Ransomware encryption behavior protection capability harmless verification method and device

By constructing bait files in the system and simulating ransomware encryption behavior, obtaining the system's response and restoration information, and comprehensively analyzing and verifying the system's protection capabilities, the problem of inaccurate protection capability determination in existing technologies is solved, and a more accurate protection capability assessment is achieved.

CN120012098BActive Publication Date: 2025-10-21SHANGHAI SHIAN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411909029.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-10-21
Estimated Expiration
2044-12-24

AI Technical Summary

Technical Problem

Existing technologies determine system protection capabilities by the number of successful encryptions of files in the system by ransomware within a historical period, which cannot accurately reflect the current system's protection capabilities, resulting in low accuracy in determining protection capabilities.

Method used

Build a bait file in the target system to simulate the encryption behavior of the ransomware virus, obtain the system's response information and restoration information, and verify the system's protection capabilities through comprehensive analysis of multiple factors, including threat detection capabilities, interception response speed, interception efficiency, and restoration capabilities.

Benefits of technology

The verification accuracy of the system's protection capabilities has been improved, which can reflect the actual protection capabilities in the current state, avoid judgment bias caused by inaccurate historical data, and does not affect the normal operation of the system during the test.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012098B_ABST
    Figure CN120012098B_ABST
Patent Text Reader

Abstract

The application discloses a ransomware encryption behavior protection capability harmless verification method and device, comprising: in response to a verification signal of a target system to a ransomware encryption behavior protection capability, constructing a decoy file in the target system, and determining an original identity check value of the decoy file; simulating the behavior of the ransomware to encrypt the decoy file at a preset encryption start time by using a preset encryption mode, and in the encryption process, obtaining response information of the target system to the encryption process; if the response information is restoration response information to the encrypted decoy file, obtaining a restoration start time and a restoration completion time of the target system for restoring the encrypted decoy file, and obtaining a current identity check value of the restored decoy file; and based on the original identity check value, the current identity check value, the preset encryption start time, the restoration start time and the restoration completion time, verifying the protection capability of the target system to the ransomware encryption behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method and device for verifying the harmlessness of the protection capability of ransomware encryption behavior. Background Art

[0002] With the acceleration of informatization, the frequency and scope of ransomware attacks are expanding. Ransomware encrypts files on target systems, forcing victims to pay a ransom for the decryption key. This can lead to the permanent loss or corruption of important data and other unnecessary losses. Therefore, it is necessary to monitor system protection capabilities to identify and remediate security vulnerabilities and weaknesses, thereby improving enterprise data security and preventing other losses.

[0003] Currently, a system's protection capability is typically determined by the number of successful ransomware encryption attempts on files within a historical period. However, due to the continuous iteration and upgrade of system software, this method of determining protection capability based on historical information cannot accurately reflect the current system's protection capability. Furthermore, since successful encryption does not necessarily indicate a system's inability to protect itself, this existing method of determining system protection capability based solely on the number of successful encryption attempts results in low accuracy. Summary of the Invention

[0004] The present invention provides a harmless verification method and device for the protection capability of ransomware encryption behavior, which mainly aims to improve the verification accuracy of the system's protection capability against ransomware encryption behavior.

[0005] According to a first aspect of the present invention, a method for verifying the harmlessness of ransomware encryption behavior protection capabilities is provided, comprising:

[0006] In response to a verification signal of the target system's ability to protect against ransomware encryption behavior, construct a bait file in the target system and determine an original identity verification value of the bait file;

[0007] Simulating the behavior of the ransomware virus, encrypting the bait file using a preset encryption method at a preset encryption start time, and obtaining response information of the target system to the encryption process during the encryption process of the bait file;

[0008] If the response information is restoration response information for the encrypted bait file, obtaining the restoration start time and restoration completion time of the target system for restoring the encrypted bait file, and obtaining the current identity verification value of the restored bait file;

[0009] Based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time, the protection capability of the target system against ransomware encryption behavior is verified.

[0010] Optionally, after obtaining response information of the target system to the encryption process, the method further includes:

[0011] If the response information is interception response information for the encryption process, then obtain the process identification time of the encryption process by the target system, the interception start time of the encryption process by the target system, the interception operation information of the encryption process by the target system (whether other files in the same path as the bait file are isolated, whether a malicious encryption alarm is triggered, the difference between the termination identity check value and the original identity check value of the bait file after termination of encryption), and the completion time of the interception of the encryption process by the target system;

[0012] determining a threat detection capability coefficient of the target system for the encryption process based on the process identification time and the preset encryption start time;

[0013] Determining an interception response speed coefficient of the target system to the encryption process based on the preset encryption start time and the interception start time;

[0014] determining an interception efficiency coefficient of the target system for the encryption process based on the interception start time and the interception completion time;

[0015] determining, based on the interception operation information, an interception effect evaluation coefficient of the target system on the encryption process;

[0016] Based on the threat detection capability coefficient, the interception response speed coefficient, the interception efficiency coefficient, and the interception effect evaluation coefficient, the protection capability of the target system against ransomware encryption behavior is verified.

[0017] Optionally, obtaining the restoration start time and restoration completion time of the target system for restoring the encrypted bait file, and obtaining the current identity verification value of the restored bait file, includes:

[0018] Determining a restoration method of the target system for the encrypted bait file;

[0019] The restoration start time and restoration completion time of the target system for restoring the encrypted bait file according to the restoration method are obtained, and the current identity verification value of the bait file restored according to the restoration method is obtained.

[0020] Optionally, the restoration method includes a backup restoration method and a decryption restoration method;

[0021] The obtaining of the restoration start time and restoration completion time of the target system for the encrypted bait file according to the restoration method, and the obtaining of the current identity verification value of the bait file after restoration according to the restoration method, include:

[0022] In the backup and restore mode, determining the current location of the bait file, and determining a backup location after backing up the bait file at the current location;

[0023] In response to the target system's response to the encrypted bait file's migration response, determine a migration start time and a migration completion time for the target system to migrate the bait file from the backup location to the current location, obtain a current identity verification value of the bait file after migrating to the current location, and determine the migration start time as the restoration start time and the migration completion time as the restoration completion time;

[0024] In the decryption and restoration mode, in response to the decryption response information of the target system to the encrypted bait file, the decryption start time and the decryption completion time of the target system for decrypting the encrypted bait file are determined, and the current identity verification value of the decrypted bait file is obtained, and the decryption start time is determined as the restoration start time and the decryption completion time is determined as the restoration completion time.

[0025] Optionally, the verifying the target system's protection capability against ransomware encryption based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time includes:

[0026] Determining a restoration integrity coefficient of the target system for the decoy file based on the original identity verification value and the current identity verification value;

[0027] Determining a restoration speed coefficient of the target system for the decoy file based on the restoration start time and the restoration completion time;

[0028] Determining a recovery speed coefficient of the target system for the ransomware encryption behavior based on the preset encryption start time and the restoration completion time;

[0029] Based on the restoration completeness coefficient, the restoration speed coefficient, and the recovery speed coefficient, the protection capability of the target system against ransomware encryption behavior is verified.

