Data exception processing method and device, equipment, medium and product

By analyzing the target log and evaluating ransomware risk values ​​in the backup storage system of the banking business system, combining multiple risk identification strategies, detecting and handling ransomware threats, the problem of fast and accurate detection and avoiding data losses is solved, and data security is achieved.

CN120068155APending Publication Date: 2025-05-30INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510244066.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

How to quickly and accurately detect whether data such as banking business systems are encrypted by ransomware, avoid data losses, and ensure data security.

Method used

By analyzing the target log in the backup storage system, determining the target backup file with a risk of ransomware, and performing anomaly detection operations, evaluating the first ransomware risk value. At the same time, the target production files are determined and risk identification strategies such as feature matching, reputation scores and encrypted traffic analysis are used to evaluate the second ransomware risk value. When a ransomware threat is detected, the policy is handled based on preset exception response.

Benefits of technology

It realizes timely and accurate abnormal detection of data files, avoids the losses caused by data encryption by ransomware, and ensures the security of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068155A_ABST
    Figure CN120068155A_ABST
Patent Text Reader

Abstract

The invention discloses a data exception processing method and device, equipment, a medium and a product. Relates to the field of big data, can be applied to the technical field of finance, and comprises the following steps: determining a target backup file with a ransomware risk according to a target log in a backup storage system, and executing an anomaly detection operation on the target backup file to determine a first ransomware risk value corresponding to the target backup file; determining a target production file corresponding to the target backup file, and determining a second ransomware risk value corresponding to the target production file by adopting at least two preset risk identification strategies; and according to the first ransomware risk value and the second ransomware risk value, performing exception handling based on a preset exception coping strategy when detecting that the ransomware threat risk exists. According to the technical scheme, anomaly detection can be carried out on the data file timely and accurately, loss caused by data encryption by ransomware is avoided, and data safety is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of big data and can be applied to the field of financial technology. In particular, it relates to a method, device, equipment, medium and product for data anomaly processing. Background Art

[0002] Ransomware is a type of malware that obtains profits by encrypting user data and demanding a ransom. With the continuous evolution of ransomware, especially in fields with high data security such as banking business systems, quickly detecting whether data has been encrypted by ransomware has become an important task.

[0003] Therefore, how to use file logs to detect data files for anomalies in a timely and accurate manner, avoid losses caused by data being encrypted by ransomware, and ensure data security is an urgent problem to be solved at present. Summary of the Invention

[0004] The present invention provides a method, device, equipment, medium and product for data anomaly processing to detect data files for anomalies in a timely and accurate manner, avoid losses caused by data being encrypted by ransomware, and ensure data security.

[0005] According to one aspect of the present invention, there is provided a method for data anomaly processing, including:

[0006] Determine a target backup file at risk of being ransomed according to the target log in the backup storage system, and perform an anomaly detection operation on the target backup file to determine a first ransom risk value corresponding to the target backup file;

[0007] Determine a target production file corresponding to the target backup file, and use at least two preset risk identification strategies to determine a second ransom risk value corresponding to the target production file;

[0008] According to the first ransom risk value and the second ransom risk value, in the case of detecting a ransomware threat risk, perform anomaly processing based on a preset anomaly response strategy.

[0009] According to another aspect of the present invention, there is provided a data anomaly processing device, including:

[0010] A first determination module for determining a target backup file at risk of being ransomed according to the target log in the backup storage system, and performing an anomaly detection operation on the target backup file to determine a first ransom risk value corresponding to the target backup file;

[0011] A second determination module for determining a target production file corresponding to the target backup file, and using at least two preset risk identification strategies to determine a second ransom risk value corresponding to the target production file;

[0012] An exception handling module, configured to, according to a first ransom risk value and a second ransom risk value, perform exception handling based on a preset exception response strategy when detecting a risk of ransomware threat.

[0013] According to another aspect of the present invention, there is provided an electronic device, the electronic device comprising:

[0014] At least one processor; and

[0015] A memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the data exception handling method according to any embodiment of the present invention.

[0017] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the data exception handling method according to any embodiment of the present invention when executed.

[0018] According to another aspect of the present invention, there is also provided a computer program product, the computer program product comprising a computer program which, when executed by a processor, implements the data exception handling method according to any embodiment of the present invention.

