Ransomware virus protection system based on file monitoring
Through the ransomware protection system based on file monitoring, the abnormal analysis coefficient is used to identify ransomware-infected files and isolate them, which solves the problem of the inability to accurately monitor ransomware in existing technologies, realizes the function of quickly discovering and clearing ransomware, and protects user data security.
Patent Information
- Application Number
- CN202410379417.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-29
- Publication Date
- 2025-09-30
AI Technical Summary
Existing ransomware protection systems are unable to accurately monitor files in multiple aspects and are unable to accurately and promptly detect ransomware, resulting in the spread of ransomware and adversely affecting user data security.
A ransomware protection system based on file monitoring is adopted. File monitoring instructions and anomaly detection instructions are generated through the virus protection platform. The anomaly detection module, comparison information library, isolation alarm module, file monitoring module and anomaly analysis module are used. Combined with anomaly analysis information such as tolerance value, tampering value, and input value, the anomaly analysis coefficient is calculated to determine whether the file is a ransomware-infected file and isolate it.
It achieves rapid discovery, isolation and removal of ransomware, protects user data security and prevents the spread of the virus.
Smart Images

Figure CN120724433A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of ransomware protection, and in particular to a ransomware protection system based on file monitoring. Background Art
[0002] With the continuous advancement of information technology, malware such as ransomware continues to emerge, posing a serious data security threat to businesses and individual users. Traditional antivirus software typically uses signature matching and other methods to detect viruses. However, ransomware often encrypts and tamper with files to conceal its behavior, making it difficult for traditional antivirus software to effectively identify it. Therefore, it is crucial to develop a protection system that can monitor file system changes in real time and quickly detect, isolate, and remove ransomware.
[0003] The patent application number CN202111458735.5 discloses a method and system for protecting against ransomware, including: S1: when a computer program accesses a file, determine whether the computer program has permission to access the file; if so, end the judgment and return to S1; if not, go to S2; S2: move the process of the computer program into a sandbox program and record the processing behavior of the computer program; S3: determine whether the computer program is a ransomware virus based on the processing behavior; if so, process the file and / or the processing behavior, and then end the judgment; if not, end the judgment. The beneficial effect of this invention is that it solves the problem in the prior art that suspicious computer programs need to be tested in a sandbox environment manually, which has high testing costs and poor real-time performance, thereby realizing the normalized monitoring of ransomware viruses under normal working environments, and better adapting to the enterprise's local area network environment. However, there are still the following shortcomings: it is impossible to accurately monitor files in multiple aspects, and it is impossible to accurately and timely detect ransomware viruses, resulting in the spread of ransomware viruses and adverse effects on user data security. Summary of the Invention
[0004] In order to overcome the above-mentioned technical problems, the purpose of the present invention is to provide a ransomware protection system based on file monitoring, which solves the problem that the existing ransomware protection methods and systems are unable to accurately monitor files in multiple aspects and cannot accurately and timely detect ransomware, resulting in the spread of ransomware and adversely affecting user data security.
[0005] The purpose of the present invention can be achieved through the following technical solutions:
[0006] A ransomware protection system based on file monitoring, comprising:
[0007] The virus protection platform is used to obtain the monitored file i, generate a file monitoring instruction and anomaly detection instruction, and send the anomaly detection instruction to the anomaly detection module and the file monitoring instruction to the file monitoring module; it is also used to obtain abnormal files based on the anomaly analysis coefficient YF i, obtain dangerous suffixes, send the dangerous suffixes to the comparison information library, generate a file transfer instruction, and send the file transfer instruction to the isolation alarm module;
[0008] An anomaly detection module is used to obtain the monitoring suffix after receiving the anomaly detection instruction and send the monitoring suffix to the comparison information library;
[0009] A comparison information base is used to compare the monitored suffix with the stored dangerous suffixes, generate a file quarantine instruction, and send the file quarantine instruction to the quarantine alarm module;
[0010] The isolation alarm module is used to mark the corresponding monitored file i as an infected file after receiving the file isolation instruction and transfer the infected file to the isolated storage space; it is also used to transfer abnormal files to the isolated storage space after receiving the file transfer instruction;
[0011] The file monitoring module is used to obtain the abnormality analysis information of the monitored file i after receiving the file monitoring instruction, and send the abnormality analysis information to the abnormality analysis module; wherein the abnormality analysis information includes the tolerance value RC, the tampering value DC and the read-sink value KS;
[0012] The anomaly analysis module is used to obtain an anomaly analysis coefficient YFi according to the anomaly analysis information, and send the anomaly analysis coefficient YFi to the virus protection platform.
