Intermittent cryptographic attack detection based on modified data fragment accumulation
By employing an intermittent encryption attack detection engine and encryption detection technology, and utilizing a modified data fragment detector and accumulator buffer, the problem of difficulty in detecting intermittent encryption attacks in existing technologies is solved, enabling rapid identification and response to data objects and reducing the risk of data loss.
Patent Information
- Application Number
- CN202510102884.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-04-25
- Filing Date
- 2025-01-22
- Publication Date
- 2025-10-28
AI Technical Summary
Existing ransomware attack detection technologies struggle to detect intermittent encryption attacks in real time, making it difficult to recover partially encrypted data objects, and existing systems are unable to effectively identify intermittent encryption behavior.
The intermittent encryption attack detection engine utilizes a modified data fragment detector and accumulator buffer, combined with encryption detection techniques such as Shannon entropy, chi-square test, and CUMSUM test, to collect and analyze different versions of data objects to determine whether an intermittent encryption attack exists.
It improves the reliability and timeliness of detecting intermittent encryption attacks, enabling rapid identification and response to encryption behaviors, and reducing data loss.
Smart Images

Figure CN120850282A_ABST
Abstract
Description
Background Art
[0001] Ransomware attacks involve encrypting data on a single computer or multiple computers connected via a network. In ransomware attacks, an encryption key is used to encrypt the data, making it inaccessible to users unless a ransom is paid to retrieve the encryption key. Ransomware attacks can cause significant damage to businesses, including commercial companies, government agencies, educational organizations, and individuals. Attached Figure Description
[0002] Some embodiments of this disclosure are described with reference to the following figures.
[0003] Figure 1 It is a block diagram of a computer system that includes an intermittent cryptographic attack detection engine, based on some examples.
[0004] Figure 2 This is a block diagram illustrating different versions of some example files.
[0005] Figure 3A and Figure 3B This is a block diagram depicting a value calculator that calculates a set of values based on the data portion of a first version of a data object in a sliding window, as shown in some examples.
[0006] Figure 4A and Figure 4B This is a block diagram depicting a value calculator that calculates values based on the data portion of a second version of a data object in a sliding window, as shown in some examples.
[0007] Figure 4C This is a block diagram illustrating a series of sliding windows based on some examples.
[0008] Figure 5 This is a flowchart illustrating the process of modifying a data fragment detector based on some examples.
[0009] Figure 6 It is a block diagram of an accumulator buffer and an encrypted detection window that overlays data segments in the accumulator buffer, based on some examples.
[0010] Figure 7 It is a block diagram of a storage medium with machine-readable instructions based on some examples of storage.
[0011] Figure 8 It is a block diagram of a system based on some examples.
[0012] Figure 9 It is a flowchart based on some examples.
[0013] Throughout the accompanying drawings, the same reference numerals denote similar but not necessarily identical elements. The drawings are not necessarily drawn to scale, and some parts may be enlarged to illustrate the examples more clearly. Furthermore, the drawings provide examples and / or embodiments consistent with the description; however, the description is not limited to the examples and / or embodiments provided in the drawings. Detailed Implementation
[0014] Ransomware attacks can be difficult to detect. By the time users (e.g., individual users, organizations such as commercial companies, governments, or educational institutions, or any other type of entity) become aware of the attack, most or all of the data may have been encrypted and therefore inaccessible. The inability to detect ransomware attacks in real time can reduce a user's ability to recover from an attack.
[0015] In some cases, ransomware can encrypt an entire data object, where "data object" can refer to any one or a combination of the following: a file in a file system, an image, a video, executable program code, or any other data container. In other cases, ransomware can perform intermittent encryption of a data object, where the ransomware encrypts selected portions of the data object without encrypting the rest. While ransomware protection systems can detect ransomware that encrypts the entire data object, such systems are ineffective against ransomware that applies intermittent encryption. Intermittent encryption can encrypt small fragments of the data object (e.g., 16-byte fragments or other small fragments) at random locations within the data object. Therefore, ransomware attacks based on intermittent encryption can evade detection. Because users may not be able to recover the original data from the partially encrypted data object, any partially encrypted (intermittently encrypted) data object may be lost.
[0016] According to some embodiments of this disclosure, an intermittent encryption attack detector can determine the presence of an intermittent encryption attack based on collected fragments of a data object that have been modified relative to different versions (e.g., previous or later versions). The collected fragments are accumulated in an accumulator buffer, the size of which is greater than a size threshold. For example, the accumulator buffer may have a size greater than 2 kilobytes (kB) or some other size threshold. The intermittent encryption attack detector applies encryption detection techniques (or multiple different encryption detection techniques) to the data in the accumulator buffer. The accumulator buffer effectively concentrates the modified fragments of the data object, allowing the applied encryption detection techniques to effectively detect intermittent encryption of the data object.
[0017] Encryption detection techniques calculate a measure of the randomness of data in an accumulator buffer to determine whether the data in the accumulator buffer has been encrypted. For example, encryption detection techniques may calculate entropy based on the data in the accumulator buffer. In some examples, the calculated entropy may include Shannon entropy, which measures the uncertainty of a random process. In other examples, encryption detection techniques may apply the chi-square test, the National Institute of Standards and Technology (NIST) Cumulative Summation Test (CUMSUM), serial correlation, Monte Carlo estimation, or any computation that quantifies the randomness of the data or otherwise indicates that encryption has occurred. In further examples, a variety of different encryption detection techniques can be applied to the data accumulated in the accumulator buffer. By collecting a sufficient amount of data—either by focusing or accumulating modified data fragments of a data object into an accumulator buffer larger than a size threshold—a randomness-based encryption detection technique can be applied to said data.
[0018] An "accumulator buffer" (or more simply, a "buffer") can refer to any storage resource that can be used to store data. For example, a buffer can be implemented using one or more memory devices (or portions of one or more memory devices), registers, or other types of storage elements.