[0019] The technical solution of the embodiment of the present invention determines a target backup file at risk of being ransomed according to the target log in the backup storage system, and performs an exception detection operation on the target backup file to determine a first ransom risk value corresponding to the target backup file; determines a target production file corresponding to the target backup file, and uses at least two preset risk identification strategies to determine a second ransom risk value corresponding to the target production file; according to the first ransom risk value and the second ransom risk value, when detecting a risk of ransomware threat, performs exception handling based on a preset exception response strategy. By performing exception detection on data files in a timely and accurate manner, losses caused by data being encrypted by ransomware can be avoided, and the security of the data can be guaranteed.

[0020] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. Description of the Drawings

[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0022] Figure 1 It is a flowchart of a data anomaly processing method provided in Embodiment 1 of the present invention;

[0023] Figure 2 It is a flowchart of a data anomaly processing method provided in Embodiment 2 of the present invention;

[0024] Figure 3 It is a structural block diagram of a data anomaly processing device provided in Embodiment 3 of the present invention;

[0025] Figure 4 It is a schematic structural diagram of an electronic device provided in Embodiment 4 of the present invention. Detailed implementation manners

[0026] In order to enable those skilled in the art of the present technology to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0027] It should be noted that the terms "first", "second", "target", "candidate", "alternative", etc. in the specification and claims of the present invention and the above accompanying drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices. The acquisition, storage, use, processing, etc. of data in the technical solutions of this application all comply with the relevant regulations of national laws and regulations.

[0028] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of the relevant data comply with the relevant laws, regulations, and standards of the relevant regions.

[0029] Embodiment 1

[0030] Figure 1 FIG. 1 is a flowchart of a data anomaly processing method provided in Embodiment 1 of the present invention; this embodiment is applicable to the situation where a banking business system analyzes backup data and production data for risk assessment and timely discovers risks for anomaly processing. This method can be executed by a data anomaly processing device, which can be implemented in the form of hardware and / or software. The data anomaly processing device can be configured in an electronic device and executed by a business system of a bank, such as a production system. As Figure 1 shown, the data anomaly processing method includes:

[0031] S101. Determine a target backup file at risk of being ransomed according to the target log in the backup storage system, and perform an anomaly detection operation on the target backup file to determine a first ransom risk value corresponding to the target backup file.

[0032] Among them, the backup storage system can be a system associated with the business system of the bank, specifically used for backup storage of the backup data and production data of the business system. The target log refers to the log in the backup storage system that records the deletion operation performed on the backup file. The target backup file refers to the backup file on which the deletion operation is recorded in the target log. The first ransom risk value refers to the risk value for evaluating the threat of ransomware to the target backup file.

[0033] Optionally, determining a target backup file at risk of being ransomed according to the target log in the backup storage system includes: determining candidate logs in the backup storage system, and determining the logs that record the deletion operation performed on the files in the backup storage system as the target logs; according to the target logs, determining the target backup file identifier corresponding to the deletion operation to obtain the target backup file at risk of being ransomed.

[0034] Among them, the candidate logs can refer to all audit logs stored in the backup storage system, and the target backup file identifier can be the file name or unique identification code of the target backup file.

[0035] Optionally, text identification matching can be performed on the log content of the target log, and the file identifier obtained by the matching is determined as the target backup file identifier corresponding to the deletion operation. Further, the file corresponding to the target backup file identifier is searched in the file recycle bin and determined as the target backup file at risk of being ransomed.

[0036] It should be noted that the above technical solution of the present invention identifies the deletion operation to screen the candidate logs, and obtains the target backup files that need to be detected for anomalies, which can quickly and accurately identify the target backup texts stolen by ransomware and improve the efficiency of anomaly handling.

[0037] Optionally, an anomaly detection operation is performed on the target backup file to determine the first ransom risk value corresponding to the target backup file, including: determining the deletion time according to the target log, and determining the target process that initiated the deletion operation and the target process identifier corresponding to the target process; determining whether the target backup file is abnormal according to the target process identifier, the deletion time, and the target backup file identifier corresponding to the target backup file; if so, determining the preset backup risk value as the first ransom risk value corresponding to the target backup file.

[0038] Among them, the deletion time refers to the time when the deletion operation is performed on the target backup file, the target process refers to the process that performs the deletion operation on the target backup file, and the target process identifier refers to the identifier number that can uniquely identify the target process. The preset backup risk value refers to the evaluation risk value preset when it is detected that the target backup file is abnormal, and the preset backup risk value can be 80, for example.

