A ransom attack resistant data recovery method, device and equipment

CN122816993APending Publication Date: 2026-09-25CHENGDU HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510314948.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

相比快照,由于涉及的数据量较大,因此生成备份副本以及后续进行数据恢复操作的耗时间更久,且需要占用大量存储空间

Benefits of technology

[0027]第五方面,本申请实施例提供一种计算机程序产品,其特征在于,当计算机程序产品在处理器上运行时,使得处理器执行第一方面或第一方面的任一种可能的实现方式所描述的方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122816993A_ABST
    Figure CN122816993A_ABST
Patent Text Reader

Abstract

A ransom attack resistant data recovery method, device and equipment relate to the technical field of data storage. The method comprises: receiving a write operation instruction for a first logical address LBA in a storage area, the first LBA creating a first snapshot, the first snapshot having the latest time stamp in a history snapshot record of the first LBA, and in the first snapshot, the first LBA being mapped to a first physical address PBA; the first LBA having a state flag and a PBA chain, the state flag being used to represent whether the data in the first LBA has been read, and the PBA chain including the PBA to which the first LBA is mapped in the history snapshot and being sorted according to the time stamp; if the data in the first LBA has been read, redirecting the write operation instruction to a second PBA; creating a second snapshot for the second PBA, and adding the second PBA to the PBA chain according to the time stamp order of the second snapshot and the history snapshot; and when it is identified that the write operation instruction is one of the behaviors of implementing a ransom attack, determining the first PBA closest to the second PBA from the PBA chain to execute data recovery.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data storage technology, and in particular to a data recovery method, apparatus and equipment for preventing ransomware attacks. Background Technology

[0002] Ransomware attacks occur when attackers encrypt or steal data, demanding a ransom from victims to regain access or prevent data breaches. For storage systems, data backup and recovery are the last line of defense against ransomware attacks. Currently, mainstream ransomware protection solutions typically combine snapshots and backup copies to record the original data. After a ransomware attack, the goal is to recover the data from the most recent clean snapshot or copy, restoring it to the state just before the attack.

[0003] In data backup and logical corruption protection scenarios, such as ransomware protection, snapshots are used to provide a read-only copy of data at a specified point in time, recording data changes since the last snapshot. However, snapshots are usually created at certain time intervals. Thus, if new data is written between two snapshots, and this new data is not protected by the snapshot but is still subject to a ransomware attack, when the storage system performs data recovery using the most recent snapshot, this newly written data will be corrupted or lost, resulting in low reliability of the data recovery operation.

[0004] A backup copy is a complete copy of the data in the storage system. Creating a backup copy typically involves all data blocks (the smallest unit of data storage and transmission mentioned above), and these blocks are fully copied regardless of whether they have changed. This ensures that data can be recovered from the backup copy in the event of a ransomware attack. Compared to snapshots, because of the larger amount of data involved, creating a backup copy and subsequent data recovery operations take longer and require more storage space.

[0005] In summary, none of the aforementioned anti-ransomware solutions in the relevant technologies can meet user needs. Summary of the Invention

[0006] This application provides a data recovery method, apparatus, computing device, computer storage medium, and computer program product to prevent ransomware attacks, which can improve the reliability of data recovery operations and reduce the occupation of storage space.

[0007] In a first aspect, embodiments of this application provide a data recovery method against ransomware attacks. The method includes: receiving a write operation instruction on a first logical address (LBA) in a storage area, wherein the first LBA has a first snapshot, which is a snapshot with the latest timestamp among historical snapshots of the first LBA, and the first snapshot records a mapping relationship between the first LBA and a first physical address (PBA); the first LBA has a status flag and a PBA chain, wherein the status flag is used to indicate whether the data in the first LBA has been read, and the PBA chain includes the PBAs mapped by the first LBA in the historical snapshots, and the PBAs in the PBA chain are arranged in the order of their respective historical snapshot timestamps; if the status flag indicates that the data in the first LBA has been read, then a write operation instruction is executed on a second PBA, wherein the second PBA is a redirection address of the first LBA; a second snapshot is created for the second PBA, and the second PBA is added to the PBA chain according to the timestamp order of the second snapshot and the historical snapshots; if it is determined that the write operation instruction is one of the acts of a ransomware attack, the first PBA with the closest timestamp to the second PBA is determined from the PBA chain, and a data recovery operation is performed from the first PBA.

