Spare end backup data protection method, device and system

By monitoring and refusing to disable operations in the backup data protection system, the problem that backup data in the existing technology cannot effectively prevent malicious tampering or theft is solved, and data backup security is improved under real-time updates.

CN120144357APending Publication Date: 2025-06-13INFORMATION2 SOFTWARE SHANGHAI
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510088717.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The existing backup data protection methods cannot effectively prevent backup data from being maliciously tampered with or stolen, especially when backup data needs to be updated in real time with source data.

Method used

By monitoring the file system according to preset protection rules in the backup data protection system, identifying and denying disabling operations, malicious programs prevent backup data from being tampered with or stealing.

Benefits of technology

While ensuring that the backup data and source data are updated in real time, it effectively prevents malicious programs from tampering or stealing the backup data on the backup data, improving the security of data backup.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120144357A_ABST
    Figure CN120144357A_ABST
Patent Text Reader

Abstract

The invention provides a backup end backup data protection method, device and system, and the method comprises the steps: monitoring a file system according to a protection rule of backup end backup data, and monitoring that a preset operation exists; wherein the protection rule is used for protecting a preset operation and protecting a file catalog which is associated with the preset operation; and if it is judged that the preset operation is the forbidden operation, refusing execution of the preset operation. A layer of protection is added on traditional backup data, because the backup data needs to be updated, a backup end needs to be communicated with a source end to guarantee the consistency of the data, the backup data is further connected with the outside, and the backup data and the source end data have the danger of being attacked. However, different from the source end data, the source end data cannot determine which programs are effective to operate the data, and the backup data of the standby end are updated through the fixed programs, so that the backup data of the standby end is protected by utilizing the characteristic.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer data backup and disaster recovery, and specifically relates to a method, device, and system for protecting backup data at the backup end. Background Art

[0002] With the development of the computer industry and the advent of the big data era, data has become increasingly important. In the Internet era, as people attach importance to data, they naturally start to pay attention to data protection and backup to minimize losses in the event of a disaster.

[0003] Generally, most companies perform regular backups for data protection, that is, they select a time point with relatively less business volume for regular backups, update the backup data at the backup end for backup, and generally, the backup data needs to be updated in real time as the source data changes. For an environment where there are a large number of reads and writes to change the source data, the backup at the backup end also adopts the method of regular backup. Generally speaking, the backup at the backup end adopts regular backup. The backup data at the backup end is not static and needs to be updated as the source data changes, which means that the backup data cannot be completely separated from the outside world. This means that the data at the backup end, like the source data, is at risk of being attacked, and the existing methods cannot provide better protection for the backup data at the backup end.

[0004] Therefore, a new protection scheme for backup data at the backup end is needed. Summary of the Invention

[0005] In view of this, embodiments of this specification provide a new method, device, and system for protecting backup data at the backup end.

[0006] Embodiments of this specification provide the following technical solutions:

[0007] Embodiments of this specification provide a method for protecting backup data at the backup end, including:

[0008] Monitoring the file system according to the protection rules of the backup data at the backup end, and a preset operation is detected; wherein the protection rules protect against the preset operation and also protect the file directory set in association with the preset operation;

[0009] If it is determined that the preset operation is a disabling operation, the execution of the preset operation is rejected.

[0010] Embodiments of this specification also provide a device for protecting backup data at the backup end, including:

[0011] A protection module for monitoring the file system according to the protection rules of the backup data at the backup end, and a preset operation is detected; wherein the protection rules protect against the preset operation and also protect the file directory set in association with the preset operation;

[0012] An execution module, configured to reject the execution of a preset operation if it is determined that the preset operation is a disabling operation.

[0013] An embodiment of this specification further provides a standby backup data protection system, including: a memory, a processor, and a computer program. The computer program is stored in the memory, and the processor runs the computer program to execute the standby backup data protection method described in the above technical solution.

