Protection guiding method and device, storage medium and electronic equipment
By dividing the ransomware incident process into multiple stages and displaying protection operations and guidance signs on a visual page, the problem that traditional protection measures are unable to cope with ransomware attacks is solved, user-friendly ransomware protection process guidance is implemented, and protection efficiency and data security are improved.
Patent Information
- Application Number
- CN202510805532.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-10-03
AI Technical Summary
Traditional security protection measures cannot effectively deal with complex and diverse ransomware attacks, especially for small and medium-sized enterprises with weak prevention and response capabilities. Simply relying on firewalls or virus scanning cannot effectively resist modern ransomware attacks.
The ransomware incident process is divided into multiple stages, the ransomware behavior in each stage is determined, and the corresponding protection operations and guidance signs are displayed through a visual page to guide users to perform protection operations.
It reduces the difficulty of protection operations, enables users to quickly respond to and accurately execute ransomware protection, improves protection efficiency, and greatly improves the data security of electronic devices.
Smart Images

Figure CN120743408A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a protective boot method, device, storage medium, and electronic device. Background Art
[0002] In recent years, with the continuous evolution of ransomware attack techniques, the security threats facing enterprises have become increasingly complex and diverse. These attacks not only employ increasingly sophisticated techniques, but their attack patterns are also becoming increasingly commonplace and industrialized. Some criminal gangs have even used ransomware attacks as a sustainable and stable source of profit. This rapidly evolving attack model has rendered traditional security measures ineffective in addressing the growing security risks. For small and medium-sized enterprises, this is particularly true, as their ability to prevent and respond to ransomware is particularly limited. Relying solely on traditional firewalls or virus scanners is no longer effective in defending against modern ransomware attacks. Summary of the Invention
[0003] The embodiments of the present application provide a protection boot method, device, storage medium, and electronic device that can solve the above problems. The technical solution is as follows:
[0004] In a first aspect, an embodiment of the present application provides a protection guidance method, the method comprising:
[0005] Obtain ransomware incidents targeting electronic devices;
[0006] Determining, based on the multiple stages of the ransomware incident, the ransomware behavior corresponding to each stage and the protective action for each ransomware behavior;
[0007] The protection operations corresponding to the multiple stages are displayed on the visualization page, and a guidance mark for instructing the user to start the protection operation is displayed.
[0008] In a second aspect, an embodiment of the present application provides a protection and guidance device, the device comprising:
[0009] An event acquisition module, used to acquire ransomware events targeting electronic devices;
[0010] A stage determination module is used to determine the ransom behavior corresponding to each stage and the protection operation for each ransom behavior according to the multiple stages of the ransom incident;
[0011] The identification display module is used to display the protection operations corresponding to the multiple stages on the visual page, and to display a guiding identification for instructing the user to start the protection operation.
[0012] In a third aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the above-mentioned method steps.
[0013] In a fourth aspect, an embodiment of the present application provides an electronic device, which may include: a processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the above-mentioned method steps.
[0014] The beneficial effects of the technical solutions provided by some embodiments of the present application include at least:
[0015] In the present application, the entire process of a ransomware incident against an electronic device is divided into multiple stages, and the ransomware behavior that will occur in each stage is determined. Thus, based on the specific information of the ransomware behavior in each stage, the protective operation used to protect the electronic device from being damaged by the ransomware behavior is determined in each stage. Furthermore, the protective operations corresponding to the multiple stages are displayed on a visual page, and a guide logo is displayed near each protective operation on the visual page. The guide logo is used to guide the user to pay attention to and start the protective operation. In other words, the present application decomposes the complex protection configuration process into easy-to-understand steps through a visual wizard. In the present application, through the guidance and prompts of multiple stages, the user can clearly understand the protective operations that need to be performed at each stage in the protection process against ransomware incidents, reduce the operational difficulty of protection, enable the user to quickly respond to and accurately execute ransomware protection, improve protection efficiency, and greatly improve the data security of electronic devices. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0017] Figure 1 This is a schematic diagram of the architecture of a protection guidance method provided in an embodiment of the present application;
[0018] Figure 2 This is a flowchart of a protection guidance method provided in an embodiment of the present application;
[0019] Figure 3 This is a schematic diagram of a visualization page provided by an embodiment of the present application;
[0020] Figure 4 This is a schematic diagram of a configuration of multiple protection operations provided in an embodiment of the present application;
[0021] Figure 5 This is a schematic diagram of a visualization page provided by an embodiment of the present application;
[0022] Figure 6 This is a flowchart of a protection guidance method provided in an embodiment of the present application;
[0023] Figure 7 This is a flowchart of a protection guidance method provided in an embodiment of the present application;
[0024] Figure 8 This is a schematic diagram of a visualization page provided by an embodiment of the present application;
[0025] Figure 9 This is a schematic structural diagram of a protective guidance device provided in an embodiment of the present application;
[0026] Figure 10 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0027] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0028] In the description of this application, it should be understood that the terms "first", "second", etc. are used for descriptive purposes only and should not be understood to indicate or imply relative importance. In the description of this application, it should be noted that, unless otherwise expressly specified and limited, "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units inherent to these processes, methods, products or devices. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to the specific circumstances. In addition, in the description of this application, unless otherwise specified, "multiple" refers to two or more. "and / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.
[0029] The present application is described in detail below with reference to specific embodiments.
[0030] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in the embodiments of this application are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the features, information, and data involved in this application are all obtained with full authorization.