[0013] As a further solution of the present invention: the specific process of the abnormality analysis module obtaining the abnormality analysis coefficient YF i is as follows:
[0014] The tolerance value RC, the tampering value DC and the input value KS are quantified, the values of the tolerance value RC, the tampering value DC and the input value KS are extracted, and substituted into the formula for calculation. According to the formula Obtain the abnormality analysis coefficient YF i, where ε is the preset error adjustment factor, which is set to 1.059, π is a mathematical constant, f1, f2, and f3 are the preset weight factors corresponding to the set tolerance value RC, tampering value DC, and input value KS, respectively. f1, f2, and f3 satisfy f2>f3>f1>2.321, and f1=2.65, f2=3.38, and f3=2.93;
[0015] The abnormality analysis coefficient YFi is sent to the virus protection platform.
[0016] As a further solution of the present invention, the specific process of the virus protection platform generating file monitoring instructions and anomaly detection instructions is as follows:
[0017] Obtain all files in the storage space and mark them as monitoring files i in turn, i = 1, ..., n, n is a positive integer, and generate file monitoring instructions and anomaly detection instructions at the same time, and send the anomaly detection instructions to the anomaly detection module and the file monitoring instructions to the file monitoring module.
[0018] As a further solution of the present invention, the specific process of the anomaly detection module obtaining the monitoring suffix is as follows:
[0019] After receiving the anomaly detection instruction, the monitoring file i is detected for anomalies, the suffix name of the monitoring file i is obtained, and it is marked as the monitoring suffix, and the monitoring suffix is sent to the comparison information library.
[0020] As a further solution of the present invention, the specific process of generating the file isolation instruction by comparing the information library is as follows:
[0021] The monitored suffix is compared with the stored dangerous suffixes. If there is a dangerous suffix that is the same as the monitored suffix, a file isolation instruction is generated and sent to the isolation alarm module.
[0022] As a further solution of the present invention, the specific process of the isolation alarm module obtaining the infected file is as follows:
[0023] After receiving the file isolation instruction, the corresponding monitoring file i will be marked as an infected file, and the infected file will be displayed as "infected" to form a prompt alarm, and the infected file will be transferred to the isolated storage space and stored in the "infected file" folder.
[0024] As a further solution of the present invention, the specific process of the file monitoring module obtaining the tolerance value RC is as follows:
[0025] After receiving the file monitoring instruction, the monitoring file i is monitored, the file size of the monitoring file i at the last active storage moment and the file size at the current moment are obtained, the difference between the two is obtained, and it is marked as the tolerance value RC; active storage means the operation process of storing after receiving the keyboard operation instruction or the mouse operation instruction.
[0026] As a further solution of the present invention: the specific process of the file monitoring module obtaining the tampering value DC is as follows:
[0027] Obtain the number of passive storage times and the number of modifications of monitoring file i during the time period between the last active storage time of monitoring file i and the current time, and mark them as stored value BC and modified value XG respectively. Quantify the stored value BC and modified value XG, extract the values of stored value BC and modified value XG, and substitute them into the formula for calculation. The tampered value DC is obtained, where c1 and c2 are the preset proportional coefficients corresponding to the set stored value BC and the modified value XG respectively, c1 and c2 satisfy c1+c2=1, 0<c1<c2<1, and c1=0.36 and c2=0.64 are taken; passive storage means that no keyboard operation instruction or mouse operation instruction is received, but the storage operation process is still performed.