[0039] Optionally, the log content of the target log can be parsed, the process that initiated the deletion operation is determined as the target process, and the process number of the target process is determined as the target process identifier.

[0040] Optionally, if it is determined that the target backup file is not abnormal, the first ransom risk value corresponding to the target backup file can be determined to be 0.

[0041] It should be noted that the above technical solution of the present invention comprehensively evaluates whether the target backup file is abnormal through the target process and the deletion time to obtain the first ransom risk value, which can more comprehensively detect the abnormal situation of the target backup file and obtain an accurate ransom risk value.

[0042] Optionally, determine whether there is an abnormality in the target backup file according to the target process identifier, the deletion time, and the target backup file identifier corresponding to the target backup file, including: determine whether the target process is a malicious process according to the target process identifier and the preset authorized process identifier; if not, determine the creation time of the target backup file according to the target backup file identifier; according to the creation time and the deletion time, and in combination with the preset expiration deletion rule, determine whether the expiration deletion condition and the regular deletion condition are met; if so, determine that there is no abnormality in the target backup file.

[0043] Among them, the authorized process identifier refers to the process identifier of a legally designated process. A malicious process refers to a process controlled by ransomware to steal data from the business system. The creation time refers to the time when the target backup file is created. The expiration deletion rule refers to a rule for periodically deleting different types of target backup files based on a preset deletion period. The preset deletion period can be a fixed value such as 1 year, 1 month, or 5 years. The expiration deletion condition refers to the condition for evaluating whether the target backup file is deleted at the expected time, and the regular deletion condition refers to the condition for evaluating whether the target backup file is periodically deleted when the deletion period is met.

[0044] Optionally, according to the target process identifier and the preset authorized process identifier, it can be determined whether the target process identifier belongs to the preset authorized process identifier; if so, determine that the target process is a malicious process, and further execute the judgment process of the expiration deletion condition and the regular deletion condition; if not, it can be directly determined that there is an abnormality in the target backup file. At this time, the preset backup risk value can be determined as the first ransom risk value corresponding to the target backup file.

[0045] Optionally, according to the target backup file identifier, it can be matched in the log recording the file creation situation to determine the creation time of the target backup file, and it can also be matched in the corresponding file attribute information according to the target backup file identifier to determine the expiration time of the target backup file.

[0046] Optionally, it can be determined whether the deletion time and the expiration time are consistent; if not, it is determined that the expiration deletion condition is not met, and it can be directly determined that there is an abnormality in the target backup file; if so, further determine whether the regular deletion condition is met according to the creation time and the deletion time.

[0047] Optionally, the preset deletion period corresponding to the target backup file can be determined, and the time interval between the creation time and the deletion time can be determined. By judging whether the time interval is consistent with the preset deletion period, it can be determined whether the condition for regular deletion is met. Specifically, if the two are consistent, the condition for regular deletion is met. At this time, it is considered that the deletion operation performed on the target backup file is normal, that is, the target backup file has no abnormality. If they are inconsistent, it is determined that the condition for regular deletion is not met, and it is considered that the target backup file is at risk of being threatened by ransomware, that is, there is an abnormality.

[0048] It should be noted that in the above technical solution of the present invention, whether the deletion process is legal is determined by comparing the target process and the authorized process. By combining the file deletion time and the creation time with the expired deletion rule, it is determined whether the file is legally deleted, and an implementable method for anomaly detection through the process identifier and the file processing time is given, which can accurately identify the abnormal operation behavior of ransomware on the backup file.

[0049] S102. Determine the target production file corresponding to the target backup file, and use at least two preset risk identification strategies to determine the second ransom risk value corresponding to the target production file.

[0050] Among them, the target production file refers to the data file generated during the actual operation of the system. The risk identification strategy may include at least one of the following: feature matching risk identification strategy, reputation scoring risk identification strategy, and encrypted traffic analysis strategy. The second ransom risk value refers to the risk value for evaluating the threat of the target production file being threatened by ransomware.

[0051] Optionally, the target production file corresponding to the target backup file can be determined according to the corresponding relationship between the preset backup file and the production file.