[0031] like Figure 1 As shown, Figure 1 It is a flow chart of a protection guidance method provided in an embodiment of the present application. Figure 1 The system includes at least a server 101 that provides protection services to electronic devices, and also includes multiple electronic devices that execute a protection guidance method to guide users to start protection operations. The multiple electronic devices include at least an electronic device 1021, an electronic device 1022, and an electronic device 1023. It is understood that Figure 1 The number of servers and electronic devices shown is for illustration only and is not limited in this embodiment of the present application.
[0032] The above-mentioned server 101 can be a separate server device, such as: a rack-mounted, blade, tower, or cabinet-mounted server device, or a hardware device with strong computing power such as a workstation or a mainframe computer; it can also be a server cluster composed of multiple servers. The servers in the service cluster can be composed in a symmetrical manner, wherein each server has equivalent functions and status in the transaction link, and each server can provide services to the outside world independently. Providing services independently can be understood as not requiring the assistance of other servers.
[0033] For example, the server may be multiple physical servers that are independent in hardware. Alternatively, the server may be multiple virtual servers that are deployed in the same hardware resource pool. Virtual server deployment methods include, but are not limited to, VMware, Virtual Box, and Virtual PC.
[0034] It is understood that the server 101 also has other service capabilities and functions to complete the tasks in the following embodiments. For example, the server 101 also provides portal services, resource management services, and CI / CD services.
[0035] Electronic devices include, but are not limited to, wearable devices, handheld devices, personal computers, tablets, in-vehicle devices, smartphones, computing devices, or other processing devices connected to a wireless modem. Electronic devices may be referred to by different names in different networks, such as user equipment, access terminals, subscriber units, subscriber stations, mobile stations, mobile stations, remote stations, remote terminals, mobile devices, user terminals, terminals, wireless communication devices, user agents or user devices, cellular phones, cordless phones, personal digital assistants (PDAs), and electronic devices in 5G networks or future evolution networks.
[0036] In the embodiment of the present application, electronic devices such as electronic device 1021, electronic device 1022 and electronic device 1023 may also be installed with a display device, and the display device may be various devices that can realize a display function, for example: the display device may be a cathode ray tube display (Cathode ray tube display, abbreviated as CR), a light emitting diode display (Light-emitting diode display, abbreviated as LED), an electronic ink screen, a liquid crystal display (Liquid crystal display, abbreviated as LCD), a plasma display panel (Plasma display panel, abbreviated as PDP), etc.
[0037] The electronic device displays a visual page to the user based on a display device. The visual page displays protection operations corresponding to multiple stages of the ransomware incident, as well as a guidance icon for instructing the user to initiate the protection operation. The user can use the display device of the electronic device to send an activation instruction for a protection operation to the server 101, so that the server 101 provides the protection service for the protection operation to the electronic device.
[0038] Multiple electronic devices and multiple servers can communicate with each other through communication links established by a communication protocol, for example: wherein the network can be a wireless network or a wired network, the wireless network includes but is not limited to a cellular network, a wireless local area network, an infrared network or a Bluetooth network, and the wired network includes but is not limited to an Ethernet, a universal serial bus (USB) or a controller area network. In one or more embodiments of the specification, technologies and / or formats including Hypertext Markup Language (HTML), Extensible Markup Language (XML), etc. are used to represent data (such as a target compressed package) exchanged through the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPsec), etc. can also be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above-mentioned data communication technologies.
[0039] In one embodiment, Figure 2 The figure below is a flow chart of a protective boot method provided in an embodiment of the present application. This method can be implemented using a computer program and can be run on a protective boot device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone tool application.
[0040] Specifically, the protection guidance method includes:
[0041] S101. Obtain a ransomware incident targeting an electronic device.
[0042] Ransomware incidents targeting electronic devices refer to incidents in which attackers encrypt, lock, change, or delete electronic devices or data stored in electronic devices in some way, causing adverse consequences such as loss of user interests.
[0043] There are many types of ransomware incidents. For example, a ransomware incident is a ransomware attack (Ransomware), which specifically encrypts a file in an electronic device or the system of an electronic device through malicious software (such as ransomware). Common ransomware viruses include WannaCry, NotPetya, etc. For another example, a ransomware incident is a vulnerability attack, in which attackers exploit security vulnerabilities in the system or application (such as unpatched vulnerabilities, zero-day vulnerabilities) to invade electronic devices and thereby damage the electronic devices. For another example, a ransomware incident is a brute force attack, in which attackers invade electronic devices by brute force cracking passwords (for example, trying all possible password combinations). This type of attack can target weak passwords, default passwords, and other easily guessed password settings. For another example, a ransomware incident is a phishing and social engineering attack, in which attackers disguise themselves as legitimate entities (such as technical support, banks, or government agencies) to trick users into clicking malicious links or downloading malicious attachments, and then carry out ransomware attacks.
[0044] Obtaining ransomware incidents targeting electronic devices can be obtained from log data of the electronic devices. By analyzing the log data of the electronic devices, it is possible to identify whether there are abnormal activities in the historical time period, such as unauthorized access, file encryption incidents, etc., thereby obtaining ransomware incidents targeting electronic devices that occurred in the historical time period.
[0045] Ransomware incidents targeting electronic devices can also be obtained from public platforms. For example, reports on ransomware incidents are regularly released by many cybersecurity platforms. These reports provide information on the attack methods, targets, scope of impact, and prevention recommendations for different types of ransomware incidents.
[0046] S102: Determine, based on multiple stages of a ransomware incident, the ransomware behavior corresponding to each stage and a protective operation for each ransomware behavior.
