Detection method and device, medium and program product

By detecting the file volume of backup files and generating encryption matrix, using the time series anomaly detection model and classifier, the encryption matrix is ​​directly analyzed, solving the ransomware attack problem that cannot detect universal format backup files in the existing technology, and achieving efficient and accurate virus encryption detection.

CN120234803APending Publication Date: 2025-07-01HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311856164.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Existing ransomware detection methods cannot accurately detect ransomware attacks on backup data, especially backup files for binary structures, because these files lack full file structure information in conventional meaning. The existing methods rely on parsing and cannot effectively detect backup files in general formats.

Method used

By detecting whether the number of files in the backup file increases abnormally, generating an encryption matrix and classifying it, using the time series anomaly detection model and classifier, directly analyzing the encryption matrix to avoid parsing the backup file, and realizing virus encryption detection of common format backup files.

Benefits of technology

Virus encryption detection of common format backup files is realized, detection efficiency and accuracy is improved, backup files that cannot be parsed, and dependence on backup file parsing is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120234803A_ABST
    Figure CN120234803A_ABST
Patent Text Reader

Abstract

The invention provides a detection method and device, a medium and a program product in the field of storage, which are used for carrying out virus encryption detection on a backup file in a general format so as to improve the security of backup storage. The method comprises the steps that a first backup file is detected, a first detection result is obtained, and the first detection result indicates the abnormal condition of the file number of the first backup file; according to the first detection result, abnormal encryption detection is carried out on the first backup file to obtain a second detection result, the abnormal encryption detection is used for carrying out virus encryption detection on a backup file in a general format, and the second detection result indicates the situation that the first backup file is encrypted by the virus.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the storage field, and in particular to a detection method, device, medium, and program product. Background Art

[0002] Ransomware is a type of malicious software that encrypts user data locally on a user's computer using strong encryption algorithms such as AES and RSA, making the data unrecoverable and inaccessible except by paying a ransom to obtain the decryption key, with the aim of extorting money. If the ransom is not paid within a specified time, these file data will be permanently lost. Currently, the attack frequency of ransomware is high, and the economic losses caused are as high as hundreds of billions of dollars. Therefore, in response to the explosive growth of the ransomware industry, in order to reduce data loss and the resulting economic losses, it is urgent to conduct further research on ransomware attack detection.

[0003] Currently, existing ransomware attack detection methods rely to a great extent on structural information such as the head, middle, and tail of files. However, for backup files in binary structure, which are formed by stacking multiple files by backup software into binary structure data without complete file structure information in the conventional sense, the data describing the file stacking rules is stored in a separate encrypted metadata file. Therefore, existing ransomware attack detection methods cannot accurately detect ransomware attacks on backup data and can only detect conventional files. Summary of the Invention

[0004] This application provides a detection method, device, medium, and program product for performing virus encryption detection on backup files in a general format, thereby improving the security of backup storage.

[0005] In view of this, in a first aspect, this application provides a detection method, including: First, obtain a first backup file to be detected, and the first backup file can be a backup file in any format; after obtaining the first backup file, the file quantity of the first backup file can be detected to obtain a first detection result, and the first detection result indicates the abnormal situation of the file quantity of the first backup file; subsequently, according to the first detection result, perform abnormal encryption detection on the first backup file to obtain a second detection result. Among them, the abnormal encryption detection is used to perform virus encryption detection on backup files in a general format, and the obtained second detection result indicates the situation where the first backup file is encrypted by a virus.

[0006] In the embodiments of this application, virus encryption detection can be performed on backup files in a general format according to the detection of the file quantity of the backup files. It can not only detect the backed-up files after parsing, but also detect unparsable backup files, thus no longer relying on the parsing of backup files and having the ability to perform virus encryption detection on the internal data of backup files in a general format.

[0007] In a possible implementation manner, the foregoing detection of the first backup file to obtain a first detection result may include: detecting the first backup file through a file volume anomaly detection model to obtain a first detection result.

[0008] In the embodiments of the present application, the file volume of the backup file can be detected. By detecting whether the file volume of the backup file has an abnormal increase, it can be initially determined whether the backup file may be encrypted and attacked by a virus, providing a basis for subsequent abnormal encryption detection.

[0009] In a possible implementation manner, the foregoing abnormal encryption detection of the first backup file according to the first detection result may include: if the first detection result is that the data volume of the first backup file exceeds a preset value, then performing abnormal encryption detection on each second backup file in the first backup file through a time series anomaly detection model, where the first backup file includes multiple second backup files; if the first detection result is that the data volume of the first backup file does not exceed the preset value, then performing abnormal encryption detection on X second backup files in the first backup file through a time series anomaly detection model, where X is a positive integer.

[0010] In the embodiments of the present application, it is possible to select all or part of the second backup files in the first backup file for abnormal encryption detection according to whether the file volume of the first backup file has an abnormal increase. And when the file volume of the first backup file does not have an abnormal increase, only part of the second backup files can be detected, reducing the file volume to be detected, thereby improving the detection efficiency.