[0019] An “encryption attack” refers to one or more unauthorized data encryption operations. Data encryption can be performed during normal operation of a computer system to protect data from unauthorized access. Such data encryption operations associated with planned or programmed operations are considered authorized data encryption operations. However, an attacker, including human users, programs, or machines, may perform unauthorized data encryption operations.
[0020] Examples of cryptographic attacks are executed by ransomware, which includes malware that has been activated on a system to perform data encryption. Entities launching ransomware attacks typically attempt to extort a ransom from victims in exchange for encryption keys that the victims can use to decrypt the encrypted data. In other examples, attackers may execute cryptographic attacks in different contexts.
[0021] Intermittent encryption attacks are encryption attacks that encrypt less than the entire data object. An intermittent encryption attack seeks to encrypt one or more sub-parts of a data object while leaving the rest of the data object unencrypted. A "sub-part" of a data object refers to a portion of the data object whose size is smaller than the total size of the data object.
[0022] Figure 1This is a block diagram of a computer system 100 including an intermittent encryption attack detection engine 102. The "engine" can be implemented using one or more hardware processing circuits, which may include any or a combination of a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or other hardware processing circuits. Alternatively, the "engine" can be implemented using one or more hardware processing circuits combined with machine-readable instructions (software and / or firmware) executable on the one or more hardware processing circuits.
[0023] Examples of computing system 100 may include any one or a combination of the following: a collection of computers (e.g., server computers, desktop computers, laptop computers, tablet computers, or other types of computers), a collection of smartphones, a collection of Internet of Things (IoT) devices, a collection of home appliances, a collection of vehicles, a collection of gaming devices, or a collection of other types of electronic devices. As used herein, a “collection” of items may refer to a single item or multiple items.
[0024] Storage system 104 is coupled to computer system 100. Storage system 104 may be internal to computer system 100, or alternatively, storage system 104 may be external to computer system 100. Storage system 104 may be implemented using a collection of storage devices. Examples of storage devices may include any one or a combination of the following: disk-based storage devices, solid-state drives, or other types of storage devices.
[0025] Data 106 can be stored in storage system 104. In some examples, data 106 stored in storage system 104 may include files, such as files in a file system. In other examples, data 106 may include other types of data objects. While some examples of this disclosure involve detecting intermittent cryptographic attacks on files, similar techniques or mechanisms may be used in other examples to detect intermittent cryptographic attacks on other types of data objects.
[0026] exist Figure 1 In the example, the intermittent encryption attack detection engine 102 receives file 108, which in this example is file version i+1 (hereinafter referred to as "file version i+1"). In the following discussion, a file version refers to a file containing content at a given point in time. Write operations may cause changes to the file content. Therefore, writing to a file can result in a new version of the file. Thus, file version i+1 is a newer version of the file compared to file version i.
[0027] To determine whether an intermittent encryption attack exists, the intermittent encryption attack detection engine 102 receives the following as inputs: (1) file version i+1 (108) and (2) a representation 130 of file version i. The representation 130 of file version i may include file version i itself or a set of hash values derived from a portion of file version i. Based on file version i+1 and the representation 130 of file version i, the intermittent encryption attack detection engine 102 determines whether an intermittent encryption attack exists (i.e., has occurred or is occurring).
[0028] The intermittent cryptographic attack detection engine 102 includes a modified data fragment detector 110, an accumulator buffer 112, and a data encryption detector 114. The modified data fragment detector 110 and the data encryption detector 114 can be implemented using portions of the hardware processing circuitry of the intermittent cryptographic attack detection engine 102, or they can be implemented as machine-readable instructions executed by the processing resources of the intermittent cryptographic attack detection engine 102. "Processing resources" can refer to one or more processors. Processors can include microprocessors, the cores of multi-core microprocessors, microcontrollers, programmable integrated circuits, programmable gate arrays, or other hardware processing circuitry.
[0029] The accumulator buffer 112 can be implemented using the storage resources of the intermittent cryptographic attack detection engine 102 or using storage resources external to the intermittent cryptographic attack detection engine 102. The modified data fragment detector 110 determines which data fragments of file version i+1 have been modified relative to file version i based on the representation 130 of file version i+1 and file version i.
[0030] The representation 130 of file version i is stored in memory 132 of computer system 100. Memory 132 may be implemented using one or more memory devices, such as any one or a combination of the following: dynamic random access memory (DRAM) device, static random access memory (SRAM) device, flash memory device, or other types of memory or storage device.
[0031] The representation 130 of file version i includes a set of values. In some examples, this set of values includes the data portion of file version i. In such examples, the "values" in this set of values include a collection of bytes of file version i (e.g., one byte or more). In other examples, the set of values includes a set of hash values generated based on the application of a function to the corresponding data portion of file version i. The applied function may include a cryptographic hash function or another type of function. The "hash function" produces a fixed-length value based on the input data. The "hash values" in this set of hash values are generated by applying the function to the corresponding data portion of file version i (e.g., a collection of bytes).
[0032] In some examples, the modified data fragment detector 110 can compare a set of values representing file version i+1 with the same set of values representing file version i. This comparison allows the modified data fragment detector 110 to determine which data portions of file version i+1 have been modified relative to file version i. The data portions of file version i+1 that the modified data fragment detector 110 determines have been modified relative to file version i are output by the modified data fragment detector 110 as modified data fragment 120.
[0033] Any modified data segment 120 is added to the accumulator buffer 112 by the modified data segment detector 110. Unmodified data segments of file version i+1 are not added to the accumulator buffer 112. In the accumulator buffer 112, new modified data segments 120 can be appended to any previously modified data segments already in the accumulator buffer 112.