[0028] As a further solution of the present invention, the specific process of the file monitoring module obtaining the input value KS is as follows:
[0029] Obtain the number of times the monitoring file i has been viewed and the number of times the file has been transferred during the time period between the last active storage time of the monitoring file i and the current time, and mark them as the viewing value CK and the transfer value CS respectively. Quantify the viewing value CK and the transfer value CS, extract the values of the viewing value CK and the transfer value CS, and substitute them into the formula for calculation. According to the formula The viewing and transmission value KS is obtained, where s1 and s2 are the preset proportional coefficients corresponding to the set viewing value CK and transmission value CS respectively, s1 and s2 satisfy s1+s2=1, 0<s1<s2<1, and s1=0.41 and s2=0.59.
[0030] As a further solution of the present invention: the specific process of the virus protection platform generating the file transfer instruction is as follows:
[0031] Compare the abnormality analysis coefficient YFi with the preset abnormality analysis threshold YFy:
[0032] If the abnormality analysis coefficient YFi≥the abnormality analysis threshold YFy, the monitoring file i corresponding to the abnormality analysis coefficient YFi is marked as an abnormal file, and the suffix name of the abnormal file is obtained and marked as a dangerous suffix. The dangerous suffix is sent to the comparison information library, and a file transfer instruction is generated at the same time, and the file transfer instruction is sent to the isolation alarm module.
[0033] As a further solution of the present invention: the working method of the ransomware protection system based on file monitoring includes the following steps:
[0034] Step 1: The virus protection platform obtains the monitoring file i, generates a file monitoring instruction and an anomaly detection instruction, and sends the anomaly detection instruction to the anomaly detection module and the file monitoring instruction to the file monitoring module;
[0035] Step 2: After receiving the anomaly detection instruction, the anomaly detection module performs an anomaly detection on the monitoring file i, obtains the monitoring suffix, and sends the monitoring suffix to the comparison information library;
[0036] Step 3: The comparison information database compares the monitored suffix with the stored dangerous suffixes, generates a file quarantine instruction, and sends the file quarantine instruction to the quarantine alarm module;
[0037] Step 4: After receiving the file quarantine instruction, the quarantine alarm module marks the corresponding monitored file i as an infected file and transfers the infected file to the isolated storage space;
[0038] Step 5: After receiving the file monitoring instruction, the file monitoring module monitors the monitoring file i, obtains the abnormality analysis information of the monitoring file i, wherein the abnormality analysis information includes the tolerance value RC, the tampering value DC, and the read-sink value KS, and sends the abnormality analysis information to the abnormality analysis module;
[0039] Step 6: The anomaly analysis module obtains the anomaly analysis coefficient YF i based on the anomaly analysis information, and sends the anomaly analysis coefficient YF i to the virus protection platform;
[0040] Step 7: The virus protection platform obtains abnormal files based on the abnormal analysis coefficient YF i, obtains dangerous suffixes, sends the dangerous suffixes to the comparison information library, generates a file transfer instruction, and sends the file transfer instruction to the isolation alarm module;
[0041] Step 8: After receiving the file transfer instruction, the isolation alarm module transfers the abnormal file to the isolated storage space.
[0042] Beneficial effects of the present invention:
[0043] The present invention provides a ransomware protection system based on file monitoring. The ransomware protection system first compares the monitored file with a large number of known dangerous suffixes stored in a comparison information library, and can directly determine whether the monitored file is a ransomware-infected file. Then, data collection and analysis are performed on other monitored files to obtain abnormality analysis information. The abnormality analysis coefficient obtained based on the abnormality analysis information can comprehensively measure the abnormality degree of the monitored file, and the larger the abnormality analysis coefficient, the higher the abnormality degree. The abnormality analysis coefficient is used to determine whether there is ransomware behavior. If the abnormality analysis coefficient is large, it is determined that there is ransomware behavior, and then an isolation module is triggered to isolate the infected file to prevent the spread of the virus.