[0011] In a possible implementation manner, the foregoing abnormal encryption detection of the first backup file may include: generating an encryption matrix of the second backup file according to the second backup file, where the encryption matrix includes the encryption status of the second backup file; classifying the encryption matrix through a first classifier to obtain a first classification result, where the first classification result includes a normal encryption matrix and an abnormal encryption matrix; calculating an encryption score of the second backup file according to the first classification result, where the encryption score represents the abnormal situation of the encryption matrix; performing abnormal encryption detection on the time series through a time series anomaly detection model to obtain a second detection result, where the time series includes the encryption scores of multiple second backup files.

[0012] In the embodiments of the present application, the detection of the backup file can be converted into the detection of the encryption matrix of the backup file. Therefore, it is not necessary to first parse the backup file and then detect the parsed file. Abnormal encryption detection can be performed on both unparsable and parsable backup files, and it no longer depends on the parsing of the backup file, thereby realizing abnormal encryption detection of backup files in a general format.

[0013] In a possible implementation, generating an encryption matrix for the foregoing second backup file may include: extracting features from the second backup file based on N sampling points of the second backup file to obtain M-byte feature data for each sampling point, where M and N are positive integers; calculating the eigenvalues of the M-byte feature data, and the eigenvalues represent the encryption condition of the feature data in the second backup file; generating an encryption matrix based on the N eigenvalues, and the encryption matrix includes the N eigenvalues.

[0014] In a possible implementation, generating an encryption matrix based on the foregoing N eigenvalues may include: calculating the multi-dimensional channel values corresponding to the eigenvalues according to a dimensionality increase formula; mapping the second backup file to a space-filling curve to obtain the coordinates of the data of each byte in the second backup file; generating an encryption matrix based on the N multi-dimensional channel values and the coordinates, and each element in the encryption matrix includes the multi-dimensional channel value and the corresponding coordinate.

[0015] In the embodiments of the present application, the eigenvalues can be converted into multi-dimensional channel values according to the dimensionality increase formula, and combined with the space-filling curve, the encryption matrix can be displayed in the form of a picture, so that the encryption condition of the encryption matrix can be displayed more intuitively.

[0016] In a possible implementation, calculating the encryption score of the second backup file based on the foregoing first classification result may include: if the first classification result is an abnormal encryption matrix, setting the value of the encryption score to a specific value; if the first classification result is a normal encryption matrix, dividing the encryption matrix into Y encryption sub-matrices, where Y is a positive integer; calculating the encryption score based on the Y encryption sub-matrices.

[0017] In a possible implementation, calculating the encryption score based on the foregoing Y encryption sub-matrices may include: classifying the Y encryption sub-matrices through a second classifier to obtain Y second classification results; calculating a sub-matrix ratio based on the number of normal encryption sub-matrices and the number of abnormal encryption sub-matrices in the Y second classification results; using the sub-matrix ratio as the encryption score.

[0018] In a possible implementation, detecting the time series to obtain a second detection result may include: combining a plurality of encryption scores to obtain a time series; detecting the time series through a time series anomaly detection model to obtain a second detection result.

[0019] In a second aspect, the present application provides a detection device, including:

[0020] A first detection module, configured to detect a first backup file to obtain a first detection result, where the first detection result indicates the file quantity anomaly condition of the first backup file;

[0021] A second detection module, configured to perform abnormal encryption detection on the first backup file according to the first detection result, so as to obtain a second detection result. The abnormal encryption detection is used to perform virus encryption detection on backup files in a general format, and the second detection result indicates the situation where the first backup file is encrypted by a virus.

[0022] In a possible implementation manner, the above-mentioned first detection module is specifically configured to: detect the first backup file through a file volume abnormal detection model to obtain a first detection result.

[0023] In a possible implementation manner, the above-mentioned second detection module is specifically configured to: if the first detection result is that the data volume of the first backup file exceeds a preset value, perform abnormal encryption detection on each second backup file in the first backup file through a time series abnormal detection model. The first backup file includes multiple second backup files; if the first detection result is that the data volume of the first backup file does not exceed the preset value, perform abnormal encryption detection on X second backup files in the first backup file through a time series abnormal detection model, where X is a positive integer.

[0024] In a possible implementation manner, the above-mentioned second detection module is specifically configured to: generate an encryption matrix of the second backup file according to the second backup file. The encryption matrix includes the encryption status of the second backup file; classify the encryption matrix through a first classifier to obtain a first classification result. The first classification result includes a normal encryption matrix and an abnormal encryption matrix; calculate an encryption score of the second backup file according to the first classification result. The encryption score represents the abnormal situation of the encryption matrix; perform abnormal encryption detection on the time series through a time series abnormal detection model to obtain a second detection result. The time series includes encryption scores of multiple second backup files.

[0025] In a possible implementation manner, the above-mentioned second detection module is specifically configured to: extract features from the second backup file according to N sampling points of the second backup file to obtain M-byte feature data for each sampling point, where M and N are positive integers; calculate the eigenvalue of the M-byte feature data. The eigenvalue represents the encryption situation of the feature data in the second backup file; generate an encryption matrix according to the N eigenvalues. The encryption matrix includes the N eigenvalues.

[0026] In a possible implementation manner, the above-mentioned second detection module is specifically configured to: calculate the multi-dimensional channel value corresponding to the eigenvalue according to the dimensionality increase formula; map the second backup file to a space-filling curve to obtain the coordinates of the data of each byte in the second backup file; generate an encryption matrix according to the N multi-dimensional channel values and the coordinates. Each element in the encryption matrix includes the multi-dimensional channel value and the corresponding coordinate.