[0034] Once the accumulator buffer 112 is filled, the data encryption detector 114 can apply a set of encryption detection techniques (N encryption detection techniques, where N≥1) to the data in the accumulator buffer 112 to determine whether the data in the accumulator buffer 112 has been encrypted. "Filling" the accumulator buffer 112 can mean that the entire accumulator buffer 112 is filled, or that a specified portion (e.g., a percentage) of the accumulator buffer 112 is filled with data. Examples of encryption detection techniques include any one or a combination of the following: encryption detection techniques that calculate Shannon entropy, encryption techniques that apply the chi-square test, encryption detection techniques that apply the CUMSUM test, encryption detection techniques based on sequence correlation, encryption detection techniques that apply Monte Carlo estimation, or any other encryption detection technique.
[0035] In an example where the data encryption detector 114 applies multiple encryption detection techniques, the data encryption detector 114 considers the output of each encryption detection technique to determine whether the data in the accumulator buffer 112 has been encrypted. If the metric generated by the encryption detection technique has a value falling within a specified range (e.g., the metric has a value exceeding or falling below a threshold), the encryption detection technique can indicate that the data has been encrypted. If the value of the metric generated by the encryption detection technique does not fall within the specified range, the encryption detection technique can indicate that the data has not been encrypted.
[0036] In some cases, multiple encryption detection techniques may produce inconsistent results. For example, a first encryption detection technique may indicate that the data in accumulator buffer 112 has been encrypted, while a second encryption detection technique may indicate that the data in accumulator buffer 112 has not been encrypted. If the data encryption detector 114 applies an odd number of encryption detection techniques, then the data encryption detector 114 can indicate that the data in accumulator buffer 112 has been encrypted when most of the encryption detection techniques indicate that the data in accumulator buffer 112 has been encrypted. For example, if three encryption detection techniques are used, then the data encryption detector 114 indicates that the data in accumulator buffer 112 has been encrypted when at least two of the three encryption detection techniques indicate that data encryption has occurred. In other examples using an even number of encryption detection techniques, the data encryption detector 114 can apply different weights to different encryption detection techniques. In such examples, the result of the first encryption detection technique can be given a greater weight than the result of the second encryption detection technique. Therefore, the determination of whether the data in accumulator buffer 112 is encrypted can be based on a weighted aggregation of the results from different encryption detection techniques.
[0037] In response to the data encryption detector 114 determining that each instance of data in the accumulator buffer 112 is encrypted, the data encryption detector 114 updates the encrypted data count 134 stored in the memory 136. The memory 136 may be the same as or different from the memory 132.
[0038] In some examples, the encrypted data count 134 can be an encrypted data byte count, which counts the number of encrypted bytes of file version i. Note that in some cases, file version i+1 can be much larger than accumulator buffer 112. Therefore, the data encryption detection performed by data encryption detector 114 is based on segments of file version i+1 added to accumulator buffer 112 (where said segments contain modified data fragments). After a segment of file version i+1 in accumulator buffer 112 has been processed by data encryption detector 114, said segment can be removed from accumulator buffer 112, and a new segment of file version i+1 (containing modified data fragments) can be added to accumulator buffer 112 for data encryption detector 114 to process. The continuous processing of segments of file version i+1 in accumulator buffer 112 by data encryption detector 114 causes encrypted data count 134 to be updated incrementally. As encrypted data count 134 is updated, data encryption detector 114 can calculate the percentage of file version i+1 that has been encrypted. This percentage is based on the ratio of the encrypted data count 134 to the total size of file version i+1. If this percentage exceeds a percentage threshold (e.g., 5%, 10%, or any other percentage), the data encryption detector 114 can determine that file version i+1 has been intermittently encrypted. However, if the percentage of file version i+1 that has been encrypted is less than the percentage threshold, the data encryption detector 114 does not indicate that file version i+1 has been intermittently encrypted. More generally, if the data encryption detector 114 determines that more than a certain threshold amount of file version i+1 has been encrypted, the data encryption detector 114 indicates that file version i+1 has been intermittently encrypted.
[0039] The data encryption detector 114 generates encryption detection output 116, which may include an indicator indicating whether file version i+1 has been intermittently encrypted. The indicator may include information elements (e.g., flags, fields, etc.) that can be set to different values. A first value of the indicator may specify that file version i+1 has been intermittently encrypted, and a different second value of the indicator may specify that file version i+1 has not been intermittently encrypted. The encryption detection output 116 may also include a value (e.g., a percentage value) indicating how much of file version i+1 has been intermittently encrypted.
[0040] If the data encryption detector 114 determines, based on the latest segment of file version i+1 in the accumulator buffer 112, that the percentage of file version i+1 that is encrypted exceeds a percentage threshold, the data encryption detector 114 can generate an encryption detection output 116 indicating that intermittent encryption has been detected, without having to process the rest of file version i+1.
[0041] The encryption detection output 116 can be provided to a remedy 118 within the computer system 100. In other examples, the remedy 118 can be located outside the computer system 100. The remedy 118 can be implemented using one or more hardware processing circuits or machine-readable instructions that execute on one or more hardware processing circuits. In response to the encryption detection output 116 indicating that file version i+1 has been encrypted, the remedy 118 can take one or more remedial actions.
[0042] The remedial action taken by the remedy device 118 may include any one or a combination of the following: providing an alert for an encryption attack, disabling components of the computer system 100 (e.g., stopping programs, shutting down electronic components, disabling network access, etc.), disabling the entire computer system 100 (e.g., putting the computer system 100 into a lower power state such as hibernation or power-off), or any other remedial action.
[0043] In an example where the remedy 118 is located outside the computer system 100, the computer system 100 may send the encryption detection output 116 to the remedy 118, for example, in a message or information element, such as via a network.
[0044] By concentrating modified data fragments into accumulator buffer 112, encryption detection techniques can more reliably detect encryption of data in the buffer compared to attempting to detect encryption in intermittently encrypted files.