[0047] Based on the complete process of a ransomware incident, the process is divided into multiple stages. For example, a ransomware incident can be divided into the pre-incident stage, the mid-incident stage, and the post-incident stage. A ransomware incident consists of multiple ransomware behaviors. For example, a ransomware incident may include at least login, data search, and data deletion. Based on the multiple stages, the ransomware behaviors corresponding to each stage are determined. For example, the ransomware behavior corresponding to the mid-incident stage is data deletion. It is understood that each stage may correspond to one or more ransomware behaviors.
[0048] According to the extortion behavior at each stage, a protection operation is determined to protect the electronic device from being damaged by the extortion behavior or to minimize the adverse effects of the extortion behavior. The protection operation can be provided by the server 101 and executed by the electronic device or the server 101.
[0049] The following example uses the division of a ransomware incident into the pre-incident, in-incident, and post-incident stages for a detailed explanation. Pre-incident protection measures primarily focus on ransomware prevention. For example, these include cloud file backups, data safes (encrypting data), and ransomware risk assessments.
[0050] During the incident, for ransomware that involves brute-force attacks on encrypted terminals or servers, login protection can be implemented. For another example, for ransomware that involves attacks on encrypted terminals or servers through ransomware, ransomware virus killers or remote protection settings can be implemented. For another example, for ransomware that exploits vulnerabilities in electronic devices, vulnerability immunity can be implemented to check whether the electronic device's system contains vulnerabilities. For ransomware that exploits vulnerabilities in domain controllers, penetration vulnerability protection and domain policy scanning can be implemented.
[0051] Post-incident protection measures are primarily aimed at reducing losses. For example, protection measures include ransomware decryption, data recovery, and post-mortem summaries.
[0052] It can be understood that there can be one or more types of protection operations in each stage.
[0053] S103: Displaying protection operations corresponding to the multiple stages on the visualization page, and displaying a guidance mark for instructing the user to start the protection operation.
[0054] A visualization page is an interface that displays information through graphics, charts, or other visual elements, designed to help users quickly understand the multiple stages of a ransomware incident and the protective actions that should be taken at each stage. In this application, a guidance sign is an interactive element that guides users to interact with the guidance sign to trigger the protective action associated with the guidance sign.
[0055] like Figure 3 As shown, Figure 3 This is a schematic diagram of a visualization page provided by an embodiment of the present application. The present application divides ransomware incidents into pre-incident, in-incident, and post-incident stages. For example, on the visualization page, a graphic symbol 201 represents a protective operation "ransomware risk assessment" that can be initiated in the pre-incident stage, and a guide symbol 202 is set near the protective operation. The user can interact with the guide symbol 202 through interactive methods such as mouse clicks or touches, thereby controlling the electronic device to initiate a protective operation with the content "ransomware risk assessment."
[0056] like Figure 4 As shown, Figure 4This is a configuration diagram of multiple protection operations provided by an embodiment of the present application. In this application, the constructed ransomware protection engine can provide multiple ransomware protection operations, including multiple ransomware virus decryption, multiple ransomware protection rules, and multiple ransomware virus query protection operations. It can also include file format tampering monitoring, file deletion monitoring, file suffix tampering monitoring, file abnormal reading monitoring, password credential theft, system backup monitoring, and other protection operations.
[0057] Depend on Figure 4 It can be seen that the ransomware defense engine constructed in this application includes multiple protection operations. Based on the ransomware behaviors corresponding to the multiple stages of the ransomware incident, the ransomware behaviors are associated with the protection operations, so that at least one protection operation is reasonably set in each stage, such as Figure 3 Therefore, users can intuitively see Figure 4 The multiple protection actions provided show how to protect electronic devices at multiple stages of a ransomware incident.
[0058] In the present application, the entire process of a ransomware incident against an electronic device is divided into multiple stages, and the ransomware behavior that will occur in each stage is determined. Thus, based on the specific information of the ransomware behavior in each stage, the protective operation used to protect the electronic device from being damaged by the ransomware behavior is determined in each stage. Furthermore, the protective operations corresponding to the multiple stages are displayed on a visual page, and a guide logo is displayed near each protective operation on the visual page. The guide logo is used to guide the user to pay attention to and start the protective operation. In other words, the present application decomposes the complex protection configuration process into easy-to-understand steps through a visual wizard. In the present application, through the guidance and prompts of multiple stages, the user can clearly understand the protective operations that need to be performed at each stage in the protection process against ransomware incidents, reduce the operational difficulty of protection, enable the user to quickly respond to and accurately execute ransomware protection, improve protection efficiency, and greatly improve the data security of electronic devices.
[0059] In one embodiment, the protection operations corresponding to the multiple stages are displayed on the visualization page through a preset first graphic mark, and a guidance mark for instructing the user to start the protection operation is displayed.
[0060] The guide mark and the first graphic mark are different. For example, the type of the guide mark is different from the type of the first graphic mark. The mark showing the protection operation is a graphic mark composed of an image and text, and the guide mark displayed to instruct the user to start the protection operation can be a mark composed of text only or a mark composed of an image only. For another example, the specific content of the guide mark is different from the specific content of the first graphic mark. Figure 3As shown, the protection operation is represented by the first graphic mark with the content of "ransomware risk assessment", and the guidance mark with the content of a circle represents that the user needs to start the protection operation.
[0061] In this embodiment, different identifiers are used to distinguish the specific content of the protection operation and the guidance identifier used to instruct the user to start the protection operation. Clear identifiers help users quickly understand the differences between different protection operations and how to start the protection operation, so that users can perform related operations more efficiently, reduce learning costs, thereby reducing the possibility of user misoperation and improving the usability of the system.
[0062] In one embodiment, the protection operations and ransomware behaviors corresponding to the multiple stages are displayed on the visualization page, and a guidance mark for instructing the user to start the protection operation is displayed.