[0052] Optionally, using at least two preset risk identification strategies to determine the second ransom risk value corresponding to the target production file includes: using the feature matching risk identification strategy and the preset first scoring weight to determine the first risk value, and using the reputation scoring risk identification strategy and the preset second scoring weight to determine the second risk value; using the encrypted traffic analysis strategy and the preset third scoring weight to determine the third risk value, and determining the second ransom risk value corresponding to the target production file according to the first risk value, the second risk value, and the third risk value.

[0053] Among them, the preset first scoring weight, the preset second scoring weight, and the preset third scoring weight can be 40%, 10%, and 50% respectively. The first risk value, the second risk value, and the third risk value are the risk values obtained by evaluating abnormal situations using the feature matching risk identification strategy, the reputation scoring risk identification strategy, and the encrypted traffic analysis strategy respectively. The second ransom risk value can be the sum of the first risk value, the second risk value, and the third risk value.

[0054] The principle of the feature matching risk identification strategy is to collect specific features of ransomware-encrypted data, such as specific header information of encrypted files, specific encryption algorithm flags, the changing rules of encrypted file extensions, etc., and establish a feature library. Compare the data to be detected with the features in the feature library. If a matching item is found, it is determined that the data may be encrypted by ransomware. It is applicable to detecting data encrypted by known ransomware families and can quickly locate data encrypted by specific ransomware in scenarios such as enterprise internal data security detection and personal computer protection against ransomware attacks.

[0055] The principle of the reputation scoring risk identification strategy is to evaluate the credibility of data sources and related operations from multiple dimensions, such as the reputation of data providers, the security of data transmission paths, the compliance of data operation behaviors, etc. Assign certain weights to each dimension and calculate comprehensively to obtain a reputation score. If the score is lower than the threshold, the data may be encrypted by ransomware. It is commonly used in scenarios such as network data transmission and cloud storage to determine whether the received or stored data has the risk of being encrypted by ransomware and helps network security administrators evaluate the overall data security situation.

[0056] The principle of the encrypted traffic analysis strategy is to monitor the encrypted traffic in the network, analyze features such as the size, frequency, flow direction, and protocol of the traffic, and use machine learning or statistical analysis methods to establish a normal traffic model and an abnormal model for ransomware-encrypted traffic. When the encrypted traffic has a high degree of matching with the abnormal model, it is speculated that the data may be encrypted by ransomware and is being transmitted. It is applied in the field of network security protection, such as enterprise network exits and network monitoring of Internet service providers, and can timely detect possible ransomware-encrypted data transmission behaviors in the network.

[0057] It should be noted that the advantage of the feature matching risk identification strategy is its fast detection speed and high accuracy, which can accurately identify ransomware-encrypted data with known features. The disadvantage is that it may not be able to detect ransomware-encrypted data that has newly emerged and has no feature records, and ransomware can easily bypass detection if it uses encryption obfuscation and other means; the advantage of the reputation scoring risk identification strategy is that it can comprehensively judge data security from a macroscopic perspective, and data encrypted by unknown ransomware may also be identified through abnormal reputation performance. The disadvantage is that it is difficult to fully and accurately quantify all factors and there may be misjudgments; the advantage of the encrypted traffic analysis strategy is that it can detect without decrypting the traffic, can monitor the data transmission situation in the network in real time, and has a good detection effect on ransomware that spreads and encrypts data through the network. The disadvantage is that it is difficult to detect ransomware with complex encryption methods or atypical traffic features, and normal fluctuations in encrypted traffic may lead to false alarms. The present invention takes into account the different degrees of credibility of the above different strategies for evaluating abnormal situations, and sets corresponding scoring weights for them respectively to better evaluate the risk situation and obtain an accurate ransom risk value.

[0058] It should be noted that the above technical solution of the present invention performs a risk assessment on the target generated file through three different risk identification strategies to obtain the final risk value, which can comprehensively and quickly perform a risk assessment on the target production file and obtain an accurate risk value.

[0059] S103. According to the first ransom risk value and the second ransom risk value, when it is detected that there is a ransomware threat risk, perform anomaly handling based on a preset anomaly response strategy.

[0060] Among them, the preset anomaly response strategy may include at least one of the following: alarm, preventing malicious processes from running, and setting the target backup file and the target production file to a prohibited deletion state.