[0045] In some examples, the intermittent encryption attack detection engine 102 can be used for intermittent encryption detection of selected files (or more generally, data objects). For example, a user or another entity can select more important files to be protected by the intermittent encryption attack detection engine 102. Such "more important" files may include, for example, files containing sensitive or confidential data. Furthermore, some files may be encrypted during normal operation. The user or another entity can provide hints about which files are expected to be encrypted, so that the intermittent encryption attack detection engine 102 is not applied to such files. If a file is not expected to be encrypted, the intermittent encryption attack detection engine 102 can achieve a high degree of confidence in more quickly identifying a file as a subject of an intermittent encryption attack (e.g., when a portion of a file is detected as encrypted, the entire file need not be considered).
[0046] Figure 2An example of file version i and file version i+1 is illustrated. In file version i+1, data fragments 202, 204, 206, 208, and 210 have been modified relative to their corresponding data fragments 212, 214, 216, 218, and 220 in file version i. One or more of the modified data fragments 202, 204, 206, 208, and 210 in file version i+1 can be generated by encrypting the corresponding data fragments 212, 214, 216, 218, and 220 in file version i. The remainder of file version i+1 (excluding data fragments 202, 204, 206, 208, and 210) has not been modified relative to file version i. The modified data fragment detector 110 is able to determine, based on the representation 130 of file version i+1 and file version i, which data fragments of file version i+1 have been modified relative to their corresponding data fragments of file version i.
[0047] Figure 3A and Figure 3B This illustrates how a representation of file version i can be generated based on file version i 130 ( Figure 1 Example of ). In Figure 3A and Figure 3B In the example, the representation of file version i as 130 includes a set of values 310.
[0048] Figure 3A A sliding window 302 is shown, with its starting point positioned at the beginning 304 of file version i. The sliding window 302 has a specified small window size, such as 4 to 8 bytes (or some other window size). In some examples, the window size of the sliding window 302 can be adjusted. A smaller window size can increase the concentration of modified data fragments in the accumulator buffer 112, but this results in increased usage of processing resources. A larger window size can decrease the concentration of modified data fragments in the accumulator buffer 112, but this uses fewer processing resources. A smaller window size can increase the reliability of encryption detection, but performance can be affected if processing resources are overloaded. The choice of window size can be based on experimentation or on results detected during the use of the intermittent encryption attack detection engine 102.
[0049] The data portion 320 of file version i in sliding window 302 is provided to value calculator (VC) 306, which calculates the value to be added to the set of values 310 based on the data portion 320 in sliding window 302. VC 306 may be part of intermittent cryptographic attack detection engine 102 or external to intermittent cryptographic attack detection engine 102. For example, VC 306 may include a hardware accelerator for calculating values based on the data portion of file version i. In other examples, VC 306 may be implemented using machine-readable instructions.
[0050] Note that when the sliding window 302 is in the position shown... Figure 3A As shown in its initial position, the set of values 310 can be initially empty. The value calculated by VC 306 based on the data portion 320 in the sliding window 302 can be simply the bits (or bytes) of the data portion 320 itself, or alternatively, the value calculated by VC 306 based on the data portion 320 is obtained by applying a function (e.g., a hash function) to the data portion 320 in the sliding window 302. The value calculated by VC 306 is added to the set of values 310.
[0051] exist Figures 3A to 3B In the example, the sliding window 302 moves from left to right in direction 308 (from the beginning 304 of file version i to the end 312 of file version i). In other examples, the sliding window 302 may move in the opposite direction from the end 312 of file version i to the beginning 304 of file version i.
[0052] With each iteration, the sliding window 302 advances by a specified sliding increment. For example, for each iteration of the calculated value based on the corresponding data portion of file version i, the sliding window 302 may advance M bytes (M≥1). When the sliding window 302 has moved to... Figure 3B Following the position shown, the data portion 322 in the sliding window 302 is provided to the VC 306, which calculates a value based on the data portion 322. This value is then added to the set of values 310.
[0053] VC 306 generates corresponding values added to the set of values 310 for multiple iterations of different positions of the sliding window 302. This set of values 310 includes values corresponding to different positions of the sliding window 302 (and corresponding different data portions of file version i). Indices can be used to represent different positions of the sliding window 302 (and therefore different data portions of file version i). Values in this set of values 310 can be associated with corresponding indices.
[0054] In some examples, the values in the set of values 310 can be computed in parallel by multiple instances of VC 306. For example, multiple instances of hardware accelerators or machine-readable instructions of VC 306 can be used to compute values at different positions of the sliding window 302 in parallel. Multiple instances of VC 306 can then add corresponding values to the set of values 310. Computing the set of values 310 in parallel can improve the performance and speed of the intermittent cryptographic attack detection engine 102.
[0055] Once the set of values 310 is obtained based on file version i, the modified data fragment detector 110 can use the set of values 310 to detect modified data fragments in file version i+1.
[0056] Figure 4A and Figure 4B An example is shown of how the modified data fragment detector 110 detects modified data fragments in file version i+1. For example, (window size and...) Figure 3A and Figure 3B (The same as sliding window 302) Sliding window 402 can move across file version i+1 in direction 408.
[0057] Figure 4A The diagram shows a sliding window 402 at its initial position relative to file version i+1, with the starting point of the sliding window 402 located at the beginning 404 of file version i+1. The data portion 420 of file version i+1 in the sliding window 402 is provided to VC 406, which calculates the value 422 based on the data portion 420 in the sliding window 402. VC 406 performs an operation... Figure 3A and Figure 3B The same calculation as VC 306.
[0058] Value 422 is associated with a first index corresponding to the initial position of sliding window 402. Value 422 is compared with a first comparison value from the set of values 310, where the first comparison value is associated with the first index corresponding to the initial position of sliding window 402. If value 422 matches the first comparison value, the modified data fragment detector 110 determines that data portion 420 is not a modified data fragment. However, if value 422 does not match the first comparison value, the modified data fragment detector 110 determines that data portion 420 is a modified data fragment.