[0030] Optionally, constructing a bait file in the target system includes:

[0031] Obtaining encryption tendency information of the ransomware and predicted demand information for protection capabilities of the target system;

[0032] Determining the type and content of the bait file based on the encryption tendency information and the predicted demand information;

[0033] The bait file is constructed in the target system based on the bait file type and bait file content.

[0034] Optionally, before encrypting the decoy file at a preset encryption start time using a preset encryption method by simulating the behavior of the ransomware, the method further includes:

[0035] Determining the anti-attack capability information, encryption speed information, and resource usage information of the encryption method to be selected based on the predicted demand information of the protection capability of the target system and the available memory resource information of the target system;

[0036] The preset encryption mode is determined among different encryption modes based on the anti-attack capability information, the encryption speed information, and the occupied resource information.

[0037] According to a second aspect of the present invention, a harmless verification device for protecting against ransomware encryption behavior is provided, comprising:

[0038] A construction unit, configured to construct a bait file in the target system in response to a verification signal of the target system's ability to protect against ransomware encryption behavior, and determine an original identity verification value of the bait file;

[0039] an encryption simulation unit, configured to simulate the behavior of a ransomware virus, encrypt the decoy file using a preset encryption method at a preset encryption start time, and obtain response information of the target system to the encryption process during the encryption process of the decoy file;

[0040] an acquiring unit, configured to acquire, if the response information is restoration response information for the encrypted bait file, a restoration start time and a restoration completion time for the target system to restore the encrypted bait file, and acquire a current identity verification value of the restored bait file;

[0041] A determination unit is configured to verify the target system's protection capability against ransomware encryption behavior based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time.

[0042] According to a third aspect of the present invention, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the harmless verification of the above-mentioned ransomware encryption behavior protection capability.

[0043] According to a fourth aspect of the present invention, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, harmless verification of the above-mentioned ransomware encryption protection capability is achieved.

[0044] According to a harmless verification method and device for ransomware encryption behavior protection capability provided by the present invention, compared with the current method of determining the system's protection capability by the number of successful and failed encryptions of files in the system by ransomware within a historical time period, the present invention constructs a bait file in the target system in response to a verification signal of the target system's protection capability against ransomware encryption behavior, and determines the original identity verification value of the bait file; and simulates the behavior of the ransomware to encrypt the bait file using a preset encryption method at a preset encryption start time, and in the encryption process of encrypting the bait file, obtains the target system's response information to the encryption process; then, if the response information is restore response information for the encrypted bait file, obtains the restore start time and restore completion time for the target system to restore the encrypted bait file, and obtains the current identity verification value of the restored bait file; and finally, based on the original identity verification value, the current identity verification value, the preset encryption start time, the restore start time, and the restore completion time, verifies the target system's protection capability against ransomware encryption behavior. Therefore, when receiving a prediction signal of the target system's protection capability, the protection capability of the target system is verified by encrypting the bait file through on-site simulation of ransomware behavior, which can reflect the real protection capability of the target system in the current state. At the same time, the protection capability of the target system against ransomware encryption behavior is verified by comprehensively analyzing multiple factors such as the original identity verification value and the current identity verification value of the bait file, the preset encryption start time, the restoration start time, and the restoration completion time, thereby improving the verification accuracy of the system's protection capability. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0046] Figure 1 A flowchart of a method for verifying the harmlessness of ransomware encryption behavior protection capabilities provided by an embodiment of the present invention is shown;

[0047] Figure 2 A flowchart of another method for verifying the harmlessness of ransomware encryption behavior protection capabilities provided by an embodiment of the present invention is shown;

[0048] Figure 3 A schematic diagram illustrating the structure of a harmlessness verification device for protecting against ransomware encryption behavior provided by an embodiment of the present invention is shown;

[0049] Figure 4 A schematic diagram illustrating the structure of another harmlessness verification device for protecting against ransomware encryption behavior provided by an embodiment of the present invention is shown;

[0050] Figure 5 A schematic diagram of the physical structure of a computer device provided by an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0051] The present invention will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that, unless there is a conflict, the embodiments and features in the embodiments of the present application can be combined with each other.

[0052] Currently, determining the system's protection capability by counting the number of successful encryption attempts of files in the system by ransomware within a historical period cannot accurately reflect the current system's protection capability. Furthermore, since successful encryption does not indicate that the system has no protection capability, the existing method of determining the system's protection capability based solely on the number of successful encryption attempts results in low accuracy in determining the system's protection capability.

[0053] In order to solve the above problems, the embodiment of the present invention provides a harmless verification method for the protection capability of ransomware encryption behavior, such as Figure 1 As shown, the method includes:

[0054] 101. In response to a verification signal of the target system's ability to protect against ransomware encryption behavior, a bait file is constructed in the target system, and an original identity verification value of the bait file is determined.

[0055] The target system is the specific computer system or network for which a protection capability assessment is required. The target system can be any type of computer system, including but not limited to servers, personal computers, mobile devices, and IoT devices. Ransomware is a type of malware whose primary purpose is to encrypt the victim's files for illegal profit. The original identity verification value of the bait file can be a hash value, digital signature, message authentication code, or other verification value that uniquely identifies the bait file.

[0056] For an embodiment of the present invention, when a harmless verification signal of the ransomware encryption behavior protection capability is received, a bait file is created in a commonly used storage path for data files of the target system to be predicted (such as desktop, ~\documents (documents) ~\downloads (downloads), \tmp (temporary files), etc.). The type of the bait file can be selected according to the prediction requirements, including but not limited to image files, text files, audio files, etc., and the content of the bait file can also be set according to the prediction requirements. The content of the bait file will not cause direct damage to the system or user, and should also avoid containing any sensitive information, etc. For example, the bait file can be a randomly generated password book of type txt. After the bait file is created, the original identity verification value of the bait file is determined, such as a hash value. After the bait file is constructed in the preset folder of the target system, the bait file and other files in the same folder can be backed up together to other file storage locations of the target system, such as backing up to a new directory at the same level as the parent directory of the bait file, and the original identity verification values ​​of other files are determined and recorded. So that it can be used in the subsequent process of detecting the protection capability of the target system. When receiving a prediction signal about the target system's protection capabilities, the embodiment of the present invention verifies the target system's protection capabilities by encrypting and testing the bait file through on-site simulation of ransomware behavior. This can reflect the target system's true protection capabilities in its current state, avoiding the problem of using historical data that cannot accurately reflect the system's protection capabilities in its current state. At the same time, the embodiment of the present invention predicts the target system's protection capabilities by creating a bait file. By monitoring the state changes of the bait file, it can be understood whether the system can promptly identify and intercept ransomware attacks, reducing the risk of real data being damaged during the test process, thereby ensuring the harmless verification of the embodiment of the present invention.

