A security protection detection method and system for a solid state drive
By building sensors in solid-state drives and building a normalized benchmark behavior model, identifying real-time access behaviors and generating protection strategies, the problem of inability to identify security threats in real time and accurately in the existing technology is solved, and intelligent and automated security protection for solid-state drives is achieved, improving the security and stability of hard disks.
Patent Information
- Application Number
- CN202510652676.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-05-21
AI Technical Summary
The existing solid-state drive security protection methods cannot identify complex security threats in real time and accurately. They rely on manual intervention to be inefficient, cannot achieve real-time early warning and automated protection, and cannot effectively identify and locate abnormal locations, resulting in high risk of data loss or system crash.
Through built-in temperature and physical vibration sensors, historical security monitoring logs are obtained, normalized benchmark behavior models are built, real-time access behaviors are identified, deviation detection and traceability are carried out, protection strategies are generated, and intelligent collaborative protection framework is built to achieve multi-level and all-round security protection.
Real-time and accurate security threat identification and location of solid-state drives is realized, reducing the risk of data loss and system crashes, extending the service life of the hard drive, and improving system management efficiency and security.
Smart Images

Figure CN120180520B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of solid-state drive security protection, and particularly to a security protection detection method and system for a solid-state drive. Background Art
[0002] With the continuous development of information technology, as a high-performance and highly reliable storage device, solid-state drives (SSDs) have been widely used in various fields such as computer systems, servers, and mobile devices. Especially driven by technologies such as big data storage, cloud computing, and artificial intelligence, the demand for solid-state drives continues to grow. Compared with traditional hard disk drives (HDDs), solid-state drives have faster read and write speeds, lower power consumption, and stronger anti-seismic performance, so they have significant advantages in improving the performance of storage systems. However, with the wide application of solid-state drives in important data storage and transmission tasks, their security issues have become increasingly prominent.
[0003] During the long-term operation of solid-state drives, due to the continuous writing, erasing, and rewriting of internal storage units, the health of the hard disk will gradually deteriorate, resulting in physical damage or performance degradation of the storage units. At the same time, security threats such as external malicious attacks and unauthorized access may also pose serious security risks to solid-state drives. These factors may cause the loss, damage, or leakage of stored data, and in severe cases, may even lead to the collapse of the entire storage system. Therefore, ensuring the security of solid-state drives, especially in the face of potential failures and security attacks, has become an urgent problem to be solved.
[0004] Traditional solid-state drive security protection methods mainly rely on redundant mechanisms in hardware design and simple monitoring tools, such as SMART monitoring technology and health status detection. Although these methods can monitor the basic operating status of the hard disk, they often lack pertinence and cannot identify various complex security threats and performance problems in real time and accurately. In addition, existing security protection means mostly rely on manual intervention or regular inspections, with low efficiency and unable to achieve real-time early warning and automated protection. In order to address the complex security problems of modern solid-state drives during high-speed operation, there is an urgent need for an intelligent and real-time solid-state drive security protection detection method. Summary of the Invention
[0005] To solve the above technical problems, the present invention proposes a security protection detection method and system for a solid-state drive to solve at least one of the above technical problems.
[0006] To achieve the above object, the present invention provides a security protection detection method for a solid-state drive. The solid-state drive is built-in with temperature and physical vibration sensors, and the method includes the following steps:
[0007] Step S1: Obtain the historical security monitoring logs of the solid-state drive, conduct regular fluctuation pattern mining and benchmark behavior evolution, and construct a regular benchmark behavior model;
[0008] Step S2: Identify the real-time access behavior data of the solid-state drive; analyze the access method of each behavior storage unit according to the real-time access behavior data, and conduct real-time access behavior feature recognition to generate real-time access behavior features;
[0009] Step S3: Conduct benchmark access deviation detection on the real-time access behavior features according to the regular benchmark behavior model, and conduct access location tracing to locate maliciously accessed storage units;
[0010] Step S4: Mine the security risk diffusion path of maliciously accessed storage units, and then conduct abnormal access protection processing to generate an abnormal access protection strategy;
[0011] Step S5: Conduct hard disk micro-damage prediction and potential hardware fault prevention optimization according to the historical security monitoring logs, and construct a hardware fault prevention strategy;
[0012] Step S6: Conduct intelligent collaborative protection optimization according to the hardware fault prevention strategy and the abnormal access protection strategy, and construct a hard disk intelligent collaborative protection framework.
[0013] By collecting historical security monitoring logs, the present invention can obtain the past access patterns and security events of the solid-state drive, thereby understanding its normal working mode. This lays a foundation for subsequent behavior analysis. Extracting the regular fluctuation patterns from historical data can help identify the normal working fluctuation range of the solid-state drive. Understanding such fluctuation patterns will assist in distinguishing normal and abnormal behaviors. Establishing a baseline behavior model enables the system to identify the normal operating state of the solid-state drive and provides a reference for subsequent anomaly detection. The continuous evolution of the model can be dynamically updated as the working state of the hard drive changes, improving the accuracy and timeliness of detection. Through the analysis of real-time data, potential abnormal behaviors can be discovered in a timely manner, and potential security threats can be quickly responded to. Through the analysis of the access behavior of each storage unit, refined management of the hard drive operations can be achieved, ensuring that the status of each storage unit is monitored. With the help of feature recognition technology, the key features of real-time access behaviors can be efficiently extracted, providing an accurate basis for subsequent anomaly detection. Based on the regular baseline behavior model, any anomalies deviating from normal behaviors can be efficiently identified, and the specific storage unit can be located, avoiding the problem in traditional methods where the specific anomaly location cannot be determined. When a deviation is detected, an alarm can be immediately issued and the source of the abnormal behavior can be located, reducing the response time to security threats. Precise location can provide more specific protection strategies, achieving targeted protection and avoiding unnecessary interference and resource waste. By analyzing the attack path, malicious behaviors can be prevented from spreading from one storage unit to other areas, ensuring the overall security of the hard drive data. Based on the analysis of the diffusion path, the system can dynamically generate countermeasures, avoiding the limitations of static rules. By isolating the storage unit with malicious access, data leakage or further damage can be prevented, and the risk source can be blocked in a timely manner. Through the analysis of electrical characteristics, signs of microdamage to the hard drive can be detected in advance, providing a warning for subsequent repair or replacement and avoiding the occurrence of failures. Through hardware fault prevention strategies, data loss or system failures caused by hard drive damage can be effectively avoided. Taking optimization measures in advance for potential faults helps extend the service life of the hard drive and improve its stability. Combining hardware fault prevention and abnormal access protection forms a multi-level and all-round intelligent protection system, enhancing the overall security. Through intelligent collaborative optimization, when the hard drive is threatened, the protection measures can be adjusted in real time, and the efficiency and accuracy of protection can be ensured. Through the collaborative protection framework, automated security detection and response can be achieved, improving the system management efficiency and reducing human intervention.
[0014] In this specification, a security protection detection system for a solid-state drive is provided, which is used to execute the security protection detection method for the solid-state drive as described above, and includes:
[0015] A baseline behavior module, configured to obtain the historical security monitoring logs of the solid-state drive, perform mining of regular fluctuation patterns and evolution of baseline behaviors, and construct a regular baseline behavior model;
[0016] An access behavior recognition module, configured to recognize real-time access behavior data of a solid-state drive; analyze the access mode of each behavior storage unit according to the real-time access behavior data, and perform real-time access behavior feature recognition to generate real-time access behavior features;
[0017] A benchmark deviation detection module, configured to perform benchmark access deviation detection on real-time access behavior features according to a normalized benchmark behavior model, and perform access location tracing to locate malicious access storage units;
[0018] An abnormal access protection module, configured to mine the security risk diffusion path of malicious access storage units, and then perform abnormal access protection processing to generate an abnormal access protection policy;
[0019] A hardware fault prevention module, configured to perform hard disk micro-damage prediction and potential hardware fault prevention optimization according to the historical security monitoring log, and construct a hardware fault prevention policy;
[0020] An intelligent collaborative protection module, configured to perform intelligent collaborative protection optimization according to the hardware fault prevention policy and the abnormal access protection policy, and construct a hard disk intelligent collaborative protection framework.
[0021] By analyzing the historical security monitoring logs of the solid-state drive, the normal operation mode and behavior trends of the hard drive can be identified. By extracting the regular fluctuations, the normal working state of the hard drive can be effectively understood. The construction of the baseline behavior model takes into account the behavior evolution during the long-term use of the hard drive, which helps to adapt to the gradually changing usage patterns of the solid-state drive, such as workload changes or performance degradation. By continuously updating and evolving the baseline behavior model, it can be ensured that the behavior judgment of the hard drive always conforms to its current working state, reducing the possibility of false positives and false negatives. Real-time access behavior data of the hard drive is obtained, and any abnormal access behavior is identified through the analysis of the access method of each storage unit. This real-time nature enables immediate measures to be taken when potential malicious attacks occur. By analyzing the access method of each storage unit, it helps to identify abnormal behaviors in different areas inside the hard drive, avoiding limiting the problem to the overall access pattern and ignoring the details. Generating real-time access behavior characteristics helps to understand the current access load and state changes of the hard drive, providing a basis for subsequent deviation detection and formulation of protection strategies. By comparing with the baseline behavior model, the deviation of the access behavior can be accurately identified, and potential malicious attacks or faults can be discovered. This helps to detect attacks or abnormal operations on the hard drive in a timely manner, avoiding serious damage. Deviation detection can not only discover problems, but also accurately locate the source of malicious behavior through access location tracing, helping to quickly take targeted protection measures and reducing the risk of data loss and damage. Through precise deviation identification, an efficient alarm mechanism can be provided to notify relevant personnel to take measures in a timely manner to prevent the problem from deteriorating further. By analyzing the paths and patterns of malicious accesses, possible diffusion paths of security risks are identified to prevent malicious attacks from spreading to the entire hard drive system. According to the mined risk paths, targeted protection strategies are generated. These strategies can help isolate or repair malicious accesses, preventing attacks from having a serious impact on storage units. Through timely protection measures, the risk of data loss, damage or performance degradation caused by abnormal access can be effectively reduced, protecting the security of the hard drive. By analyzing historical logs, the module can identify early micro-damage signals of the hard drive. This can prevent the hard drive from failing before a major failure occurs, reducing the risk of sudden downtime. Based on the prediction results, the module can provide suggestions for optimizing fault prevention for the hard drive, improving the operational reliability of the hard drive. By detecting and handling potential hardware problems in a timely manner, the service life of the hard drive can be effectively extended, reducing the frequency of hardware replacement and related costs. Co-optimize the hardware fault prevention and abnormal access protection strategies to avoid conflicts between the two. Through intelligent co-optimization, the hard drive can maximize the protection of data and performance when facing attacks or faults. By integrating different protection strategies, an intelligent and collaborative protection framework is constructed, enabling the system to dynamically adjust protection strategies in real time to cope with different threats and risks.This module can enhance the overall security protection ability, providing comprehensive protection from hardware failures to malicious attacks, and ensuring the high reliability of the hard disk in various complex environments. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 It is a schematic diagram of the step - by - step process of a security protection detection method for a solid - state drive of the present invention;
[0023] Figure 2 It is a schematic diagram of the detailed implementation steps of step S1;
[0024] Figure 3 It is a schematic diagram of the detailed implementation steps of step S2;
[0025] Figure 4 It is a schematic diagram of the detailed implementation steps of step S3. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0027] The embodiments of the present application provide a security protection detection method and system for a solid - state drive. The execution entities of the security protection detection method and system for the solid - state drive include, but are not limited to, mechanical devices, data processing platforms, cloud server nodes, network upload devices, etc. that carry this system, which can be regarded as general computing nodes of the present application. The data processing platform includes, but is not limited to, at least one of an audio - image management system, an information management system, and a cloud - based data management system.
