovery speed coefficient.
[0108] In a specific application scenario, in order to construct a bait file, the construction unit 31 includes a second acquisition module 311 , a second determination module 312 , and a construction module 313 .
[0109] The second acquisition module 311 can be used to obtain encryption tendency information of the ransomware virus and obtain predicted demand information for protection capability of the target system.
[0110] The second determination module 312 may be configured to determine the type and content of the bait file based on the encryption tendency information and the predicted demand information.
[0111] The construction module 313 may be used to construct the bait file in the target system based on the bait file type and the bait file content.
[0112] In a specific application scenario, in order to determine the preset encryption method, the determination unit 34 can also be used to determine the anti-attack capability information, encryption speed information, and occupied resource information of the encryption method to be selected based on the predicted demand information of the protection capability of the target system and the available memory resource information of the target system; based on the anti-attack capability information, the encryption speed information, and the occupied resource information, determine the preset encryption method among different encryption methods.
[0113] It should be noted that for other corresponding descriptions of the functional modules involved in the harmless verification device for protecting against ransomware encryption behavior provided by the embodiment of the present invention, please refer to Figure 1 The corresponding description of the method shown will not be repeated here.
[0114] Based on the above Figure 1The method shown, accordingly, an embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the following steps are implemented: in response to a verification signal of the target system's ability to protect against ransomware encryption behavior, a bait file is constructed in the target system, and an original identity verification value of the bait file is determined; the behavior of the ransomware is simulated to encrypt the bait file at a preset encryption start time using a preset encryption method, and in the encryption process of encrypting the bait file, the response information of the target system to the encryption process is obtained; if the response information is the restoration response information of the encrypted bait file, the restoration start time and the restoration completion time of the target system for restoring the encrypted bait file are obtained, and the current identity verification value of the restored bait file is obtained; based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time, the protection capability of the target system against ransomware encryption behavior is verified.
[0115] Based on the above Figure 1 The method shown and Figure 3 The embodiment of the device shown in the figure, the embodiment of the present invention also provides a physical structure diagram of a computer device, such as Figure 5 As shown, the computer device includes: a processor 41, a memory 42, and a computer program stored in the memory 42 and executable on the processor, wherein the memory 42 and the processor 41 are both arranged on a bus 43, and the processor 41 implements the following steps when executing the program: in response to a verification signal of the target system's ability to protect against ransomware encryption behavior, construct a bait file in the target system, and determine the original identity verification value of the bait file; encrypt the bait file at a preset encryption start time using a preset encryption method to simulate the behavior of the ransomware, and in the encryption process of encrypting the bait file, obtain the response information of the target system to the encryption process; if the response information is the restoration response information of the encrypted bait file, then obtain the restoration start time and restoration completion time of the target system for restoring the encrypted bait file, and obtain the current identity verification value of the restored bait file; based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time, verify the protection capability of the target system against ransomware encryption behavior.
[0116] Through the technical solution of the present invention, the present invention constructs a bait file in the target system and determines the original identity verification value of the bait file in response to a verification signal of the target system's protection capability against ransomware encryption behavior; and encrypts the bait file at a preset encryption start time using a preset encryption method to simulate the behavior of the ransomware, and in the encryption process of encrypting the bait file, obtains the response information of the target system to the encryption process; thereafter, if the response information is the restoration response information of the encrypted bait file, the restoration start time and the restoration completion time of the target system for restoring the encrypted bait file are obtained, and the current identity verification value of the restored bait file is obtained; and finally, based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time, the protection capability of the target system against ransomware encryption behavior is verified. Therefore, when it is necessary to detect the protection capability of the target system, after receiving the prediction signal, a bait file is constructed in the target system, and the bait file is encrypted by simulating the behavior of the ransomware virus. The protection capability of the target system is judged by the response information of the target system to the ransomware virus. That is, the present invention can perform protection capability detection on the target system after receiving the protection capability prediction signal, and can accurately reflect the protection capability of the target system at the current moment. At the same time, the protection capability of the target system against the encryption behavior of the ransomware virus is verified by comprehensively analyzing various factors such as the original identity verification value and the current identity verification value of the bait file, the preset encryption start time, the restoration start time, and the restoration completion time, so as to improve the verification accuracy of the system protection capability.
[0117] Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, and optionally, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be executed in a different order than here, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the present invention is not limited to any specific combination of hardware and software.
[0118] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A method for verifying the harmlessness of the protection capability of ransomware encryption behavior, characterized in that: include: In response to a verification signal of the target system's ability to protect against ransomware encryption behavior, construct a bait file in the target system and determine an original identity verification value of the bait file; Simulating the behavior of the ransomware virus, encrypting the bait file at a preset encryption start time using a preset encryption method, and obtaining response information of the target system to the encryption process during the encryption process of encrypting the bait file; If the response information is restoration response information for the encrypted bait file, then obtaining the restoration start time and restoration completion time for the target system to restore the encrypted bait file, and obtaining the current identity verification value of the restored bait file; Based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time, the protection capability of the target system against the ransomware encryption behavior is verified.