[0044] The file monitoring-based ransomware protection system of the present invention monitors file system changes in real time, identifies ransomware behavior patterns, and achieves the functions of quickly discovering, isolating, and clearing ransomware, effectively protecting user data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The present invention will be further described below with reference to the accompanying drawings.
[0046] Figure 1 This is a principle block diagram of a ransomware protection system based on file monitoring in the present invention;
[0047] Figure 2 This is a flowchart of a working method of a ransomware protection system based on file monitoring in the present invention. DETAILED DESCRIPTION
[0048] The following will be combined with the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.
[0049] Example 1:
[0050] See also Figure 1 As shown, this embodiment is a ransomware protection system based on file monitoring, which includes the following modules: virus protection platform, anomaly detection module, comparison information library, isolation alarm module, file monitoring module and anomaly analysis module;
[0051] The virus protection platform is used to obtain the monitoring file i, generate a file monitoring instruction and an anomaly detection instruction, send the anomaly detection instruction to the anomaly detection module, and send the file monitoring instruction to the file monitoring module; it is also used to obtain abnormal files based on the anomaly analysis coefficient YF i, obtain dangerous suffixes, send the dangerous suffixes to the comparison information library, generate a file transfer instruction, and send the file transfer instruction to the isolation alarm module;
[0052] The anomaly detection module is used to obtain the monitoring suffix after receiving the anomaly detection instruction, and send the monitoring suffix to the comparison information library;
[0053] The comparison information library is used to compare the monitored suffix with the stored dangerous suffixes, generate a file isolation instruction, and send the file isolation instruction to the isolation alarm module;
[0054] The isolation alarm module is used to mark the corresponding monitored file i as an infected file after receiving the file isolation instruction and transfer the infected file to the isolated storage space; it is also used to transfer the abnormal file to the isolated storage space after receiving the file transfer instruction;
[0055] The file monitoring module is used to obtain abnormal analysis information of the monitored file i after receiving the file monitoring instruction, and send the abnormal analysis information to the abnormal analysis module; wherein the abnormal analysis information includes the tolerance value RC, the tampering value DC and the read-out value KS;
[0056] The anomaly analysis module is used to obtain an anomaly analysis coefficient YF i according to the anomaly analysis information, and send the anomaly analysis coefficient YF i to the virus protection platform.
[0057] Example 2:
[0058] See also Figure 2 As shown, this embodiment is a working method of a ransomware protection system based on file monitoring, comprising the following steps:
[0059] Step 1: The virus protection platform obtains the monitoring file i, generates a file monitoring instruction and an anomaly detection instruction, and sends the anomaly detection instruction to the anomaly detection module and the file monitoring instruction to the file monitoring module;
[0060] Step 2: After receiving the anomaly detection instruction, the anomaly detection module performs an anomaly detection on the monitoring file i, obtains the monitoring suffix, and sends the monitoring suffix to the comparison information library;
[0061] Step 3: The comparison information database compares the monitored suffix with the stored dangerous suffixes, generates a file quarantine instruction, and sends the file quarantine instruction to the quarantine alarm module;
[0062] Step 4: After receiving the file quarantine instruction, the quarantine alarm module marks the corresponding monitored file i as an infected file and transfers the infected file to the isolated storage space;
[0063] Step 5: After receiving the file monitoring instruction, the file monitoring module monitors the monitoring file i, obtains the abnormality analysis information of the monitoring file i, wherein the abnormality analysis information includes the tolerance value RC, the tampering value DC, and the read-sink value KS, and sends the abnormality analysis information to the abnormality analysis module;
[0064] Step 6: The anomaly analysis module obtains the anomaly analysis coefficient YF i based on the anomaly analysis information, and sends the anomaly analysis coefficient YF i to the virus protection platform;
[0065] Step 7: The virus protection platform obtains abnormal files based on the abnormal analysis coefficient YF i, obtains dangerous suffixes, sends the dangerous suffixes to the comparison information library, generates a file transfer instruction, and sends the file transfer instruction to the isolation alarm module;
[0066] Step 8: After receiving the file transfer instruction, the isolation alarm module transfers the abnormal file to the isolated storage space.