[0028] Please refer to Figures 1 to 4 , the present invention provides a security protection detection method for a solid - state drive. The security protection detection method for the solid - state drive includes the following steps:
[0029] Step S1: Obtain the historical security monitoring logs of the solid - state drive, and conduct regular fluctuation pattern mining and benchmark behavior evolution to construct a regular benchmark behavior model;
[0030] Step S2: Identify the real - time access behavior data of the solid - state drive; analyze the access method of each behavior storage unit according to the real - time access behavior data, and conduct real - time access behavior feature recognition to generate real - time access behavior features;
[0031] Step S3: Conduct benchmark access deviation detection on the real - time access behavior features according to the regular benchmark behavior model, and conduct access location tracing to locate maliciously accessed storage units;
[0032] Step S4: Mine the security risk diffusion path of the maliciously accessed storage unit, and then conduct abnormal access protection processing to generate an abnormal access protection strategy;
[0033] Step S5: Perform hard disk micro-damage prediction and potential hardware fault prevention optimization based on the historical security monitoring logs, and construct a hardware fault prevention strategy;
[0034] Step S6: Perform intelligent collaborative protection optimization based on the hardware fault prevention strategy and the abnormal access protection strategy, and construct a hard disk intelligent collaborative protection framework.
[0035] By collecting historical security monitoring logs, the present invention can obtain the past access patterns and security events of the solid-state drive, so as to understand its normal working mode. This lays a foundation for subsequent behavior analysis. Extracting the normalized fluctuation law from historical data can help identify the normal working fluctuation range of the solid-state drive. Understanding this fluctuation law will help distinguish normal and abnormal behaviors. Establishing a benchmark behavior model enables the system to identify the normal operating state of the solid-state drive and provides a reference for subsequent anomaly detection. The continuous evolution of the model can be dynamically updated as the working state of the hard disk changes, improving the accuracy and timeliness of detection. Through the analysis of real-time data, potential abnormal behaviors can be discovered in a timely manner, and potential security threats can be quickly responded to. Through the analysis of the access behavior of each storage unit, refined management of hard disk operations can be achieved, ensuring that the state of each storage unit is monitored. With the help of feature recognition technology, the key features of real-time access behavior can be efficiently extracted, providing an accurate basis for subsequent anomaly detection. Based on the normalized benchmark behavior model, any anomaly deviating from the normal behavior can be efficiently identified, and the specific storage unit can be located, avoiding the problem of unable to locate the specific anomaly position in traditional methods. When a deviation is detected, an alarm can be immediately issued and the source of the abnormal behavior can be located, reducing the response time of security threats. Precise positioning can provide more specific protection strategies, achieve targeted protection, and avoid unnecessary interference and resource waste. By analyzing the attack path, malicious behaviors can be prevented from spreading from one storage unit to other areas, ensuring the overall security of the hard disk data. Based on the analysis of the diffusion path, the system can dynamically generate countermeasures, avoiding the limitations of static rules. By isolating the storage unit with malicious access, data leakage or further damage can be prevented, and the risk source can be blocked in a timely manner. Through the analysis of electrical characteristics, signs of micro-damage to the hard disk can be discovered in advance, providing a warning for subsequent repair or replacement and avoiding failures. Through the hardware fault prevention strategy, data loss or system failures caused by hard disk damage can be effectively avoided. Taking optimization measures in advance for potential faults helps extend the service life of the hard disk and improve the stability of the hard disk. Combining hardware fault prevention and abnormal access protection forms a multi-level and all-round intelligent protection system, enhancing the overall security. Through intelligent collaborative optimization, when the hard disk is threatened, the protection measures can be adjusted in real time, and the efficiency and accuracy of protection can be ensured. Through the collaborative protection framework, automated security detection and response can be achieved, improving system management efficiency and reducing human intervention.
[0036] In an embodiment of the present invention, referring to Figure 1 , it is a schematic diagram of the step flow of a security protection detection method for a solid-state drive of the present invention. In this example, the steps of the security protection detection method for the solid-state drive include:
[0037] Step S1: Obtain the historical security monitoring logs of the solid-state drive, and conduct regular fluctuation pattern mining and benchmark behavior evolution to construct a regular benchmark behavior model;
[0038] In this embodiment, the data source is determined, which is the historical security monitoring logs of the solid-state drive. These logs usually include timestamps of read and write operations, data volume, access conditions of storage units, error records, etc. Obtain these log files through a suitable interface (such as API or directly extract from the file system) to ensure the integrity and accuracy of the data. It is recommended to set the time range for data extraction, such as the logs of the past six months, for long-term trend analysis. The collected log data needs to be preliminarily sorted out, removing redundant data and invalid records to ensure the data quality for subsequent analysis. Filtering conditions can be set, such as only retaining valid read and write operation records and removing error messages and irrelevant operations. Format the collected log data to make it structured for easy analysis and modeling. Common formatting steps include converting the data into a table form and extracting necessary fields (such as time, operation type, data volume, etc.). Perform data cleaning to handle missing values and outliers. For example, if the read and write operation data within a certain time period is abnormally high, a detailed review should be carried out to determine whether it is caused by data entry errors or other factors. Record the data processing process, including the data source, processing methods, and results, to ensure the traceability of the analysis process. Use statistical analysis methods to mine the fluctuation patterns of the sorted historical security monitoring logs. Descriptive statistical analysis can be used to calculate the mean, standard deviation, skewness, and kurtosis of each key indicator to identify the distribution characteristics of the data. Set the analysis time window, such as every hour or every day, and calculate indicators such as the number of read and write operations and response time within each window to capture the fluctuation trends of the operations. In this way, the peaks and valleys of normal operations can be identified. Perform time series analysis to identify periodic fluctuations and trend changes. For example, methods such as autocorrelation analysis and Fourier transform can be used to detect potential periodic patterns. According to the results of the fluctuation pattern analysis, extract key features. These features should be able to effectively reflect the normal behavior of the hard disk, such as the time distribution of normal read and write operations and the changes in operation frequency. Build a normal benchmark behavior model. Statistical modeling methods (such as linear regression, ARIMA model, etc.) can be used to describe and predict the behavior of normal operations. The model should be able to capture the trends and fluctuation characteristics of the historical data for subsequent anomaly detection. After building the normal benchmark behavior model, update the model regularly to adapt to new data and environmental changes. Set the update frequency, such as monthly or quarterly, and retrain and evaluate the model. Combine new historical data and re-evaluate the parameters of the model to ensure that the benchmark behavior can accurately reflect the current operation status. Compare the new and old models and evaluate the differences in their prediction accuracy. Visualize the results of the benchmark behavior model to help analysts understand the patterns of normal operations. Trend charts, box plots, etc. can be generated to show the read and write operation conditions and fluctuation ranges in different time periods. Through visualization tools, analysts can intuitively identify the range of normal behavior and compare it with real-time monitoring data for subsequent anomaly detection and risk assessment.