[0059] Figure 4B This shows that the sliding window 402 is in a different position relative to file version i+1. Figure 4B The data portion 424 of file version i+1 in the sliding window 402 at the position shown is provided to VC 406, which calculates value 426 based on the data portion 424 in the sliding window 402.
[0060] The value 426 corresponds to Figure 4B The position of the sliding window 402 is associated with a second index. The value 426 is compared with a second comparison value from the set of values 310, wherein the second comparison value in the set of values 310 corresponds to... Figure 4B The second index of the position of the sliding window 402 is associated. If the value 426 matches the second comparison value, the modified data fragment detector 110 determines that the data portion 424 is not a modified data fragment. However, if the value 426 does not match the second comparison value, the modified data fragment detector 110 determines that the data portion 424 is a modified data fragment.
[0061] The advancement of the sliding window 402 in the successive iterations of the modified data fragment detector 110 for detecting modified data fragments can have the same characteristics as... Figure 3A and Figure 3B The sliding window 302 uses the same sliding increment. For example, the sliding window 402 can advance M bytes (M≥1).
[0062] To increase the likelihood that data segments added to accumulator buffer 112 include modified data (and correspondingly reduce the likelihood that data segments added to accumulator buffer 112 include unmodified data), data segments identified as modified by modified data segment detector 110 include data from a subset of the window in which modified data segments are detected. Figure 4C It shows Figure 4A and Figure 4B The sliding window 402 has four different positions. The first sliding window at the first position is denoted as 402A, the second sliding window at the second position is denoted as 402B, the third sliding window at the third position is denoted as 402C, and the fourth sliding window at the fourth position is denoted as 402D.
[0063] These four sliding windows together constitute a sliding window run. In other words, the sliding window run covers multiple consecutive positions of a given sliding window relative to the file.
[0064] The first sliding window 402A starts at position 430A. The second sliding window 402B is offset by a sliding increment relative to sliding window 402A. The second sliding window 402B starts at position 430B. The third sliding window 402C is offset by a sliding increment relative to sliding window 402B. The third sliding window 402C starts at position 430C. The fourth sliding window 402D is offset by a sliding increment relative to sliding window 402C. The fourth sliding window 402D starts at position 430D. Therefore, Figure 4C The sliding window operation shown includes four sliding windows 402A to 402D that are continuously offset from each other by sliding increments. In other words, sliding window 402B is offset by a sliding increment relative to sliding window 402A, sliding window 402C is offset by a sliding increment relative to sliding window 402B, and sliding window 402D is offset by a sliding increment relative to sliding window 402C.
[0065] More generally, the operation of a sliding window can include P (P>1) sliding windows that are successively offset from each other by sliding increments. In other words, in the operation of P sliding windows, a second sliding window is offset from the first sliding window by a sliding increment, a third sliding window is offset from the second sliding window by a sliding increment, and so on.
[0066] The first sliding window 402A contains data segment 442A, which is detected as modified by the modified data segment detector 110, and the fourth sliding window 402D contains data segment 442D, which is detected as modified by the modified data segment detector 110. Note that the modified data segment detector 110 may assume that the inner data segments 442B and 442C are modified because they are located between the first data segment 442A and the last data segment 442D detected as modified in the operation. Therefore, the modified data segment detector 110 does not need to separately compare the values corresponding to the inner data segments 442B and 442C with the corresponding values in the set of values 310 representing file version i. Skipping the comparison of the inner data segments 442B and 442C reduces the workload of the modified data segment detector 110 and improves its efficiency.
[0067] Although all four data segments 442A through 442D are identified as modified data segments, the modified data segment detector 110 does not add all four data segments 442A through 442D to the accumulator buffer 112. Instead, the modified data segment detector 110 selects a subset of data segments 442A through 442D to add to the accumulator buffer 112. For example, the modified data segment detector 110 selects the inner data segments 442B and 442C (covered by the corresponding inner sliding windows 402B and 402C) to add to the accumulator buffer 112. The modified data segment detector 110 does not add the outer data segments 442A and 442D (covered by the corresponding outer sliding windows 402A and 402D) to the accumulator buffer 112.
[0068] More generally, in a given run of P sliding windows containing modified data segments, the modified data segment detector 110 selects data segments from a subset of the P sliding windows and adds them to the accumulator buffer 112. For example, the selected subset of sliding windows includes the inner sliding windows of the run, and the selected subset of sliding windows does not include the outer sliding windows of the run, such as the first and last sliding windows of the run.
[0069] Figure 5 This is a flowchart of the process of modifying the data fragment detector 110. For the current position of the sliding window 402 relative to file version i+1, the modified data fragment detector 110 compares the current value of the data portion in the sliding window 402 at the current position with the corresponding comparison value in the set of values 310 representing file version i (at 502). If the current value matches the corresponding comparison value, the modified data fragment detector 110 slides the sliding window 402 by the sliding increment (at 504) and moves forward back to task 502.
[0070] However, if the current value does not match the corresponding comparison value, it indicates that the data portion in the sliding window 402 at the current position is a modified data fragment. In response to determining that the current value does not match the corresponding comparison value, the modified data fragment detector 110 determines (at 506) whether the sliding window at the current position is the first sliding window in operation. In response to determining that the sliding window at the current position is the first sliding window in operation, the modified data fragment detector 110 slides (at 508) the window size of the sliding window 402 (rather than just the sliding increment). For example, the sliding increment could be 1 byte, and the window size could be 4 bytes. In this example, sliding the window size of the sliding window 402 means sliding the sliding window 402 by 4 bytes.
[0071] If the sliding window at the current position is the first sliding window in operation, then sliding the sliding window by the window size will skip the comparison of the internal data segments covered by the inner sliding window in operation.