[0067] Example 3:
[0068] Based on any of the above embodiments, embodiment 3 of the present invention is a virus protection platform, which has two functions:
[0069] One of its functions is to generate file monitoring instructions and anomaly detection instructions. The specific process is as follows:
[0070] The virus protection platform obtains all files in the storage space and marks them as monitoring files i, i = 1, ..., n, where n is a positive integer. At the same time, it generates file monitoring instructions and anomaly detection instructions, and sends the anomaly detection instructions to the anomaly detection module and the file monitoring instructions to the file monitoring module;
[0071] The second function is to generate file transfer instructions. The specific process is as follows:
[0072] The virus protection platform compares the anomaly analysis coefficient YF i with the preset anomaly analysis threshold YFy:
[0073] If the abnormality analysis coefficient YFi≥the abnormality analysis threshold YFy, the monitoring file i corresponding to the abnormality analysis coefficient YFi is marked as an abnormal file, and the suffix name of the abnormal file is obtained and marked as a dangerous suffix. The dangerous suffix is sent to the comparison information library, and a file transfer instruction is generated at the same time, and the file transfer instruction is sent to the isolation alarm module.
[0074] Example 4:
[0075] Based on any of the above embodiments, embodiment 4 of the present invention is an anomaly detection module. The function of the anomaly detection module is to obtain a monitoring suffix. The specific process is as follows:
[0076] After receiving the anomaly detection instruction, the anomaly detection module performs an anomaly detection on the monitoring file i, obtains the suffix name of the monitoring file i, marks it as the monitoring suffix, and sends the monitoring suffix to the comparison information library.
[0077] Example 5:
[0078] Based on any of the above embodiments, embodiment 5 of the present invention is a comparison information library. The function of the comparison information library is to generate a file isolation instruction. The specific process is as follows:
[0079] The comparison information library compares the monitored suffix with the stored dangerous suffixes. If there is a dangerous suffix that is the same as the monitored suffix, a file isolation instruction is generated and sent to the isolation alarm module.
[0080] Example 6:
[0081] Based on any of the above embodiments, embodiment 6 of the present invention is an isolation alarm module, which has two functions:
[0082] One of its functions is to transfer infected files to isolated storage space. The specific process is as follows:
[0083] After receiving the file quarantine instruction, the isolation alarm module marks the corresponding monitored file i as an infected file, displays the word "infected" on the infected file, generates a prompt alarm, and transfers the infected file to the isolated storage space and stores it in the "infected file" folder;
[0084] The second function is to transfer abnormal files to isolated storage space. The specific process is as follows:
[0085] After receiving the file transfer instruction, the isolation alarm module transfers the abnormal file to the isolated storage space and stores it in the "abnormal file" folder.
[0086] Example 7:
[0087] Based on any of the above embodiments, embodiment 7 of the present invention is a file monitoring module. The function of the file monitoring module is to obtain abnormality analysis information, wherein the abnormality analysis information includes a tolerance value RC, a tampering value DC, and a checksum value KS. The specific process is as follows:
[0088] After receiving the file monitoring instruction, the file monitoring module monitors the monitored file i, obtains the file size of the monitored file i at the last active storage time and the file size at the current time, obtains the difference between the two, and marks it as the tolerance value RC; active storage refers to the operation process of receiving a keyboard operation instruction or a mouse operation instruction to perform a storage operation;
[0089] The file monitoring module obtains the number of passive storage times and the number of modification times of the monitoring file i in the time period between the last active storage time of the monitoring file i and the current time, and marks them as the stored value BC and the modified value XG respectively, quantifies the stored value BC and the modified value XG, extracts the values of the stored value BC and the modified value XG, and substitutes them into the formula for calculation. Obtain the tampered value DC, where c1 and c2 are the preset proportional coefficients corresponding to the stored value BC and the modified value XG, respectively. c1 and c2 satisfy c1+c2=1, 0<c1<c2<1, and c1=0.36 and c2=0.64. Passive storage means that no keyboard operation command or mouse operation command is received, but the storage operation process is still carried out.