[0039] Step S2: Identify the real-time access behavior data of the solid-state drive; analyze the access mode of each behavior storage unit according to the real-time access behavior data, and identify the real-time access behavior characteristics to generate real-time access behavior characteristics;
[0040] In this embodiment, a real-time monitoring tool is deployed on the controller of the solid-state drive to continuously track and record access behavior data. This tool should have the ability to collect data at a high frequency, and it is recommended to set it to collect once per second to ensure that all access events are captured. The monitored data includes the timestamps of read and write operations, the addresses of the storage units accessed, the access types (such as sequential access or random access), the data size, etc. These data will provide the basis for subsequent analysis. The collected real-time access behavior data is processed through a data stream management system to ensure the stability and reliability of the data stream. A message queue system (such as Kafka) can be used to process the high-frequency data stream to ensure the effective transmission and storage of real-time data. The real-time data stream is initially filtered to delete redundant or invalid data. For example, if the time interval between the timestamp of an operation and the previous operation is too short (less than millisecond level), it may be an input error, and such data should be excluded. The valid real-time access behavior data is stored in a database in a structured format (such as a relational database or a NoSQL database) for subsequent analysis. Each record should include fields such as timestamp, storage unit address, access type, and data size. A backup strategy for data storage is set to ensure that real-time data is not lost due to system failures. At the same time, expired data is regularly cleared to maintain the efficiency of the database. The access mode of the real-time access behavior data is analyzed for each storage unit one by one. First, for each storage unit, information such as the frequency of its access, access type, and access time is statistically analyzed. Using the window analysis method, the data is divided into time windows (such as every minute), and the access situation of each storage unit within this time window is calculated. This method can effectively capture the access patterns within a short period. Based on the characteristics of the access behavior, the access modes of the storage units are divided into different categories. For example, the access modes can be divided into random access, sequential access, and mixed access. By analyzing the ratio of read and write operations, the usage pattern of the storage unit can be determined. Clustering algorithms (such as K-means or DBSCAN) are used to further classify the access modes to identify the typical patterns of access behavior. This will help in subsequent analysis of potential abnormal behaviors. Feature extraction is performed on the identified access patterns, including access frequency, access latency, access data volume, etc. These features are recorded to form an access behavior profile of a storage unit. Machine learning algorithms (such as decision trees, support vector machines, etc.) are applied to identify the features of the real-time access behavior data. By training the model, the key features of the access behavior are identified, such as the storage units with high-frequency access, abnormal access latency, etc. The model is verified using the training set and test set to ensure that the model has a high recognition accuracy. Metrics such as accuracy and recall are set to evaluate the performance of the model. During the operation of the system, a real-time feature update mechanism is set. Whenever new access behavior data is generated, the model should be able to automatically update the identified features to adapt to the new access patterns and behaviors.Record the time and content of each feature update to ensure the transparency and traceability of the feature recognition process.
[0041] Step S3: Perform benchmark access deviation detection on the real-time access behavior features according to the normalized benchmark behavior model, and conduct access location tracing to locate malicious access storage units;
[0042] In this embodiment, the previously constructed normalized benchmark behavior model is used to detect the real-time access behavior features. This model should include typical features of normal access behavior, such as access frequency, access pattern, and response time, etc. Set the threshold for deviation detection. For example, for access frequency, a standard deviation range can be set to judge normal fluctuations, and access behaviors beyond this range are determined to be abnormal. In the real-time access data, compare the access features of each storage unit with the features of the benchmark behavior model one by one. Once a deviation is detected (such as the access frequency is significantly higher than the normal range), mark this behavior as abnormal. Record the specific details of the deviation, including the degree of deviation, relevant timestamps, and access types. This will provide important information for subsequent location and analysis. Generate an analysis report on benchmark access deviation detection, recording all detected abnormal behaviors. The report should include information such as the nature of the deviation (such as frequency, pattern, etc.), time period, and affected storage units. According to the detection results, formulate subsequent monitoring and response measures to ensure that potential security threats can be handled in a timely manner. For each detected abnormal access behavior, trace the access path. Use the timestamps and storage unit address information in the data log to reconstruct the path of the abnormal access. Determine the starting point and ending point of the abnormal behavior, and analyze its propagation path in the storage system. This process can be achieved through graphical tools to help analysts visualize the access network. Compare the path of the abnormal access with the historical normal access paths to identify the characteristics of the abnormal access. Analyze the differences in access frequency, access time, and access behavior to determine which storage units have been abnormally affected. Record the comparison results, including the storage units accessed abnormally, access methods, and their differences from normal behaviors, in order to provide clues for subsequent location. According to the tracing results of the access path, locate the specific malicious access storage units. A rule-based algorithm can be used to judge which storage units' access behaviors do not conform to the normal pattern and may have malicious behaviors. Record the location results, including the detailed information of the storage units marked as malicious access, such as the number of accesses, access time, and access types, etc. This will provide an important basis for subsequent security responses. Integrate the results of deviation detection and access tracing to generate a comprehensive analysis report. The report should describe in detail the detected abnormal deviations, access paths, and located malicious storage units. In addition to listing all detected problems, the report should also provide a risk assessment, explaining the potential impacts and their severity. This can help management make timely decisions.
[0043] Step S4: Mine the security risk diffusion path for malicious access to the storage unit, and then perform abnormal access protection processing to generate an abnormal access protection policy;
[0044] In this embodiment, a diffusion path model is constructed based on the previously located malicious access storage unit. This model should consider the physical and logical connection relationships between storage units, including data flow paths, access frequencies, and interdependencies. Set the analysis scope. For example, starting from the malicious storage unit, analyze the storage units directly connected to it and their access behaviors to determine potential diffusion paths. Use breadth-first search (BFS) or depth-first search (DFS) algorithms in graph theory to traverse the access records of storage units and identify the storage units that may be affected. During the analysis process, focus on the storage units that are immediately subsequent to the malicious access in terms of time. Record the access frequency and timestamp of each storage unit and compare them with the baseline behavior model to determine whether any abnormal behavior has occurred. This will help identify potential risk diffusion paths. Conduct a risk assessment for each identified diffusion path. A risk scoring system can be set based on metrics such as changes in access frequency and increased response time to score each path. Organize the evaluation results into a report clearly indicating high-risk storage units and possible diffusion paths for subsequent protection processing. Based on the analysis results of the risk diffusion paths, formulate targeted abnormal access protection strategies. The strategies should include measures such as isolating malicious access storage units, monitoring the access behaviors of relevant storage units, and implementing access restrictions. Determine the priority of the protection strategies. According to the risk assessment results, prioritize the handling of high-risk storage units to minimize potential security threats. For the identified malicious access storage units, immediately implement access restrictions. The read and write operations to these storage units can be prohibited by adjusting the access permissions of the storage controller to prevent the spread of malware. Record the specific operations of each access restriction, including the time, the address of the restricted storage unit, and the reason for the restriction, to ensure that all measures are well-documented. After implementing the protection strategies, establish a real-time monitoring mechanism to continuously track the access behaviors of the storage units related to the malicious access storage unit. Set the monitoring frequency, for example, collect data once a minute, to promptly detect any abnormal situations. Once the monitoring system detects new abnormal access behaviors, a preset response mechanism should be immediately triggered, including notifying the security team and recording relevant data for subsequent investigation. After implementing the abnormal access protection strategies, regularly evaluate their effectiveness. Collect and analyze the access data for a period of time after implementation and compare the changes in access patterns before and after the protection measures. Set evaluation metrics such as the reduction in the number of abnormal accesses and the normalization of response time to ensure that the protection measures can effectively reduce risks. Optimize the protection strategies based on the evaluation results. If it is found that some measures are ineffective, consider adjusting the strategies or implementing new protection measures. For example, it may be necessary to strengthen the monitoring of specific storage units or adjust the access permission levels. Record the optimization process, including the content, reason, and expected effect of each adjustment, for future improvement of protection strategies.
[0045] Step S5: Perform hard disk micro-damage prediction and potential hardware fault prevention optimization based on the historical security monitoring logs, and construct a hardware fault prevention strategy;
[0046] In this embodiment, historical security monitoring logs of the solid-state drive are collected. These logs record the operating status, access behavior, error information, and any abnormal events of the hard disk. To ensure the integrity and accuracy of the data, it is generally recommended to extract data from the past six months to one year to identify long-term trends. Preprocess the collected log data, including removing duplicate records, correcting error data, and filling in missing values. For example, for events with read errors, a detailed review is required to ensure the authenticity and validity of these records. Extract key features from the historical logs, such as read and write counts, error rates, temperature changes, response times, and access latencies. These features will be used for the subsequent construction of the micro-damage prediction model. Conduct descriptive statistical analysis to calculate the mean, standard deviation, and distribution of each feature. This will help identify the range of features in the normal operating state and thus provide a benchmark for micro-damage judgment. Mark abnormal behaviors in the historical data by setting thresholds. For example, if the error rate exceeds twice the normal range, mark this data as abnormal. This process can be achieved through control charts or Z-score analysis to ensure the effective identification of abnormal behaviors. Record all marked abnormal events and classify them for subsequent analysis reference. Select a suitable micro-damage prediction model based on the extracted features and marked abnormal events. Machine learning algorithms such as random forest, support vector machine, or logistic regression can be considered according to their effectiveness in classification problems. Divide the data into a training set and a test set. Usually, it is recommended to use 70% as the training set and 30% as the test set to ensure the generalization ability of the model. Train the model on the training set and optimize the model's performance by adjusting hyperparameters. Use cross-validation techniques to ensure the stable performance of the model on different data subsets. Verify the accuracy of the model on the test set, and the evaluation metrics include accuracy, recall, and F1-score, etc. Ensure that the model can effectively identify potential micro-damages and give early warnings. Apply the trained model to evaluate the micro-damage risk of the historical data. Calculate the micro-damage risk score for each storage unit and classify it according to the risk level (such as high, medium, low). Record the evaluation results, including the risk score, potential problems, and recommended measures for each storage unit, for subsequent formulation of prevention strategies. Based on the results of the micro-damage prediction model, formulate corresponding hardware fault prevention strategies. The strategies should include measures such as regular monitoring, backup plans, temperature control, and read and write operation restrictions to reduce the risk of hardware faults. Develop a regular inspection and maintenance plan, such as conducting a detailed inspection of high-risk storage units every month to ensure their normal operating status.
[0047] Step S6: Perform intelligent collaborative protection optimization according to the hardware fault prevention strategy and the abnormal access protection strategy, and construct a hard disk intelligent collaborative protection framework.
