Detection and protection method for ransomware virus

The kernel layer driver module performs hook operation and isolate and backup of the underlying files of the system, detect ransomware in real time and restore encrypted files, solving the problem of ineffective detection of unknown viruses and inaccurate backups in the existing technology, and achieving effective protection of ransomware and complete recovery of data.

CN120068065APending Publication Date: 2025-05-30XIAMEN ANSCEN NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411920357.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-25
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing ransomware detection technology cannot effectively detect unknown viruses, and the backup technology cannot accurately reach the specific files that need to be backed up, resulting in some files being ransom-encrypted.

Method used

The kernel layer driver module hooks the underlying file of the system to detect the access behavior of the file in real time, and perform isolation and backup before the file is opened. If the frequency of the file being modified and encrypted within a unit time exceeds the preset threshold, it is determined that ransomware is discovered, the ransomware process is aborted and isolated, and the backup file is restored.

Benefits of technology

Real-time detection and protection of ransomware is realized, ensuring the complete recovery of encrypted files, reducing the risk of data loss and business interruption, and improving disk utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068065A_ABST
    Figure CN120068065A_ABST
Patent Text Reader

Abstract

The invention discloses a ransomware detection and protection method which specifically comprises the following steps: opening an api function by utilizing a kernel layer driving module to carry out hook operation on a system underlying file, and detecting an access behavior of the file in real time; when a file opening operation is detected, performing isolation backup on the file before the file is opened; if it is detected that the frequency of modifying and encrypting the file in unit time exceeds a preset threshold value, it is judged that ransomware is found; if the ransomware is found, the ransomware process is stopped and isolated, the corresponding backup file is recovered, after the recovery operation is completed, the backup file is cleared, and meanwhile, the user layer interaction module sends out ransomware early warning; if the ransomware is not found, the backup file is cleared, and a kernel layer driving module opens an api function to continue to monitor a system bottom layer file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network virus prevention and handling, and mainly relates to a method for detecting and protecting against ransomware. Background Art

[0002] With the acceleration of the digitalization process and the improvement of network security awareness, ransomware attack incidents occur frequently, bringing serious financial losses and data security risks to individuals and enterprises. Effective detection and data recovery can not only help organizations quickly discover attacks, but also reduce potential losses and ensure the integrity and availability of data. Therefore, it is particularly important to improve ransomware detection and data recovery technologies.

[0003] Currently, the related detection technologies for ransomware mainly include methods such as signature matching, behavior analysis, and machine learning. Signature matching, although accurate in detection, highly depends on virus signatures and cannot detect unknown viruses. Behavior detection can make up for the ransomware that cannot be captured by signature detection, but if the ransomware changes the encryption algorithm logic, there may still be a situation where it cannot be detected. Machine learning can improve the detection rate of behavior detection, but still has the disadvantages based on behavior detection. For example, multi-process or grouped encryption can bypass it. Therefore, the above ransomware detection methods cannot avoid some files being encrypted by ransomware. To deal with the damage of ransomware to files, relevant files can be backed up in advance. Currently, the related backup technologies mainly include cloud host backup, cloud hard disk backup, and database backup. The above backup methods cannot accurately target the specific files to be backed up, or directly perform full-volume backups, wasting disk space and increasing the backup cost. Summary of the Invention

[0004] In view of the above deficiencies of the prior art, the purpose of the present invention is to provide a method for detecting ransomware and completely recovering encrypted files, and the specific steps are as follows:

[0005] Use the kernel layer driver module to open the api function to perform a hook operation on the system underlying files, and real-time detect the access behavior of files; when a file open operation is detected, isolate and back up the file before the file is opened;

[0006] If the frequency of detecting that a file is modified and encrypted within a unit time exceeds a preset threshold, it is determined that ransomware is found; if ransomware is found, abort and isolate the ransomware process, and restore the corresponding backup file. After the restoration operation is completed, delete the backup file, and at the same time, the user layer interaction module issues a ransomware warning; if ransomware is not found, delete the backup file, and the kernel layer driver module opens the api function to continue monitoring the system underlying files.