[0063] The visualization page not only displays the corresponding protection operations in multiple stages and the corresponding guidance signs for each protection operation, but also displays the ransomware behavior that occurs in each stage. Figure 3 As shown, for the ransomware behavior "brute force cracking" occurring during the incident, the ransomware behavior with the content "brute force cracking" is displayed near the identifier of the incident stage on the visualization page, and a guidance icon for launching the protection operation with the content "login protection" is displayed near the ransomware behavior of "brute force cracking". For another example, for the ransomware behavior "vulnerability attack" occurring during the incident, the ransomware behavior with the content "vulnerability attack" is displayed near the identifier of the incident stage on the visualization page, and a guidance icon for launching the protection operation with the content "vulnerability immunity" is displayed near the ransomware behavior of "vulnerability attack".
[0064] In other words, in this embodiment, the visualization page also displays the ransom behavior that will occur at each stage, and displays a guide logo for the ransom operation used to protect against the ransom behavior near the logo representing the ransom behavior, so that the user can more clearly understand the ransom behavior that will occur at each stage, and understand which ransom behavior the protection operation taken at each stage is aimed at, thereby reducing the user's understanding cost of understanding the ransom event and the protection operation, and better utilizing the protection system to protect electronic devices.
[0065] In this embodiment, the protection operations corresponding to the multiple stages are displayed on the visualization page through a preset second graphic icon, the ransomware behaviors corresponding to the multiple stages are displayed through a preset third graphic icon, and a guidance icon for instructing the user to start the protection operation is displayed.
[0066] The guidance sign is different from the second graphic sign and the third graphic sign. For example, the type of the guidance sign is different from the type of the second graphic sign and the third graphic sign. The sign indicating the protection operation is a graphic sign composed of an image and text, and the sign indicating the ransomware behavior is a graphic sign composed of an image and text. The guidance sign displayed to instruct the user to initiate the protection operation can be a sign composed of text only or a sign composed of an image only.
[0067] For another example, the specific content of the guide sign is different from the specific content of the second graphic sign and the third graphic sign. Figure 3 As shown, the protection operation is represented by the second graphic logo with the content of "ransomware risk assessment", the ransomware behavior is represented by the second graphic logo with the content of "brute force cracking", and the guidance logo with the content of a circle represents that the user needs to start the protection operation.
[0068] In this embodiment, different identifiers are used to distinguish between protection operations, specific ransomware behaviors, and guidance indicators for instructing users to initiate protection operations. These clear identifiers help users quickly understand the differences between different protection operations and ransomware behaviors, as well as how to initiate protection operations. This allows users to perform related operations more efficiently, reduces learning costs, and thus reduces the possibility of user errors and improves system usability.
[0069] In one embodiment, at least one protection method corresponding to each of the multiple stages is displayed on a visualization page, as well as a guide mark corresponding to an unactivated protection operation and an activated mark corresponding to an activated protection operation in at least one protection method of each stage.
[0070] The guide mark is used to guide the user to start the instruction of the protection operation that has not been started. In other words, in this embodiment, the guide mark of the protection operation that has been started is different from the guide mark of the protection operation that has not been started.
[0071] like Figure 5 As shown, Figure 5 This is a schematic diagram of a visualization page provided by an embodiment of the present application. Pre-stage protection operations include at least cloud disk file backup, data safe, and ransomware risk assessment. The cloud disk file backup protection operation has been enabled, as indicated by a guide marker 301. The ransomware risk assessment protection operation has not been enabled, as indicated by a guide marker 302.
[0072] In this embodiment, different identifiers are used to distinguish between the guidance identifiers of activated protection operations and unactivated protection operations. Clear identifiers help users notice unactivated protection operations, reduce learning costs, and improve system usability.
[0073] In one embodiment, Figure 6 The figure below is a flow chart of a protective boot method provided in an embodiment of the present application. This method can be implemented using a computer program and can be run on a protective boot device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone tool application.
[0074] Specifically, the protection guidance method includes:
[0075] S201. Obtain a ransomware event targeting an electronic device.
[0076] See the above S101, which will not be repeated here.
[0077] S202: Determine, according to multiple stages of the extortion incident, extortion behavior information corresponding to each stage.
[0078] The ransom behavior information includes at least one of the following information: the behavior type of the ransom behavior, the target data targeted by the ransom behavior, and the type of electronic device targeted by the ransom behavior.
[0079] Specifically, the behavior type refers to the specific ransomware behavior, such as data encryption, data theft, ransom demands, etc. For example, during the incident, the ransomware behavior may be phishing through social engineering means, while during the data encryption phase, the ransomware behavior may be file encryption.
[0080] Target data refers to the data that is targeted or encrypted during ransomware attacks. For example, ransomware attacks may target a company's financial data, customer databases, R&D materials, and other important documents by encrypting or destroying them.
[0081] Electronic device type refers to the type of device being attacked, such as desktop computers, servers, mobile devices, and embedded devices. Different types of devices may be affected by different attack methods. For example, servers may be subject to large-scale data encryption, while mobile devices may be more susceptible to ransomware attacks through malicious applications.
[0082] S203: Determine a protection operation against the ransomware behavior based on the ransomware behavior information corresponding to each stage.
[0083] After analyzing the ransom behavior information of the ransom behavior at each stage, a protection operation corresponding to the ransom behavior is determined based on the ransom behavior information.
[0084] For example, for ransomware with an intrusion behavior and a server as the electronic device, the protection action could be strengthening network security defenses, such as using firewalls and IDS / IPS (Intrusion Detection / Prevention Systems) to prevent unauthorized access. For another example, for ransomware with data deletion as the behavior, the protection action could be encrypting the target data and backing it up to a secure location.