[0048] In this embodiment, collect and organize the previously formulated hardware fault prevention strategies and abnormal access protection strategies. Conduct an in-depth analysis of both to identify their commonalities and differences in order to determine how to effectively integrate them. Set integration goals, such as enhancing overall security, reducing the failure rate, and improving the system response speed. Ensure that the integrated strategies can cover the prevention of hardware faults and the real-time monitoring of abnormal access. Based on the analysis results, construct a comprehensive strategy model. This model should include unified management of hardware monitoring, abnormal behavior detection, and fault response. A decision tree model can be adopted to define response measures and priorities in different situations. Set the interaction mechanism between various strategies. For example, when detecting abnormal access behavior, immediately trigger hardware health monitoring and decide on subsequent measures based on the monitoring results. Determine the indicators for evaluating the effectiveness of the integrated strategies, such as the failure rate, abnormal access detection rate, response time, and system availability, etc. It is recommended to set benchmark values for subsequent evaluation and optimization. Record the initial values of each indicator for comparative analysis after implementing the intelligent collaborative protection framework. Design the overall architecture of the intelligent collaborative protection framework, including the data collection layer, analysis and decision-making layer, and response execution layer. The data collection layer is responsible for real-time monitoring of the hard disk status and access behavior. The analysis and decision-making layer is responsible for data analysis and strategy judgment. The response execution layer is responsible for implementing corresponding protection measures. Determine the communication mechanism between layers to ensure that real-time data can be transmitted quickly. For example, adopt message queue technology (such as RabbitMQ) to achieve efficient data transmission between layers. In the data collection layer, integrate data from hardware monitoring and abnormal access detection. This includes information such as temperature, read / write times, error rate, etc. collected from hardware sensors, as well as log data of real-time access behavior. Use machine learning algorithms (such as clustering analysis and anomaly detection algorithms) to conduct intelligent analysis on the fused data to identify potential risks and fault warnings. For example, the K-means clustering algorithm can be used to classify access patterns to help identify abnormal behavior. In the response execution layer, establish an automatic response mechanism to ensure that measures can be taken immediately when detecting abnormal situations. Set multiple response strategies, such as temporarily isolating suspicious storage units, restricting access permissions, or starting a fault recovery program, etc. Record the detailed information of each response, including time, triggering reason, and measures taken, for subsequent evaluation and optimization of the effectiveness of the response mechanism. After the intelligent collaborative protection framework has been running for a period of time, collect relevant data for effectiveness monitoring. The indicators include the system failure rate, abnormal access detection rate, and response time, etc., to ensure that the effectiveness of the framework can be comprehensively evaluated. Set the monitoring frequency, such as conducting a comprehensive evaluation once a week, to promptly discover problems and make adjustments. Analyze the collected data and compare the changes in various indicators before and after implementation. For example, if the failure rate is significantly reduced, it indicates that the prevention strategy and monitoring measures are effective; if the abnormal access detection rate does not meet the expectation, the detection algorithm needs to be further optimized. Record the results and analysis of each evaluation to form a report to provide decision-making support for management.
[0049] In this embodiment, refer to Figure 2 , which is a schematic diagram of the detailed implementation steps of step S1. In this embodiment, the detailed implementation steps of the said step S1 include:
[0050] Obtain the historical security monitoring logs of the solid-state drive;
[0051] Mine the normal fluctuation law of the historical security monitoring logs to generate normal benchmark behavior characteristics;
[0052] Analyze the hardware interaction status according to the historical security monitoring logs to generate hardware interaction status characteristics;
[0053] Conduct in-depth mining between storage units on the historical security monitoring logs to generate the storage unit association logic;
[0054] Evolve the normal benchmark behavior characteristics according to the storage unit association logic and the hardware interaction status characteristics to construct a normal benchmark behavior model.
[0055] In this embodiment, determine the monitoring tools or software used by the solid-state drive (SSD) to ensure access to relevant security monitoring logs. These logs typically contain information about the hard drive's operating status, error reports, read / write operations, and firmware information. Set the log collection scope, usually selecting data from the past few months to a year to obtain sufficient samples for analysis. Ensure the integrity of the log data within the selected time period to avoid affecting subsequent analysis due to missing data. Format the collected raw log data to ensure its consistent structure and facilitate subsequent processing. Data processing tools (such as Excel, Python, etc.) can be used to integrate logs in different formats into a unified format (such as CSV or JSON). Perform data cleaning to remove duplicate records and invalid data (such as incorrect timestamps or irrelevant log entries) to ensure the accuracy of subsequent analysis. Store the cleaned historical security monitoring logs in a database, selecting a suitable database system (such as MySQL, PostgreSQL, or NoSQL databases) for subsequent data query and analysis. Extract key features from the historical security monitoring logs, such as read / write speed, error rate, temperature change, and service life. These features can reflect the performance of the SSD under normal operating conditions. Use statistical analysis methods (such as mean, standard deviation, and peak value) to describe the extracted features and generate a preliminary feature dataset. Based on the extracted feature data, conduct normalization analysis. Set a threshold range to identify behavioral characteristics within the normal fluctuation range. The Z-score normalization method can be used to convert each feature into a standard score for subsequent analysis. Record the normalized fluctuation pattern and generate benchmark behavioral characteristics. These benchmark features will serve as a reference standard for subsequent anomaly detection. Collect relevant data on hardware interaction from the monitoring logs, such as the communication frequency between the SSD and the host, I / O request response time, and data transfer errors. This data can provide information on the interaction status of the SSD under different loads. Ensure the timeliness and integrity of the data to avoid affecting the analysis results due to missing data. Extract features from the collected interaction data to generate hardware interaction status features. These features can include average response time, maximum concurrent request number, error rate, etc., which can reflect the stability and reliability of the SSD during use. Apply statistical analysis methods to calculate the mean and standard deviation of each interaction feature for subsequent analysis. Analyze the extracted hardware interaction status features to identify potential performance bottlenecks or abnormal interaction situations. For example, if a significant increase in response time is found during a certain period, further investigation can be considered based on the usage situation during that period. Deeply mine the usage of storage units in the historical security monitoring logs to identify the interaction and dependency relationships between different storage units. Analysis can be performed from aspects such as the number of reads, writes, and erasures. Apply association rule mining algorithms (such as the Apriori algorithm) to analyze the correlation between storage units to identify potential logical relationships and behavioral patterns.Construct a relationship network between storage units based on the mined storage unit association logic. Record the status of each storage unit and its association with other units. Use a graphical tool to display the storage unit logic relationship to facilitate the analysis and understanding of the interaction between storage units. Evolve the normalized benchmark behavior characteristics based on the storage unit association logic and the hardware interaction status characteristics, and update the benchmark model. Use the weighted average method to consider the importance of each feature to generate new benchmark behavior characteristics. Set the update frequency, such as updating the benchmark behavior characteristics once a month or once a quarter, to ensure its adaptability and accuracy. Construct a normalized benchmark behavior model and incorporate the updated benchmark behavior characteristics into the model. Machine learning methods (such as clustering analysis or classification algorithms) can be used to model the benchmark behavior for subsequent anomaly detection. Record the performance metrics of the model (such as accuracy, recall, etc.) to ensure the effectiveness and usability of the model. Validate the constructed normalized benchmark behavior model and use historical data to test the accuracy and robustness of the model. Record the validation results and adjust the model as needed. Apply the benchmark behavior model to the real-time monitoring system to detect in real time whether the behavior of the SSD deviates from the norm and identify potential security risks and faults in a timely manner.
[0056] In this embodiment, the specific steps for mining the normalized fluctuation law of the historical security monitoring log to generate the normalized benchmark behavior characteristics are as follows:
[0057] Perform statistics on the normal read and write behaviors of the historical security monitoring log and extract all the monitoring data of the normal read and write behaviors;
[0058] Calculate the data transfer rate of the normal read and write behavior monitoring data to generate the data transfer rate of the read and write behavior;
[0059] Identify the distribution characteristics of the number of flash block erasures of the normal read and write behavior monitoring data;
[0060] Calculate the execution frequency of the TRIM command based on the normal read and write behavior monitoring data;
[0061] Mine the normalized fluctuation law of the data transfer rate of the read and write behavior, the distribution characteristics of the number of flash block erasures, and the execution frequency of the TRIM command to generate the normalized benchmark behavior characteristics.
[0062] In this embodiment, all records related to read and write operations are extracted from the obtained historical security monitoring logs. These records usually include information such as timestamps, operation types (read or write), transfer sizes, and target storage units. Ensure that the time range of the selected data is wide enough for comprehensive analysis. Clean the data by removing invalid records and duplicate data to ensure the quality of the final dataset. For example, records with inconsistent timestamps can be set as invalid, or records with a transfer size of zero can be excluded. Classify the extracted read and write operation records, and count the total number of each operation type, the average data size per operation, and the time interval between operation executions. This can be achieved using simple counting and aggregation functions. Record the statistical results, such as the number of read and write operations per minute or per hour, and the average data size of each operation. These statistical data will provide a basis for subsequent analysis. Determine the calculation method for the data transfer rate. Usually, the transfer rate (unit: MB / s) can be calculated by dividing the data size of each operation by the time taken for the operation. The formula is: Rate = Data Size / Operation Time. Collect the timestamps of each read and write operation to calculate the duration of each operation. This can be achieved by calculating the difference between adjacent operation timestamps. Calculate the rate for all read and write operations, record the rate of each operation, and calculate statistical measures such as the overall average transfer rate, maximum transfer rate, and minimum transfer rate. Analyze the changes in the transfer rate over different time periods, identify peak and trough periods, and record the reasons for these changes, such as whether they are related to system load or operation type. Extract the information on the number of erase and write cycles for each flash block from the historical monitoring logs. This information usually appears as separate records in the logs and may include the number of writes and erasures for each block. Ensure the integrity of the data to accurately reflect the usage status of each flash block. Statistically analyze the extracted data on the number of erase and write cycles to generate the distribution of the number of erase and write cycles for each flash block. This can be achieved by calculating measures such as the mean, standard deviation, maximum, and minimum of the number of erase and write cycles for each block. Identify the distribution characteristics of the number of erase and write cycles and analyze whether there is a phenomenon of frequent erase and write cycles for specific blocks. This may indicate potential performance issues or uneven data distribution. Extract all records related to the TRIM command from the historical security monitoring logs. The TRIM command is usually triggered during SSD deletion operations to assist the SSD in optimizing storage space. Ensure that the records contain timestamps and the execution details of the TRIM command for subsequent analysis. Count the number of executions of the TRIM command within the selected time range and calculate its frequency. For example, the execution frequency of the TRIM command can be counted hourly or daily to identify high-frequency execution time periods. Record the average frequency and peak frequency of the TRIM command execution and analyze the performance of the TRIM command under specific workloads. Determine the normalization method. Usually, methods such as Z-score normalization or Min-Max normalization can be adopted.Select a standardization technique suitable for the data distribution to uniformly compare the fluctuations of different features. Set a normalized threshold range, and usually select the values within ±1 standard deviation as the normal fluctuation range. Normalize the data such as the data transfer rate of read and write behavior, the distribution characteristics of the number of flash block erasures, and the execution frequency of the TRIM command to generate normalized baseline behavior characteristics. Identify and record the fluctuation patterns of each feature, including the normal range, abnormal fluctuations, and potential fault indicators. Store the normalized baseline behavior characteristics in a database for subsequent analysis and comparison. Record the normal fluctuation range and abnormal identification of each feature. Generate a visualization chart to display the normalized fluctuation patterns of each feature, so that analysts can identify potential abnormal patterns and trends.