[0090] The file monitoring module obtains the number of times the monitored file i is viewed and the number of times the file is transferred during the time period between the last active storage time of the monitored file i and the current time, and marks them as the viewing value CK and the transfer value CS respectively. The viewing value CK and the transfer value CS are quantified, and the values of the viewing value CK and the transfer value CS are extracted and substituted into the formula for calculation. According to the formula Get the viewing value KS, where s1 and s2 are the preset proportional coefficients corresponding to the set viewing value CK and transmission value CS respectively, s1 and s2 satisfy s1+s2=1, 0<s1<s2<1, and take s1=0.41 and s2=0.59;
[0091] The file monitoring module sends the tolerance value RC, tampering value DC and input value KS to the anomaly analysis module.
[0092] Example 8:
[0093] Based on any of the above embodiments, embodiment 8 of the present invention is an abnormality analysis module. The function of the abnormality analysis module is to obtain the abnormality analysis coefficient YF i. The specific process is as follows:
[0094] The abnormality analysis module quantifies the tolerance value RC, the tampering value DC and the input value KS, extracts the values of the tolerance value RC, the tampering value DC and the input value KS, and substitutes them into the formula for calculation. Obtain the abnormality analysis coefficient YF i, where ε is the preset error adjustment factor, which is set to 1.059, π is a mathematical constant, f1, f2, and f3 are the preset weight factors corresponding to the set tolerance value RC, tampering value DC, and input value KS, respectively. f1, f2, and f3 satisfy f2>f3>f1>2.321, and f1=2.65, f2=3.38, and f3=2.93;
[0095] The anomaly analysis module sends the anomaly analysis coefficient YFi to the virus protection platform.
[0096] Based on the above embodiments 1-8, the working principle of the present invention is as follows:
[0097] A ransomware protection system based on file monitoring of the present invention obtains a monitoring file through a virus protection platform, and simultaneously generates a file monitoring instruction and an anomaly detection instruction; after receiving the anomaly detection instruction through the anomaly detection module, an anomaly detection is performed on the monitoring file to obtain a monitoring suffix; the monitoring suffix is compared with a stored dangerous suffix through a comparison information library, and a file isolation instruction is generated; after receiving the file isolation instruction through the isolation alarm module, the corresponding monitoring file is marked as an infected file; after receiving the file monitoring instruction through the file monitoring module, file monitoring is performed on the monitoring file to obtain anomaly analysis information of the monitoring file; the anomaly analysis coefficient is obtained according to the anomaly analysis information through the anomaly analysis module; an abnormal file is obtained according to the anomaly analysis coefficient through the virus protection platform, and a file transfer instruction is generated; after receiving the file transfer instruction through the isolation alarm module, the abnormal file is transferred to an isolated storage space;
[0098] The ransomware protection system first compares the monitored file with a large number of known dangerous suffixes stored in the comparison information database, and can directly determine whether the monitored file is a ransomware-infected file. It then collects and analyzes data on other monitored files to obtain abnormal analysis information. The abnormal analysis coefficient obtained based on the abnormal analysis information can comprehensively measure the abnormality level of the monitored file, and the larger the abnormal analysis coefficient, the higher the abnormality level. The abnormal analysis coefficient is used to determine whether there is ransomware behavior. If the abnormal analysis coefficient is large, it is determined that there is ransomware behavior, and the isolation module is triggered to isolate the infected file to prevent the spread of the virus.
[0099] The file monitoring-based ransomware protection system of the present invention monitors file system changes in real time, identifies ransomware behavior patterns, and achieves the functions of quickly discovering, isolating, and clearing ransomware, effectively protecting user data security.