[0072] After sliding window 402 resizes (at 508), the Modify Data Fragment Detector 110 returns to execute tasks 502, 504, and 506. The Modify Data Fragment Detector 110 determines (at 510) whether the sliding window at its current position is the last sliding window in the process. If not, the Modify Data Fragment Detector 110 slides the sliding window (at 504) by a sliding increment and proceeds back to task 502.
[0073] In response to determining that the sliding window at the current position is the last sliding window in the run, the data fragment detector 110 modifies the data fragment of the inner sliding window (at 512) to the accumulator buffer 112. Then, the data fragment detector 110 modifies the sliding window to slide (at 508) the window size and moves forward back to task 502 for the next run.
[0074] When the accumulator buffer 112 is filled, the data encryption detector 114 applies a set of encryption detection techniques (single encryption technique or multiple encryption techniques) to the data segments in the accumulator buffer 112. For example, the data segments in the accumulator buffer 112 to which the data encryption detector 114 applies the set of encryption detection techniques can have a size of 512 bytes or some other size, such as 1kB, 2kB, etc., up to the total size of the accumulator buffer 112.
[0075] like Figure 6 As shown, the encryption detection window 602 covers the data segment 604 in the accumulator buffer 112. The encryption detection window 602 may span less than the entire accumulator buffer 112 (in... Figure 6(as shown in the example), or alternatively, the encryption detection window 602 can span the entire accumulator buffer 112.
[0076] Data encryption detector 114 applies a set of encryption detection techniques to data segment 604 defined by encryption detection window 602. When data encryption is detected with high confidence (e.g., two or more encryption detection techniques indicate that data encryption has occurred, or alternatively, the encryption detection techniques output a metric indicating that data encryption has been detected by exceeding a threshold value), data encryption detector 114 can indicate that the data in data segment 604 has been encrypted. Data encryption detector 114 can update encrypted data count 134 (e.g., increment encrypted data count 134 by a certain number of bytes). If data segment 604 is not encrypted, data encryption detector 114 does not update encrypted data count 134.
[0077] After applying a set of encryption detection techniques to data segment 604, data encryption detector 114 can shift the position of encryption detection window 602 to cover another data segment in accumulator buffer 112. Data encryption detector 114 can then determine whether the data segment covered by the shifted encryption detection window 602 is encrypted.
[0078] When the data encryption detector 114 reaches the last data segment in the accumulator buffer 112, it can shift the encryption detection window 602 to the beginning of the accumulator buffer 112. Note that after applying data encryption detection to a given data segment at the current position of the encryption detection window 602, the data segment can be removed from the accumulator buffer 112, allowing the modified data segment detector 110 to add additional modified data segments to the empty portion of the accumulator buffer 112. In this way, the accumulator buffer 112 can be continuously filled with modified data segments while the data encryption detector 114 determines whether any of the data segments in the accumulator buffer 112 covered by the encryption detection window 602 has been encrypted.
[0079] As described above, if the data encryption detector 114 determines that more than a certain threshold amount of file version i+1 has been encrypted (e.g., based on the ratio of encrypted data count 134 to the total size of file version i+1), the data encryption detector 114 may stop the encryption detection process and may mark file version i+1 as encrypted.
[0080] Then, the data encryption detector 114 can proceed to process another file. Being able to stop the encryption detection process early when a threshold amount of a file is determined to be encrypted allows the encryption detection of the file to proceed more quickly.
[0081] Figure 7This is a block diagram of a non-transitory machine-readable or computer-readable storage medium 700 that stores machine-readable instructions that, when executed, cause the system to perform various tasks. The system may include one or more computers.
[0082] Machine-readable instructions include a modified data fragment identification instruction 702, used to identify data fragments of a data object that have been modified relative to different versions of the data object. In some examples, different versions of the data object are defined by a set of values (e.g., Figure 3A and Figure 3B (310) indicates that the data fragment identification instruction 702 can compare a value obtained from a data portion of a data object with a corresponding value in that set of values. In some examples, based on the comparison instruction, a given data fragment of the data object is identified as being modified relative to a different version of the data object, whereby a first value obtained from a first portion of the data object differs from a second value corresponding to a corresponding portion of a different version of the data object.
[0083] Machine-readable instructions include a data fragment accumulation instruction 704, used to accumulate data fragments into a buffer. Data fragments accumulated into the buffer are modified data fragments. Data fragments not recognized as modified are not added to the buffer. In some examples, the buffer includes... Figure 1 The accumulator buffer 112.
[0084] The machine-readable instructions include cryptographic metric calculation instructions 706 for calculating a metric based on data in a buffer, said data including modified data segments. The metric is generated by applying one or more cryptographic detection techniques to the data in the buffer. The metric may include one or more measures of randomness generated by one or more cryptographic detection techniques.
[0085] The machine-readable instructions include intermittent encryption attack determination instructions 708, which are used to determine, based on metrics, whether a data object is a subject of an intermittent encryption attack. If a data object is encrypted for a quantity exceeding a certain threshold, an intermittent encryption attack is indicated.
[0086] In some examples, values from a set of values representing different versions of an object are obtained by a value calculator, which can be implemented using hardware or machine-readable instructions. Multiple instances of the value calculator can be used to obtain the values from this set of values in parallel.
[0087] In some examples, identifying modified data fragments of the data object relative to different versions of the data object includes obtaining a first value based on the data portion of the data object covered by a window of a specified size.
[0088] In some examples, the window is a sliding window that moves relative to the data object to obtain the data portion of the data object, from which a first value is obtained.
[0089] In some examples, the metric is calculated based on a data segment within a specified-size encryption detection window in the buffer. In other examples, the size of the encryption detection window is smaller than the size of the buffer.