[0063] In this embodiment, refer to Figure 3 , which is a schematic diagram of the detailed implementation steps of step S2. In this embodiment, the detailed implementation steps of the said step S2 include:
[0064] Identify the real-time access behavior data of the solid-state drive;
[0065] Analyze the access method of each behavior storage unit according to the real-time access behavior data to generate the storage unit access method;
[0066] Calculate the access frequency within a period for the real-time access behavior data to generate the periodic access frequency;
[0067] Calculate the wear degree of the flash block according to the real-time access behavior data;
[0068] Based on the storage unit access method, the periodic access frequency, and the wear degree of the flash block, identify the real-time access behavior characteristics to generate the real-time access behavior characteristics.
[0069] In this embodiment, a real-time monitoring system is constructed to capture the access behavior data of a solid state drive (SSD). The system needs to be able to continuously record all read and write operations on the SSD, including information such as timestamp, operation type (read or write), data size, target storage unit, etc. Ensure that the system can handle high-frequency access requests and can store and update access data in real time. A buffer can be set up to store access data within a short period to avoid data loss. Each time the SSD is accessed, record the relevant access behavior information and write the data into a dedicated log file or database. Ensure that the recorded content includes the type of operation, time, accessed storage unit, data size, etc. Set the data storage format and adopt a structured data format (such as JSON or CSV) to facilitate subsequent analysis and processing. Regularly verify the collected real-time access behavior data to check the integrity and accuracy of the data. Remove duplicate records and invalid data (such as records with incorrect timestamps or zero data size). Define the classification criteria for the access mode of the storage unit, which may include sequential access and random access, read access and write access, etc. According to the characteristics of the SSD, formulate classification rules to reflect the impact of different access modes on performance. Set the analysis time window, for example, conduct statistics on the access mode every minute or every hour, so as to accurately capture changes in the access mode. Classify and statistically analyze the access mode of each storage unit according to the real-time access behavior data. Record the occurrence times and proportions of each access mode within the specified time window. Calculate the access mode characteristics of each storage unit, such as the random access ratio, sequential access ratio, etc., and generate corresponding access mode characteristic data. According to the real-time access behavior data, set a time period (such as every hour, every day) to calculate the access frequency of each storage unit. Record the number of read and write operations within each period. Group the access records using timestamps and summarize the access behaviors within the same time period. Statistically analyze the access frequency of each storage unit within the set period, calculate the total access times and average access frequency of each storage unit. Analyze the changes in access frequency at different time periods, and identify the storage units with high-frequency access and possible usage patterns. For example, the difference in access frequency during peak and off-peak working hours can be recorded. Determine the calculation standard for the wear level of the flash block. Usually, the wear level can be evaluated by recording the number of erase-write cycles of each flash block. Set the wear threshold, usually based on the number of erase-write cycles. For example, the maximum number of erase-write cycles for each block is 3000. Collect the read and write operation records of each flash block, especially the records of erase operations, for calculating the wear level. Statistically analyze the collected data on the number of erase-write cycles, calculate the number of erase-write cycles of each flash block, and calculate its ratio relative to the maximum allowable number of erase-write cycles to obtain the wear level (for example, wear percentage = current number of erase-write cycles / maximum number of erase-write cycles). Record the wear status of each flash block and analyze which blocks have a higher wear level and may require more frequent maintenance or replacement.Store the calculated wear level data of the flash memory blocks in a database to ensure the convenience of subsequent queries and analysis. Generate a visual chart (such as a heat map) of the wear level to show the wear conditions of different flash memory blocks, so as to facilitate the timely identification of storage units that need attention. Based on data such as the access mode of storage units, the cycle access frequency, and the wear level of flash memory blocks, comprehensively identify the characteristics of real-time access behavior. This step requires integrating the various characteristics extracted previously to identify the overall access behavior pattern. Set the feature weights, considering the importance of each feature to the access behavior, and comprehensively calculate the scores of the access behavior characteristics. Use machine learning algorithms (such as clustering analysis or decision trees) to perform real-time identification of the comprehensive characteristics, mark different types of access behavior, such as normal access, abnormal access, etc. Record the feature values of each access behavior and generate a real-time access behavior feature data set for subsequent analysis and use.
[0070] In this embodiment, refer to Figure 4 , which is a schematic diagram of the detailed implementation steps of step S3. In this embodiment, the detailed implementation steps of step S3 include:
[0071] Perform benchmark access deviation detection on the real-time access behavior characteristics according to the normalized benchmark behavior model, and mark the access deviation behavior data;
[0072] Conduct a potential security threat analysis on the access deviation behavior data to generate potential security threat characteristics;
[0073] Classify the types of malicious behavior according to the potential security threat characteristics to obtain the types of malicious behavior of abnormal access;
[0074] Trace back the malicious access for the types of malicious behavior of abnormal access to extract the malicious access behavior cycle chain;
[0075] Based on the malicious access behavior cycle chain, trace the access location to locate the malicious access storage unit.
[0076] In this embodiment, the normalized baseline behavior model is applied to real-time access behavior characteristics for baseline access deviation detection. First, real-time access behavior characteristics are extracted, including the storage unit access method, access frequency, and flash block wear level, etc. Each real-time access feature value is compared with the corresponding value in the baseline model to calculate the deviation. For example, the standard deviation method can be used to set a deviation threshold (such as ±2 standard deviations) to determine when to mark it as a deviation behavior. According to the calculated deviation value, the access deviation behavior data is marked. The specific information of the mark is recorded, including the timestamp, access type, storage unit, and deviation degree, etc. A deviation behavior database is generated to store all the marked deviation behavior data for subsequent analysis and query. Potential security threat analysis is performed on the marked access deviation behavior data to extract relevant threat characteristics. These characteristics may include abnormal access patterns, frequent write operations, extreme access frequencies, etc. Statistical methods are used to analyze the significant differences between these characteristics and normal behaviors, such as calculating the abnormal frequency, the interval of access time, etc. A security threat assessment criterion is set, and potential security threats are judged based on the extracted threat characteristics. For example, if it is found that the write frequency of a certain storage unit increases abnormally, it may indicate potential malicious behavior. The assessment results of each potential security threat are recorded, including the assessment indicators and the judgment basis, to form a threat analysis report. According to the potential security threat characteristics, various types of malicious behaviors are defined, such as data theft, malicious writing, denial-of-service attacks, etc. Each type should have a clear characteristic description for easy classification and identification. Relevant historical data is collected to facilitate the establishment of a classification model for malicious behavior characteristics. Machine learning algorithms (such as decision trees, support vector machines, or random forests) are used to construct a classification model for malicious behavior types. The extracted potential security threat characteristics are used as inputs, and the malicious behavior types are used as outputs. The model is trained using the marked historical data for training and validation to ensure the accuracy and stability of the model. Real-time classification is performed on the marked access deviation behavior data to generate abnormal access malicious behavior types. The classification results of each behavior are recorded, including the behavior type and the corresponding feature values. The classification results are stored in the database to form an abnormal access behavior type database for subsequent analysis and traceability. For the marked abnormal access malicious behaviors, their access cycle chains are extracted. This includes recording information such as the timestamp, access type, and storage unit of each malicious behavior to form a complete access chain. A time window is set to ensure that the extracted cycle chain can reflect the duration and frequency of the malicious behavior. The extracted access cycle chain is analyzed to identify the patterns and trends of malicious access. For example, analyze the storage units and access types that frequently appear in the access chain to identify potential attack paths. The analysis results are recorded to generate a cycle chain analysis report to help the security team understand the nature and scope of the malicious behavior. The malicious access behavior cycle chain is stored in the database to ensure the traceability and query convenience of the data.Based on the extracted malicious access behavior cycle chain, trace the access location to identify the storage unit of malicious access. Record all involved storage units, their access frequencies, and behavior types. Set the priority of the storage units, sort them according to the access frequency and malicious behavior type, to facilitate locating the storage unit most likely to be attacked. Combine the usage history and access characteristics of the storage unit to further analyze the malicious access and identify the specific storage unit of malicious access. For example, if a storage unit is frequently accessed during malicious behavior, the possibility of it being attacked is relatively high. Record the results of the traceability analysis, generate an access location traceability report to help the security team take corresponding measures. Store the traceability results of the malicious access storage unit in the database for subsequent investigation and evidence collection. According to the traceability results, formulate corresponding security policies, such as strengthening the monitoring of specific storage units or blocking abnormal access behaviors.
[0077] In this embodiment, step S4 includes the following steps:
[0078] Mine the security risk diffusion paths of the malicious access storage unit and extract multiple security risk diffusion paths;
[0079] Based on multiple security risk diffusion paths, predict the hard disk risk loss to generate a hard disk risk loss prediction value;
[0080] Based on the hard disk risk loss prediction value, evaluate the risk level and make an adaptive early warning decision to generate an adaptive early warning strategy;
[0081] According to multiple security risk diffusion paths, predict the hidden access location and mark multiple hidden access storage units;
[0082] Based on the adaptive early warning strategy, perform abnormal access protection processing on the malicious access storage unit and multiple hidden access storage units to generate an abnormal access protection strategy.