[0027] In a possible implementation manner, the above-mentioned second detection module is specifically configured to: if the first classification result is an abnormal encryption matrix, set the value of the encryption score to a specific value; if the first classification result is a normal encryption matrix, divide the encryption matrix into Y encryption sub-matrices, where Y is a positive integer; calculate the encryption score according to the Y encryption sub-matrices.

[0028] In a possible implementation manner, the above-mentioned second detection module is specifically configured to: classify the Y encryption sub-matrices through a second classifier to obtain Y second classification results; calculate a sub-matrix ratio according to the number of normal encryption sub-matrices and the number of abnormal encryption sub-matrices in the Y second classification results; use the sub-matrix ratio as the encryption score.

[0029] In a possible implementation manner, the above-mentioned second detection module is specifically configured to: combine multiple encryption scores to obtain a time series; detect the time series through a time series anomaly detection model to obtain a second detection result.

[0030] In a third aspect, the present application provides a detection device, which includes: a processor, a memory, an input / output device, and a bus; computer instructions are stored in the memory; when the processor executes the computer instructions in the memory, the computer instructions are stored in the memory; when the processor executes the computer instructions in the memory, it is used to implement any implementation manner in the first aspect.

[0031] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium. Computer instructions are stored in the computer-readable storage medium; when the computer instructions run on a computer, the computer is caused to execute the method described in the possible implementation manner in the first aspect.

[0032] In a fifth aspect, an embodiment of the present application provides a computer program product. The computer program product includes a computer program or instructions, and when the computer program or instructions run on a computer, the computer is caused to execute the method described in the possible implementation manner in the first aspect. Description of the Drawings

[0033] Figure 1 It is a framework diagram of a backup storage system provided by the present application;

[0034] Figure 2 It is a process framework diagram for detecting a backup file in a general format;

[0035] Figure 3 It is a schematic flowchart of a detection method provided by the present application;

[0036] Figure 4 It is a schematic flowchart for detecting abnormal encryption of a backup file;

[0037] Figure 5 Flow schematic diagram of an abnormal encryption detection method provided for this application;

[0038] Figure 6 Flow schematic diagram for generating an encryption matrix based on a backup file;

[0039] Figure 7 Flow schematic diagram for generating an encryption matrix based on the encryption matrix and filling rules;

[0040] Figure 8 Structural schematic diagram of a detection device provided for this application;

[0041] Figure 9 Structural schematic diagram of another detection device provided for this application. Detailed implementation manners

[0042] Next, the technical solutions in the embodiments of this application will be described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope protected by this application.

[0043] Next, the backup storage system framework on which this application is based will be introduced.

[0044] Refer to Figure 1 , this application provides a backup storage system 100. The backup storage system 100 includes a controller 110 and a storage disk 120. The controller 110 includes a reading module 111 and a backup file ransomware detection framework 112. The reading module 111 in the controller 110 can obtain a backup file in a general format from the storage disk 120 and transmit the obtained backup file in the general format to the backup file ransomware detection framework 112. The backup file ransomware detection framework 112 can perform ransomware encryption detection on the backup file or other virus encryption detection on the backup file, and no specific limitation is made.

[0045] It should be noted that in actual applications, the backup file in the general format obtained by the reading module 111 may not necessarily be obtained from the storage disk 120, and it may also be obtained from a database or other storage devices. The above description should not be used as a limitation to the embodiments of this application.

[0046] It is worth noting that the attached Figure 1 is only a schematic diagram of a system architecture provided by the embodiments of this application. The positional relationships between the devices, components, modules, etc. shown in the figure do not constitute any limitation. For example, in Figure 1Among them, the reading module 111 is an internal module relative to the controller 110. In other cases, the reading module 111 can also be placed outside the controller 110.

[0047] Based on the above system framework, the flowchart for detecting backup files in a general format will be introduced below.

[0048] Figure 2 It is a flowchart for detecting backup files in a general format. This flowchart includes an abnormal detection module for the quantity of backup files and an abnormal detection module for internal encryption of backups. The abnormal detection module for the quantity of backup files is used to detect whether there is an abnormal increase in the quantity of backup files. According to the detection result obtained by the abnormal detection module for the quantity of backup files, further detection for abnormal encryption of the internal data of the backup file is carried out. If there is no abnormal increase in the quantity of the backup file, the abnormal detection module for internal encryption of backups can detect some backup files; otherwise, the abnormal detection module for internal encryption of backups can detect all backup files to obtain a detection result, and this detection result includes that the backup file is normal and the backup file is abnormal.

[0049] Among them, a normal backup file means that the backup file has not been encrypted and attacked by a virus, and an abnormal backup file means that the backup file has been encrypted and attacked by a virus. The abnormal detection module for internal encryption of backups can also be divided into format-aware detection and format-unaware detection. Format-aware detection is to detect abnormal encryption of resolvable backup files, and format-unaware detection is to detect abnormal encryption of unresolvable backup files. The abnormal detection module for internal encryption of backups can detect both resolvable backup files and unresolvable backup files, so as to realize the detection of backup files in a general format.