[0090] In some examples, machine-readable instructions can shift the encryption detection window across data segments in the buffer, and corresponding metrics can be calculated based on the data segments covered when the encryption detection window is in different positions. The determination of whether a data object is a subject of an intermittent encryption attack is based on these metrics.
[0091] In some examples, machine-readable instructions can determine whether a data object has been encrypted if more than a threshold amount is processed based on the modified data fragments accumulated in the buffer. Machine-readable instructions can then indicate that the data object is a subject of an intermittent encryption attack in response to determining that more than a threshold amount of data object has been encrypted.
[0092] In some examples, machine-readable instructions can cause a sliding window to move relative to a data object. Identifying modified data fragments of the data object includes performing a run covering multiple consecutive positions of the sliding window, including a sliding window at the first position and a sliding window at the last position of the run. Accumulating data fragments into the buffer includes adding data fragments covered by a sliding window at an intermediate position between the first and last positions to the buffer, and refusing to add data fragments covered by sliding windows at both the first and last positions to the buffer.
[0093] Figure 8 This is a block diagram of a system 800 that may include one or more computers. System 800 includes a processor 802 (or multiple processors). System 800 includes a storage medium 804 storing machine-readable instructions that can be executed on processor 802 to perform various tasks. The machine-readable instructions executable on the processor may refer to instructions that can be executed on a single processor or instructions that can be executed on multiple processors.
[0094] The machine-readable instructions in storage medium 804 include first data object representation instructions 806 for calculating a set of values representing a first version of a data object. The values in this set may include a corresponding data portion of the first version of the data object or a hash value obtained by applying a hash function to the corresponding data portion of the first version of the data object.
[0095] The machine-readable instructions in storage medium 804 include modified data fragment detection instructions 808, used to detect modified data fragments by comparing the value of a data portion based on a second version of the data object with a corresponding value in the set of values. In some examples, the value of the second version of the data object is obtained by sliding a window across the second version of the data object. The first set of values is obtained by sliding a window across the first version of the data object.
[0096] The machine-readable instructions in storage medium 804 include a modified data fragment accumulation instruction 810, which is used to accumulate modified data fragments into a buffer.
[0097] The machine-readable instructions in storage medium 804 include encryption detection instructions 812, used to apply encryption detection techniques to the data in the buffer. In some cases, multiple encryption detection techniques can be applied to the data in the buffer.
[0098] The machine-readable instructions in storage medium 804 include intermittent cryptographic attack determination instructions 814, which are used to determine whether a data object is a subject of an intermittent cryptographic attack based on the application of cryptographic detection techniques to the data in the buffer.
[0099] Figure 9 This is a flowchart of process 900 based on some examples of this disclosure. For example, process 900 may be... Figure 1 The intermittent encryption attack detection engine 102 is executed.
[0100] Process 900 includes identifying (at 902) a first data segment of a data object that has been modified relative to a different version of the data object. Identifying the modified data segment includes comparing a value obtained from the data portion of the data object with a corresponding value from a set of values representing different versions of the data object.
[0101] Process 900 includes adding a first data fragment (at 904) to a buffer. Process 900 includes determining (at 906) whether the first data in the buffer, including the first data fragment, is encrypted based on applying an encryption detection technique to the first data in the buffer. The encryption detection technique generates a metric indicating whether the first data is likely to be encrypted.
[0102] Process 900 includes adding (at 908) a second data fragment of a data object to the buffer, the second data fragment being identified as modified relative to a different version of the data object, wherein the second data fragment replaces the first data fragment after determining whether the first data is encrypted. While data in the buffer is being processed, said data may be removed, and additional data fragments may be added to the buffer.
[0103] Process 900 includes determining (at 910) whether the second data in the buffer is encrypted based on applying encryption detection technology to the second data in the buffer, which includes the second data fragment.
[0104] Process 900 includes determining (at 912) whether a threshold amount of a data object has been encrypted based on applying encryption detection techniques to first and second data in the buffer, wherein the encryption of the threshold amount of the data object indicates that the data object is a subject of intermittent encryption attacks.
[0105] Storage media (e.g., Figure 7 700 or Figure 8 The 804 in the specification can include any one or a combination of the following: semiconductor memory devices, such as DRAM or SRAM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory; disks, such as fixed disks, floppy disks, and removable disks; another magnetic medium, including magnetic tape; optical media, such as optical discs (CDs) or digital video discs (DVDs); or another type of storage device. Note that the instructions discussed above may be provided on a single computer-readable or machine-readable storage medium, or alternatively, on multiple computer-readable or machine-readable storage media distributed across a large system having potentially multiple nodes. Such one or more computer-readable or machine-readable storage media are considered part of an article (or article of manufacture). An article or article of manufacture can refer to any single or multiple manufactured components. One or more storage media may be located in a machine that executes the machine-readable instructions or at a remote site from which the machine-readable instructions can be downloaded via a network for execution.
[0106] In this disclosure, unless the context clearly indicates otherwise, the terms “a,” “an,” or “the” are intended to include the plural form as well. Similarly, when used in this disclosure, the terms “includes / including / comprises / comprising” or “have / having” indicate the presence of the stated element but do not preclude the presence or addition of other elements.
[0107] In the foregoing description, numerous details have been set forth to facilitate understanding of the subject matter disclosed herein. However, embodiments may be practiced without some of these details. Other embodiments may include modifications and variations of the details discussed above. The appended claims are intended to cover such modifications and variations.
Claims
1. A non-transitory machine-readable storage medium, comprising instructions that, when executed, cause a system to perform the following operations: Identify data fragments of a data object that have been modified relative to different versions of the data object; The data fragments are accumulated into a buffer; The metric is calculated based on the data in the buffer, the data including the data fragment; as well as The metric is used to determine whether the data object is a subject of intermittent cryptographic attacks.