[0061] Optionally, according to the first ransom risk value and the second ransom risk value, when it is detected that there is a ransomware threat risk, performing anomaly handling based on a preset anomaly response strategy includes: determining a target ransom risk value according to the first ransom risk value and the second ransom risk value; according to the association relationship between the target ransom risk value and the preset risk range, when it is detected that there is a ransomware threat risk, determining a target response strategy from the preset anomaly response strategies and using the target response strategy to perform anomaly handling.

[0062] Among them, the target ransom risk value may be the sum of the first ransom risk value and the second ransom risk value, and the preset range refers to the risk value range of the preset threat risk. The target response strategy refers to the response strategy corresponding to the anomaly type in the preset anomaly response strategy.

[0063] Optionally, if it is detected that the target ransom risk value is within the preset risk range, it can be determined that there is a ransomware threat risk detected.

[0064] Exemplarily, for the target backup file, adopting the above anomaly recognition method of the present invention, once it is determined to be abnormal, it can be determined that the corresponding first ransom risk value is 80. When using the feature matching risk identification strategy, the reputation scoring risk identification strategy, and the encrypted traffic analysis strategy to determine that there is an anomaly respectively, the corresponding risk values can be 40 points for feature matching, 10 points for reputation scoring, and 50 points for encrypted process analysis. Finally, the second ransom risk value can be S1 + S2 + … + Sn, where S1 to Sn represent different data anomaly detection technologies and are scores obtained by scoring according to the intuitiveness and accuracy of the anomaly judgment.

[0065] It should be noted that the larger the target ransom risk value, the greater the possibility that a ransom attack has occurred. When it is determined that there is a ransomware threat risk detected, corresponding measures should be taken according to the type of abnormal behavior, such as alarm, preventing malicious processes from running, etc.

[0066] It should be noted that, for the above technical solution of the present invention, by evaluating the target risk value obtained from the target backup file and the target production file, and combining the preset risk range, the corresponding exception handling strategy is determined for exception handling, which can quickly and accurately determine the most appropriate response strategy, improve the efficiency of exception handling, and ensure data security.

[0067] In the technical solution of the embodiment of the present invention, according to the target log in the backup storage system, the target backup file at risk of being ransomed is determined, and an anomaly detection operation is performed on the target backup file to determine the first ransom risk value corresponding to the target backup file; the target production file corresponding to the target backup file is determined, and at least two preset risk identification strategies are used to determine the second ransom risk value corresponding to the target production file; according to the first ransom risk value and the second ransom risk value, in the case of detecting the risk of ransomware threat, exception handling is performed based on the preset exception handling strategy. By detecting data files for anomalies in a timely and accurate manner, losses caused by encrypting data with ransomware can be avoided, and the security of the data can be guaranteed.

[0068] Embodiment 2

[0069] Figure 2 It is a flowchart of a data anomaly handling method provided by Embodiment 2 of the present invention; on the basis of the above embodiment, a preferred example of analyzing and risk assessing backup data and production data to detect risks in a timely manner for anomaly handling is provided. Specifically, as Figure 2 shown, the method includes the following processes:

[0070] S201. Determine the candidate logs in the backup storage system, and determine the logs that record the deletion operations on the files in the backup storage system as the target logs.

[0071] S202. According to the target logs, determine the target backup file identifier corresponding to the deletion operation to obtain the target backup file at risk of being ransomed.

[0072] S203. Determine the deletion time according to the target logs, and determine the target process that initiates the deletion operation and the target process identifier corresponding to the target process.

[0073] S204. According to the target process identifier, the deletion time, and the target backup file identifier corresponding to the target backup file, determine whether the target backup file is abnormal.

[0074] S205. If so, determine the preset backup risk value as the first ransom risk value corresponding to the target backup file.

[0075] S206. Determine the first risk value by adopting a feature matching risk identification strategy and a preset first scoring weight, and determine the second risk value by adopting a reputation scoring risk identification strategy and a preset second scoring weight.

[0076] S207. Determine the third risk value by adopting an encrypted traffic analysis strategy and a preset third scoring weight, and determine the second ransom risk value corresponding to the target production file according to the first risk value, the second risk value, and the third risk value.

[0077] S208. Determine the target ransom risk value according to the first ransom risk value and the second ransom risk value.

[0078] S209. According to the correlation between the target ransom risk value and the preset risk range, in the case of detecting a ransomware threat risk, determine the target response strategy from the preset abnormal response strategies, and perform abnormal processing by using the target response strategy.