[0008] In this embodiment, since ransomware attacks require reading data first, then encrypting it and writing it back to the storage system, corresponding status identifiers can be added to the LBAs in the storage area of ​​the storage system to describe the data read records on these LBAs. Thus, when the storage system creates a snapshot according to a preset snapshot creation strategy, if a write operation instruction for a certain LBA (first LBA) is received between two global snapshot creations (i.e., snapshots created by the storage system for all protected LBAs in the storage area), a redirected write operation is performed to prevent the current redirected write operation from overwriting the data on the PBA previously mapped to the first LBA, and a separate snapshot (second snapshot) is created for the PBA (second PBA) involved in the current redirected write operation. Then, the second snapshot and the PBAs mapped to the first LBA in historical snapshots are sorted according to their respective historical snapshot timestamps to form a new PBA chain. Therefore, if the current redirected write operation is a normal operation, then the second snapshot reflects the latest copy of the newly written data. If the redirected write operation is part of a ransomware attack, then the PBA with the closest timestamp to the second PBA is queried from the PBA chain, and this PBA is used as the recovery point for data recovery. In other words, the PBA with the closest timestamp to the second PBA is the PBA in the current PBA chain that is adjacent to the second PBA and whose timestamp is earlier than the second PBA (i.e., the first LBA). In this way, data loss can be avoided during data recovery, improving the reliability of data recovery. Furthermore, since a separate snapshot (non-global) is created for the newly written data between two global snapshots, the storage space occupied is very small, avoiding a significant burden on the storage system.

[0009] In some possible implementations, after receiving a write operation instruction for a first logical address (LBA) in the memory area, the method includes: if a status flag indicates that the data in the first LBA has not been read, then searching for a target PBA mapped to the first LBA in the memory area, wherein the target PBA is the first PBA or a PBA other than the first PBA; and executing the write operation instruction on the target PBA.

[0010] In this way, if the LBA flag indicates that the data has not been read, write operations such as overwrite or append write will be performed normally, ensuring the normal writing of user data.

[0011] In some possible implementations, the first LBA is a part of the protected LBAs in the storage area. Before receiving the write operation instruction for the first logical address LBA in the storage area, the method includes: creating a first global snapshot for the protected LBAs according to a preset snapshot creation strategy. The first global snapshot is used to record the mapping relationship between each protected LBA and the corresponding PBA. The first LBA has a mapping relationship with the third PBA in the first global snapshot. The third PBA is added to the PBA chain according to the timestamp order of the first global snapshot and the historical snapshot.

[0012] Thus, the method in this embodiment does not affect the normal creation of global snapshots by the storage system, meaning it is compatible with the storage system's snapshot creation strategy. Furthermore, the generated global snapshot can be linked to the LBA's individual snapshot generation timeline to update the PBA chain, which can be used for subsequent data recovery, improving compatibility while ensuring data recovery reliability.

[0013] In some possible implementations, before receiving a write operation instruction to a first logical address (LBA) in the memory area, the method includes: receiving a read operation instruction to the first LBA; executing the read operation instruction on the first PBA; and setting the status flag of the first LBA to a state where data has been read.

[0014] In this way, given the read-before-write characteristic of ransomware attacks, the read status of LBAs can be recorded using status flags, which facilitates the rapid identification of all LBAs suspected of being under ransomware attacks and improves data recovery efficiency.