[0007] Further, before the file is opened, the file is isolated and backed up. Among them, only the kernel layer driver module has access to the isolated backup file, and other processes cannot access it.

[0008] By hooking the file operation interface (API) at the operating system kernel layer, real-time monitoring of file opening, reading, writing and other behaviors can capture all file access operations, even those performed through ordinary applications or malware, ensuring that capture and recording can be carried out when file operations occur, and potential ransomware activities can be detected in a timely manner. The monitoring scope includes all types of files, especially important system files and user data files.

[0009] Further, during the isolation backup, if it is detected that the disk storage space is insufficient, the access to the file is interrupted, and an alarm notification of insufficient disk space is sent in the user layer interaction module.

[0010] When the system detects that a file is opened, the file is first backed up and the backup file is isolated and stored. In this way, even if the ransomware encrypts the original file, the backup file is still safe.

[0011] Further, the real-time detection of file access behaviors includes file hash values, file extensions, and file attribute statuses.

[0012] Through the monitoring of file attribute changes, it can be detected whether the file has been encrypted or tampered with by ransomware. Among them, the change of the hash value can help identify abnormal file operations.

[0013] Further, the access permission uses a strong encryption algorithm to encrypt the backup file, and the backup file is dispersed and stored in different physical locations or cloud storage.

[0014] Enhance the security of the backup file, prevent ransomware or other malicious programs from encrypting or deleting them by accessing the backup file, thereby ensuring the integrity of the backup data.

[0015] Further, the cleaning of backup files automatically clears old backup files or low-priority files according to preset rules to free up storage space.

[0016] After confirming that the virus has been cleared, the system will use the previous backup file to restore the encrypted file, and at the same time clean up the backup files that are no longer needed. By restoring the backup file, it is ensured that the user's data can be restored to the original state after a ransomware attack, avoiding data loss and business interruption. The cleaning of backup files is to prevent backup files from occupying too much space in the system.

[0017] Further, perform an operation to terminate and isolate the ransomware process, wherein redirect the ransomware process to run in a sandbox environment, record the behavior performance of the ransomware process, so as to further optimize the preset threshold of the file.

[0018] The system continuously monitors file operations to ensure that file access behaviors are continuously tracked, and new security threats are discovered in a timely manner. Ensure that the real-time monitoring of file access is not interrupted, and enhance the ability to prevent potential virus activities. Continuous monitoring can ensure the security of the file system and discover new attack patterns in a timely manner.

[0019] According to a second aspect of the present invention, there is provided a computer program product, on which one or more computer programs are stored, and when the one or more computer programs are executed by a computer processor, the above-mentioned method is implemented.

[0020] One or more of the above technical solutions in the embodiments of the present application have at least one of the following technical effects:

[0021] By using the kernel layer driver to hook and monitor the file read and write APIs and synchronously isolate and back up the accessed files. After detecting the ransomware behavior, block and isolate the ransomware, recover the encrypted files, and notify the desktop for warning. The technology of the present invention can improve the utilization rate of the disk and the recovery ability of the encrypted files. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The drawings are included to provide a further understanding of the embodiments and are incorporated into and constitute a part of this specification. The drawings illustrate the embodiments and, together with the description, are used to explain the principles of the present invention. Other embodiments and many of the intended advantages of the embodiments will be readily appreciated as they become better understood by reference to the following detailed description. The elements of the drawings are not necessarily to scale with each other. The same reference numerals refer to corresponding like parts.

[0023] Figure 1 A flowchart showing the detection and protection method of ransomware according to an embodiment of the present invention is shown.

[0024] Figure 2 A schematic structural diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] The present application will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention and are not intended to limit the invention. Additionally, it should be noted that, for the sake of convenience of description, only the parts related to the invention are shown in the drawings.