[0079] Embodiment III

[0080] Figure 3 It is a structural block diagram of a data anomaly processing device provided in Embodiment III of the present invention; this embodiment is applicable to the situation where a banking business system analyzes and evaluates backup data and production data to detect risks in a timely manner and perform anomaly processing. The data anomaly processing device provided in the embodiments of the present invention can execute the data anomaly processing method provided in any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method; the data anomaly processing device can be implemented in the form of hardware and / or software, and is configured in an electronic device with a data anomaly processing function, and is executed by a business system of a bank, such as a production system, as Figure 3 shown, the data anomaly processing device may specifically include:

[0081] The first determination module 301 is configured to determine a target backup file at risk of being ransomed according to the target log in the backup storage system, and perform an anomaly detection operation on the target backup file to determine the first ransom risk value corresponding to the target backup file;

[0082] The second determination module 302 is configured to determine the target production file corresponding to the target backup file, and adopt at least two preset risk identification strategies to determine the second ransom risk value corresponding to the target production file;

[0083] The anomaly processing module 303 is configured to perform anomaly processing based on a preset anomaly response strategy in the case of detecting a ransomware threat risk according to the first ransom risk value and the second ransom risk value.

[0084] The technical solution of the embodiment of the present invention determines a target backup file at risk of being ransomed according to the target log in the backup storage system, and performs an anomaly detection operation on the target backup file to determine the first ransom risk value corresponding to the target backup file; determines the target production file corresponding to the target backup file, and uses at least two preset risk identification strategies to determine the second ransom risk value corresponding to the target production file; according to the first ransom risk value and the second ransom risk value, in the case of detecting a ransomware threat risk, performs anomaly handling based on a preset anomaly response strategy. By detecting anomalies in data files in a timely and accurate manner, losses caused by data being encrypted by ransomware can be avoided, and the security of the data can be guaranteed.

[0085] Further, the first determination module 301 may include:

[0086] A process determination unit, configured to determine a deletion time according to the target log, and determine a target process that initiates a deletion operation and a target process identifier corresponding to the target process;

[0087] A judgment unit, configured to determine whether the target backup file is abnormal according to the target process identifier, the deletion time, and the target backup file identifier corresponding to the target backup file;

[0088] A risk value determination unit, configured to, if so, determine a preset backup risk value as the first ransom risk value corresponding to the target backup file.

[0089] Further, the judgment unit is specifically configured to:

[0090] Determine whether the target process is a malicious process according to the target process identifier and a preset authorized process identifier, and if not, determine the creation time of the target backup file according to the target backup file identifier;

[0091] According to the creation time and the deletion time, in combination with a preset expiration deletion rule, determine whether the expiration deletion condition and the regular deletion condition are satisfied;

[0092] If so, determine that the target backup file is not abnormal.

[0093] Further, the first determination module 301 is specifically configured to:

[0094] Determine candidate logs in the backup storage system, and determine the logs that record deletion operations on files in the backup storage system in the candidate logs as target logs;

[0095] According to the target log, determine the target backup file identifier corresponding to the deletion operation, so as to obtain a target backup file at risk of being ransomed.

[0096] Further, the second determination module 302 is specifically configured to:

[0097] Determine the first risk value by adopting a feature matching risk identification strategy and a preset first scoring weight, and determine the second risk value by adopting a reputation scoring risk identification strategy and a preset second scoring weight;

[0098] Determine the third risk value by adopting an encrypted traffic analysis strategy and a preset third scoring weight, and determine the second ransom risk value corresponding to the target production file according to the first risk value, the second risk value, and the third risk value.

[0099] Further, the exception handling module 303 is specifically configured to:

[0100] Determine the target ransom risk value according to the first ransom risk value and the second ransom risk value;

[0101] According to the association relationship between the target ransom risk value and the preset risk range, in the case of detecting a ransomware threat risk, determine the target response strategy from the preset exception response strategies, and perform exception handling by using the target response strategy.

[0102] Embodiment IV

[0103] Figure 4 It is a schematic structural diagram of an electronic device provided in Embodiment IV of the present invention. Figure 4 It shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device (such as a helmet, glasses, a watch, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0104] As Figure 4As shown, the electronic device 10 includes at least one processor 11 and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 11 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.