[0015] In some possible implementations, the method further includes: receiving a deletion instruction for the first LBA; if a status flag indicates that the data in the first LBA has been read, then rejecting the deletion instruction and maintaining the valid state of the first PBA, where valid state refers to a state that has not been identified as garbage collection space.

[0016] In this way, by using status flags, LBAs in the data-reading state can be prevented from performing deletion operations, thereby improving the security of data storage.

[0017] In some possible implementations, the method also includes: periodically deleting historical snapshots according to a preset snapshot recycling strategy; after a historical snapshot is deleted, releasing the PBA recorded in the deleted historical snapshot; and updating the corresponding status flag for the LBA recorded in the deleted historical snapshot, so that the corresponding status flag is reset to the data not read state.

[0018] In this way, by periodically reclaiming snapshots through a snapshot reclamation strategy, excessive storage space consumption can be prevented, which helps to ensure the performance of the storage system.

[0019] Secondly, embodiments of this application provide a data recovery device for preventing ransomware attacks. The device includes: a receiving module, configured to receive a write operation instruction for a first logical address (LBA) in a storage area; the first LBA has a first snapshot created on it, the first snapshot being a snapshot with the latest timestamp from historical snapshots of the first LBA, and the first snapshot recording a mapping relationship between the first LBA and a first physical address (PBA); the first LBA has a status flag and a PBA chain, the status flag being used to indicate whether the data in the first LBA has been read, and the PBA chain including the PBAs mapped to the first LBA in historical snapshots, and the PBA chain containing... The PBAs are arranged in order of their respective historical snapshot timestamps; the processing module is used to execute a write operation instruction on the second PBA if the status flag indicates that the data in the first LBA has been read, and the second PBA is the redirection address of the first LBA; the creation module is used to create a second snapshot for the second PBA and add the second PBA to the PBA chain according to the timestamp order of the second snapshot and the historical snapshots; the recovery module is used to determine the first PBA with the closest timestamp to the second PBA from the PBA chain if it is determined that the write operation instruction is one of the actions of a ransomware attack, so as to perform a data recovery operation from the first PBA.

[0020] In some possible implementations, the processing module is also used to: if the status flag indicates that the data in the first LBA has not been read, then search for the target PBA mapped by the first LBA in the storage area, where the target PBA is the first PBA or a PBA other than the first PBA; and execute a write operation instruction on the target PBA.

[0021] In some possible implementations, the first LBA is a part of the protected LBAs in the storage area. The creation module is also used to: create a first global snapshot for the protected LBA according to a preset snapshot creation strategy. The first global snapshot is used to record the mapping relationship between each protected LBA and the corresponding PBA. The first LBA has a mapping relationship with the third PBA in the first global snapshot. The third PBA is added to the PBA chain according to the timestamp order of the first global snapshot and the historical snapshot.

[0022] In some possible implementations, the receiving module is further configured to: receive a read operation instruction for the first LBA; the processing module is further configured to execute the read operation instruction on the first PBA and set the status flag of the first LBA to the state that data has been read.

[0023] In some possible implementations, the receiving module is further configured to: receive a deletion instruction for the first LBA; the processing module is further configured to: if a status flag indicates that the data in the first LBA has been read, refuse to execute the deletion instruction and maintain the valid state of the first PBA, where valid state refers to a state that has not been identified as a garbage collection space.

[0024] In some possible implementations, the processing module is also used to periodically delete historical snapshots according to a preset snapshot recycling strategy; after a historical snapshot is deleted, release the PBA recorded in the deleted historical snapshot; and update the corresponding status flag for the LBA recorded in the deleted historical snapshot, so that the corresponding status flag is reset to the data not read state.

[0025] Thirdly, embodiments of this application provide a computing device, including: at least one memory for storing a program; and at least one processor for executing the program stored in the memory; wherein, when the program stored in the memory is executed, the processor is used to execute the method described in the first aspect or any possible implementation of the first aspect.

[0026] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when run on a processor, causes the processor to perform the method described in the first aspect or any possible implementation thereof.