[0014] Compared with the prior art, the at least one technical solution adopted in the embodiment of this specification can achieve at least the following beneficial effects:

[0015] This application provides a new solution for protecting standby backup data. While ensuring that the backup data can still be updated in real time as the source data changes, it protects these backup data, that is, adds a layer of protection to the traditional backup data. Since the backup data needs to be updated, the standby needs to be connected to the source to ensure data consistency, which results in the backup data still being connected to the outside world. Therefore, the backup data also has the risk of being attacked like the source data. However, different from the source data, it is impossible to determine which programs' operations on the data are effective for the source data, while the backup data of the standby is updated through fixed programs. This application utilizes this feature to protect the standby backup data. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] To more clearly illustrate the technical solutions in the embodiments of this application, the following will briefly introduce the drawings required for the embodiments. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0017] Figure 1 is a flowchart of the standby backup data protection method provided by the embodiment of this specification;

[0018] Figure 2 is a schematic diagram of the principle of standby backup data protection provided by the embodiment of this specification;

[0019] Figure 3 is a schematic diagram of standby backup data protection provided by the embodiment of this specification;

[0020] Figure 4 is a schematic diagram of the standby backup data protection device provided by the embodiment of this specification;

[0021] Figure 5 is a schematic diagram of the standby backup data protection system provided by the embodiment of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0022] The embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0023] The following specific examples illustrate the implementation manners of the present application. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The present application can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without making creative efforts belong to the scope protected by the present application.

[0024] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present application, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number and aspects described herein can be used to implement the device and / or practice the method. Additionally, this device and / or this method can be implemented using other structures and / or functionality in addition to one or more of the aspects described herein.

[0025] It should also be noted that the drawings provided in the following embodiments only illustrate the basic concept of the present application in a schematic manner. The drawings only show the components related to the present application and are not drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.

[0026] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the examples can be practiced without these specific details.

[0027] With the development of the computer industry and the advent of the big data era, people increasingly understand the importance of data. In the Internet era, data is wealth. Whoever masters the data masters the wealth. As people attach importance to data, naturally they also begin to pay attention to data protection and backup to minimize losses when disasters occur.

[0028] Generally, most companies protect data by performing regular backups, and the backup data generally needs to be updated in real time as the source data changes. For environments where there are a large number of reads and writes to change the source data, regular backups are also adopted, that is, mainly by selecting a time point with relatively less business to perform regular backups and update the backup data at the backup end. Generally speaking, the backup data at the backup end is not static and needs to be updated as the source data changes, which means that the backup data cannot be completely isolated from the outside world. This means that the backup data at the backup end, like the source data, is at risk of being attacked. Therefore, the backup data at the backup end also requires a protection mechanism to prevent the already backed-up data from being maliciously tampered with or read.

[0029] In view of this, the inventor found that the backup data at the backup end is different from the source data. For example, it is impossible to determine which programs' operations on the data are valid for the source data, while the backup data at the backup end is updated through fixed programs. Therefore, this feature can be utilized to protect the backup data at the backup end.

[0030] Based on this, the embodiments of this specification propose a new scheme for protecting backup data at the backup end: utilize the fact that the backup data at the backup end is updated through fixed programs. Thus, it is possible to determine which programs' operations on the backup data are valid. Therefore, a layer of protection is added to the traditional backup data. Breaking through the prior art that the backup data at the backup end is updated regularly, when the backup end is updated in real time as the source data changes, protect these backup data to prevent malicious programs from tampering with the backup data at the backup end or avoid stealing data information through the backup data.

[0031] The following will describe the technical solutions provided by the embodiments of this application with reference to the accompanying drawings.

[0032] As Figure 1 shown, the embodiments of this specification provide a method for protecting backup data at the backup end, including step S101 and step S102. Among them, step S101: Monitor the file system according to the protection rules of the backup data at the backup end, and there is a preset operation during the monitoring; the protection rules protect against the preset operation and also protect the file directory associated with the preset operation. Step S102: If it is determined that the preset operation is a disabling operation, reject the execution of the preset operation. Among them, the preset operation includes read, write, or read-write operations. For example, the read / write operation on the file directory indicates the reading / writing of the content of the file directory. The file directory is set according to the fixed program of the backup data. The file directory includes elements such as the root directory, directory, subdirectory, and file.

[0033] Specifically, in the embodiments of this specification, a layer of protection is added to the traditional backup data. Since the backup data needs to be updated, the backup end needs to be connected to the source end to ensure data consistency. This results in the backup data still being connected to the outside world, and the backup data is also at risk of being attacked like the source-end data.

[0034] Therefore, a layer of protection is added to the backup data at the backup end to improve security.

[0035] Among them, the protection rules can be set according to the fixed procedures of the backup data. For example, the object of this protection rule is the file directory (generally the directory where the backup data is located).

[0036] During the process of protecting the backup data at the backup end in step S101, the file system is monitored according to the protection rules of the backup data at the backup end, and there are preset operations during the monitoring.