[0057] In another embodiment of the present invention, the target system can also be judged based on the bait file construction process to determine whether it meets the preset conditions for protection capability testing. Based on this, the method includes: judging whether there are any anomalies in the bait file construction process; if so, determining that the target system does not meet the preset conditions for protection capability prediction, and prohibiting protection capability prediction for the target system; otherwise, judging whether there are any anomalies in the bait file backup process; if so, determining that the target system does not meet the preset conditions for protection capability prediction, and prohibiting protection capability prediction for the target system. Specifically, the bait file generation anomaly occurs when generating the bait file for encryption testing, the task fails to successfully create the bait file, or the generated file content does not meet expectations. This anomaly can cause subsequent tasks (such as backup and encryption) to fail normally. Backup failure occurs when the bait file and other files in the target directory are copied or moved to the backup directory during task execution, and one of the following problems occurs, causing the backup anomaly: due to path problems, disk space, file access conflicts, concurrency issues, hardware anomalies, etc. At the same time, the bait file creation process or backup process may be intercepted by security equipment and identified as potentially dangerous, causing the bait file creation task and backup task to be interrupted or failed. When the above exceptions occur, it means that it is not suitable to perform a protection capability test on the target system at this time. If the test is forced, it will cause damage to the target system or cause inaccurate testing. Therefore, the embodiment of the present invention determines whether the target system meets the preset conditions for protection capability detection. If it meets the preset conditions, it will perform a protection capability test on it, which can avoid system failures or inaccurate testing.

[0058] 102. The behavior of simulating the ransomware virus is to encrypt the bait file using a preset encryption method at a preset encryption start time, and during the encryption process of encrypting the bait file, obtain the target system's response information to the encryption process.

[0059] Among them, the preset encryption method can be an encryption method commonly used by ransomware, and can also be an encryption method selected based on the predicted demand for the target system's protection capability. For example, if the predicted demand for the target system's protection capability is high, the preset encryption method can select an encryption method that is more difficult to crack. If the predicted demand for the target system's protection capability is low, the preset encryption method can select an encryption method that is relatively easy to crack. The preset encryption start time can be set according to actual needs. The response information includes restoration response information and interception response information. The restoration response information refers to an operation signal for restoring the encrypted bait file. The interception response information refers to an operation signal for intercepting the encryption process of the bait file to avoid encrypting the bait file.

[0060] For the embodiment of the present invention, the behavior of the ransomware is simulated. When the preset encryption start time is reached, the bait file is encrypted using the preset encryption method. When the encryption starts, the response information of the target system to the encryption process is obtained in real time to determine whether the target system adopts the method of intercepting the encryption process or restoring the encrypted bait file. That is, whether it is the method of intercepting the encryption process or restoring the encrypted bait file, it can reflect the target system's protection ability against the encryption behavior of the ransomware. If it can be determined through the response information of the target system that the protection measure of the target system against the ransomware encryption behavior is: intercepting the encryption process of the bait file, then under this protection measure, in order to verify the protection capability of the target system, the method includes: if the response information is interception response information for the encryption process, obtaining the process identification time of the encryption process by the target system, the interception start time of the encryption process by the target system, the interception operation information of the encryption process by the target system, and the interception completion time of the encryption process by the target system; determining the threat detection capability coefficient of the target system for the encryption process based on the process identification time and the preset encryption start time; determining the interception response speed coefficient of the target system for the encryption process based on the preset encryption start time and the interception start time; determining the interception efficiency coefficient of the target system for the encryption process based on the interception start time and the interception completion time; determining the interception effect evaluation coefficient of the target system for the encryption process based on the interception operation information; and verifying the protection capability of the target system against the ransomware encryption behavior based on the threat detection capability coefficient, the interception response speed coefficient, the interception efficiency coefficient, and the interception effect evaluation coefficient.

[0061] The interception operation information includes: whether to isolate other files in the same path as the bait file, whether to trigger a malicious encryption alarm, the difference between the termination identity check value of the bait file after encryption and the original identity check value, etc.

[0062] Specifically, the time interval between the process identification time and the preset encryption start time is determined, and based on the time interval, the threat detection capability coefficient corresponding to the time interval is determined in the preset detection capability coefficient configuration table (the preset detection capability coefficient configuration table records the threat capability detection coefficients corresponding to different time intervals). If the time interval is long, the corresponding threat capability detection coefficient is small; if the time interval is short, the corresponding threat capability detection coefficient is large. A large threat capability detection coefficient reflects that the target system has a stronger threat detection capability for the encryption process. At the same time, the time interval between the preset encryption start time and the interception start time is determined, and based on the time interval, the interception response speed coefficient corresponding to the time interval is determined in the preset interception response speed coefficient configuration table (the preset interception response speed coefficient configuration table records the interception response speed coefficients corresponding to different time intervals). If the time interval is long, the corresponding interception response speed coefficient is small; if the time interval is short, the corresponding interception response speed coefficient is large. A large interception response speed coefficient reflects that the target system has a faster interception response speed for the encryption process. At the same time, the time interval between the interception start time and the interception completion time is determined, and based on the time interval, the interception efficiency coefficient corresponding to the time interval is determined in the preset interception efficiency coefficient configuration table (the preset interception efficiency coefficient configuration table records the interception efficiency coefficients corresponding to different time intervals). If the time interval is longer, the corresponding interception efficiency coefficient is smaller, and if the time interval is shorter, the corresponding interception efficiency coefficient is larger. The larger interception efficiency coefficient reflects that the target system has a higher interception efficiency for the encryption process. At the same time, it is determined whether the target system has isolated other files with the same path as the bait file when intercepting the encryption, whether a malicious encryption alarm has been triggered, and the difference between the termination identity verification value and the original identity verification value of the bait file after the encryption is terminated is determined. If the target system has not isolated other files with the same path as the bait file, has not triggered a malicious encryption alarm, and the difference between the termination identity verification value and the original identity verification value of the bait file after the encryption is terminated is large (indicating a poor interception effect), then it is determined that the target system's interception effect evaluation coefficient for the encryption process is small. If the target system has isolated other files with the same path as the bait file, triggered a malicious encryption alarm, and the difference between the termination identity verification value and the original identity verification value of the bait file after the encryption is terminated is small or there is no difference, then it is determined that the target system's interception effect evaluation coefficient for the encryption process is large (indicating a good interception effect). The specific value of the interception effect evaluation coefficient can be determined based on the completion status of each information in the interception operation information. For example, in the above three items (item 1: whether to isolate other files in the same path as the bait file, item 2: whether to trigger a malicious encryption alarm, item 3: the difference between the termination identity verification value and the original identity verification value of the bait file after encryption), the interception effect evaluation coefficient is set by the number of items that are met and which specific item is met.Furthermore, after determining the target system's threat detection capability coefficient, interception response speed coefficient, interception efficiency coefficient, and interception effect evaluation coefficient for the encryption process, the weight coefficients corresponding to the threat detection capability coefficient, interception response speed coefficient, interception efficiency coefficient, and interception effect evaluation coefficient are determined respectively. Then, according to the weight coefficients, the threat detection capability coefficient, interception response speed coefficient, interception efficiency coefficient, and interception effect evaluation coefficient are added together to obtain the target system's comprehensive interception effect coefficient for the encryption process. Finally, the target system's protection capability is determined based on the comprehensive interception effect coefficient. For example, the larger the comprehensive interception effect coefficient, the stronger the target system's protection capability, and the smaller the comprehensive interception effect coefficient, the weaker the target system's protection capability. The present invention implements a method of determining the target system's protection capability by comprehensively analyzing the target system's threat detection capability, interception response speed, interception efficiency, and interception effect for the encryption process, thereby avoiding the problem of inaccurate judgment caused by judging the system's protection capability based solely on the number of successful encryption attempts.