[0027] Fifthly, embodiments of this application provide a computer program product, characterized in that, when the computer program product is run on a processor, it causes the processor to execute the method described in the first aspect or any possible implementation of the first aspect.

[0028] In a sixth aspect, embodiments of this application provide a chip, characterized in that it includes at least one processor and an interface; the at least one processor obtains program instructions or data through the interface; the at least one processor is used to execute program line instructions to implement the method described in the first aspect or any possible implementation of the first aspect.

[0029] It is understood that the beneficial effects of the second to sixth aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here. Attached Figure Description

[0030] Figure 1 This is a schematic diagram illustrating data recovery using related technologies;

[0031] Figure 2 This is a schematic diagram of the architecture of a data recovery device for preventing ransomware attacks provided in an embodiment of this application;

[0032] Figure 3 This is a schematic diagram of the architecture of a data recovery device for preventing ransomware attacks provided in an embodiment of this application;

[0033] Figure 4 This is a flowchart illustrating the workflow of the data recovery device against ransomware attacks provided in this application embodiment;

[0034] Figure 5 This is a storage system structure diagram provided in an embodiment of this application;

[0035] Figure 6 This is a flowchart illustrating a data recovery method for preventing ransomware attacks provided in an embodiment of this application;

[0036] Figure 7A This is a flowchart illustrating a data recovery method for preventing ransomware attacks provided in an embodiment of this application;

[0037] Figure 7B This is a flowchart illustrating a data recovery method for preventing ransomware attacks provided in an embodiment of this application;

[0038] Figure 8 This is a schematic diagram of the structure of a computing device provided in an embodiment of this application;

[0039] Figure 9 This is a schematic diagram of the structure of a computing device cluster provided in an embodiment of this application;

[0040] Figure 10 This is a schematic diagram of the structure of a computing device cluster provided in an embodiment of this application. Detailed Implementation

[0041] In this article, the term "and / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The symbol " / " in this article indicates that the related objects are in an "or" relationship; for example, A / B means A or B.

[0042] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0043] In the description of the embodiments of this application, unless otherwise stated, "multiple" means two or more, for example, multiple processing units means two or more processing units, multiple elements means two or more elements, etc.

[0044] To facilitate understanding, the technical terms used in this article are explained below.

[0045] A data snapshot is a snapshot of a data set at a specific point in time (the point at which the copy begins). It is also called an instant copy and is a complete and usable copy of the data set.

[0046] A global snapshot is a consistent copy of all protected data blocks in a storage system at a specific point in time.

[0047] Copy-on-Write (COW) is a snapshot technology that delays data protection operations until the host needs to write the data, thus achieving instantaneous data protection. COW requires that host input / output (I / O) operations can only be performed after the protected data has been copied completely.

[0048] Redirect on Write (ROW) is a snapshot technology where, when a host writes to a snapshot source Logical Unit Number (LUN), host I / O is directly redirected to a new data area, without modifying the existing data in the source LUN. When the host reads from the source LUN, I / O is directly read from the new data area. The space for redirected writes is randomly allocated by the storage pool.

[0049] Snapshot rollback refers to restoring the storage system or data state to the state it was in when a snapshot was created. In a Copy-on-Write (COW) scenario, the storage system records the current data state when a snapshot is created. During rollback, the storage system copies data blocks from the snapshot back to primary storage, overwriting the current data. In a Redirected Write-on-Write (ROW) scenario, new data is written to a new location after snapshot creation, while the snapshot retains the old data. During rollback, the storage system points the pointer to the data in the snapshot and discards the newly written data.

[0050] A recovery point is the state of data captured at the time of snapshot creation during data recovery via snapshot rollback; it is essentially a complete copy of the system or data at a specific point in time. In other words, the recovery point is the target state for data recovery.

[0051] OP is short for I / O operation (Input / Output Operation). I / O operation is the process of exchanging data between a computer and external devices (such as disks, networks, memory, etc.).