[0085] In this embodiment, the protection operation against ransomware behavior is determined based on ransomware behavior information, which can improve the accuracy of ransomware protection, dynamically adjust the protection strategy based on the actual progress of the ransomware incident, and realize intelligent protection.
[0086] S204: Displaying protection operations corresponding to the multiple stages on the visualization page, and displaying a guidance mark for instructing the user to start the protection operation.
[0087] See above S103, which will not be described again here.
[0088] In the present application, the entire process of a ransomware incident against an electronic device is divided into multiple stages, and the ransomware behavior that will occur in each stage is determined. Thus, based on the specific information of the ransomware behavior in each stage, the protective operation used to protect the electronic device from being damaged by the ransomware behavior is determined in each stage. Furthermore, the protective operations corresponding to the multiple stages are displayed on a visual page, and a guide logo is displayed near each protective operation on the visual page. The guide logo is used to guide the user to pay attention to and start the protective operation. In other words, the present application decomposes the complex protection configuration process into easy-to-understand steps through a visual wizard. In the present application, through the guidance and prompts of multiple stages, the user can clearly understand the protective operations that need to be performed at each stage in the protection process against ransomware incidents, reduce the operational difficulty of protection, enable the user to quickly respond to and accurately execute ransomware protection, improve protection efficiency, and greatly improve the data security of electronic devices.
[0089] In one embodiment, Figure 7 The figure below is a flow chart of a protective boot method provided in an embodiment of the present application. This method can be implemented using a computer program and can be run on a protective boot device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone tool application.
[0090] Specifically, the protection guidance method includes:
[0091] S301: Obtain a ransomware event targeting an electronic device.
[0092] See the above S101, which will not be repeated here.
[0093] S302: Determine, based on multiple stages of a ransomware incident, the ransomware behavior corresponding to each stage and a protective operation for each ransomware behavior.
[0094] See above S102, which will not be described again here.
[0095] S303: Displaying protection operations corresponding to the multiple stages on the visualization page, and displaying a guidance mark for instructing the user to start the protection operation.
[0096] See above S303, which will not be described again here.
[0097] S304: When a ransomware incident is detected, the target stage of the current ransomware incident is determined.
[0098] When a ransomware incident is detected, the system retrieves the ransomware behavior occurring in the current ransomware incident based on multiple preset stages and at least one ransomware behavior corresponding to each stage, and determines the target stage of the current ransomware incident. For example, if the system detects abnormal network connections or remote logins, the target stage of the ransomware incident is determined to be the mid-stage. For another example, if the system detects that the ransomware virus has begun to spread within the internal network, potentially moving laterally through shared folders, vulnerabilities, or password-less accounts, the target stage of the ransomware incident is determined to be the mid-stage.
[0099] S305: Mark the target stage with an alarm mark on the visualization page.
[0100] Among the multiple stages displayed on the visualization page, the target stage is marked with an alarm icon. Figure 8 As shown, Figure 8 This is a schematic diagram of a visualization page provided by an embodiment of the present application. The current stage where the ransomware incident "vulnerability attack" is detected is the mid-stage. Figure 8 The warning sign shown is marked with "in-progress phase".
[0101] In this embodiment, by real-time monitoring of ransomware events and marking the target stage of the current ransomware event with an alarm mark on the visualization page, it helps users to quickly identify the current stage of the ransomware event, respond in time, take necessary protective actions, optimize protection decisions, and improve user experience and the security of electronic devices.
[0102] In one embodiment, a user input instruction for an alarm identifier is received; in response to the input instruction for the alarm identifier, a window page pops up on a visualization page, and ransom information and protection suggestions related to the ransomware incident are displayed on the window page.
[0103] The alarm logo is an interactive element. Users can input input instructions for the alarm logo to the electronic device through interactive methods such as mouse clicking or touching, so that the electronic device controls a pop-up window page on the visual page, and displays ransom information and protection suggestions related to the ransomware incident on the window page.
[0104] like Figure 8 As shown, window page 401 displays the ransom information packet related to the ransomware incident, the type of the ransomware incident is a vulnerability attack, and the alarm time of the ransomware incident. It also displays the protection suggestions related to the ransomware incident: isolate this terminal and conduct a special vulnerability search for all network terminals.
[0105] In this embodiment, detailed ransomware information related to the ransomware incident is displayed in a window page, allowing users to more clearly understand the type of ransomware incident and its potential harm. Protection recommendations related to the ransomware incident are also displayed, informing users of protective strategies for the current ransomware incident, such as file backups and isolating suspected infected devices. This helps users quickly respond appropriately and minimize losses. Furthermore, by directly displaying the window page in the visual interface, users can obtain ransomware information and protection recommendations directly from the pop-up window page without having to switch between different interfaces or view log files, thus reducing time and operational costs.
[0106] In the present application, the entire process of a ransomware incident against an electronic device is divided into multiple stages, and the ransomware behavior that will occur in each stage is determined. Thus, based on the specific information of the ransomware behavior in each stage, the protective operation used to protect the electronic device from being damaged by the ransomware behavior is determined in each stage. Furthermore, the protective operations corresponding to the multiple stages are displayed on a visual page, and a guide logo is displayed near each protective operation on the visual page. The guide logo is used to guide the user to pay attention to and start the protective operation. In other words, the present application decomposes the complex protection configuration process into easy-to-understand steps through a visual wizard. In the present application, through the guidance and prompts of multiple stages, the user can clearly understand the protective operations that need to be performed at each stage in the protection process against ransomware incidents, reduce the operational difficulty of protection, enable the user to quickly respond to and accurately execute ransomware protection, improve protection efficiency, and greatly improve the data security of electronic devices.