[0063] 103. If the response information is restoration response information for the encrypted bait file, the restoration start time and restoration completion time of the target system for restoring the encrypted bait file are obtained, as well as the current identity verification value of the restored bait file.

[0064] Specifically, if it can be determined through the response information of the target system that the protection measure of the target system against the ransomware encryption behavior is: restoring the encrypted bait file, that is, restoring the encrypted bait file to the state before encryption. Under this protection measure, in order to verify the protection capability of the target system, it is first necessary to record the restoration start time and restoration completion time of the target system for restoring the encrypted bait file. At the same time, it is also necessary to determine the current identity verification value of the restored bait file. The format of the current identity verification value should be the same as the original identity verification value of the bait file before encryption. Then, a comprehensive analysis is performed on the original identity verification value, current identity verification value, restoration start time, and restoration completion time of the bait file to determine the protection capability of the target system. By evaluating the restoration capability of the encrypted bait file, the embodiment of the present invention can more comprehensively understand the recovery capability of the target system after being attacked. The interception capability mainly remains at the surface protection level, that is, preventing attackers from encrypting files or executing malicious code, while the restoration capability involves a deeper level of protection, that is, after the file is encrypted, the system can quickly take measures to restore it. That is, the restoration capability provides a long-lasting protection effect. Even if the system is attacked, the system status can be restored by restoring the file. Therefore, the present invention determines its protection capability in real time based on the target system's ability to restore the encrypted file, which can improve the comprehensiveness and accuracy of the determination of the system's protection capability.

[0065] 104. Verify the target system's protection against ransomware encryption based on the original identity verification value, current identity verification value, preset encryption start time, restore start time, and restore completion time.

[0066] Among them, the preset encryption start time refers to the time point when the simulated ransomware behavior begins to encrypt the bait file; the restore start time refers to the time point when the target system starts to perform the file restore operation after detecting the ransomware encryption behavior; the restore completion time refers to the time point when the system completes the file restore operation.

[0067] For an embodiment of the present invention, when the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time are obtained, it is necessary to perform a comprehensive analysis of the above information to determine the protection capability of the target system. Based on this, the method includes: determining the restoration integrity coefficient of the target system for the bait file based on the original identity verification value and the current identity verification value; determining the restoration speed coefficient of the target system for the bait file based on the restoration start time and the restoration completion time; determining the recovery speed coefficient of the target system for ransomware encryption behavior based on the preset encryption start time and the restoration completion time; and verifying the protection capability of the target system against ransomware encryption behavior based on the restoration integrity coefficient, the restoration speed coefficient, and the recovery speed coefficient.

[0068] Specifically, the difference between the original identity verification value and the current identity verification value is determined, and based on the size of the difference, a corresponding restoration integrity coefficient is set for it. If the difference is large, it indicates that the ransomware has destroyed the system's files, or the attacker has obtained legitimate files, then the corresponding restoration integrity coefficient is small; if the difference is small, it indicates that the system can still maintain the validity of the files after the ransomware incident occurs, then the corresponding restoration integrity coefficient is large. By the time interval between the restoration start time and the restoration completion time, the restoration speed coefficient corresponding to the time interval is determined in the preset restoration speed coefficient configuration table (the restoration speed coefficient configuration table records the restoration speed coefficients corresponding to different time periods). If the time interval is small, the corresponding restoration speed coefficient is large. If the time interval is large, the corresponding restoration speed coefficient is small. By the time interval between the preset encryption start time and the restoration completion time, the restoration speed coefficient corresponding to the time interval is determined in the preset restoration speed coefficient configuration table (the restoration speed coefficient configuration table records the restoration speed coefficients corresponding to different time periods). If the time interval is small, the corresponding restoration speed coefficient is large. If the time interval is large, the corresponding restoration speed coefficient is small. Finally, the weight coefficients corresponding to the restoration integrity coefficient, restoration speed coefficient, and recovery speed coefficient are determined respectively, and based on the weight coefficients, the restoration integrity coefficient, restoration speed coefficient, and recovery speed coefficient are added together to obtain the restoration effect coefficient of the target to restore the encrypted bait file. Finally, according to the restoration effect coefficient, the protection capability of the target system against the ransomware encryption behavior is determined, that is, the larger the restoration effect coefficient, the stronger the corresponding protection capability, and the smaller the restoration effect coefficient, the weaker the corresponding protection capability.

[0069] In summary, when the embodiment of the present invention receives a prediction signal of the protection capability of the target system, it verifies the protection capability of the target system by encrypting the bait file by simulating the ransomware behavior on site, which can reflect the real protection capability of the target system in the current state. At the same time, by simulating the ransomware encryption behavior on site, it can more accurately simulate the real-world attack scenarios and attack methods, which makes the evaluation results closer to the actual situation and can more accurately reflect the protection capability of the system. By comprehensively analyzing the original identity verification value and current identity verification value of the bait file, the preset encryption start time, the restoration start time, the restoration completion time and other factors, these data can more accurately reflect the actual performance of the system under the ransomware encryption behavior, thereby improving the accuracy of the evaluation and avoiding the problem of being too simple and one-sided in determining the system protection capability based solely on the number of historical encryption successes and failures. Moreover, when testing the system protection capability, the embodiment of the present invention does not need to re-establish a new environment, does not need to disconnect the network, does not have any impact on other components in the system network, does not require full disk encryption, and only needs to encrypt specific files and folders, so the target system can be guaranteed to be harmless. The embodiment of the present invention can also configure multiple encryption algorithms, execution time, bait file types, bait file paths, etc. to comprehensively evaluate the target system's detection, protection, and recovery capabilities against ransomware encryption behavior.

[0070] According to a harmless verification method for ransomware encryption behavior protection capability provided by the present invention, compared with the current method of determining the system's protection capability by the number of successful and failed encryptions of files in the system by ransomware within a historical time period, the present invention constructs a bait file in the target system in response to a verification signal of the target system's protection capability against ransomware encryption behavior, and determines the original identity verification value of the bait file; and simulates the behavior of the ransomware to encrypt the bait file at a preset encryption start time using a preset encryption method, and in the encryption process of encrypting the bait file, obtains the target system's response information to the encryption process; then, if the response information is restore response information for the encrypted bait file, obtains the restore start time and restore completion time for the target system to restore the encrypted bait file, and obtains the current identity verification value of the restored bait file; and finally, based on the original identity verification value, the current identity verification value, the preset encryption start time, the restore start time, and the restore completion time, verifies the target system's protection capability against ransomware encryption behavior. Therefore, when it is necessary to test the protection capability of the target system, after receiving the prediction signal, a bait file is constructed in the target system, and the bait file is encrypted by simulating the behavior of the ransomware virus. The protection capability of the target system is judged by the response information of the target system to the ransomware virus. That is, the present invention can perform protection capability detection on the target system after receiving the protection capability prediction signal, and can accurately reflect the protection capability of the target system at the current moment. At the same time, by comprehensively analyzing the original identity verification value and current identity verification value of the bait file, the preset encryption start time, the restoration start time, the restoration completion time and other factors to verify the protection capability of the target system against the ransomware virus encryption behavior, the verification accuracy of the system protection capability can be improved.