[0083] In this embodiment, a path mining algorithm in graph theory (such as depth-first search or breadth-first search) is used to analyze the access relationship between storage units and find potential risk diffusion paths. These paths can represent the way malicious access spreads between storage units. Set the screening criteria for the path, such as the path with an access frequency exceeding a certain threshold, or the path within a specific time window, to identify the diffusion path with greater impact. Extract multiple security risk diffusion paths, and record the characteristics of each path, such as the storage unit passed, the number of accesses, and the access time. Ensure that the extracted path can reflect the propagation characteristics of malicious behavior. Analyze the potential risks of each path, identify which paths may cause more serious security threats, and record relevant data for subsequent use. According to the extracted security risk diffusion path, establish a hard disk risk loss prediction model. The model should consider multiple factors that affect the loss, such as the wear degree of the storage unit, the access frequency, the historical failure rate, etc. Use regression analysis or time series prediction methods to establish the model to ensure that the model can make effective predictions based on historical data and current risk paths. Use the constructed loss prediction model to predict risk losses for each security risk diffusion path. Record the predicted loss value of each path and calculate the overall risk loss prediction value. Analyze the loss prediction results of different paths and identify the paths with higher risk losses to facilitate subsequent risk management decisions. Develop risk level assessment standards based on the hard disk risk loss prediction value. You can set grading standards, such as: low risk (0-1000 yuan), medium risk (1001-5000 yuan), and high risk (5001 yuan and above). Ensure that the assessment standards can reflect the actual risk situation and can effectively distinguish storage units of different risk levels. Assess the risk level of each security risk diffusion path and its corresponding loss prediction value. Record the assessment results in the database for subsequent query and management. Generate a risk level report to display the risk levels of different paths to support the decision-making process. Based on the risk level assessment results, develop an adaptive early warning strategy. For example, set an immediate warning for high-risk paths and set a regular inspection for medium-risk paths. Record the execution of the early warning strategy to ensure that potential security threats can be responded to in real time. Analyze the access behavior of the marked malicious access storage unit to identify potential hidden access patterns. These patterns may include features such as irregular access frequency and high frequency access in a specific time period. Set thresholds and standards to facilitate the identification of potential hidden access storage units, such as storage units with access frequencies lower than the normal range. Based on the extracted access patterns, predict multiple possible hidden access storage units and mark these units. Record the characteristics of each hidden storage unit, including the basis for prediction and potential risks. Generate a database of hidden access storage units for subsequent analysis and tracking. Based on the adaptive early warning strategy, formulate abnormal access protection strategies for malicious access storage units and multiple hidden access storage units. The strategy should include measures such as monitoring of abnormal access, restricting access rights and data encryption.Ensure that the protection policy can be automatically adjusted according to real-time access behaviors. For example, if an increase in abnormal access behaviors is detected, the monitoring level is raised. Implement the formulated abnormal access protection policy in the system to ensure real-time monitoring of access behaviors to maliciously access storage units and hidden access storage units. Record the implementation effects and evaluate the effectiveness of the protection policy, such as monitoring whether the occurrence of abnormal access events has decreased. Store the implementation results of the protection policy and the monitoring data in a database for subsequent analysis and optimization. Regularly evaluate the effectiveness of the protection policy and make adjustments and optimizations according to the actual situation to ensure long-term security protection.
[0084] In this embodiment, the specific steps of the abnormal access protection process are as follows:
[0085] Extract detailed abnormal access information based on the adaptive warning policy and synchronously upload it to the cloud;
[0086] The administrator conducts a risk assessment based on the cloud, identifies the current abnormal access risk, and obtains the abnormal access risk level; the abnormal access risk level includes low level, medium level, and high level;
[0087] Issue an administrator instruction based on the abnormal access risk level;
[0088] Parse the administrator instruction to obtain the risk handling assessment level;
[0089] When the risk handling assessment level is low;
[0090] Conduct in-depth data semantic recognition on maliciously accessed storage units and multiple hidden access storage units, and extract the data semantic features of the storage units;
[0091] Detect sensitive data according to the data semantic features of the storage units and mark the sensitive data;
[0092] Perform multiple data encryptions on the sensitive data to obtain multiple encrypted data;
[0093] When the risk handling assessment level is medium;
[0094] Identify all data interaction channels of maliciously accessed storage units and multiple hidden access storage units;
[0095] Perform regional automatic isolation processing on the data interaction channels;
[0096] When the risk handling assessment level is high;
[0097] Lock the solid-state drive.
[0098] In this embodiment, based on the adaptive warning strategy, detailed abnormal access information is extracted from the monitoring system. Such information should include the timestamp of the abnormal access, access type, storage units involved, access frequency, degree of abnormality, and access method, etc. Design the extraction logic to ensure that all relevant data can be covered and invalid or redundant information can be filtered out. Format the extracted abnormal access information to ensure that it meets the requirements for uploading to the cloud. Usually, JSON or XML formats are adopted to facilitate parsing and storage in the cloud. Ensure the integrity and consistency of the data, verify the extracted information to ensure there is no loss or error. Set up a secure upload channel and use the HTTPS protocol to upload the abnormal access information to the cloud database. Ensure data encryption during transmission to prevent data from being stolen during transmission. The administrator accesses the uploaded abnormal access information on the cloud platform and uses data analysis tools (such as SQL queries or data visualization tools) to analyze the data to identify the current abnormal access risks. Set up analysis metrics, such as abnormal access frequency, multiple accesses to specific storage units, sudden changes in access patterns, etc., and conduct a comprehensive risk assessment based on these metrics. According to the analysis results, evaluate the risk level of the abnormal access. Set clear level criteria: low level (no obvious abnormality), medium level (occasional abnormality), high level (frequent abnormality or specific pattern). Record the risk assessment results and generate a risk assessment report to show the characteristics and potential impacts of the abnormal access. Store the risk assessment results in the cloud database for subsequent query and management. Ensure the traceability of the risk assessment report. Send a notice of the risk assessment results to the administrator to ensure that they can timely understand the current abnormal access risk situation. According to the abnormal access risk level, the administrator issues corresponding instructions. For example, for low-level risks, it may only be necessary to monitor; for medium-level risks, isolation measures may be required; while for high-level risks, the hard disk needs to be locked immediately. Ensure the clarity and operability of the instructions so that the execution team can quickly understand and take actions. Set up an instruction parsing system to automatically identify and parse the instructions issued by the administrator. The parsing logic should be able to translate the instructions into specific risk handling assessment levels. Record the parsing results, including instruction content, parsing time, and processing status, for subsequent auditing and tracking. Conduct in-depth data semantic recognition for malicious access to storage units and multiple hidden access storage units. This process includes analyzing the data types in the storage units (such as documents, pictures, databases, etc.) and the content characteristics of the data. Utilize natural language processing (NLP) techniques and data mining algorithms to extract the semantic features of the data and identify potential sensitive information. According to the identified data semantic features, conduct sensitive data detection. Set standards and rules for sensitive data, such as personal identity information, financial data, etc., and match them with the data in the storage units. Mark the detected sensitive data and record its location and characteristics for subsequent processing. Perform multiple data encryptions on the marked sensitive data.Select a suitable encryption algorithm (such as AES or RSA) to ensure the security of data during storage and transmission. Generate an encrypted data copy and update the database to ensure the secure storage of data while maintaining the integrity of the original data. Identify all data interaction channels for malicious access to the storage unit and multiple hidden access storage units, including network connections, file transfer channels, etc. Ensure that all interaction methods related to the storage unit are identified. Use network monitoring tools and traffic analysis techniques to monitor and record the usage of data interaction channels in real time. Automatically isolate the identified data interaction channels by region. Set isolation policies according to the risk level to restrict the access rights to maliciously access the storage unit. Record the implementation of isolation measures, including the isolated channels, isolation time, and related operators, to ensure subsequent auditing and tracking. After implementing the isolation measures, continuously monitor the status of data interaction channels and evaluate the effectiveness of isolation measures to ensure that no new malicious access behaviors occur. After confirming that the risk treatment assessment level is high, immediately prepare to lock the solid-state drive. Ensure that all relevant data and operations can be saved before locking to prevent data loss. Record the locking process and necessary operation steps to ensure that all operations are well-documented. Perform the hard disk locking operation to ensure that malicious access cannot continue. The locking can be achieved through system settings or hardware measures, such as disabling the hard disk or setting access permissions. Record the locking time, operator, and locking reason for subsequent auditing and analysis. After locking the hard disk, conduct a risk assessment to analyze the effectiveness and potential impact of the locking measures. Evaluate whether further investigation or repair measures are required. Generate a risk assessment report after locking, recording all relevant information to support subsequent security audits and improvements.
[0099] In this embodiment, step S5 includes the following steps:
[0100] Calculate the current and voltage parameters at multiple frequencies for the historical security monitoring log, and extract the current and voltage parameters for multiple time windows;
[0101] Conduct a long-running electrical characteristic fluctuation analysis on the current and voltage parameters of each time window to generate electrical characteristic fluctuation features;
[0102] Fit the change in power consumption of the hard disk memory according to the electrical characteristic fluctuation features to construct a power consumption change curve;
[0103] Predict the micro-damage of the hard disk based on the power consumption change curve to obtain signs of hard disk micro-damage;
[0104] Based on the signs of hard disk micro-damage, optimize the prevention of potential hardware failures and construct a hardware failure prevention strategy.