[0107] In one embodiment, after displaying the protection operations corresponding to multiple stages on a visualization page, and displaying a guide identifier for instructing the user to start the protection operation, it also includes: receiving the user's input instruction for a target guide identifier among the multiple guide identifiers; and starting the protection operation corresponding to the target guide identifier in response to the input instruction for the target guide identifier.
[0108] The guidance mark is an interactive element. The user can input an input instruction for the guidance mark to the electronic device by interactive means such as clicking or touching the target guidance mark with a mouse. In response to the input instruction for the target guidance mark, the electronic device initiates the protection operation corresponding to the target guidance mark.
[0109] For example, in response to an input instruction of a target guidance identifier corresponding to a protection operation of "file cloud disk backup", the electronic device uploads a file at a specified address in the electronic device to a specified cloud disk for backup.
[0110] In this embodiment, by explicitly specifying a target guidance identifier, the electronic device can initiate precise protection operations associated with that target guidance identifier, improving protection efficiency and reducing unnecessary resource consumption. Furthermore, users can select target guidance identifiers to initiate different protection operations based on their specific needs, making protection operations more personalized.
[0111] The following are device embodiments of the present application, which can be used to implement the method embodiments of the present application. For details not disclosed in the device embodiments of the present application, please refer to the method embodiments of the present application.
[0112] See Figure 9 , which shows a schematic diagram of the structure of a protection guidance device provided by an exemplary embodiment of the present application. The protection guidance device can be implemented as all or part of the device through software, hardware, or a combination of both. The protection guidance device includes an event acquisition module 501, a stage determination module 502, and an identification display module 503.
[0113] An event acquisition module 501 is used to acquire extortion events targeting electronic devices;
[0114] A stage determination module 502 is configured to determine, based on the multiple stages of the ransomware incident, the ransomware behavior corresponding to each stage and a protective action for each ransomware behavior;
[0115] The identification display module 503 is used to display the protection operations corresponding to the multiple stages on the visual page, and to display a guiding identification for instructing the user to start the protection operation.
[0116] In one embodiment, the logo display module 503 includes:
[0117] The first display unit is used to display the protection operations corresponding to the multiple stages on the visualization page through a preset first graphic and text logo, and to display a guide logo for instructing the user to start the protection operation; wherein the guide logo and the first graphic and text logo are different.
[0118] In one embodiment, the logo display module 503 includes:
[0119] The second display unit displays the protection operations and ransomware behaviors corresponding to the multiple stages on a visual page, and displays a guidance mark for instructing the user to start the protection operation.
[0120] In one embodiment, the second display unit includes:
[0121] The identification display subunit is used to display the protection operations corresponding to the multiple stages respectively through a preset second graphic identification on the visualization page, and to display the ransomware behaviors corresponding to the multiple stages respectively through a preset third graphic identification, and to display a guidance identification for instructing the user to start the protection operation; wherein the guidance identification is different from the second graphic identification and the third graphic identification.
[0122] In one embodiment, the logo display module 503 includes:
[0123] The third display unit is used to display at least one protection method corresponding to each of the multiple stages on a visual page, and to display a guide mark corresponding to the unstarted protection operation and an started mark corresponding to the started protection operation in at least one protection method of each stage; wherein the guide mark is used to guide the user to start the instruction of the unstarted protection operation.
[0124] In one embodiment, the stage determination module 502 includes:
[0125] A first stage determining unit is configured to determine, based on the multiple stages of the ransomware incident, ransomware behavior information corresponding to each stage; wherein the ransomware behavior information includes at least one of the following information: a behavior type of the ransomware behavior, target data targeted by the ransomware behavior, and a type of electronic device targeted by the ransomware behavior;
[0126] The second stage determining unit is configured to determine a protection operation for the ransom behavior according to the ransom behavior information of the ransom behavior corresponding to each stage.
[0127] In one embodiment, the protection and guidance device further includes:
[0128] A target determination module, configured to determine the target stage of the current ransomware incident upon detecting the occurrence of the ransomware incident;
[0129] The alarm display module is used to mark the target stage on the visualization page through an alarm mark.
[0130] In one embodiment, the protection and guidance device further includes:
[0131] A first input module is used to receive an input instruction from the user for the alarm identifier;
[0132] An alarm pop-up module is used to pop up a window page on the visualization page in response to an input instruction for the alarm identifier, and display ransom information and protection suggestions related to the ransomware event on the window page.
[0133] In one embodiment, the protection and guidance device further includes:
[0134] A second input module is configured to receive a user input instruction for a target guide identifier among the plurality of guide identifiers;
[0135] The protection module is started, and is used to start the protection operation corresponding to the target guidance identifier in response to the input instruction for the target guidance identifier.
[0136] In the present application, the entire process of a ransomware incident against an electronic device is divided into multiple stages, and the ransomware behavior that will occur in each stage is determined. Thus, based on the specific information of the ransomware behavior in each stage, the protective operation used to protect the electronic device from being damaged by the ransomware behavior is determined in each stage. Furthermore, the protective operations corresponding to the multiple stages are displayed on a visual page, and a guide logo is displayed near each protective operation on the visual page. The guide logo is used to guide the user to pay attention to and start the protective operation. In other words, the present application decomposes the complex protection configuration process into easy-to-understand steps through a visual wizard. In the present application, through the guidance and prompts of multiple stages, the user can clearly understand the protective operations that need to be performed at each stage in the protection process against ransomware incidents, reduce the operational difficulty of protection, enable the user to quickly respond to and accurately execute ransomware protection, improve protection efficiency, and greatly improve the data security of electronic devices.