[0050] Existing encryption detection methods mainly rely on structural information such as the head, middle, and tail of files. However, the backup file of a binary structure is binary structure data formed by stacking multiple files, without complete file information of conventional significance, and the data describing the file stacking rule is stored in a separately encrypted metadata file. Therefore, existing encryption detection methods cannot directly and accurately detect backup files of binary structures and need to rely on the parsing of backup files. By restoring the backup file to the original data and then performing encryption detection on the original data.

[0051] To solve the existing problems, this application proposes a detection method that no longer relies on the parsing of backup files and can perform abnormal encryption detection on backup files in a general format.

[0052] Next, in combination with the foregoing system architecture and flowchart, the method flow provided by this application will be introduced.

[0053] Refer to Figure 3, The flow diagram of a detection method provided by this application is as follows.

[0054] 301. Obtain the first backup file;

[0055] Before detecting the first backup file, one or more first backup files can be obtained first. The first backup file can be obtained from the backup storage system or from the database. The specific method is not limited here.

[0056] 302. Detect the first backup file to obtain the first detection result;

[0057] After obtaining one or more first backup files, the file size of the first backup file can be detected, and the first detection result is used to preliminarily determine whether the first backup file has been encrypted and attacked by a virus.

[0058] Generally, when a virus attacks a backup file, the virus will copy one or more encrypted backup files, resulting in an abnormal increase in the number of backup files. It can be preliminarily determined whether the backup file has been encrypted and attacked by a virus by detecting whether the number of backup files has increased abnormally. And according to the detection result of the file size of the backup file, abnormal encryption detection can be further performed on the backup file to avoid performing abnormal encryption detection on all backup files each time, thereby reducing the detection cost.

[0059] Among them, the data size of the first backup file can be detected by a file size anomaly detection model to determine whether the file size of the first backup file has increased sharply, and the first detection result is obtained. The file size anomaly detection model can be a model based on machine learning, such as a deep learning model based on t-distribution learning or a neural network model. The specific method is not limited here.

[0060] In addition, the first detection result can also be obtained by analyzing the temporal characteristics of the first backup file. Since multiple backup files will be backed up during a virus attack, resulting in changes in the temporal characteristics of the backup files, the temporal characteristics of the first backup file can be analyzed to determine whether the file size of the backup file is abnormal.

[0061] 303. According to the first detection result, perform abnormal encryption detection on the first backup file to obtain the second detection result.

[0062] After preliminarily detecting the first backup file, abnormal encryption detection can be further performed on the first backup file according to the first detection result. This abnormal encryption detection can perform virus encryption detection on backup files in a general format, and the second detection result indicates the situation of the first backup file being encrypted by a virus.

[0063] Among them, the virus that encrypts the backup file can be a ransomware virus or other viruses that maliciously encrypt files. Specifically, it is not limited here.

[0064] Optionally, when the first detection result is that the data volume of the first backup file exceeds the preset value, abnormal encryption detection can be performed on each second backup file in the first backup file through a time series anomaly detection model, where the first backup file includes multiple second backup files. When the first detection result is that the data volume of the first backup file does not exceed the preset value, abnormal encryption detection can be performed on X second backup files in the first backup file. Usually, the value of X is less than the total number of second backup files.

[0065] In the embodiment of the present application, the number of files for abnormal encryption detection of the backup file can be selected according to the preliminary detection result of the first backup file. When the preliminary detection result of the first backup file is that the file volume of the first backup file is normal, abnormal encryption detection can be performed only on some second backup files in the first backup file, thereby reducing the workload of abnormal encryption detection and improving the detection efficiency.

[0066] Taking the analysis using t-distribution learning as an example, t-distribution learning can be used to analyze the file volume size of historical backup files, and the confidence interval of the average file volume size of historical backup files. If the file volume size of the first backup file is within the confidence interval, it is preliminarily determined that the file volume of the first backup file is normal, and 50 second backup files in the first backup file can be extracted for abnormal encryption detection. The first backup file includes multiple second backup files; otherwise, it is preliminarily determined that the file volume of the first backup file is abnormal, and abnormal encryption detection can be performed on each second backup file in the first backup file.

[0067] Optionally, abnormal encryption detection is performed on each second backup file or X second backup files in the first backup file. An encryption matrix of the second backup file can be generated according to the second backup file, the encryption score of the encryption matrix is calculated, multiple encryption scores are combined to obtain a time series, and abnormal encryption detection is performed on the time series to obtain a second detection result. The schematic flow diagram of abnormal encryption detection of the backup file is as Figure 4 shown.

[0068] Among them, the encryption matrix is a matrix generated according to the characteristic data of the second backup file. By calculating the eigenvalues of the characteristic data, the eigenvalues are used to indicate the encryption state of the second backup file. The encryption matrix includes multiple eigenvalues, that is, it includes the encryption state of the second backup file. Therefore, the abnormal encryption detection result of the second backup file can be obtained by analyzing the encryption matrix.

[0069] Specifically, the encryption matrix can be classified by a first classifier to obtain a first classification result, which includes a normal encryption matrix and an abnormal encryption matrix; according to the first classification result, the encryption score of the encryption matrix is calculated. A time series anomaly detection model can be used to perform anomaly encryption detection on the time series to obtain a second detection result.