2. The method according to claim 1, characterized in that After obtaining the response information of the target system to the encryption process, the method further includes: If the response information is interception response information of the encryption process, then obtaining the process identification time of the encryption process by the target system, the interception start time of the encryption process by the target system, the interception operation information of the encryption process by the target system, and the interception completion time of the encryption process by the target system; Determining a threat detection capability coefficient of the target system for the encryption process based on the process identification time and the preset encryption start time; Determining an interception response speed coefficient of the target system to the encryption process based on the preset encryption start time and the interception start time; Determining an interception efficiency coefficient of the target system for the encryption process based on the interception start time and the interception completion time; Determining, based on the interception operation information, an interception effect evaluation coefficient of the target system on the encryption process; Based on the threat detection capability coefficient, the interception response speed coefficient, the interception efficiency coefficient, and the interception effect evaluation coefficient, the protection capability of the target system against the ransomware encryption behavior is verified.
3. The method according to claim 1, characterized in that: The step of obtaining the restoration start time and restoration completion time of the target system for restoring the encrypted bait file, and obtaining the current identity verification value of the restored bait file, includes: Determining a method for restoring the encrypted bait file by the target system; The restoration start time and restoration completion time of the target system for restoring the encrypted bait file according to the restoration method are obtained, and the current identity verification value of the bait file restored according to the restoration method is obtained.
4. The method according to claim 3, characterized in that The restoration method includes a backup restoration method and a decryption restoration method; The obtaining of the restoration start time and restoration completion time of the target system for restoring the encrypted bait file according to the restoration method, and obtaining the current identity verification value of the bait file restored according to the restoration method, includes: In the backup and restore mode, determining the current location of the bait file, and determining the backup location after backing up the bait file at the current location; In response to the target system's response information on the encrypted bait file's retrieval, determine the target system's retrieval start time and retrieval completion time for retrieval of the bait file at the backup location to the current location, obtain a current identity verification value of the bait file after retrieval to the current location, and determine the retrieval start time as the restore start time and the retrieval completion time as the restore completion time; In the decryption and restoration mode, in response to the decryption response information of the target system to the encrypted bait file, the decryption start time and the decryption completion time of the target system for decrypting the encrypted bait file are determined, and the current identity verification value of the decrypted bait file is obtained, and the decryption start time is determined as the restoration start time and the decryption completion time is determined as the restoration completion time.
5. The method according to claim 1, characterized in that The verifying the protection capability of the target system against ransomware encryption behavior based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time includes: Determining a restoration integrity coefficient of the target system for the decoy file based on the original identity verification value and the current identity verification value; Determining a restoration speed coefficient of the target system for the decoy file based on the restoration start time and the restoration completion time; Determining a recovery speed coefficient of the target system for the ransomware encryption behavior based on the preset encryption start time and the restoration completion time; Based on the restoration completeness coefficient, the restoration speed coefficient, and the recovery speed coefficient, the protection capability of the target system against the encryption behavior of the ransomware virus is verified.
6. The method according to claim 1, characterized in that The constructing of the bait file in the target system includes: Obtaining encryption tendency information of the ransomware virus and obtaining predicted demand information for protection capabilities of the target system; Determining the type of bait file and the content of the bait file based on the encryption tendency information and the predicted demand information; The bait file is constructed in the target system based on the bait file type and the bait file content.
7. The method according to claim 1, characterized in that Before encrypting the decoy file at a preset encryption start time using a preset encryption method while simulating the behavior of the ransomware, the method further includes: Determine the anti-attack capability information, encryption speed information, and occupied resource information of the encryption method to be selected based on the predicted demand information of the protection capability of the target system and the available memory resource information of the target system; The preset encryption method is determined among different encryption methods based on the anti-attack capability information, the encryption speed information, and the occupied resource information.
8. A harmless verification device for protecting against ransomware encryption behavior, characterized in that: include: A construction unit, configured to construct a bait file in the target system in response to a verification signal of the target system's ability to protect against ransomware encryption behavior, and determine an original identity verification value of the bait file; An encryption simulation unit, used for simulating the behavior of the ransomware virus to encrypt the bait file at a preset encryption start time using a preset encryption method, and in the encryption process of encrypting the bait file, obtaining the response information of the target system to the encryption process; an acquiring unit, configured to acquire, if the response information is restoration response information for the encrypted bait file, a restoration start time and a restoration completion time for the target system to restore the encrypted bait file, and acquire a current identity verification value of the restored bait file; A determination unit is used to verify the protection capability of the target system against the encryption behavior of the ransomware virus based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Network security performance evaluation method
CN103618691A
Method for defending attacks based on attack organization capability evaluation
CN110798454A
Security evaluation server and security evaluation method
CN111587433A
Trapping and defending method and system for ransomware virus
CN115374441A
Method and system for testing and evaluating perimeter intrusion detection equipment
CN116401157A
Cited By
Harmless protection capability verification method and system based on ransomware virus behavior simulation
CN121356919A
Ransomware behavior simulation-based disinfection protection capability verification method and system
CN121356919B