[0137] It should be noted that the protection guidance device provided in the above embodiment, when executing the protection guidance method, only uses the division of the above-mentioned functional modules as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the protection guidance device provided in the above embodiment and the protection guidance method embodiment are based on the same concept. The implementation process is detailed in the method embodiment and will not be repeated here.
[0138] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0139] The present application also provides a computer storage medium that can store multiple instructions, which are suitable for being loaded and executed by a processor as described above. Figure 1 - Figure 8 The protection boot method of the embodiment shown, the specific execution process can be found in Figure 1 - Figure 8 The detailed description of the illustrated embodiment will not be repeated here.
[0140] The present application also provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by a processor as described above. Figure 1 - Figure 8 The protection boot method of the embodiment shown, the specific execution process can be found in Figure 1 - Figure 8 The detailed description of the illustrated embodiment will not be repeated here.
[0141] See Figure 10 , is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 10 As shown, the electronic device 600 may include: at least one processor 601 , at least one network interface 604 , a user interface 603 , a memory 605 , and at least one communication bus 602 .
[0142] The communication bus 602 is used to implement the connection and communication between these components.
[0143] The user interface 603 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 603 may also include a standard wired interface and a wireless interface.
[0144] The network interface 604 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).
[0145] The processor 601 may include one or more processing cores. The processor 601 utilizes various interfaces and lines to connect the various components within the server 600. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 605, and calling data stored in the memory 605, the processor 601 executes various functions of the server 600 and processes data. Optionally, the processor 601 may be implemented in the form of at least one hardware component selected from the group consisting of a digital signal processing (DSP), a field-programmable gate array (FPGA), and a programmable logic array (PLA). The processor 601 may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; and the modem is used to handle wireless communications. It is understood that the modem may not be integrated into the processor 601 and may be implemented separately on a single chip.
[0146] Among them, the memory 605 may include a random access memory (RAM) or a read-only memory (Read-Only Memory). Optionally, the memory 605 includes a non-transitory computer-readable storage medium. The memory 605 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 605 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 605 may also be optionally at least one storage device located away from the aforementioned processor 601. As Figure 10 As shown, the memory 605 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a protection boot application.
[0147] exist Figure 10In the electronic device 600 shown, the user interface 603 is mainly used to provide an input interface for the user and obtain user input data; and the processor 601 can be used to call the protection boot application stored in the memory 605 and specifically perform the following operations:
[0148] Obtain ransomware incidents targeting electronic devices;
[0149] Determining, based on the multiple stages of the ransomware incident, the ransomware behavior corresponding to each stage and the protective action for each ransomware behavior;
[0150] The protection operations corresponding to the multiple stages are displayed on the visualization page, and a guidance mark for instructing the user to start the protection operation is displayed.
[0151] In one embodiment, the processor 601 performs the steps of displaying the protection operations corresponding to the plurality of stages respectively through a visual page, and displaying a guidance mark for instructing the user to start the protection operation, specifically performing:
[0152] The protection operations corresponding to the multiple stages are displayed on the visualization page through a preset first graphic mark, and a guide mark for instructing the user to start the protection operation is displayed; wherein the guide mark and the first graphic mark are different.
[0153] In one embodiment, the processor 601 performs the steps of displaying the protection operations corresponding to the plurality of stages on the visual page and displaying a guidance mark for instructing the user to start the protection operation, specifically performing:
[0154] The protection operations and ransomware behaviors corresponding to the multiple stages are displayed on the visualization page, and a guidance mark for instructing the user to start the protection operation is displayed.
[0155] In one embodiment, the processor 601 displays the protection operations and ransomware behaviors corresponding to the plurality of stages on a visual page, and displays a guidance mark for instructing the user to initiate the protection operation, specifically performing:
[0156] On the visualization page, the protection operations corresponding to the multiple stages are displayed through a preset second graphic and text logo, and the ransomware behaviors corresponding to the multiple stages are displayed through a preset third graphic and text logo, and a guidance logo for instructing the user to start the protection operation is displayed; wherein the guidance logo is different from the second graphic and text logo and the third graphic and text logo, respectively.
[0157] In one embodiment, the processor 601 performs the steps of displaying the protection operations corresponding to the plurality of stages on the visual page and displaying a guidance mark for instructing the user to start the protection operation, specifically performing:
[0158] At least one protection method corresponding to each of the multiple stages is displayed on a visualization page, as well as a guidance mark corresponding to the unstarted protection operation and an activated mark corresponding to the activated protection operation in at least one protection method of each stage; wherein the guidance mark is used to guide the user to activate the instruction of the unstarted protection operation.
[0159] In one embodiment, the processor 601 executes the multiple stages of the ransomware event, determines the ransomware behavior corresponding to each stage and the protection operation for each ransomware behavior, and specifically performs:
[0160] Determining, based on the multiple stages of the ransomware incident, ransomware behavior information corresponding to each stage; wherein the ransomware behavior information includes at least one of the following information: the behavior type of the ransomware behavior, the target data targeted by the ransomware behavior, and the type of electronic device targeted by the ransomware behavior;
[0161] According to the ransom behavior information of the ransom behavior corresponding to each stage, a protection operation for the ransom behavior is determined.
[0162] In one embodiment, after the processor 601 displays the protection operations corresponding to the multiple stages on the visual page and displays a guidance mark for instructing the user to start the protection operation, it further performs:
[0163] When the ransomware incident is detected, determining the target stage of the current ransomware incident;
[0164] The target stage is marked on the visualization page by an alarm mark.