[0070] Among them, the time series anomaly detection model can analyze the time series by using the isolation forest anomaly detection algorithm, and can also use various models based on machine learning, such as the K-means clustering algorithm, support vector machine, long short-term memory network or recurrent neural network, etc. Specifically, it is not limited here.

[0071] The calculation of the encryption score of the encryption matrix can be obtained by a preliminary judgment of the encryption matrix. According to the first classification result, the encryption score of the abnormal encryption matrix in the encryption matrix is set to a specific value, such as set to 1 or other values; for the normal encryption matrix in the encryption matrix, the normal encryption matrix can be further divided into Y encryption sub-matrices, and the Y encryption sub-matrices are classified by a second classifier to obtain a second classification result. According to the number of normal encryption matrices and the number of abnormal encryption matrices in the second classification result, the abnormal sub-matrix ratio of the normal encryption matrix is calculated, and this abnormal sub-matrix ratio is used as the encryption score.

[0072] In the embodiment of the present application, the file size of the first backup file can be detected. According to the detection result, all or part of the second backup files in the first backup file are selected for anomaly encryption detection, so as to determine whether the first backup file has been encrypted and attacked by a virus. This anomaly encryption detection method can realize the detection of backup files in a general format and no longer depends on the parsing of backup files. In addition, through the method of layer-by-layer detection, when the file size of the first backup file does not increase abnormally, only part of the second backup files in the first backup file need to be subjected to anomaly encryption detection, reducing the workload of anomaly encryption detection, thereby improving the detection efficiency.

[0073] After detecting the first backup file, according to the first detection result, all or part of the second backup files in the first backup file will be subjected to anomaly encryption detection. Hereinafter, the anomaly encryption detection of one or more second backup files will be taken as an example for introduction.

[0074] Refer to Figure 5 , the flowchart of an anomaly encryption detection method provided by the present application is as follows.

[0075] 501. Generate an encryption matrix according to the second backup file;

[0076] When performing anomaly encryption detection on the second backup file in the first backup file, an encryption matrix can be generated based on the second backup file, and the encryption matrix includes the encryption status of the second backup file.

[0077] Optionally, the second backup file can be regarded as a line in a one-dimensional space. According to the length of the second backup file, N (which can also be said to be n*m, where N = n*m) sampling points can be selected at equal intervals or random intervals. Here, n and m represent the number of rows and columns of the encryption matrix of the second backup file respectively. Based on the obtained n*m sampling points, feature extraction is performed on the second backup file to obtain M-byte feature data for each sampling point.

[0078] Optionally, based on the obtained feature data, the eigenvalue of the M-byte feature data can be calculated, and this eigenvalue represents the encryption situation of the feature data in the second backup file.

[0079] Optionally, based on the n*m eigenvalues, an encryption matrix can be generated, and this encryption matrix includes the n*m eigenvalues.

[0080] Exemplarily, for each sampling point, the M-byte data around each sampling point can be selected as the feature data. For example, the 5-byte data before and after the sampling point can be selected as the feature data, or the 4-byte data before the sampling point and the 6-byte data after the sampling point can be selected as the feature data. Specifically, it is not limited here. After obtaining the M-byte feature data, the eigenvalue of this M-byte data can be calculated. This eigenvalue can be the entropy value of the M-byte data, or the p-value of the chi-square test. Specifically, it is not limited here. Both the entropy value and the p-value of the chi-square test can represent the degree of chaos of the system, that is, they can represent the encryption degree of the second backup file.

[0081] Optionally, when generating an encryption matrix based on the n*m eigenvalues, the obtained eigenvalues can be converted into multi-dimensional channel values according to the dimensionality increase formula. The multi-dimensional channel values can be RGB channel values, or four-dimensional or five-dimensional channel values. Specifically, it is not limited here. And the second backup file can be mapped to a space-filling curve to obtain the coordinates of each byte of data in the second backup file. Based on the obtained multi-dimensional channel values and the coordinates of each byte of data, an encryption matrix is generated, and each element in the encryption matrix includes the corresponding multi-dimensional channel value and the corresponding coordinate.

[0082] Among them, each byte in the second backup file is mapped to a two-dimensional space according to the filling rule, and points that are close in position in the one-dimensional space are also close in position in the space-filling curve in the two-dimensional space. The schematic flow chart of generating an encryption matrix based on the backup file is as Figure 6 shown, and the schematic flow chart of generating an encryption matrix according to the length and width of the encryption matrix and the filling rule is as Figure 7as shown

[0083] In the embodiment of the present application, by converting the obtained eigenvalue into a multi-dimensional channel value and mapping the backup file to a space-filling curve, the encryption matrix is presented in the form of a picture, which can more intuitively display the encryption state of the backup file.

[0084] 502. Classify the encryption matrix through a first classifier to obtain a first classification result;

[0085] After obtaining the encryption matrix, the encryption matrix can be classified according to the classifier to obtain the classification result of the encryption matrix, so that the encryption score of the encryption matrix can be calculated according to the classification result subsequently.

[0086] Optionally, the encryption matrix can be classified through a first classifier to obtain a first classification result, and the first classification result includes a normal encryption matrix and an abnormal encryption matrix. By initially classifying the encryption matrix through the first classifier, the abnormal encryption matrix can be directly screened out, reducing the number of encrypted sub-matrices of the encryption matrix that need to be classified subsequently, thereby improving the detection efficiency.