[0026] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The following will describe the present application in detail with reference to the drawings and in combination with the embodiments.

[0027] Figure 1 The flowchart shows a method for detecting and protecting against ransomware according to an embodiment of the present invention, as Figure 1 shown:

[0028] S1. The kernel layer driver module performs a hook operation on the system bottom layer file opening api function to monitor the file access behavior in real time;

[0029] Adopt multi-level logging: at each file access, record detailed log information (such as access time, process ID, user ID, etc.), and store it hierarchically according to the security level.

[0030] In some embodiments, a machine learning model is introduced to analyze historical access patterns and identify abnormal behaviors.

[0031] S2. When a file opening operation is detected, before the file is opened, isolate and back up the file first to prevent the backup file from being encrypted by ransomware;

[0032] For large files or frequently modified files, adopt an incremental backup method to only back up the changed parts, saving storage space. At the same time, maintain multiple backup versions for each file, allowing users to roll back to any historical version.

[0033] S3. Only the driver layer module has access rights to the isolated backup files, and other processes cannot access them;

[0034] Use a strong encryption algorithm (such as AES-256) to encrypt the backup files to ensure that even if the backup files are stolen, they cannot be decrypted.

[0035] Store the backup files dispersedly in different physical locations or cloud storages to improve data security. In some business embodiments, the backup files can also be stored in a dedicated isolated area that can only be accessed by the kernel driver module of the system. Other processes or applications do not have permission to access these backup files. This can enhance the security of the backup files and prevent ransomware or other malicious programs from encrypting or deleting them by accessing the backup files, thus ensuring the integrity of the backup data.

[0036] S4. If it is detected that the disk storage space is insufficient during backup, interrupt the file access and notify the user in the user layer interaction module that the disk space is insufficient;

[0037] When the system detects insufficient disk space, it will immediately interrupt the file access operation and prompt the user to free up space or expand the storage device to ensure the smooth progress of the file backup operation and prevent backup failures due to insufficient storage space. Notifying the user in a timely manner helps the user take measures as soon as possible to prevent data loss.

[0038] S5. Monitor the changes in the file status in real time, including file hash values, file extensions, etc.;

[0039] The system monitors changes in multiple file attributes, such as file hash values, extensions, sizes, modification times, etc. Changes in hash values are important indicators of whether a file has been tampered with or encrypted. By monitoring changes in file attributes, it is possible to detect whether a file has been encrypted or tampered with by ransomware. Changes in hash values are particularly crucial and can help identify abnormal file operations.

[0040] S6. If the frequency of file modification and encryption detected within a unit of time exceeds a preset threshold, it is determined that ransomware has been detected;

[0041] When the system detects that the frequency of file modification or encryption exceeds the set threshold within a certain period of time, the system will consider that there is ransomware activity and issue a warning.

[0042] Ransomware usually encrypts users' files in batches and adds specific extensions (such as `.encrypted`, `.locked`, `.crypt`, etc.) after encryption. If a large number of files are found to be unopenable and have no extensions within a short period of time, this may be a sign of ransomware.

[0043] By setting a reasonable threshold, it is possible to quickly identify abnormal file modification patterns, trigger the virus protection mechanism in a timely manner, and prevent further file encryption and data loss.

[0044] In this embodiment, if a certain number of files are modified or encrypted within a unit of time (such as within 1 minute, 5 minutes, or 10 minutes), an alarm may be triggered. Common thresholds may be set as follows:

[0045] 10 - 20 files / second;

[0046] 50 - 100 files / minute;

[0047] 200 - 500 files / hour;

[0048] If the number of file modifications exceeds the preset threshold, the system may consider that there is abnormal behavior (such as ransomware) and issue a warning.

[0049] S7. The threshold is a default value set in advance and can also be modified and set at the user interaction layer;

[0050] The system provides a default file modification threshold and at the same time allows users to customize the threshold according to their own needs, flexibly adapting to different usage scenarios. Ensure that the system can be optimized according to the needs of different users, such as different working environments, file importance, etc., to provide more accurate ransomware detection.