[0052] Figure 1 This illustrates the principle of data recovery from ransomware attacks using snapshot technology, as described in related techniques. For example... Figure 1 As shown in Figure (1a), the snapshot area of ​​the storage system creates snapshots of data blocks in the storage area (taking data blocks A, B, and C as examples) at certain time intervals according to the snapshot creation strategy. The snapshot area also stores the metadata of all snapshots (i.e., snapshot area metadata). The snapshot area metadata includes the mapping relationship between the logical address (LBA) and physical address (PBA) of the data blocks protected by each snapshot. This mapping relationship is the same as the address mapping table (also known as the address translation table) of the storage area.

[0053] like Figure 1 As shown in Figure (1b), the original LBA of data block B is 0x0001, and the BPA is 0x012E. After the storage system creates a snapshot Snapshot0 for data blocks A, B, and C at a certain moment, and before the next snapshot is created, if data block B protected by snapshot Snapshot0 is modified, the storage system will not overwrite the original data block B. Instead, it will find another available address (PBA: 0x0201) to write the new data block B', and change the PBA mapped by LBA: 0x0001 from 0x012E to 0x0201 from the storage area address mapping table.

[0054] Next, as Figure 1 As shown in (1c), if data block B′, which was normally written, suffers a ransomware attack before the next snapshot is created—that is, data block B′ is illegally modified to B1 and written to PBA:0x0202—the storage area address mapping table will remap LBA:0x0001 to PBA:0x0202. Subsequently, the storage system creates snapshot Snapshot00 according to the snapshot creation policy. Snapshot00 records the address mappings (0x0001:0x0202) that have changed relative to snapshot Snapshot0. Then, when the ransomware attack is detected and blocked from the storage system, because snapshot Snapshot00 contains dirty data (i.e., data that has suffered the ransomware attack), the storage system will find snapshot Snapshot0 as the latest clean copy and recover file X (including data blocks A, B, and C) based on it. Thus, the user-written data block B′ is lost.

[0055] As can be seen, since snapshots record data state over time, they cannot reliably achieve "lossless data recovery." That is, if a data block is written normally before a ransomware attack occurs between two snapshots, the storage system can only restore the data to the state of the most recent snapshot before the ransomware attack. Thus, data written by users after that snapshot is created will be discarded along with the data written during the ransomware attack, resulting in poor data recovery performance of the storage system.

[0056] Furthermore, using a complete backup copy to prevent ransomware attacks would result in long backup and recovery times due to the large amount of backup data, leading to low efficiency and excessive storage space consumption.

[0057] To improve the reliability of data recovery in ransomware attack scenarios and avoid placing a significant burden on storage space, this application provides a ransomware attack-resistant data recovery method. This method primarily uses a preset data structure to represent the data read records of the LBA protected by snapshots. After a protected LBA generates a record of data being read, a separate IO snapshot is created for each newly written data on that LBA. Thus, if newly written data is attacked by ransomware, the latest clean copy before the ransomware attack can be found based on the timing of the IO snapshots of the newly written data, allowing for data recovery and preventing damage or loss of normally written data, thereby improving the reliability of data recovery.

[0058] To facilitate understanding of the technical solution of this application, the architecture of a data recovery device for preventing ransomware attacks provided in the embodiments of this application is described below. This data recovery device for preventing ransomware attacks can be deployed in a centralized or distributed manner.

[0059] For example, Figure 2 The diagram shown is an architectural schematic of a centralized data recovery device for ransomware attack prevention provided in an embodiment of this application. Figure 2 As shown, the data recovery device 100 for preventing ransomware attacks is deployed on a computing device 10, which can be a physical computer or a virtualization device, such as a virtual machine or container.