[0087] Optionally, according to the first classification result, the normal encryption matrix can be divided into Y encrypted sub-matrices, and the Y encrypted sub-matrices are further classified through a second classifier to obtain a second classification result.

[0088] 503. Calculate the encryption score of the encryption matrix according to the first classification result;

[0089] After obtaining the classification result of the encryption matrix, the encryption score of the encryption matrix can be calculated according to the classification result, and the encryption score represents the encryption situation of the encryption matrix.

[0090] Optionally, according to the first classification result, the encryption score of the abnormal encryption matrix can be set to a specific value, which can be 1 or other specific numerical values. Specifically, it is not limited here.

[0091] Optionally, for the normal encryption matrix, according to the number y1 of normal encrypted sub-matrices and the number y2 of abnormal encrypted sub-matrices in the second classification result, the sub-matrix ratio λ can be calculated, and the sub-matrix ratio λ is used as the encryption score of the normal encryption matrix. The sub-matrix ratio can be the abnormal sub-matrix ratio or the normal sub-matrix ratio. Specifically, it is not limited here. If it is the abnormal sub-matrix ratio, the formula λ = Y2 / Y is satisfied. If it is the normal sub-matrix ratio, the formula λ = Y1 / Y is satisfied.

[0092] 504. Perform abnormal encryption detection on the time series through a time series anomaly detection model to obtain a second detection result.

[0093] After obtaining the encryption scores of the encryption matrices, the encryption scores of multiple second backup files can be combined to obtain a time series. An anomaly encryption detection is performed on the time series through a time series anomaly detection model to obtain a second detection result, which indicates the situation where the second backup file is encrypted by a virus.

[0094] Generally, when there are compressed files in the backup files, when classifying through the first classifier, the obtained first classification result is a normal encryption matrix. However, when classifying the encrypted sub-matrices through the second classifier, the compressed files may be classified as abnormal encrypted sub-matrices, thus affecting the encryption scores of the normal encryption matrix. Therefore, a time series anomaly detection model can be used to comprehensively analyze the encryption scores of the backup files. According to the analysis result, that is, the second detection result, it can be determined whether the backup file has been attacked by a ransomware virus.

[0095] In the embodiments of the present application, the detection of the backup file can be converted into the detection of the encryption matrix, so that it is no longer necessary to rely on the parsing of the backup file, and abnormal encryption detection can be performed on backup files in a general format. Among them, the feature data in the second backup file can be extracted, and the eigenvalues of multiple feature data can be calculated. According to the eigenvalues and the space filling curve, an encryption matrix is generated. Subsequently, the encryption score of the encryption matrix can be calculated, and multiple encryption scores can be combined to obtain a time series. An anomaly encryption detection is performed on the time series through a time series anomaly detection model, so as to obtain the detection result of whether the second backup file has been encrypted and attacked by a ransomware virus.

[0096] The foregoing introduced the method flow provided by the present application. Next, based on the foregoing method flow, the device provided by the present application will be introduced.

[0097] Refer to Figure 8 , the structural schematic diagram of a detection device provided by the present application, includes:

[0098] The first detection module 801 is configured to detect the first backup file to obtain a first detection result, and the first detection result indicates the abnormal situation of the number of files in the first backup file;

[0099] The second detection module 802 is configured to perform abnormal encryption detection on the first backup file according to the first detection result to obtain a second detection result. The abnormal encryption detection is used to perform virus encryption detection on backup files in a general format, and the second detection result indicates the situation where the first backup file is encrypted by a virus.

[0100] In a possible implementation manner, the foregoing first detection module 801 is specifically configured to: detect the first backup file through a file quantity anomaly detection model to obtain a first detection result.

[0101] In a possible implementation manner, the above-mentioned second detection module 802 is specifically configured to: if the first detection result indicates that the data volume of the first backup file exceeds a preset value, perform abnormal encryption detection on each second backup file in the first backup file through a time series anomaly detection model, where the first backup file includes multiple second backup files; if the first detection result indicates that the data volume of the first backup file does not exceed the preset value, perform abnormal encryption detection on X second backup files in the first backup file through the time series anomaly detection model, and X is a positive integer.

[0102] In a possible implementation manner, the above-mentioned second detection module 802 is specifically configured to: generate an encryption matrix of the second backup file according to the second backup file, where the encryption matrix includes the encryption status of the second backup file; classify the encryption matrix through a first classifier to obtain a first classification result, where the first classification result includes a normal encryption matrix and an abnormal encryption matrix; calculate an encryption score of the second backup file according to the first classification result, and the encryption score represents the abnormal situation of the encryption matrix; perform abnormal encryption detection on the time series through a time series anomaly detection model to obtain a second detection result, where the time series includes the encryption scores of multiple second backup files.

[0103] In a possible implementation manner, the above-mentioned second detection module 802 is specifically configured to: extract features from the second backup file according to N sampling points of the second backup file to obtain M-byte feature data for each sampling point, where M and N are positive integers; calculate the eigenvalue of the M-byte feature data, and the eigenvalue represents the encryption situation of the feature data in the second backup file; generate an encryption matrix according to the N eigenvalues, where the encryption matrix includes the N eigenvalues.