[0051] In some business embodiments, many modern antivirus software and IDSs set thresholds based on baseline behaviors. For example:

[0052] Normal file modification rate: When there is no ransomware, the system records the normal file modification frequency (e.g., the number of files modified per day). Once it exceeds multiple times of this normal value, it will be regarded as abnormal.

[0053] Threshold range: According to the scale of the enterprise network and the file usage pattern, the threshold may fluctuate within different ranges. For small enterprises, a lower threshold may be set, while for large enterprises, the threshold will be higher.

[0054] S8. If a ransomware is detected, perform an abort operation on the ransomware process, prohibit its operation, and perform an isolation operation on it to prevent it from running again;

[0055] When the system confirms the existence of ransomware, it will immediately abort the execution of the virus process and prohibit it from further encrypting files. At the same time, the virus process will be isolated to prevent it from restarting. By preventing the ransomware from running, minimize the damage of the virus to the system and files, and ensure that the virus cannot continue to encrypt more files. Isolating the virus process also provides space for subsequent forensics and analysis.

[0056] Furthermore, the ransomware process can be redirected to run in a sandbox environment, and the behavior of the ransomware process is recorded, so as to further optimize the preset threshold of the file.

[0057] S9. Then perform a recovery operation on the previously backed-up files and clear the backup files. The backup files are cleared according to preset rules to automatically clean up old backup files or low-priority files and release storage space;

[0058] After confirming that the virus has been cleared, the system will use the previous backup files to restore the encrypted files and at the same time clean up the backup files that are no longer needed. By restoring the backup files, ensure that the user's data can be restored to the original state after a ransomware attack, avoiding data loss and business interruption. Clearing the backup files is to prevent the backup files from occupying too much space in the system.

[0059] S10. The user layer interaction module issues a ransomware warning;

[0060] When the system detects a ransomware virus, it issues a warning through the user interaction module, notifying the user of the detection result of the ransomware virus and the current security status. Through timely warnings, users can quickly take further security measures, such as disconnecting the network, fixing system vulnerabilities, etc., to reduce the harm caused by ransomware viruses.

[0061] S11. If no ransomware virus is found, clear the previous backup files;

[0062] After confirming that the system has not been attacked by ransomware, the system will automatically delete all temporary backup files to free up storage space. Ensure that the system remains clean and avoid unnecessary storage occupation. At the same time, it also prevents the leakage or abuse of backup files without risk.

[0063] S12. The kernel layer driver module continues to monitor the system's underlying file open API functions.

[0064] The system continuously monitors file operations to ensure that file access behaviors are continuously tracked and new security threats are detected in a timely manner. Ensure that the real-time monitoring of file access is not interrupted, and enhance the ability to prevent potential virus activities. Continuous monitoring can ensure the security of the file system and detect new attack patterns in a timely manner.

[0065] In summary, the present invention uses a dual mechanism at the kernel layer and the user layer to monitor the behavior of system files in real time, protect files from being encrypted by ransomware viruses, and at the same time provide flexible backup and recovery solutions. When a virus is detected, the system can quickly respond and isolate the virus, restore the affected files, and issue a warning to the user. By intelligently adjusting thresholds, monitoring behaviors, and tracking file attributes, the system can not only effectively identify ransomware viruses, but also enhance the defense ability, reduce data loss, and system damage.

[0066] Next, refer to Figure 2 , which shows a schematic diagram of the structure of a computer system 200 of an electronic device suitable for implementing the embodiments of the present application. Figure 2 The shown electronic device is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.

[0067] As Figure 2 shown, the computer system 200 includes a central processing unit (CPU) 201, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 202 or the program loaded from the storage section 208 into the random access memory (RAM) 203. In the RAM 203, various programs and data required for the operation of the system 200 are also stored. The CPU 201, ROM 202, and RAM 203 are connected to each other through a bus 204. The input / output (I / O) interface 205 is also connected to the bus 204.