[0165] In one embodiment, after marking the target stage with an alarm indicator on the visualization page, the processor 601 further executes:
[0166] receiving an input instruction from the user for the alarm identifier;
[0167] In response to an input instruction for the alarm identifier, a window page pops up on the visualization page, and ransom information and protection suggestions related to the ransomware event are displayed on the window page.
[0168] In one embodiment, after the processor 601 displays the protection operations corresponding to the multiple stages on the visual page and displays a guidance mark for instructing the user to start the protection operation, it further performs:
[0169] receiving a user input instruction for a target guide identifier among the plurality of guide identifiers;
[0170] In response to an input instruction for the target guidance identifier, a protection operation corresponding to the target guidance identifier is started.
[0171] In the present application, the entire process of a ransomware incident against an electronic device is divided into multiple stages, and the ransomware behavior that will occur in each stage is determined. Thus, based on the specific information of the ransomware behavior in each stage, the protective operation used to protect the electronic device from being damaged by the ransomware behavior is determined in each stage. Furthermore, the protective operations corresponding to the multiple stages are displayed on a visual page, and a guide logo is displayed near each protective operation on the visual page. The guide logo is used to guide the user to pay attention to and start the protective operation. In other words, the present application decomposes the complex protection configuration process into easy-to-understand steps through a visual wizard. In the present application, through the guidance and prompts of multiple stages, the user can clearly understand the protective operations that need to be performed at each stage in the protection process against ransomware incidents, reduce the operational difficulty of protection, enable the user to quickly respond to and accurately execute ransomware protection, improve protection efficiency, and greatly improve the data security of electronic devices.
[0172] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by computer programs instructing related hardware. The corresponding programs can be stored in a computer-readable storage medium. When executed, the programs can include the processes in the above-described method embodiments. The storage medium of the electronic device 600 can be a magnetic disk, an optical disk, a read-only memory, or a random access memory.
[0173] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0174] The above disclosure is only a preferred embodiment of the present application, and certainly cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope covered by the present application.
Claims
1. A protection guidance method, characterized in that: The method comprises: Obtain ransomware incidents targeting electronic devices; Determining, based on the multiple stages of the ransomware incident, the ransomware behavior corresponding to each stage and the protective action for each ransomware behavior; The protection operations corresponding to the multiple stages are displayed on the visualization page, and a guidance mark for instructing the user to start the protection operation is displayed.
2. The protection guidance method according to claim 1, characterized in that: The displaying of the protection operations corresponding to the plurality of stages respectively through a visual page, and displaying a guidance mark for instructing the user to start the protection operation, includes: The protection operations corresponding to the multiple stages are displayed on the visualization page through a preset first graphic mark, and a guide mark for instructing the user to start the protection operation is displayed; wherein the guide mark and the first graphic mark are different.
3. The protection guidance method according to claim 1, characterized in that: The displaying of the protection operations corresponding to the plurality of stages on the visual page, and the displaying of a guidance mark for instructing the user to start the protection operation, includes: The protection operations and ransomware behaviors corresponding to the multiple stages are displayed on the visualization page, and a guidance mark for instructing the user to start the protection operation is displayed.
4. The protection guidance method according to claim 3, characterized in that: Displaying the protection operations and ransomware behaviors corresponding to the plurality of stages on a visualization page, and displaying a guidance mark for instructing a user to initiate the protection operation, including: On the visualization page, the protection operations corresponding to the multiple stages are displayed through a preset second graphic and text logo, and the ransomware behaviors corresponding to the multiple stages are displayed through a preset third graphic and text logo, and a guidance logo for instructing the user to start the protection operation is displayed; wherein the guidance logo is different from the second graphic and text logo and the third graphic and text logo, respectively.
5. The protection guidance method according to claim 1, characterized in that: The displaying of the protection operations corresponding to the plurality of stages on the visual page, and the displaying of a guidance mark for instructing the user to start the protection operation, includes: At least one protection method corresponding to each of the multiple stages is displayed on a visualization page, as well as a guidance mark corresponding to the unstarted protection operation and an activated mark corresponding to the activated protection operation in at least one protection method of each stage; wherein the guidance mark is used to guide the user to activate the instruction of the unstarted protection operation.
6. The protection guidance method according to claim 1, characterized in that: The step of determining, based on the multiple stages of the ransomware incident, the ransomware behavior corresponding to each stage and the protective operation for each ransomware behavior includes: Determining, based on the multiple stages of the ransomware incident, ransomware behavior information corresponding to each stage; wherein the ransomware behavior information includes at least one of the following information: the behavior type of the ransomware behavior, the target data targeted by the ransomware behavior, and the type of electronic device targeted by the ransomware behavior; According to the ransom behavior information of the ransom behavior corresponding to each stage, a protection operation for the ransom behavior is determined.
7. The protection guidance method according to claim 1, characterized in that: After displaying the protection operations corresponding to the plurality of stages on the visual page and displaying a guide mark for instructing the user to start the protection operation, the method further includes: When the ransomware incident is detected, determining the target stage of the current ransomware incident; The target stage is marked on the visualization page by an alarm mark.
8. A protective guiding device, characterized in that: The device comprises: An event acquisition module, used to acquire ransomware events targeting electronic devices; A stage determination module is used to determine the ransom behavior corresponding to each stage and the protection operation for each ransom behavior according to the multiple stages of the ransom incident; The identification display module is used to display the protection operations corresponding to the multiple stages on the visual page, and to display a guiding identification for instructing the user to start the protection operation.
9. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, which are suitable for being loaded by a processor and executing the method steps according to any one of claims 1 to 7.
10. An electronic device, characterized in that: include: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the method steps according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method and system of searching and killing bootstrap viruses
CN103123674A
Method and system for defense against APT attacks
CN108259449A