[0104] In a possible implementation manner, the above-mentioned second detection module 802 is specifically configured to: calculate the multi-dimensional channel value corresponding to the eigenvalue according to the dimensionality increase formula; map the second backup file to a space-filling curve to obtain the coordinates of the data of each byte in the second backup file; generate an encryption matrix according to the N multi-dimensional channel values and the coordinates, where each element in the encryption matrix includes the multi-dimensional channel value and the corresponding coordinate.

[0105] In a possible implementation manner, the above-mentioned second detection module 802 is specifically configured to: if the first classification result is an abnormal encryption matrix, set the value of the encryption score to a specific value; if the first classification result is a normal encryption matrix, divide the encryption matrix into Y encryption sub-matrices, where Y is a positive integer; calculate the encryption score according to the Y encryption sub-matrices.

[0106] In a possible implementation manner, the foregoing second detection module 802 is specifically configured to: classify Y encrypted sub-matrices through a second classifier to obtain Y second classification results; calculate a sub-matrix ratio according to the number of normal encrypted sub-matrices and the number of abnormal encrypted sub-matrices in the Y second classification results; and use the sub-matrix ratio as an encryption score.

[0107] In a possible implementation manner, the foregoing second detection module 802 is specifically configured to: combine a plurality of encryption scores to obtain a time series; and detect the time series through a time series anomaly detection model to obtain a second detection result.

[0108] Please refer to Figure 9 , a structural schematic diagram of another detection device provided by this application is described as follows.

[0109] The detection device may include a processor 901 and a memory 902. The processor 901 and the memory 902 are interconnected by a line. Among them, program instructions and data are stored in the memory 902.

[0110] The memory 902 stores the program instructions and data corresponding to the foregoing Figure 3 and Figure 5 steps.

[0111] The processor 901 is configured to execute the method steps executed by the foregoing Figure 3 and Figure 5 model determination device.

[0112] Optionally, the model determination device may further include a transceiver 903 for receiving or sending data.

[0113] In an embodiment of this application, a computer-readable storage medium is further provided. When a program stored in the computer-readable storage medium runs on a computer, the computer is caused to execute the steps in the method described in the foregoing Figure 3 and Figure 5 embodiments.

[0114] In an embodiment of this application, a computer program product is further provided. When the computer program product runs on a computer, the computer is caused to execute the method steps described in the foregoing Figure 3 or Figure 5 embodiments.

[0115] In addition, it should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the attached drawings of the device embodiments provided in this application, the connection relationships between the modules indicate that there is a communication connection between them, which can be specifically implemented as one or more communication buses or signal lines.

[0116] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0117] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0118] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0119] In addition, in each embodiment of this application, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0120] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0121] The terms "first", "second", "third", "fourth", etc. (if any) in the specification, claims, and the above-mentioned drawings of this application are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments described here can be implemented in an order different from that shown or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those clearly listed steps or units, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products, or devices.

[0122] Finally, it should be noted that the above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application.

Claims

1. A detection method, characterized in that, Including: Detecting a first backup file to obtain a first detection result, where the first detection result indicates an abnormal situation of the number of files in the first backup file; According to the first detection result, performing abnormal encryption detection on the first backup file to obtain a second detection result, where the abnormal encryption detection is used to detect virus encryption of a backup file in a general format, and the second detection result indicates the situation of the first backup file being encrypted by the virus.

2. The method according to claim 1, wherein The detecting the first backup file to obtain a first detection result includes: Detecting the first backup file through a file volume abnormal detection model to obtain the first detection result.

3. The method according to any one of claims 1 or 2, characterized in that, The performing abnormal encryption detection on the first backup file according to the first detection result includes: If the first detection result is that the data volume of the first backup file exceeds a preset value, then performing the abnormal encryption detection on each second backup file in the first backup file through a time series abnormal detection model, where the first backup file includes multiple second backup files; If the first detection result is that the data volume of the first backup file does not exceed the preset value, then performing the abnormal encryption detection on X second backup files in the first backup file through the time series abnormal detection model, where X is a positive integer.

4. The method according to claim 3, wherein The performing abnormal encryption detection on the first backup file includes: Generating an encryption matrix of the second backup file according to the second backup file, where the encryption matrix includes the encryption status of the second backup file; Classifying the encryption matrix through a first classifier to obtain a first classification result, where the first classification result includes a normal encryption matrix and an abnormal encryption matrix; Calculating an encryption score of the second backup file according to the first classification result, where the encryption score represents the abnormal situation of the encryption matrix; Performing the abnormal encryption detection on a time series through the time series abnormal detection model to obtain the second detection result, where the time series includes encryption scores of multiple second backup files.

5. The method according to claim 4, wherein The generating the encryption matrix of the second backup file according to the second backup file includes: Extracting features of the second backup file according to N sampling points of the second backup file to obtain M-byte feature data of each sampling point, where M and N are positive integers; Calculating an eigenvalue of the M-byte feature data, where the eigenvalue represents the encryption situation of the feature data in the second backup file; Generating the encryption matrix according to N eigenvalues, where the encryption matrix includes the N eigenvalues.