[0100] It should be further explained that the above formulas are obtained by collecting a large amount of data and performing software simulation, and a formula close to the actual value is selected. The coefficients in the formula are set by technical personnel in this field according to actual conditions.
[0101] Throughout this specification, references to terms such as "one embodiment," "example," or "specific example" indicate that the specific features, structures, materials, or characteristics described in conjunction with that embodiment or example are included in at least one embodiment or example of the present invention. In this specification, schematic representations of these terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.
[0102] The above contents are merely examples and explanations of the present invention. Those skilled in the art may make various modifications or additions to the described specific embodiments or replace them in similar ways. As long as they do not deviate from the invention or exceed the scope defined in this application, they should all fall within the scope of protection of the present invention.
Claims
1. A ransomware protection system based on file monitoring, characterized in that: include: The virus protection platform is used to obtain the monitoring file i, generate a file monitoring instruction and an anomaly detection instruction, and send the anomaly detection instruction to the anomaly detection module and the file monitoring instruction to the file monitoring module; It is also used to obtain abnormal files according to the abnormal analysis coefficient YFi, obtain dangerous suffixes, send the dangerous suffixes to the comparison information library, generate file transfer instructions, and send the file transfer instructions to the isolation alarm module; An anomaly detection module is used to obtain the monitoring suffix after receiving the anomaly detection instruction and send the monitoring suffix to the comparison information library; A comparison information base is used to compare the monitored suffix with the stored dangerous suffixes, generate a file quarantine instruction, and send the file quarantine instruction to the quarantine alarm module; The isolation alarm module is used to mark the corresponding monitored file i as an infected file after receiving the file isolation instruction, and transfer the infected file to the isolated storage space; It is also used to transfer abnormal files to isolated storage space after receiving a file transfer instruction; The file monitoring module is used to obtain the abnormality analysis information of the monitored file i after receiving the file monitoring instruction, and send the abnormality analysis information to the abnormality analysis module; wherein the abnormality analysis information includes the tolerance value RC, the tampering value DC and the read-sink value KS; An anomaly analysis module, used to obtain an anomaly analysis coefficient YFi according to the anomaly analysis information, and send the anomaly analysis coefficient YFi to the virus protection platform; The specific process of the abnormality analysis module obtaining the abnormality analysis coefficient YFi is as follows: The tolerance value RC, tampering value DC and input value KS are quantified according to the formula Obtain the abnormality analysis coefficient YFi, where ε is the preset error adjustment factor, π is a mathematical constant, and f1, f2, and f3 are the preset weight factors corresponding to the set tolerance value RC, tampering value DC, and input value KS, respectively; The abnormality analysis coefficient YFi is sent to the virus protection platform.
2. A ransomware protection system based on file monitoring according to claim 1, characterized in that: The specific process of the virus protection platform generating file monitoring instructions and anomaly detection instructions is as follows: Obtain all files in the storage space and mark them as monitoring files i in turn, i = 1, ..., n, n is a positive integer, and generate file monitoring instructions and anomaly detection instructions at the same time, and send the anomaly detection instructions to the anomaly detection module and the file monitoring instructions to the file monitoring module.
3. The ransomware protection system based on file monitoring according to claim 1, characterized in that: The specific process of the anomaly detection module obtaining the monitoring suffix is as follows: After receiving the anomaly detection instruction, the monitoring file i is detected for anomalies, the suffix name of the monitoring file i is obtained, and it is marked as the monitoring suffix, and the monitoring suffix is sent to the comparison information library.
4. The ransomware protection system based on file monitoring according to claim 1, characterized in that: The specific process of generating file isolation instructions by comparing the information base is as follows: The monitored suffix is compared with the stored dangerous suffixes. If there is a dangerous suffix that is the same as the monitored suffix, a file isolation instruction is generated and sent to the isolation alarm module.
5. The ransomware protection system based on file monitoring according to claim 1, characterized in that: The specific process of the isolation alert module obtaining infected files is as follows: After receiving the file isolation instruction, the corresponding monitoring file i will be marked as an infected file, and the infected file will be displayed as "infected" to form a prompt alarm, and the infected file will be transferred to the isolated storage space and stored in the "infected file" folder.