[0037] Since the backup data is still connected to the outside world, the protection rules are used to protect the backup data at the backup end.

[0038] Such as Figure 2 shown, protection rules such as policy1, policy2, etc. monitor the file system, and there are preset operations detected during the monitoring. This preset operation corresponds to the file directory.

[0039] It should be noted that the protection rules protect against the preset operations and also protect the file directories associated with the preset operations. For example, the protection rules prohibit access to some or all of the protected file directories. Also, for example, although the protection rules allow access to the protected file directories, they deny operations on the protected file directories. Another example is that the protection rules allow access to the protected file directories, and after verification, some operations are allowed to perform the preset operations on the protected file directories. Another example is that the protection rules allow access to the protected file directories, and after verification, all preset operations are allowed to be executed on the protected file directories, etc.

[0040] In step S102, if a preset operation is detected according to the protection rules, the preset operation needs to be verified. If it is determined that the preset operation is a disabled operation, the execution of the preset operation is rejected. By monitoring the preset operations on the backup data, malicious programs are prevented from tampering with the backup data or stealing data information through the backup data.

[0041] In some embodiments, if it is determined that the preset operation is a normal operation, the execution of the preset operation is allowed.

[0042] In some embodiments, a file directory corresponding to a protection rule is created, and the protection rule is used to specify that a preset script or executable program is allowed to perform read / write operations on the protected file directory. It further includes: after the protection rule is successfully created, the file directory corresponding to the protection rule is in a monitored state.

[0043] Specifically, a protection rule is created, and the object of the protection rule is a file directory (generally the directory where the backup data is located). The protection rule can specify that some scripts or executable programs are allowed to perform read or write or read-write operations on the protected directory (generally, when the backup end receives the data synchronized from the source end, the executable program or script that needs to write the synchronized data into the backup file). After the rule is successfully created, this protected directory will be under monitoring.

[0044] In some embodiments, the file directory is in a state of being updated in real time as the source-end data changes; it further includes: the protection rule protects the file directory; or, the file directory is the backup data that has been updated and exists, and the protection rule protects the file directory corresponding to the backup data at the backup end.

[0045] In the embodiments of this specification, the file directory is protected. The file directory is in a state of being updated in real time as the source-end data changes, and these backup data are protected. Or the file directory is the backup data that has been updated and exists, and the protection rule protects the file directory corresponding to the backup data at the backup end.

[0046] In some embodiments, a file directory corresponding to a protection rule is created according to the update program of the backup data at the backup end; the file directory includes its corresponding subdirectories.

[0047] Specifically, different from the source-end data, the backup data at the backup end is updated through a fixed program. The inventor creates a file directory corresponding to a protection rule according to the update program of the backup data at the backup end. The file directory includes its corresponding subdirectories.

[0048] Such as Figure 2 and Figure 3 As shown, a rule policy1 is created to protect the directory dir1. At this time, the driver will monitor the protected target directory dir1, and all subsequent read and write operations on the subdirectories or files under the dir1 directory will be captured by the driver.

[0049] In some embodiments, if a preset operation exists in the monitored file directory, the protection rule is triggered to perform a protection permission judgment. Correspondingly, if the preset operation is a disabling operation, it includes: obtaining the target protection permission carried in the preset operation instruction according to the preset operation. If the target protection permission does not match the initial protection permission stored in the protection rule, it is determined that the preset operation is a disabling operation. Among them, the protection rule includes the association relationship between the file directory, the preset operation, and the protection permission in pairs.

[0050] As Figure 3 shown, if a preset operation such as read, write, or read-write operation exists in the file directory monitored by the protection rule, the protection rule is triggered to perform a protection permission judgment. Obtain the target protection permission carried in the preset operation instruction according to the preset operation. If the target protection permission does not match the initial protection permission stored in the protection rule, it is considered a malicious operation and is rejected, and it is determined that the preset operation is a disabling operation.

[0051] For example, when using any program or script with permissions granted by a protection rule to perform read / write operations on the directory protected by the protection rule, these read / write operations are captured at this time, the protection rule is triggered, and the protection rule determines that the programs or scripts performing these read / write operations do not have the corresponding permissions and rejects these operations from continuing to execute.

[0052] Another example is using a program or script with read or write or read-write permissions to perform read-write operations on the directory it has corresponding permissions for and is protected by the protection rule. At this time, these read-write operations will be captured, the protection rule will be triggered, and it will be determined that the programs or scripts performing these read-write operations have the corresponding read or write operation permissions granted by the protection rule, and this operation can proceed normally (note: if only has the permission for a certain operation, other operations will be rejected. For example, if a program only has write permission for the protected directory, then when the program performs a write operation on the corresponding directory, it can proceed smoothly, but when performing a read operation, it will be rejected).