[0105] In this embodiment, data related to current and voltage are extracted from historical security monitoring logs. Such data usually includes timestamps, measured current values, corresponding voltage values, etc. Ensure the integrity and accuracy of the data for subsequent analysis. Set multiple time windows (e.g., every minute, every hour, or every day) for segmented calculations. Each time window should contain sufficient data points to ensure the reliability of the calculation results. Perform statistical calculations on the current and voltage data within each time window, such as calculating the average value, maximum value, minimum value, and standard deviation, etc. These statistics will be used to describe the electrical characteristics of each time window. Record the current-voltage parameters of each time window and store them in a structured database for subsequent analysis. Store the calculated current-voltage parameters in the database and generate preliminary visualization charts (such as line charts) to show the changing trends of current and voltage in different time windows. This will help analysts intuitively understand the fluctuations of electrical characteristics. Define the "long-running state", which usually refers to the electrical characteristics of the hard disk in a stable working state. It is necessary to select data over a long time period for analysis. Select appropriate time windows (such as one week, one month) to ensure that the data can reflect the performance of the hard disk under normal working conditions. Apply statistical analysis methods (such as analysis of variance, time series analysis, etc.) to perform fluctuation analysis on the current-voltage parameters of each time window. Calculate the fluctuation amplitude and changing trend within each time window. Identify high-fluctuation and low-fluctuation time periods and record relevant electrical characteristic features, such as fluctuation frequency, amplitude, etc. Based on the extracted current and voltage parameters, construct an electric energy consumption model. The electric energy consumption can be calculated by the formula: Electric energy consumption = Voltage × Current × Time. Within each time window, calculate the corresponding electric energy consumption data based on the average values of current and voltage and generate time series data. Perform curve fitting on the generated electric energy consumption data using linear regression or polynomial regression methods to generate an electric energy consumption change curve. Record the fitting parameters and the goodness of fit of the model (such as the R² value) to ensure the reliability and accuracy of the model. Determine the prediction indicators for hard disk micro-damage, such as abnormal fluctuations in electric energy consumption, continuous high energy consumption, temperature rise, etc. These indicators may indicate potential micro-damage to the hard disk. Collect relevant historical data for comparative analysis. Based on the electric energy consumption change curve and its fluctuation characteristics, establish a micro-damage prediction model. Machine learning methods (such as decision trees, random forests, etc.) can be used for modeling, and the model is trained to identify potential micro-damage signs. Use known failure data to validate the model to ensure that the model can accurately identify micro-damage. Apply the prediction model to analyze the electric energy consumption change data to identify signs of micro-damage to the hard disk. Record each identified sign, including possible causes and impacts. Generate a micro-damage prediction report to ensure that managers can timely understand the health status of the hard disk. Based on the identified signs of micro-damage, develop potential hardware failure prevention and optimization strategies.These strategies may include regular monitoring, maintenance plans, backup solutions, etc., to ensure the security and stability of the hard disk. Set the priorities of preventive strategies, taking into account the implementation costs of each strategy and its impact on the health of the hard disk. After implementing the fault prevention strategies, establish a monitoring mechanism to continuously track the operating status and electrical characteristic changes of the hard disk. Ensure that new problems can be detected and addressed in a timely manner. Collect monitoring data and regularly evaluate the effectiveness of the preventive strategies, record the implementation effects to support subsequent adjustments and optimizations. Store the implementation results of the fault prevention strategies and the monitoring data in a database to ensure data traceability. Generate regular fault prevention reports, record the current health status of the hard disk and the effects of preventive measures, and help management make decisions.
[0106] In this embodiment, step S6 includes the following steps:
[0107] Extract real-time hard disk temperature parameters and hard disk physical vibration parameters according to the built-in temperature and physical vibration sensors;
[0108] Identify the temperature distribution of the real-time hard disk temperature parameters to generate the global temperature distribution characteristics of the hard disk;
[0109] Conduct temperature distribution fluctuation analysis on the global temperature distribution characteristics of the hard disk to obtain the hard disk temperature distribution fluctuation data;
[0110] Conduct multi-period vibration trend analysis on the hard disk physical vibration parameters to extract multi-period vibration trend characteristics;
[0111] Conduct physical disassembly detection of the hard disk based on the hard disk temperature distribution fluctuation data and multi-period vibration trend characteristics. When it is detected that the hard disk is in a physical disassembly condition, perform global data cleaning on the hard disk to obtain a physical disassembly emergency strategy;
[0112] Conduct intelligent collaborative protection optimization according to the abnormal access protection strategy, hardware fault prevention strategy, and physical disassembly emergency strategy, and construct a hard disk intelligent collaborative protection framework.
[0113] In this embodiment, an internal temperature and physical vibration sensor are used to monitor the working state of a solid-state drive (SSD) in real time. Ensure that the sensor can stably and accurately collect temperature and vibration data. Usually, the data collection frequency can be set to once per second to obtain the real-time state. Record the data collected each time, including the timestamp, the current temperature value, and the vibration acceleration (which can be the acceleration of the X, Y, and Z axes), and store this data in a database for subsequent analysis. During the data collection process, regularly verify the collected temperature and vibration data to ensure that the collected data is error-free. For example, the temperature data should be within a reasonable range (such as 0°C to 85°C), and the vibration data should conform to physical significance. Eliminate outliers and noise data to ensure the quality of the data for subsequent analysis. For example, set thresholds to identify and exclude temperature and vibration readings that exceed the normal range. Analyze the collected temperature data to generate the global temperature distribution characteristics of the hard disk. Methods such as histograms or kernel density estimation can be used to show the distribution in different temperature ranges. Calculate statistical characteristics such as the mean, variance, skewness, and kurtosis of the temperature to help understand the shape of the temperature distribution. Conduct a fluctuation analysis of the global temperature distribution characteristics to identify the changes in temperature at different time periods. Time series analysis methods can be used to calculate the temperature fluctuation amplitude for each period. Record the temperature fluctuation data, including the maximum fluctuation amplitude, fluctuation frequency, etc., for subsequent analysis and evaluation of the working stability of the hard disk. Conduct a multi-period analysis of the real-time collected vibration data to extract the vibration trend characteristics at different time periods. This can be done by dividing the data into multiple periods (such as hours, days). Calculate the vibration mean, maximum value, minimum value, and fluctuation range within each period to identify changes in the vibration characteristics. Use time series analysis methods to fit the vibration data for each period to generate a vibration trend curve and extract trend characteristics (such as rising, falling, or stable). Record the vibration trend characteristics, including data such as vibration frequency and vibration intensity, for subsequent potential fault analysis. Based on the hard disk temperature distribution fluctuation data and vibration trend characteristics obtained from the analysis, set the detection criteria for physical disassembly. For example, abnormal temperature fluctuations and increased vibration may indicate that the hard disk is undergoing physical disassembly. Implement algorithms (such as rule-based detection or machine learning models) to monitor the temperature and vibration data in real time and determine whether there is a situation of physical disassembly. Once it is detected that the hard disk is in a physically disassembled state, immediately start the global data cleaning program. The cleaning process should include deleting sensitive data and system configuration data to prevent data leakage. Record the time of data cleaning, the content of cleaning, and the processing results to ensure traceability in the future. Based on the results of physical disassembly detection, formulate a physical disassembly emergency strategy. This should include immediately notifying the management personnel, starting the hardware fault troubleshooting process, and data cleaning measures. Generate an emergency response report, recording the detection results and the measures taken to ensure that all steps are recorded and traceable. Integrate the abnormal access protection strategy, hardware fault prevention strategy, and physical disassembly emergency strategy to build an intelligent collaborative protection framework.Ensure that various strategies can cooperate with each other to jointly enhance the security of the system. Set comprehensive protection standards and evaluation indicators to measure the effectiveness of protection strategies. Establish an intelligent monitoring system to monitor the hard disk status in real time and automatically trigger corresponding protection measures. The system should be able to analyze real-time data, predict potential risks, and respond according to existing strategies. Record the operating status and response of the monitoring system to ensure that subsequent analysis and optimization can be carried out. Regularly evaluate the effectiveness of the intelligent collaborative protection framework and optimize and adjust the strategies according to the analysis results. Collect and analyze the implementation effects of protection measures for continuous improvement.
[0114] In this embodiment, a security protection detection system for a solid-state drive is provided, including:
[0115] A benchmark behavior module, configured to obtain the historical security monitoring logs of the solid-state drive, perform regular fluctuation pattern mining and benchmark behavior evolution, and construct a regular benchmark behavior model;
[0116] An access behavior recognition module, configured to recognize the real-time access behavior data of the solid-state drive; analyze the access method of each behavior storage unit according to the real-time access behavior data, and perform real-time access behavior feature recognition to generate real-time access behavior features;
[0117] A benchmark deviation detection module, configured to perform benchmark access deviation detection on the real-time access behavior features according to the regular benchmark behavior model, and perform access location tracing to locate malicious access storage units;
[0118] An abnormal access protection module, configured to mine the security risk diffusion path of malicious access storage units, and then perform abnormal access protection processing to generate an abnormal access protection strategy;
[0119] A hardware failure prevention module, configured to perform hard disk micro-damage prediction and potential hardware failure prevention optimization according to the historical security monitoring logs, and construct a hardware failure prevention strategy;
[0120] An intelligent collaborative protection module, configured to perform intelligent collaborative protection optimization according to the hardware failure prevention strategy and the abnormal access protection strategy, and construct a hard disk intelligent collaborative protection framework.
[0121] By analyzing the historical security monitoring logs of a solid-state drive, the normal operation mode and behavior trends of the drive can be identified. By extracting the regular fluctuation patterns, the normal working state of the drive can be effectively understood. The construction of the baseline behavior model takes into account the behavior evolution during the long-term use of the drive, which helps to adapt to the gradually changing usage patterns of the solid-state drive, such as workload changes or performance degradation. By continuously updating and evolving the baseline behavior model, it can be ensured that the behavior judgment of the drive always conforms to its current working state, reducing the possibility of false alarms and missed detections. Real-time access behavior data of the drive is obtained, and any abnormal access behavior is identified through the analysis of the access method for each storage unit. This real-time nature enables immediate measures to be taken when a potential malicious attack occurs. By analyzing the access method for each storage unit, it helps to identify abnormal behaviors in different areas inside the drive, avoiding limiting the problem to the overall access pattern and ignoring the details. Generating real-time access behavior characteristics helps to understand the current access load and state changes of the drive, providing a basis for subsequent deviation detection and the formulation of protection strategies. By comparing with the baseline behavior model, the deviation of the access behavior can be accurately identified, and potential malicious attacks or faults can be discovered. This helps to promptly detect attacks or abnormal operations on the drive and avoid serious damage. Deviation detection can not only discover problems but also accurately locate the source of malicious behavior through access location tracing, helping to quickly take targeted protection measures and reducing the risk of data loss and damage. Through precise deviation identification, an efficient alarm mechanism can be provided to notify relevant personnel to take measures in a timely manner to prevent the problem from worsening. By analyzing the paths and patterns of malicious access, possible diffusion paths of security risks can be identified to prevent malicious attacks from spreading to the entire hard drive system. According to the mined risk paths, targeted protection strategies are generated. These strategies can help isolate or repair malicious access and prevent the attack from having a serious impact on the storage units. Through timely protection measures, the risk of data loss, damage, or performance degradation caused by abnormal access can be effectively reduced, protecting the security of the hard drive. By analyzing historical logs, the module can identify early micro-damage signals of the hard drive. This can prevent the hard drive from failing before a major failure occurs and reduce the risk of sudden shutdown. Based on the prediction results, the module can provide suggestions for hard drive fault prevention optimization to improve the operational reliability of the hard drive. By promptly detecting and handling potential hardware problems, the service life of the hard drive can be effectively extended, reducing the frequency of hardware replacement and related costs. Co-optimize the hardware fault prevention and abnormal access protection strategies to avoid conflicts between the two. Through intelligent co-optimization, the hard drive can maximize the protection of data and performance when facing attacks or faults. By integrating different protection strategies, an intelligent and collaborative protection framework is constructed, enabling the system to dynamically adjust protection strategies in real time to cope with different threats and risks.This module can enhance the overall security protection ability, providing comprehensive protection from hardware failures to malicious attacks, and ensuring the high reliability of the hard disk in various complex environments.