[0071] Furthermore, in order to better illustrate the above process of classifying data, as a refinement and extension of the above embodiment, the embodiment of the present invention provides another harmless verification method for the protection capability of ransomware encryption behavior, such as Figure 2 As shown, the method includes:

[0072] 201. In response to a verification signal of the target system's ability to protect against ransomware encryption behavior, construct a bait file in the target system and determine an original identity verification value of the bait file.

[0073] For an embodiment of the present invention, in order to simulate the encryption behavior of the ransomware virus and avoid problems such as data corruption caused by using real data in the system, it is necessary to create a bait file. Based on this, the method includes: obtaining the encryption tendency information of the ransomware virus, and obtaining the predicted demand information of the protection capability of the target system; based on the encryption tendency information and the predicted demand information, determining the bait file type and bait file content; based on the bait file type and bait file content, constructing the bait file in the target system.

[0074] Among them, encryption tendency information includes information such as file types that ransomware likes to encrypt, file contents, file locations that it likes to attack, and commonly used encryption methods; predicted demand information refers to: system type, system architecture, system purpose, existing protection mechanisms of the target system, backup and restore mechanisms, system performance, resource usage, important file types in the system, and protection information expected for the system.

[0075] Specifically, the type and content of the decoy file to be constructed can be determined based on the file types and content that the ransomware is likely to target. Alternatively, the type of the decoy file to be constructed can be determined based on the file types of important files that need to be protected in the target system. Alternatively, the type and content of the decoy file to be constructed can be determined by combining ransomware propensity information with predicted target system demand information. Analyzing the target system's type, architecture, and purpose, as well as the ransomware's propensity for attack, can help determine the location and method of deploying the decoy file within the target system. In another embodiment of the present invention, a preset file prediction model can be used to determine the file type and file content of the bait file to be constructed. In order to improve the prediction accuracy of the preset file prediction model, it is first necessary to train and construct the preset file prediction model. Based on this, the method includes: constructing an initial model and obtaining a sample data set, wherein the sample data set includes encryption tendency information of a sample ransomware virus with label information and predicted demand information of a sample system, and the label information is the file type and file content of the sample bait file for accurately detecting the system protection capability; dividing the sample data set into training data and test data, using the training data to train the initial model, and using the test data to test the trained initial model; and finally determining the initial model that meets the test conditions as the preset file prediction model. Furthermore, after constructing the preset file prediction model, it is necessary to use the model to predict the file type and file content of the bait file to be constructed. Based on this, the method includes: determining the tendency feature vector corresponding to the encrypted tendency information and the demand feature vector corresponding to the predicted demand information; cross-processing the tendency feature vector and the demand feature vector to obtain a file cross-feature vector; inputting the file cross-feature vector into the preset file prediction model to predict the file type and file content, and obtaining the file type and file content of the bait file to be constructed. Among them, the process of cross-processing the tendency feature vector and the demand feature vector includes: performing feature-level cross-processing on the tendency feature vector and the demand feature vector to obtain a feature cross-vector; performing element-level cross-processing on the tendency feature vector and the demand feature vector to obtain an element cross-vector; performing low-level cross-processing on the tendency feature vector and the demand feature vector to obtain a low-level cross-vector; using a preset transformation function to transform the feature cross-vector, the element cross-vector, and the low-level cross-vector to obtain a file cross-feature vector.

[0076] Specifically, in order to make full use of the relationship between data, extract more implicit features, and take into account both high-order and low-order processing, so that data utilization is more sufficient, the subsequent prediction results are more accurate, and meet the needs of actual application scenarios, it is necessary to cross-process the tendency feature vector and the demand feature vector. The specific cross-processing method is as follows: if the tendency feature vector is (a1, a2) and the demand feature vector is (b1, b2), the specific cross-processing method includes: performing feature-level crossover between different feature vectors, that is, performing Hadamard product on all elements between vectors, and then performing convolution transformation under certain weights to obtain a feature cross vector of f(w*(a1*b1, a2*b2)); at the same time, for all feature vectors The data is crossed at the element level, that is, after making a Hadamard product for each element between the vectors, a different weight value is assigned to the result of each product, and then a linear transformation is performed, and the obtained element cross vector is f(w1*a1*b1,w2*a2*b2); in addition, all feature vectors are subjected to low-order cross processing, and the results after the cross processing are assigned weight coefficients, and then a linear transformation is performed, and the obtained low-order cross vector is f(w2(a1,a2,b1,b2)); finally, the preset transformation function is used (the preset transformation function can be set according to the actual situation, and this embodiment does not limit this) to transform the above feature cross vectors, element cross vectors, and low-order cross vectors, such as horizontal splicing, to obtain a file cross feature vector. It should be noted that the above examples are only illustrative and do not limit the embodiments of the present application. Therefore, by cross-processing the tendency feature vector and the demand feature vector, different features can be automatically or explicitly combined to generate new feature combinations. These combined features may contain complex nonlinear relationships between the original features, so that the model can capture more detailed and rich information in the data, that is, it can make full use of the relationship between various data and extract more implicit features. At the same time, it takes into account high-order and low-order processing, so that data utilization is more sufficient, and the subsequent file type and file content predictions are more accurate, meeting the needs of actual application scenarios.

[0077] Furthermore, after determining the file type and content of the decoy file to be constructed, a decoy file is constructed based on the file type and content. The decoy file is then stored in a corresponding location in the target system. By constructing a decoy file to test the system's protection capabilities, the embodiment of the present invention can avoid the risk of file corruption caused by testing with real files in the system.

[0078] 202. Simulate the behavior of the ransomware virus to encrypt the bait file using a preset encryption method at a preset encryption start time, and obtain response information of the target system to the encryption process during the encryption process of the bait file.

[0079] For the embodiment of the present invention, in order to ensure the predicted effect of the protection capability of the target system, it is first necessary to select a suitable preset encryption method. Based on this, the method includes: determining the anti-attack capability information, encryption speed information, and occupied resource information of the encryption method to be selected based on the predicted demand information of the protection capability of the target system and the available memory resource information of the target system; based on the anti-attack capability information, the encryption speed information, and the occupied resource information, determining the preset encryption method among different encryption methods.