[0053] In some embodiments, it further includes: if the monitored file directory is accessed, the protection rule is triggered to perform a protection permission judgment; if the file directory information carried in the access instruction matches the file directory information corresponding to the protection rule, then judge whether the preset operation is a disabling operation according to the protection permission. In some embodiments, the file directory information includes the name of the directory, etc.

[0054] Specifically, the protection rule first monitors the access to the file directory. When it is detected that the file directory is accessed, the protection rule is triggered to perform a protection permission judgment. If the file directory information carried in the access instruction matches the file directory information corresponding to the protection rule, then a judgment is made on whether the preset operation is a disabling operation according to the protection permission. The judgment on whether the preset operation is a disabling operation is similar to the foregoing embodiments and will not be elaborated here.

[0055] Or, if it is monitored that the file directory is accessed and the protection rule is triggered to perform a protection permission judgment, and if the file directory information carried in the access instruction does not match the file directory information corresponding to the protection rule, then it is directly determined that the preset operation is a disabling operation and is considered a malicious operation and is rejected.

[0056] In some embodiments, it further includes: after the preset operation is rejected, the event that the execution of the preset operation on the file directory is rejected will be recorded and saved for subsequent viewing.

[0057] Specifically, after it is determined through the protection rule that the preset operation is rejected, that is, the preset operation will be considered a malicious operation and rejected, and then the program that executes the operation will record the event that the operation on the file directory such as dir1 is rejected for subsequent viewing. This in turn proves that the file directory such as dir1 is being protected by the protection rule such as policy1.

[0058] In summary, the embodiments of the present invention mainly judge whether the read / write operation on the backup data of the protected standby end is initiated by a program permitted by the protection rule. First, a rule policy1 is created to protect the directory dir1 (refer to Figure 2 and Figure 3 for the example of protecting the backup data of the standby end). At this time, the driver program will monitor the protected target directory dir1, and then all read / write operations on the subdirectories or files under the dir1 directory will be captured by the driver.

[0059] For example, if a program that is not granted permission by policy1 is used to perform a read / write operation on the dir1 directory or a file under the dir1 directory, after this operation is captured by the driver, it will be determined according to policy1 that the program that initiated the captured operation does not have the corresponding permission granted by policy1. At this time, the operation will not be continued, the operation will be considered a malicious operation and rejected, and the event that the program that executes the operation is rejected for performing the operation on the dir1 directory will be recorded for subsequent viewing. At the same time, this step also proves that the dir1 directory is being protected by policy1.

[0060] For another example, if a program with the corresponding permissions for dir1 granted by policy1 is used to perform corresponding operations on the dir1 directory or the files under the dir1 directory, after this operation is captured by the driver, it will also be determined according to policy1 that the originating program of the captured operation has the corresponding permissions granted by policy1, and then the operation will continue to execute normally.

[0061] The solution for protecting the backup data at the standby end in the embodiments of this specification has passed verification. Mainly, while ensuring that the backup data can be updated in real time as the source data changes, the backup data is protected to prevent malicious programs from tampering with the backup data or to avoid stealing data information through the backup data. When ensuring that the backup data can be normally backed up, it is protected from being attacked, tampered with, or stolen by malicious programs, so as to avoid the loss or damage of the backup data, and further improve the security of data backup.

[0062] Figure 4 An apparatus for protecting backup data at the standby end is provided in the embodiments of this specification. As Figure 4 shown, the apparatus 40 for protecting backup data at the standby end includes:

[0063] A protection module 41 is configured to monitor the file system according to the protection rules for the backup data at the standby end, and monitor that there are preset operations; wherein the protection rules protect against the preset operations and also protect the file directories associated with the preset operations.

[0064] An execution module 42 is configured to, if it is determined that the preset operation is a disabling operation, reject the execution of the preset operation.

[0065] Figure 4 The apparatus for protecting backup data at the standby end in the shown embodiment can correspondingly be used to execute the steps in the method embodiment shown in Figure 1 The implementation principle and technical effects are similar, and will not be elaborated here.