[0060] In this example, the computing device 10 may include a processor 110, a memory 120 communicatively connected to the processor 110, and a communication interface 130, wherein the processor 110 is the control center of the computing device 10. The processor 110 may be a central processing unit (CPU), a graphics processing unit (GPU), a data processing unit (DPU), a neural processing unit (NPU), etc., but is not limited thereto. The memory 120 may be RAM, such as random access memory (RAM), used to store instructions or data that the processor 110 may access multiple times. The memory 120 may also be a persistent storage disk, such as a disk, hard disk, optical disk, register, read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), non-volatile RAM (NVRAM), etc. The memory 120 can also be used to store programs related to this embodiment.The communication interface 130 may include, but is not limited to, the following types: wired interfaces (such as Ethernet, Universal Serial Bus (USB) interfaces, wireless interfaces (such as Wi-Fi, Bluetooth, ZigBee, Near Field Communication (NFC), cellular network interfaces, etc.), and interfaces within the computing device 10 used for software or hardware interaction (such as Peripheral Component Interconnect Express (PCIe), Serial Advanced Technology Attachment (SATA), Non-Volatile Memory Express (NVMe), Inter-Integrated Circuit (2CI), Serial Peripheral Interface (SPI), Universal Asynchronous Receiver / Transmitter (UART), Application Programming Interface (API), Inter-Process Communication (IPC), shared memory, message queues, sockets, etc.), used for data transmission and reception under the control of the processor 110.

[0061] Figure 2 The device structure shown does not constitute a limitation on the computing device 10 and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0062] In this embodiment, the ransomware-resistant data recovery device 100 can be implemented as part of the storage system X00, participating in the OP operation processing of the storage system X00 and the data recovery process when a ransomware attack is received. The storage system X00 includes a storage area X01 and a snapshot area X02. The storage area X01 is the actual location where data is stored, and the snapshot area X02 is used to manage snapshots. For example, the computing device 10 can receive OP commands issued by upper-layer applications (such as file systems) through the communication interface 130, such as write operation commands, read operation commands, delete commands, etc. The ransomware-resistant data recovery device 100 can perform a series of processing on these OP commands, thereby improving the reliability of data recovery in the event that the storage area X01 is subjected to a ransomware attack.

[0063] For example, such as Figure 2 As shown, the data recovery device 100 for preventing ransomware attacks may include a receiving module 101, a processing module 102, a creation module 103, and a recovery module 104. Among them,

[0064] The receiving module 101 can be used to receive write operation instructions for a first logical address (LBA) in memory area X01. In this example, a first snapshot is created for the first LBA. The first snapshot is the snapshot with the latest timestamp among the historical snapshots of the first LBA. Furthermore, the first snapshot can be a global snapshot of all protected LBAs in memory area X01, or it can be a snapshot that records the mapping relationship of the first LBA separately (also referred to herein as an IO snapshot). In addition, the latest global snapshot before receiving the write operation instruction, and the IO snapshot created separately for the first LBA (or the PBA mapped by the first LBA) after the latest global snapshot and before the write operation instruction, can all be referred to as historical snapshots of the first LBA. In this example, the first LBA also has a status flag and a PBA chain. The status flag is used to indicate whether the data in the first LBA has been read. The PBA chain includes the PBAs mapped by the first LBA in each historical snapshot. The PBAs in the PBA chain are arranged in chronological order from earliest to latest according to the timestamp of their respective historical snapshots.

[0065] The processing module 102 can be used to execute a write operation instruction in the second PBA if the status flag indicates that the data in the first LBA has been read. The second PBA is the redirected address of the first LBA. In this way, if the current write operation instruction is a normal write operation instruction from the user, the new data can be written normally through this redirected write operation, while avoiding the new data from overwriting the original data on the PBA previously mapped by the first LBA.

[0066] The creation module 103 can be used to create a second snapshot for the second PBA and add the second PBA to the PBA chain according to the timestamp order of the second snapshot and the historical snapshot. In this way, a separate snapshot will be created for newly written data to capture the latest data state, and the second PBA that wrote the data will be added to the PBA chain corresponding to the first LBA.