[0105] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0106] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the data anomaly handling method.

[0107] In some embodiments, the data anomaly handling method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the data anomaly handling method described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the data anomaly handling method by any other appropriate means (e.g., by means of firmware).

[0108] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.

[0109] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine or entirely on the remote machine or server.

[0110] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0111] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0112] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.

[0113] The computing system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system to address the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0114] In one embodiment, the embodiment of the present invention further includes a computer program product, where the computer program product includes a computer program that, when executed by a processor, implements the data exception handling method of any embodiment of the present invention.

[0115] In the process of implementing the computer program product, computer program code for performing the operations of the present invention can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages and also conventional procedural programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network - including a local area network (LAN) or a wide area network (WAN) - or, alternatively, can be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0116] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is imposed herein.

[0117] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for processing data anomalies, characterized in that: include: Determine, according to the target log in the backup storage system, a target backup file that is at risk of being ransomed, and perform an anomaly detection operation on the target backup file to determine a first ransom risk value corresponding to the target backup file; Determine a target production file corresponding to the target backup file, and use at least two preset risk identification strategies to determine a second ransomware risk value corresponding to the target production file; According to the first ransomware risk value and the second ransomware risk value, when a ransomware threat risk is detected, exception handling is performed based on a preset exception response strategy.

2. The method according to claim 1, characterized in that: An anomaly detection operation is performed on the target backup file to determine a first ransomware risk value corresponding to the target backup file, including: Determine the deletion time according to the target log, and determine the target process that initiates the deletion operation and the target process ID corresponding to the target process; Determine whether the target backup file has an abnormality according to the target process identifier, the deletion time, and the target backup file identifier corresponding to the target backup file; If so, the preset backup risk value is determined as the first ransomware risk value corresponding to the target backup file.

3. The method according to claim 2, characterized in that According to the target process ID, deletion time, and the target backup file ID corresponding to the target backup file, determine whether the target backup file is abnormal, including: Determine whether the target process is a malicious process based on the target process identifier and the preset authorized process identifier. If not, determine the creation time of the target backup file based on the target backup file identifier. According to the creation time and deletion time, combined with the preset expiration deletion rules, determine whether the expiration deletion conditions and regular deletion conditions are met; If so, it is determined that there is no abnormality in the target backup file.

4. The method according to claim 1, characterized in that: According to the target log in the backup storage system, determine the target backup files that are at risk of being ransomware, including: Determine candidate logs in the backup storage system, and determine the logs in the candidate logs that record the deletion operation on the files in the backup storage system as target logs; According to the target log, the target backup file identifier corresponding to the deletion operation is determined to obtain the target backup file that is at risk of being blackmailed.

5. The method according to claim 1, characterized in that At least two preset risk identification strategies are used to determine the second ransomware risk value corresponding to the target production file, including: A first risk value is determined by using a feature matching risk identification strategy and a preset first scoring weight, and a second risk value is determined by using a reputation scoring risk identification strategy and a preset second scoring weight; An encrypted traffic analysis strategy and a preset third scoring weight are used to determine the third risk value, and based on the first risk value, the second risk value and the third risk value, the second ransomware risk value corresponding to the target production file is determined.

6. The method according to claim 1, characterized in that According to the first ransomware risk value and the second ransomware risk value, when a ransomware threat risk is detected, an exception handling is performed based on a preset exception response strategy, including: Determining a target ransom risk value according to the first ransom risk value and the second ransom risk value; According to the correlation between the target ransomware risk value and the preset risk range, when the ransomware threat risk is detected, the target response strategy is determined from the preset exception response strategies, and the target response strategy is used to handle the exception.

7. A data anomaly processing device, characterized in that: include: A first determination module is used to determine a target backup file that has a ransom risk according to a target log in a backup storage system, and perform an anomaly detection operation on the target backup file to determine a first ransom risk value corresponding to the target backup file; A second determination module is used to determine a target production file corresponding to the target backup file, and to determine a second ransomware risk value corresponding to the target production file by using at least two preset risk identification strategies; The exception handling module is used to perform exception handling based on a preset exception response strategy when a ransomware threat risk is detected according to the first ransomware risk value and the second ransomware risk value.

8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the data exception processing method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the data exception processing method according to any one of claims 1 to 6 when executed.

10. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the computer program implements the data exception processing method according to any one of claims 1 to 6.