[0080] Specifically, if the predicted demand for the protection capability of the target system is high, an encryption method with strong anti-attack capability and fast encryption speed can be selected. If the predicted demand for the protection capability of the target system is low, an encryption method with weak anti-attack capability and slow encryption speed can be selected. At the same time, according to the structure, type and other information of the target system, an encryption method that matches it is selected. According to the available resource space of the target system, that is, the available storage space, an encryption method that can run smoothly is selected, that is, the resource occupancy information of the selected encryption method can match the available resource space of the system. Finally, based on the anti-attack capability, encryption speed, occupied resources and other information of the encryption method to be selected, a preset encryption method is selected from multiple known encryption methods. In another embodiment of the present invention, the preset encryption method can also be determined based on the encryption method tending to be used by the ransomware, or the preset encryption method can be determined by comprehensively analyzing the encryption method tending to be used by the ransomware and the predicted demand information of the target system. The embodiment of the present invention encrypts the bait file by selecting a suitable encryption method to simulate the behavior of the ransomware. The suitable encryption method can verify the actual effect of the system protection technology. At the same time, the suitable encryption method can truly simulate the encryption behavior of the ransomware, including its encryption mechanism, encryption strength, and the status of the encrypted file. This helps to ensure the prediction accuracy and effectiveness of the system protection capability, making the evaluation results closer to the actual ransomware attack situation.

[0081] 203. If the response information is restoration response information for the encrypted bait file, determine a restoration method for the target system to restore the encrypted bait file.

[0082] Specifically, the restoration method includes a backup restoration method and a decryption restoration method. The backup restoration method is to restore the bait file that was previously backed up to another location in the system (the backup location) to the starting location of the bait file (the current location). The decryption restoration method is to decrypt the encrypted bait file to restore the encrypted bait file.

[0083] 204. Obtain the restoration start time and restoration completion time of the target system for the encrypted bait file according to the restoration method, and obtain the current identity verification value of the bait file after restoration according to the restoration method.

[0084] For an embodiment of the present invention, if the restoration method is a backup restoration method, the method for obtaining the restoration start time, the restoration completion time, and the current identity verification value includes: in the backup restoration method, determining the current location of the bait file, and determining the backup location after backing up the bait file at the current location; in response to the target system's migration response information for the encrypted bait file, determining the migration start time and migration completion time for the target system to migrate the bait file at the backup location to the current location, and obtaining the current identity verification value of the bait file after migrating to the current location, and determining the migration start time as the restoration start time and the migration completion time as the restoration completion time.

[0085] Specifically, if the backup and restore method is adopted, after receiving the migration response information, the migration start time and migration completion time of migrating the bait file at the backup location to the current location through copy and paste operations are determined, the migration start time is determined as the restore start time of the encrypted bait file, and the migration completion time is determined as the restore completion time of the encrypted bait file. At the same time, after migrating the backed-up bait file to the current location, the bait file before the backup needs to be deleted. At the same time, the current identity verification value of the bait file after migration is determined, and finally the protection capability of the target system against the ransomware encryption behavior is verified based on the original identity verification value of the bait file, the current identity verification value of the bait file after backup and restoration, the preset encryption start time, the migration start time, and the migration completion time.

[0086] In another embodiment of the present invention, if a decryption and restoration method is used, after receiving the decryption response information, the target system determines the interpretation start time and decryption completion time of the encrypted bait file. The decryption start time is determined as the restoration start time, and the decryption completion time is determined as the restoration completion time. After the decryption is completed, the current identity verification value of the decrypted bait file is determined. Finally, based on the original identity verification value of the bait file, the current identity verification value of the decrypted bait file, the preset encryption start time, the decryption start time, and the decryption completion time, the target system's protection capability against ransomware encryption is verified.

[0087] 205. Verify the target system's protection against ransomware encryption based on the original identity verification value, the current identity verification value, the preset encryption start time, the restore start time, and the restore completion time.

[0088] For the embodiment of the present invention, in the backup and restore mode, the protection capability of the target system against ransomware encryption behavior is verified based on the original identity verification value of the bait file, the current identity verification value of the bait file after the backup and restore, the preset encryption start time, the migration start time, and the migration completion time. For example, based on the original identity verification value and the current identity verification value, the target system's restoration integrity coefficient for the bait file is determined; based on the migration start time and the migration completion time, the target system's migration restoration speed coefficient for the bait file is determined; based on the preset encryption start time and the migration completion time, the target system's migration recovery speed coefficient for ransomware encryption behavior is determined; based on the restoration integrity coefficient, the migration speed coefficient, and the migration recovery speed coefficient, the target system's protection capability against ransomware encryption behavior is verified.

[0089] In the decryption and restoration mode, the target system's protection capability against ransomware encryption is verified based on the original identity verification value of the bait file, the current identity verification value of the decrypted bait file, the preset encryption start time, the decryption start time, and the decryption completion time. For example, based on the original identity verification value and the current identity verification value, the target system's restoration integrity coefficient for the bait file is determined; based on the decryption start time and the decryption completion time, the target system's decryption restoration speed coefficient for the bait file is determined; based on the preset encryption start time and the decryption completion time, the target system's decryption recovery speed coefficient for ransomware encryption is determined; and based on the restoration integrity coefficient, the decryption speed coefficient, and the decryption recovery speed coefficient, the target system's protection capability against ransomware encryption is verified.

[0090] According to another harmless verification method for the protection capability of ransomware encryption behavior provided by the present invention, compared with the current method of determining the protection capability of a system by the number of successful and failed encryptions of files in the system by ransomware within a historical time period, the present invention constructs a bait file in the target system in response to a verification signal of the target system's protection capability against ransomware encryption behavior, and determines the original identity verification value of the bait file; and simulates the behavior of the ransomware to encrypt the bait file at a preset encryption start time using a preset encryption method, and in the encryption process of encrypting the bait file, obtains the response information of the target system to the encryption process; then, if the response information is restoration response information for the encrypted bait file, obtains the restoration start time and restoration completion time of the target system for restoring the encrypted bait file, and obtains the current identity verification value of the restored bait file; and finally, based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time, verifies the protection capability of the target system against ransomware encryption behavior. Therefore, when it is necessary to test the protection capability of the target system, after receiving the prediction signal, a bait file is constructed in the target system, and the bait file is encrypted by simulating the behavior of the ransomware virus. The protection capability of the target system is judged by the response information of the target system to the ransomware virus. That is, the present invention can perform protection capability detection on the target system after receiving the protection capability prediction signal, and can accurately reflect the protection capability of the target system at the current moment. At the same time, by comprehensively analyzing the original identity verification value and current identity verification value of the bait file, the preset encryption start time, the restoration start time, the restoration completion time and other factors to verify the protection capability of the target system against the ransomware virus encryption behavior, the verification accuracy of the system protection capability can be improved.

[0091] Further, as Figure 1 The specific implementation of the present invention provides a harmless verification device for the protection capability of ransomware encryption behavior, such as Figure 3 As shown, the device includes: a construction unit 31, an encryption simulation unit 32, an acquisition unit 33, and a determination unit 34.

[0092] The construction unit 31 can be used to construct a bait file in the target system in response to a verification signal of the target system's ability to protect against ransomware encryption behavior, and determine an original identity verification value of the bait file.

[0093] The encryption simulation unit 32 can be used to simulate the behavior of the ransomware virus to encrypt the bait file using a preset encryption method at a preset encryption start time, and obtain the response information of the target system to the encryption process during the encryption process of the bait file.