[0068] The following components are connected to the I / O interface 205: an input section 206 including a keyboard, a mouse, etc.; an output section 207 including a liquid crystal display (LCD) etc. and a speaker etc.; a storage section 208 including a hard disk etc.; and a communication section 209 including a network interface card such as a LAN card, a modem, etc. The communication section 209 performs communication processing via a network such as the Internet. A drive 210 is also connected to the I / O interface 205 as required. A removable medium 211, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is mounted on the drive 210 as required so that a computer program read out therefrom is installed into the storage section 208 as required.

[0069] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a computer-readable storage medium, and the computer program includes program code for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 209 and / or installed from the removable medium 211. When the computer program is executed by the central processing unit (CPU) 201, the above-described functions defined in the method of the present application are performed. It should be noted that the computer-readable storage medium of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable storage medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0070] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0071] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0072] The modules described in the embodiments of this application can be implemented in software or in hardware.

[0073] As another aspect, the present application also provides a computer-readable storage medium, which may be included in the electronic device described in the above embodiments; or may exist separately without being assembled into the electronic device. The above computer-readable storage medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device is enabled to: use the kernel layer driver module to open the api function to perform a hook operation on the system underlying files, and detect the access behavior of files in real time; when a file open operation is detected, isolate and back up the file before the file is opened; if the frequency of detecting that the file is modified and encrypted within a unit time exceeds a preset threshold, it is determined that a ransomware virus is found; if a ransomware virus is found, the ransomware virus process is aborted and isolated, and the corresponding backup file is restored. After the restoration operation is completed, the backup file is cleared, and at the same time, the user layer interaction module issues a ransomware virus warning; if no ransomware virus is found, the backup file is cleared, and the kernel layer driver module opens the api function to continue monitoring the system underlying files.

[0074] The above description is only the preferred embodiments of the present application and the description of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present application.

Claims

1. A method for detecting and protecting against ransomware, characterized in that: include: Use the kernel layer driver module to open the API function to hook the underlying system files and detect the file access behavior in real time; When a file opening operation is detected, the file is isolated and backed up before the file is opened; If the frequency of file modification and encryption detected in a unit time exceeds the preset threshold, it is determined that a ransomware virus has been discovered; If a ransomware virus is found, the ransomware virus process is terminated and isolated, and the corresponding backup files are restored. After the restoration operation is completed, the backup files are cleared, and the user layer interaction module issues a ransomware virus warning; If no ransomware virus is found, the backup files are cleared and the kernel layer driver module opens the API function to continue monitoring the underlying system files.

2. The detection and protection method according to claim 1, characterized in that: The file is isolated and backed up before the file is opened, wherein only the kernel layer driver module has access rights to the isolated backup file.

3. The detection and protection method according to claim 1, characterized in that: When the isolated backup is backing up, if it is detected that the disk storage space is insufficient, the access to the file is interrupted, and an alarm notification of insufficient disk space is issued in the user layer interaction module.

4. The detection and protection method according to claim 1, characterized in that: The real-time detection of file access behavior includes file hash value, file extension and file attribute status.

5. The detection and protection method according to claim 2, characterized in that: The access rights use a strong encryption algorithm to encrypt the backup files, and the backup files are dispersedly stored in different physical locations or cloud storage.

6. The detection and protection method according to claim 1, characterized in that: The backup file clearing method automatically clears old backup files or low-priority files according to preset rules to release storage space.

7. The detection and protection method according to claim 1, characterized in that: The ransomware process is terminated and isolated, wherein the ransomware process is redirected to a sandbox environment for execution, and the behavior of the ransomware process is recorded, thereby further optimizing the preset threshold of the file.

8. A computer program product, characterized in that A computer program is stored thereon, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

9. A computing system, characterized in that: The method comprises a processor and a memory, wherein the processor is configured to execute the method according to any one of claims 1 to 7.