2. The non-transitory machine-readable storage medium as described in claim 1, wherein, The size of the buffer is greater than a size threshold, and the instruction, when executed, causes the system to perform the following operations: The data has been detected to have filled the buffer. The calculation of the metric is performed in response to the data filling the buffer.
3. The non-transitory machine-readable storage medium as described in claim 1, wherein, The data fragments that identify the data object and have been modified relative to different versions of the data object include: The first value obtained based on a portion of the data object is compared with the corresponding second value based on a different version of the data object.
4. The non-transitory machine-readable storage medium as described in claim 3, wherein, When the instruction is executed, it causes the system to perform the following operations: The second value is obtained in parallel using multiple instances of a value calculator, which calculates the second value based on portions of different versions of the data object.
5. The non-transitory machine-readable storage medium as described in claim 3, wherein, The data fragments that identify the data object and have been modified relative to different versions of the data object include: The first value is obtained based on data in a window of a specified size.
6. The non-transitory machine-readable storage medium as described in claim 5, wherein, The window is a sliding window that moves relative to the data object to obtain a portion of the data object, from which the first value is obtained.
7. The non-transitory machine-readable storage medium as described in claim 3, wherein, The first value includes a portion of the data object.
8. The non-transitory machine-readable storage medium as described in claim 3, wherein, The first value is obtained based on a partial application function to the data object.
9. The non-transitory machine-readable storage medium as described in claim 3, wherein, When the instruction is executed, it causes the system to perform the following operations: Based on the comparison indication, a first value obtained based on a first part of the data object is different from a second value corresponding to a corresponding part of a different version of the data object, and a given data segment of the data object is identified as a data segment that has been modified relative to a different version of the data object.
10. The non-transitory machine-readable storage medium as claimed in claim 1, wherein, The metric is calculated based on a data segment within a specified-size encryption detection window in the buffer.
11. The non-transitory machine-readable storage medium of claim 10, wherein, The size of the encryption detection window is smaller than the size of the buffer.
12. The non-transitory machine-readable storage medium of claim 10, wherein, When the instruction is executed, it causes the system to perform the following operations: Shift the encryption detection window across the data segment in the buffer; and The corresponding metric is calculated based on the data segments covered by the encryption detection window at different positions. The determination of whether the data object is the subject of the intermittent encryption attack is based on the corresponding metric.
13. The non-transitory machine-readable storage medium of claim 12, wherein, When the instruction is executed, it causes the system to perform the following operations: Determining whether the data object is encrypted based on processing the modified data fragments accumulated in the buffer; and In response to determining that the amount of data object encrypted exceeds a threshold, the data object is indicated to be the subject of the intermittent encryption attack.
14. The non-transitory machine-readable storage medium as claimed in claim 1, wherein, The metric is a first metric obtained using a first encryption detection technique, and the instruction, when executed, causes the system to perform the following operations: A second encryption detection technique, different from the first encryption detection technique, is used to calculate a second metric based on the data in the buffer. The determination of whether the data object is the subject of the intermittent encryption attack is based on the first metric and the second metric.
15. The non-transitory machine-readable storage medium as claimed in claim 1, wherein, When the instruction is executed, it causes the system to perform the following operations: Move the sliding window relative to the data object. The modified data fragment used to identify the data object includes: The operation covers multiple consecutive positions of the sliding window, including the sliding window at the first position during the operation and the sliding window at the last position during the operation. Accumulating the data fragments into the buffer includes: Add a data segment to the buffer that is covered by a sliding window located at an intermediate position between the first and last positions, and Refuse to add the data segments covered by the sliding window at the first and last positions to the buffer.
16. A system comprising: processor; as well as A non-transitory storage medium including instructions that can be executed on the processor to perform the following operations: Calculate a set of values representing the first version of the data object; Modified data fragments are detected by comparing the values of a second version of the data object with corresponding values from the set of values. The modified data fragments are accumulated into a buffer; Encryption detection technology is applied to the data in the buffer; as well as The encryption detection technique is applied to the data in the buffer to determine whether the data object is a subject of intermittent encryption attacks.
17. The system of claim 16, wherein, The instructions can be executed on the processor to perform the following operations: Multiple encryption detection techniques are applied to the data in the buffer. Specifically, determining whether the data object is the subject of the intermittent encryption attack is based on applying the various encryption detection techniques to the data in the buffer.
18. The system of claim 16, wherein, The instructions can be executed on the processor to perform the following operations: The set of values representing the first version of the data object is calculated using the following operations: To slide the first window relative to a first version of the data object, and The value in the set of values is obtained based on the portion of data covered by the first window at a different position relative to the first version of the data object; The second window is slid relative to a second version of the data object; The second version of the value of the data object is obtained based on the data portion of the second window; as well as The value obtained for the second version of the data object is compared with the corresponding value in the set of values representing the first version of the data object.
19. A method comprising: A first data fragment that has been modified relative to a different version of the data object, identified by a system including a hardware processor; The system adds the first data fragment to the buffer; The system determines whether the first data in the buffer is encrypted by applying encryption detection technology to the first data in the buffer, which includes the first data fragment; The system adds a second data fragment of the data object to the buffer, the second data fragment being identified as being modified relative to a different version of the data object, wherein, after determining whether the first data is encrypted, the second data fragment replaces the first data fragment; The system determines whether the second data in the buffer is encrypted by applying the encryption detection technique to the second data in the buffer, which includes the second data fragment; and The system determines whether a threshold value of a data object has been encrypted by applying the encryption detection technology to the first data and the second data in the buffer, wherein the encryption of the threshold value of the data object indicates that the data object is a subject of intermittent encryption attacks.
20. The method of claim 19, wherein, The first data fragment that identifies the data object and is modified relative to a different version of the data object includes: The value obtained from the data portion of the data object is compared with a set of values representing different versions of the data object. Wherein, a value obtained from the data portion of the data object does not match the value in the set of values, indicating that the data segment should be modified.