[0094] The acquisition unit 33 can be used to obtain the restoration start time and restoration completion time of the target system for the encrypted bait file if the response information is the restoration response information of the encrypted bait file, and obtain the current identity verification value of the restored bait file.

[0095] The determining unit 34 may be configured to verify the target system's protection capability against ransomware encryption based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time.

[0096] In a specific application scenario, when the response information is interception response information to the encryption process, in order to determine the system protection capability, the acquisition unit 33 can also be used to obtain the process identification time of the target system for the encryption process, the interception start time of the target system for the encryption process, the interception operation information of the target system for the encryption process, and the interception completion time of the target system for the encryption process if the response information is interception response information to the encryption process.

[0097] The determining unit 34 may also be configured to determine a threat detection capability coefficient of the target system for the encryption process based on the process identification time and the preset encryption start time.

[0098] The determining unit 34 may also be configured to determine an interception response speed coefficient of the target system to the encryption process based on the preset encryption start time and the interception start time.

[0099] The determining unit 34 may also be configured to determine an interception efficiency coefficient of the target system for the encryption process based on the interception start time and the interception completion time.

[0100] The determining unit 34 may also be configured to determine an interception effect evaluation coefficient of the target system on the encryption process based on the interception operation information.

[0101] The determining unit 34 may also be configured to verify the target system's protection capability against ransomware encryption behavior based on the threat detection capability coefficient, the interception response speed coefficient, the interception efficiency coefficient, and the interception effect evaluation coefficient.

[0102] In a specific application scenario, in order to obtain the target system's restoration start time and restoration completion time for the encrypted bait file, and obtain the current identity verification value of the restored bait file, such as Figure 4 As shown, the acquisition unit 33 includes a first determination module 331 and a first acquisition module 332 .

[0103] The first determining module 331 may be configured to determine a restoration method for the target system to restore the encrypted decoy file.

[0104] The first acquisition module 332 can be used to obtain the restoration start time and restoration completion time of the target system for the encrypted bait file according to the restoration method, and obtain the current identity verification value of the bait file after restoration according to the restoration method.

[0105] In a specific application scenario, in the backup and restore mode, in order to obtain information, the first acquisition module 332 can be specifically used to determine the current location of the bait file in the backup and restore mode, and determine the backup location after backing up the bait file at the current location; in response to the target system's migration response information for the encrypted bait file, determine the migration start time and migration completion time for the target system to migrate the bait file at the backup location to the current location, and obtain the current identity verification value of the bait file after migrating to the current location, and determine the migration start time as the restore start time and the migration completion time as the restore completion time.

[0106] In the decryption and restoration mode, in order to obtain information, the first acquisition module 332 can be specifically used to determine the decryption start time and decryption completion time of the target system for decrypting the encrypted bait file in response to the decryption response information of the target system for the encrypted bait file in the decryption and restoration mode, and obtain the current identity verification value of the decrypted bait file, and determine the decryption start time as the restoration start time and the decryption completion time as the restoration completion time.

[0107] In a specific application scenario, in order to determine the protection capability of the target system, the determination unit 34 can be specifically used to determine the restoration completeness coefficient of the target system for the bait file based on the original identity verification value and the current identity verification value; determine the restoration speed coefficient of the target system for the bait file based on the restoration start time and the restoration completion time; determine the recovery speed coefficient of the target system for ransomware encryption behavior based on the preset encryption start time and the restoration completion time; and verify the protection capability of the target system against ransomware encryption behavior based on the restoration completeness coefficient, the restoration speed coefficient, and the recovery speed coefficient.

[0108] In a specific application scenario, in order to construct a bait file, the construction unit 31 includes a second acquisition module 311 , a second determination module 312 , and a construction module 313 .

[0109] The second acquisition module 311 can be used to obtain encryption tendency information of the ransomware virus and obtain predicted demand information for the protection capability of the target system.

[0110] The second determining module 312 may be configured to determine the type and content of the bait file based on the encryption tendency information and the predicted demand information.

[0111] The construction module 313 may be configured to construct the bait file in the target system based on the bait file type and bait file content.

[0112] In a specific application scenario, in order to determine the preset encryption method, the determination unit 34 can also be used to determine the anti-attack capability information, encryption speed information, and occupied resource information of the encryption method to be selected based on the predicted demand information of the protection capability of the target system and the available memory resource information of the target system; based on the anti-attack capability information, the encryption speed information, and the occupied resource information, the preset encryption method is determined among different encryption methods.

[0113] It should be noted that for other corresponding descriptions of the functional modules involved in the harmless verification device for protecting against ransomware encryption provided by the embodiment of the present invention, please refer to Figure 1 The corresponding description of the method shown will not be repeated here.

[0114] Based on the above Figure 1The method shown, accordingly, an embodiment of the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the following steps: in response to a verification signal of the target system's ability to protect against ransomware encryption behavior, construct a bait file in the target system, and determine the original identity verification value of the bait file; simulate the behavior of the ransomware virus to encrypt the bait file at a preset encryption start time using a preset encryption method, and in the encryption process of encrypting the bait file, obtain the response information of the target system to the encryption process; if the response information is the restoration response information of the encrypted bait file, then obtain the restoration start time and restoration completion time of the target system for restoring the encrypted bait file, and obtain the current identity verification value of the restored bait file; based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time, verify the protection capability of the target system against ransomware encryption behavior.

[0115] Based on the above Figure 1 The method shown and Figure 3 The embodiment of the device shown in the figure, the embodiment of the present invention also provides a physical structure diagram of a computer device, such as Figure 5 As shown, the computer device includes: a processor 41, a memory 42, and a computer program stored in the memory 42 and executable on the processor, wherein the memory 42 and the processor 41 are both arranged on a bus 43, and when the processor 41 executes the program, the following steps are implemented: in response to a verification signal of the target system's ability to protect against ransomware encryption behavior, a bait file is constructed in the target system, and an original identity verification value of the bait file is determined; the behavior of the ransomware is simulated to encrypt the bait file at a preset encryption start time using a preset encryption method, and in the encryption process of encrypting the bait file, response information of the target system to the encryption process is obtained; if the response information is a restoration response information of the encrypted bait file, the restoration start time and restoration completion time of the target system for restoring the encrypted bait file are obtained, as well as the current identity verification value of the restored bait file; based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time, the protection capability of the target system against ransomware encryption behavior is verified.