[0122] Therefore, in all respects, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Thus, all changes that fall within the meaning and scope of the equivalent elements of the application documents are intended to be encompassed within the present invention.
[0123] As described above, these are only specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1. A security protection detection method for a solid-state drive, characterized in that, The solid-state drive is built-in with temperature and physical vibration sensors, including the following steps: Step S1: Obtain the historical security monitoring logs of the solid-state drive, conduct regular fluctuation pattern mining and benchmark behavior evolution, and construct a regular benchmark behavior model; Step S2: Identify the real-time access behavior data of the solid-state drive; analyze the access method of each behavior storage unit according to the real-time access behavior data, and identify the real-time access behavior characteristics to generate real-time access behavior characteristics; Step S3: Detect the benchmark access deviation of the real-time access behavior characteristics according to the regular benchmark behavior model, and conduct access location tracing to locate the maliciously accessed storage unit; Step S4: Mine the security risk diffusion path of the maliciously accessed storage unit, and then conduct abnormal access protection processing to generate an abnormal access protection strategy; Step S5: Predict the micro-damage of the hard disk and optimize the prevention of potential hardware failures according to the historical security monitoring logs, and construct a hardware failure prevention strategy; Step S6: Conduct intelligent collaborative protection optimization according to the hardware failure prevention strategy and the abnormal access protection strategy, and construct a hard disk intelligent collaborative protection framework; Among them, the specific steps of Step S3 are: Detect the benchmark access deviation of the real-time access behavior characteristics according to the regular benchmark behavior model, and mark the access deviation behavior data; Conduct potential security threat analysis on the access deviation behavior data to generate potential security threat characteristics; Classify the malicious behavior types according to the potential security threat characteristics to obtain the abnormal access malicious behavior types; Trace the malicious access of the abnormal access malicious behavior type, and extract the malicious access behavior cycle chain; Based on the malicious access behavior cycle chain, conduct access location tracing to locate the maliciously accessed storage unit; Among them, the specific steps of Step S4 are: Mine the security risk diffusion path of the maliciously accessed storage unit, and extract multiple security risk diffusion paths; Based on multiple security risk diffusion paths, predict the hard disk risk loss to generate a hard disk risk loss prediction value; Based on the hard disk risk loss prediction value, conduct risk level assessment and adaptive early warning decision-making to generate an adaptive early warning strategy; Predict the hidden access location according to multiple security risk diffusion paths, and mark multiple hidden access storage units; Based on the adaptive early warning strategy, conduct abnormal access protection processing on the maliciously accessed storage unit and multiple hidden access storage units to generate an abnormal access protection strategy.
2. The security protection detection method for the solid-state drive according to claim 1, wherein The specific steps of Step S1 are: Obtain the historical security monitoring logs of the solid-state drive; Conduct regular fluctuation pattern mining on the historical security monitoring logs to generate regular benchmark behavior characteristics; Analyze the hardware interaction status according to the historical security monitoring logs to generate hardware interaction status characteristics; Conduct in-depth mining between storage units on the historical security monitoring logs to generate the storage unit association logic; According to the storage unit association logic and the hardware interaction status characteristics, conduct benchmark behavior evolution on the regular benchmark behavior characteristics to construct a regular benchmark behavior model.
3. The security protection detection method for the solid state drive according to claim 2, characterized in that, The specific steps of conducting regular fluctuation pattern mining on the historical security monitoring logs to generate regular benchmark behavior characteristics are: Perform routine read and write behavior statistics on the historical security monitoring log, and extract all routine read and write behavior monitoring data; Calculate the data transfer rate of the routine read and write behavior monitoring data to generate the read and write behavior data transfer rate; Identify the flash block erase count distribution characteristics of the routine read and write behavior monitoring data; Calculate the execution frequency of the TRIM command based on the routine read and write behavior monitoring data; Mine the normalized fluctuation law of the read and write behavior data transfer rate, the flash block erase count distribution characteristics, and the execution frequency of the TRIM command to generate the normalized benchmark behavior characteristics.
4. The security protection detection method for the solid state drive according to claim 1, wherein The specific steps of step S2 are as follows: Identify the real-time access behavior data of the solid-state drive; Analyze the access method of each behavior storage unit based on the real-time access behavior data to generate the storage unit access method; Calculate the access frequency within a period for the real-time access behavior data to generate the periodic access frequency; Calculate the flash block wear degree based on the real-time access behavior data; Identify the real-time access behavior characteristics based on the storage unit access method, the periodic access frequency, and the flash block wear degree to generate the real-time access behavior characteristics.
5. The security protection detection method for the solid state drive according to claim 1, wherein The specific steps of the abnormal access protection process are as follows: Extract detailed abnormal access information based on the adaptive warning strategy and synchronously upload it to the cloud; The administrator conducts a risk assessment based on the cloud to identify the current abnormal access risk and obtain the abnormal access risk level; The abnormal access risk level includes low level, medium level, and high level; Issue an administrator instruction based on the abnormal access risk level; Parse the administrator instruction to obtain the risk handling assessment level; When the risk handling assessment level is low; Perform in-depth data semantic recognition on maliciously accessed storage units and multiple hidden accessed storage units, and extract the data semantic characteristics of the storage units; Detect sensitive data based on the data semantic characteristics of the storage units and mark the sensitive data; Perform multiple data encryptions on the sensitive data to obtain multiple encrypted data; When the risk handling assessment level is medium; Identify all data interaction channels of maliciously accessed storage units and multiple hidden accessed storage units; Perform regional automatic isolation processing on the data interaction channels; When the risk handling assessment level is high; Lock the solid-state drive.
6. The security protection detection method for a solid-state drive according to claim 1, wherein The specific steps of step S5 are as follows: Calculate the multi-frequency current and voltage parameters of the historical security monitoring log, and extract the current and voltage parameters of multiple time windows; Perform long-running electrical characteristic fluctuation analysis on the current and voltage parameters of each time window to generate electrical characteristic fluctuation characteristics; Fit the power consumption change of the hard disk memory based on the electrical characteristic fluctuation characteristics to construct a power consumption change curve; Predict the micro-damage of the hard disk based on the power consumption change curve to obtain signs of hard disk micro-damage; Prevent and optimize potential hardware failures based on the signs of hard disk micro-damage to construct a hardware failure prevention strategy.
7. The security protection detection method of the solid-state drive according to claim 1, wherein The specific steps of step S6 are as follows: Extract the real-time hard disk temperature parameter and the hard disk physical vibration parameter according to the built-in temperature and physical vibration sensors; Identify the temperature distribution of the real-time hard disk temperature parameter to generate the global hard disk temperature distribution characteristics; Conduct temperature distribution fluctuation analysis on the global temperature distribution characteristics of the hard disk to obtain hard disk temperature distribution fluctuation data; Conduct multi-period vibration trend analysis on the physical vibration parameters of the hard disk to extract multi-period vibration trend characteristics; Conduct physical disassembly detection of the hard disk based on the hard disk temperature distribution fluctuation data and multi-period vibration trend characteristics. When it is detected that the hard disk is in a physical disassembly state, perform global data cleaning processing on the hard disk to obtain a physical disassembly emergency strategy; Conduct intelligent collaborative protection optimization according to the abnormal access protection strategy, hardware failure prevention strategy, and physical disassembly emergency strategy, and construct a hard disk intelligent collaborative protection framework.
8. A security protection detection system for a solid state drive, characterized in that, For executing the security protection detection method of the solid-state drive as described in claim 1, including: A benchmark behavior module for obtaining the historical security monitoring logs of the solid-state drive, conducting regular fluctuation pattern mining and benchmark behavior evolution, and constructing a regular benchmark behavior model; An access behavior recognition module for identifying the real-time access behavior data of the solid-state drive; analyzing the access method of each behavior storage unit according to the real-time access behavior data, and conducting real-time access behavior feature recognition to generate real-time access behavior features; A benchmark deviation detection module for conducting benchmark access deviation detection on the real-time access behavior features according to the regular benchmark behavior model, and conducting access location tracing to locate malicious access storage units; An abnormal access protection module for mining the security risk diffusion path of malicious access storage units, and then conducting abnormal access protection processing to generate an abnormal access protection strategy; A hardware failure prevention module for predicting hard disk micro-damage and optimizing potential hardware failure prevention according to the historical security monitoring logs, and constructing a hardware failure prevention strategy; An intelligent collaborative protection module for conducting intelligent collaborative protection optimization according to the hardware failure prevention strategy and the abnormal access protection strategy, and constructing a hard disk intelligent collaborative protection framework.
Citation Information
Patent Citations
Mechanism to reduce sensitive telemetry data exposure in computing networks
CN116244046A
Security risk protection method and system for mobile solid state disk
CN119089481A