6. The method according to claim 5, characterized in that, The generating the encryption matrix according to N eigenvalues includes: Calculating a multi-dimensional channel value corresponding to the eigenvalue according to a dimension elevation formula; Mapping the second backup file to a space filling curve to obtain coordinates of data of each byte in the second backup file; Generating the encryption matrix according to N multi-dimensional channel values and the coordinates, where each element in the encryption matrix includes the multi-dimensional channel value and the corresponding coordinate.

7. The method according to any one of claims 4 to 6, characterized in that Calculating the encryption score of the second backup file according to the first classification result includes: If the first classification result is the abnormal encryption matrix, set the value of the encryption score to a specific value; If the first classification result is the normal encryption matrix, divide the encryption matrix into Y encryption sub-matrices, where Y is a positive integer; Calculate the encryption score according to the Y encryption sub-matrices.

8. The method according to claim 7, wherein Calculating the encryption score according to the Y encryption sub-matrices includes: Classify the Y encryption sub-matrices through a second classifier to obtain Y second classification results; Calculate the sub-matrix ratio according to the number of normal encryption sub-matrices and the number of abnormal encryption sub-matrices in the Y second classification results; Use the sub-matrix ratio as the encryption score.

9. According to the method of any one of claims 4 to 8, characterized in that, Detecting the time series to obtain the second detection result includes: Combine multiple encryption scores to obtain the time series; Detect the time series through the time series anomaly detection model to obtain the second detection result.

10. A detection device, characterized in that, Including: A first detection module for detecting a first backup file to obtain a first detection result, where the first detection result indicates the abnormal situation of the file quantity of the first backup file; A second detection module for performing abnormal encryption detection on the first backup file according to the first detection result to obtain a second detection result. The abnormal encryption detection is used for virus encryption detection of backup files in a general format, and the second detection result indicates the situation where the first backup file is encrypted by the virus.

11. The device according to claim 10, wherein Specifically, the first detection module is used for: Detect the first backup file through a file quantity anomaly detection model to obtain the first detection result.

12. The device according to any one of claims 10 or 11, characterized in that, Specifically, the second detection module is used for: If the first detection result is that the data volume of the first backup file exceeds a preset value, perform the abnormal encryption detection on each second backup file in the first backup file through a time series anomaly detection model. The first backup file includes multiple second backup files; If the first detection result is that the data volume of the first backup file does not exceed the preset value, perform the abnormal encryption detection on X second backup files in the first backup file through the time series anomaly detection model, where X is a positive integer.

13. The device according to claim 12, wherein Specifically, the second detection module is used for: Generate an encryption matrix of the second backup file according to the second backup file, where the encryption matrix includes the encryption status of the second backup file; Classify the encryption matrix through a first classifier to obtain a first classification result, where the first classification result includes a normal encryption matrix and an abnormal encryption matrix; Calculate the encryption score of the second backup file according to the first classification result, where the encryption score represents the abnormal situation of the encryption matrix; Perform the abnormal encryption detection on the time series through the time series anomaly detection model to obtain the second detection result, where the time series includes encryption scores of multiple second backup files.

14. The device according to claim 13, wherein Specifically, the second detection module is used for: Extract features from the second backup file according to N sampling points of the second backup file to obtain M-byte feature data for each of the sampling points, where M and N are positive integers; Calculate the eigenvalue of the M-byte feature data, where the eigenvalue represents the encryption situation of the feature data in the second backup file; Generate the encryption matrix according to the N eigenvalues, where the encryption matrix includes the N eigenvalues.

15. The device according to claim 14, characterized in that, The second detection module is specifically configured to: Calculate the multi-dimensional channel value corresponding to the eigenvalue according to the dimensionality increase formula; Map the second backup file to a space-filling curve to obtain the coordinates of the data of each byte in the second backup file; Generate the encryption matrix according to the N multi-dimensional channel values and the coordinates, where each element in the encryption matrix includes the multi-dimensional channel value and the corresponding coordinate.

16. The device according to any one of claims 13 to 15, characterized in that, The second detection module is specifically configured to: If the first classification result is the abnormal encryption matrix, set the value of the encryption score to a specific value; If the first classification result is the normal encryption matrix, divide the encryption matrix into Y encryption sub-matrices, where Y is a positive integer; Calculate the encryption score according to the Y encryption sub-matrices.

17. The device according to claim 16, characterized in that, The second detection module is specifically configured to: Classify the Y encryption sub-matrices through a second classifier to obtain Y second classification results; Calculate the sub-matrix ratio according to the number of normal encryption sub-matrices and the number of abnormal encryption sub-matrices in the Y second classification results; Use the sub-matrix ratio as the encryption score.

18. The device according to any one of claims 13 to 17, characterized in that, The second detection module is specifically configured to: Combine multiple encryption scores to obtain the time series; Detect the time series through the time series anomaly detection model to obtain the second detection result.

19. A detection device, characterized in that, Includes: A processor and a memory, where the processor is coupled to the memory; The memory is used to store programs; The processor is configured to execute the programs in the memory so as to execute the method according to any one of claims 1 to 9.

20. A computer-readable storage medium includes instructions that, when run on a computer, cause the computer to execute the method according to any one of claims 1 to 9.

21. A computer program product containing instructions that, when run on a computer, cause the computer to execute the method according to any one of claims 1 to 9.