[0116] Through the technical solution of the present invention, the present invention constructs a bait file in the target system and determines the original identity verification value of the bait file in response to a verification signal of the target system's protection capability against ransomware encryption behavior; and simulates the behavior of the ransomware to encrypt the bait file at a preset encryption start time using a preset encryption method, and in the encryption process of encrypting the bait file, obtains the response information of the target system to the encryption process; thereafter, if the response information is the restoration response information of the encrypted bait file, the restoration start time and restoration completion time of the target system for restoring the encrypted bait file are obtained, and the current identity verification value of the restored bait file is obtained; finally, based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time, the protection capability of the target system against ransomware encryption behavior is verified. Therefore, when it is necessary to test the protection capability of the target system, after receiving the prediction signal, a bait file is constructed in the target system, and the bait file is encrypted by simulating the behavior of the ransomware virus. The protection capability of the target system is judged by the response information of the target system to the ransomware virus. That is, the present invention can perform protection capability detection on the target system after receiving the protection capability prediction signal, and can accurately reflect the protection capability of the target system at the current moment. At the same time, by comprehensively analyzing the original identity verification value and current identity verification value of the bait file, the preset encryption start time, the restoration start time, the restoration completion time and other factors to verify the protection capability of the target system against the ransomware virus encryption behavior, the verification accuracy of the system protection capability can be improved.

[0117] Obviously, those skilled in the art will appreciate that the various modules or steps of the present invention described above can be implemented using a general-purpose computing device, centralized on a single computing device, or distributed across a network of multiple computing devices. Alternatively, they can be implemented using program code executable by a computing device, which can then be stored in a storage device and executed by the computing device. In some cases, the steps shown or described can be performed in a different order than that shown, or can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.

[0118] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.

Claims

1. A method for verifying the harmlessness of the protection capability of ransomware encryption behavior, characterized in that: include: In response to a verification signal of the target system's ability to protect against ransomware encryption behavior, construct a bait file in the target system and determine an original identity verification value of the bait file; Simulating the behavior of the ransomware virus, encrypting the bait file using a preset encryption method at a preset encryption start time, and obtaining response information of the target system to the encryption process during the encryption process of the bait file; If the response information is restoration response information for the encrypted bait file, obtaining the restoration start time and restoration completion time of the target system for restoring the encrypted bait file, and obtaining the current identity verification value of the restored bait file; Verifying the target system's protection capability against ransomware encryption based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time; The verifying the target system's protection capability against ransomware encryption based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time includes: Determining a restoration completeness coefficient of the target system for the decoy file based on the original identity check value and the current identity check value; determining a restoration speed coefficient of the target system for the decoy file based on the restoration start time and the restoration completion time; determining a recovery speed coefficient of the target system for ransomware encryption behavior based on the preset encryption start time and the restoration completion time; and verifying the target system's protection capability against ransomware encryption behavior based on the restoration completeness coefficient, the restoration speed coefficient, and the recovery speed coefficient. The constructing of the bait file in the target system includes: Obtain encryption tendency information of the ransomware virus and predicted demand information for protection capabilities of the target system; determine the bait file type and bait file content based on the encryption tendency information and the predicted demand information; and construct the bait file in the target system based on the bait file type and bait file content.

2. The method according to claim 1, characterized in that After obtaining response information of the target system to the encryption process, the method further includes: If the response information is interception response information of the encryption process, then obtaining the process identification time of the encryption process by the target system, the interception start time of the encryption process by the target system, the interception operation information of the encryption process by the target system, and the interception completion time of the encryption process by the target system; determining a threat detection capability coefficient of the target system for the encryption process based on the process identification time and the preset encryption start time; Determining an interception response speed coefficient of the target system to the encryption process based on the preset encryption start time and the interception start time; determining an interception efficiency coefficient of the target system for the encryption process based on the interception start time and the interception completion time; determining, based on the interception operation information, an interception effect evaluation coefficient of the target system on the encryption process; Based on the threat detection capability coefficient, the interception response speed coefficient, the interception efficiency coefficient, and the interception effect evaluation coefficient, the protection capability of the target system against ransomware encryption behavior is verified.

3. The method according to claim 1, characterized in that The obtaining of the restoration start time and restoration completion time of the target system for restoring the encrypted bait file, and obtaining the current identity verification value of the restored bait file, includes: Determining a restoration method of the target system for the encrypted bait file; The restoration start time and restoration completion time of the target system for restoring the encrypted bait file according to the restoration method are obtained, and the current identity verification value of the bait file restored according to the restoration method is obtained.

4. The method according to claim 3, characterized in that The restoration method includes a backup restoration method and a decryption restoration method; The obtaining of the restoration start time and restoration completion time of the target system for the encrypted bait file according to the restoration method, and the obtaining of the current identity verification value of the bait file after restoration according to the restoration method, include: In the backup and restore mode, determining the current location of the bait file, and determining a backup location after backing up the bait file at the current location; In response to the target system's response to the encrypted bait file's migration response, determine a migration start time and a migration completion time for the target system to migrate the bait file from the backup location to the current location, obtain a current identity verification value of the bait file after migrating to the current location, and determine the migration start time as the restoration start time and the migration completion time as the restoration completion time; In the decryption and restoration mode, in response to the decryption response information of the target system to the encrypted bait file, the decryption start time and the decryption completion time of the target system for decrypting the encrypted bait file are determined, and the current identity verification value of the decrypted bait file is obtained, and the decryption start time is determined as the restoration start time and the decryption completion time is determined as the restoration completion time.

5. The method according to claim 1, wherein Before encrypting the decoy file using a preset encryption method at a preset encryption start time by simulating the behavior of the ransomware, the method further includes: Determining the anti-attack capability information, encryption speed information, and resource usage information of the encryption method to be selected based on the predicted demand information of the protection capability of the target system and the available memory resource information of the target system; The preset encryption mode is determined among different encryption modes based on the anti-attack capability information, the encryption speed information, and the occupied resource information.

6. A harmless verification device for protecting against ransomware encryption behavior, characterized in that: include: A construction unit, configured to construct a bait file in the target system in response to a verification signal of the target system's ability to protect against ransomware encryption behavior, and determine an original identity verification value of the bait file; The constructing of the bait file in the target system includes: obtaining encryption tendency information of the ransomware virus and obtaining predicted demand information for the protection capability of the target system; determining the type and content of the bait file based on the encryption tendency information and the predicted demand information; and constructing the bait file in the target system based on the type and content of the bait file. an encryption simulation unit, configured to simulate the behavior of a ransomware virus, encrypt the decoy file using a preset encryption method at a preset encryption start time, and obtain response information of the target system to the encryption process during the encryption process of the decoy file; an acquiring unit, configured to acquire, if the response information is restoration response information for the encrypted bait file, a restoration start time and a restoration completion time for the target system to restore the encrypted bait file, and acquire a current identity verification value of the restored bait file; A determination unit is configured to verify the target system's protection capability against ransomware encryption behavior based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time; wherein, the verification of the target system's protection capability against ransomware encryption behavior based on the original identity verification value, the current identity verification value, the preset encryption start time, the restoration start time, and the restoration completion time includes: determining the target system's restoration integrity coefficient for the bait file based on the original identity verification value and the current identity verification value; determining the target system's restoration speed coefficient for the bait file based on the restoration start time and the restoration completion time; determining the target system's recovery speed coefficient for ransomware encryption behavior based on the preset encryption start time and the restoration completion time; and verifying the target system's protection capability against ransomware encryption behavior based on the restoration integrity coefficient, the restoration speed coefficient, and the recovery speed coefficient.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Network security performance evaluation method

    CN103618691A

  • Method for defending attacks based on attack organization capability evaluation

    CN110798454A