[0066] Figure 5 A schematic diagram of a system for protecting backup data at the standby end is provided in the embodiments of this specification. As Figure 5 shown, the system 50 includes: a processor 51, a memory 52, and a computer program; wherein

[0067] The memory 51 is configured to store the computer program, and this memory can also be a flash memory. The computer program is, for example, an application program, a functional module, etc. that implements the above method.

[0068] The processor 52 is configured to execute the computer program stored in the memory to implement each step performed by the device in the above method. For specific details, reference can be made to the relevant descriptions in the previous method embodiments.

[0069] Optionally, the memory 52 can be either independent or integrated with the processor 51.

[0070] When the memory 52 is a device independent of the processor 51, the device may further include:

[0071] A bus 53 for connecting the memory 52 and the processor 51.

[0072] This application also provides a readable storage medium storing a computer program, which when executed by a processor is used to implement the methods provided by the above various embodiments.

[0073] Among them, the readable storage medium can be a computer storage medium or a communication medium. The communication medium includes any medium facilitating the transmission of a computer program from one place to another. The computer storage medium can be any available medium accessible by a general or special purpose computer. For example, the readable storage medium is coupled to the processor so that the processor can read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an Application Specific Integrated Circuit (ASIC). Additionally, the ASIC can be located in a user device. Of course, the processor and the readable storage medium can also exist as discrete components in a communication device. The readable storage medium can be a read only memory (ROM), a random access memory (RAM), a CD-ROM, magnetic tape, a floppy disk, and an optical data storage device, etc.

[0074] For the same or similar parts among the various embodiments in this specification, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the product embodiments described later, since they correspond to the methods, the descriptions are relatively simple, and for the relevant parts, reference can be made to the partial descriptions of the system embodiments.

[0075] The above are only the specific embodiments of this application, but the protection scope of this application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed in this application should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A backup data protection method for a standby end, characterized in that: include: The file system is monitored according to the protection rules of backup data on the standby side, and there are preset operations for monitoring; The protection rules protect the preset operations and also protect the file directories associated with the preset operations; If it is determined that the preset operation is a disabled operation, execution of the preset operation is rejected.

2. The backup data protection method according to claim 1, characterized in that: Creating a file directory corresponding to a protection rule, wherein the protection rule is used to specify that a preset script or executable program is allowed to perform read / write operations on the protected file directory; It also includes: after the protection rule is successfully created, the file directory corresponding to the protection rule is in a monitoring state.

3. The backup data protection method according to claim 2, characterized in that: Create a file directory corresponding to the protection rule according to the backup data update program on the standby end; The file directory includes its corresponding subdirectories.

4. The backup data protection method according to claim 1, characterized in that: Also includes: If there are preset operations in the monitored file directory, the protection rule is triggered and the protection permission is determined; Correspondingly, if the preset operation is a disabled operation, it includes: The target protection authority carried in the preset operation instruction is obtained according to the preset operation. If the target protection authority does not match the initial protection authority stored in the protection rule, the preset operation is determined to be a disabled operation; wherein the protection rule includes the association relationship between the file directory, the preset operation and the protection authority.

5. The backup data protection method according to claim 1, characterized in that: Also includes: If the monitored file directory is accessed, the protection rule is triggered and the protection permission is determined; If the file directory information carried in the access instruction matches the file directory information corresponding to the protection rule, the preset operation is judged according to the protection authority.

6. The backup data protection method according to claim 1, characterized in that: The file directory is updated in real time as the source data changes; It also includes: the protection rule protects the file directory; or, The file directory is the backup data that has been updated and exists, and the protection rule protects the file directory corresponding to the backup data on the standby side.

7. The backup data protection method according to claim 1, characterized in that: After rejecting the execution of the preset operation, it also includes: The event that the preset operation on the file directory is rejected will be recorded and saved for subsequent review.

8. The backup data protection method according to any one of claims 1 to 7, characterized in that: Also includes: If the preset operation is a normal operation, the preset operation is allowed to be executed.

9. A backup data protection device at a standby end, characterized in that: include: The protection module is used to monitor the file system according to the protection rules of the backup data on the standby side, and the monitoring has preset operations; The protection rules protect the preset operations and also protect the file directories associated with the preset operations; The execution module is used to reject the execution of the preset operation if it is determined that the preset operation is a disabled operation.

10. A backup data protection system at a standby end, characterized in that: include: A memory, a processor, and a computer program, wherein the computer program is stored in the memory, and the processor runs the computer program to execute the backup data protection method according to any one of claims 1 to 8.

Citation Information

Cited By

  • Directory backup method and system

    CN122470438A