6. The ransomware protection system based on file monitoring according to claim 1, characterized in that: The specific process of the file monitoring module obtaining the tolerance value RC is as follows: After receiving the file monitoring instruction, the monitoring file i is monitored, the file size of the monitoring file i at the last active storage time and the file size at the current time are obtained, the difference between the two is obtained, and it is marked as the tolerance value RC.
7. The ransomware protection system based on file monitoring according to claim 1, characterized in that: The specific process of the file monitoring module obtaining the tampering value DC is as follows: Obtain the passive storage times and modification times of monitoring file i during the period between the last active storage time and the current time, and mark them as stored value BC and modified value XG respectively. The stored value BC and modified value XG are quantified according to the formula The tampered value DC is obtained, wherein c1 and c2 are preset proportional coefficients corresponding to the set stored value BC and the modified value XG respectively.
8. The ransomware protection system based on file monitoring according to claim 1, characterized in that: The specific process of the file monitoring module obtaining the input value KS is as follows: Obtain the number of times the monitoring file i has been viewed and the number of times the file has been transferred during the time period between the last active storage time of the monitoring file i and the current time, and mark them as the viewing value CK and the transfer value CS respectively. The viewing value CK and the transfer value CS are quantified according to the formula The viewing value KS is obtained, where s1 and s2 are the preset proportional coefficients corresponding to the set viewing value CK and transmission value CS respectively.
9. The ransomware protection system based on file monitoring according to claim 1, characterized in that: The specific process of the virus protection platform generating a file transfer instruction is as follows: Compare the anomaly analysis coefficient YFi with the preset anomaly analysis threshold YFy: If the abnormality analysis coefficient YFi ≥ the abnormality analysis threshold YFy, the monitoring file i corresponding to the abnormality analysis coefficient YFi is marked as an abnormal file, and the suffix name of the abnormal file is obtained and marked as a dangerous suffix. The dangerous suffix is sent to the comparison information library, and a file transfer instruction is generated at the same time, and the file transfer instruction is sent to the isolation alarm module.
10. A working method of a ransomware protection system based on file monitoring according to any one of claims 1 to 9, characterized in that: The following steps are involved: Step 1: The virus protection platform obtains the monitoring file i, generates a file monitoring instruction and an anomaly detection instruction, and sends the anomaly detection instruction to the anomaly detection module and the file monitoring instruction to the file monitoring module; Step 2: After receiving the anomaly detection instruction, the anomaly detection module performs an anomaly detection on the monitoring file i, obtains the monitoring suffix, and sends the monitoring suffix to the comparison information library; Step 3: The comparison information database compares the monitored suffix with the stored dangerous suffixes, generates a file quarantine instruction, and sends the file quarantine instruction to the quarantine alarm module; Step 4: After receiving the file quarantine instruction, the quarantine alarm module marks the corresponding monitored file i as an infected file and transfers the infected file to the isolated storage space; Step 5: After receiving the file monitoring instruction, the file monitoring module monitors the monitoring file i, obtains the abnormality analysis information of the monitoring file i, wherein the abnormality analysis information includes the tolerance value RC, the tampering value DC, and the read-sink value KS, and sends the abnormality analysis information to the abnormality analysis module; Step 6: The anomaly analysis module obtains an anomaly analysis coefficient YFi based on the anomaly analysis information, and sends the anomaly analysis coefficient YFi to the virus protection platform; Step 7: The virus protection platform obtains abnormal files based on the abnormal analysis coefficient YFi, obtains dangerous suffixes, sends the dangerous suffixes to the comparison information library, generates a file transfer instruction, and sends the file transfer instruction to the isolation alarm module; Step 8: After receiving the file transfer instruction, the isolation alarm module transfers the abnormal file to the isolated storage space.
Citation Information
Patent Citations
Ransomware protection method and system
CN114186222A