[0067] Recovery module 104 can be used to determine, in the case that a write operation instruction is one of the acts of a ransomware attack, the first PBA whose timestamp is closest to the second PBA in the PBA chain, so as to perform a data recovery operation from the first PBA.

[0068] Thus, since ransomware attacks require reading data first, then encrypting it and writing it back to storage system X00, this embodiment can add corresponding status identifiers to the LBAs in storage area X01 of storage system X00 to describe the data read records on these LBAs. Subsequently, when storage system X00 creates a snapshot according to a preset snapshot creation strategy, if a write operation instruction for a certain LBA (first LBA) is received between two global snapshot creations (i.e., snapshots created by storage system X00 for all protected LBAs in storage area X01), a redirected write operation is performed to prevent the current redirected write operation from overwriting the data on the PBAs previously mapped to the first LBA, and a separate snapshot (second snapshot) is created for the PBA (second PBA) involved in the current redirected write operation. Then, the second snapshot and the PBAs mapped to the first LBA in historical snapshots are sorted according to their respective historical snapshot timestamps to form a new PBA chain. Therefore, if the current redirected write operation is a normal operation, then the second snapshot reflects the latest copy of the newly written data. If the redirected write operation is part of a ransomware attack, then the PBA with the closest timestamp to the second PBA is queried from the PBA chain. The first PBA, which is closest to the second PBA and has a timestamp earlier than the second PBA, is then used as the recovery point for data recovery. In this way, data loss can be avoided during data recovery, improving the reliability of data recovery. Furthermore, because a separate (non-global) snapshot is created for the newly written data between two global snapshots, the storage space occupied is very small, avoiding a significant burden on the X00 storage system.

[0069] It should be noted that in practical applications, the above... Figure 2 The data recovery device 100 shown for preventing ransomware attacks can be implemented through software, or through hardware or a combination of hardware and software.

[0070] The ransomware-resistant data recovery device 100, as an example of a software functional unit, may include code running on a computing instance. The computing instance may include at least one of a host, a virtual machine, and a container. Further, the aforementioned computing instance may be one or more. For example, the ransomware-resistant data recovery device 100 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including one or more geographically proximate data centers. Typically, a region may include multiple AZs.

[0071] Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same Virtual Private Cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, as well as between VPCs in different regions, requires a communication gateway to be set up within each VPC to enable interconnection between VPCs.

[0072] In some possible implementations, the ransomware-resistant data recovery device 100 can also be as follows: Figure 3 As shown, multiple computing devices 10 are distributed and deployed in the device cluster 00 to achieve the data recovery operation against ransomware attacks as described above, which will not be repeated here.

[0073] Next, the working principle of the data recovery device 100 for preventing ransomware attacks provided in this embodiment will be described in detail.

[0074] In this embodiment, reference continues to be made to Figure 1 Users can specify which data in the X00 storage system to protect, such as bank call detail records or user log data. The X00 storage system can then create snapshots of this protected data (also known as "sensitive data") at regular intervals (e.g., seconds, hours, days). Essentially, creating a snapshot of the protected data means creating a snapshot of the logical block address (LBA) storing this data, also known as the protected LBA and physical block address (PBA), to capture the latest data state on the LBA at the time of the snapshot. Sensitive data is stored in blocks, and snapshots of these blocks can be stored in the snapshot area X02. The snapshot area records the mapping relationship between the LBA and PBA protected by the snapshot through snapshot area metadata.

[0075] In this embodiment, the data recovery device 100 for ransomware attack protection also creates an LBA bitmap for the LBAs protected by the snapshot. A status flag, also called a status bit, is set for each protected LBA in the LBA bitmap to indicate whether the corresponding LBA has been subjected to a data read operation after the snapshot was created.

[0076] For example, the status flags in the LBA bitmap can represent LBA data read records in a Boolean-like manner. For instance, a status flag value of "0" indicates that the data in the corresponding LBA has not been read, and a status flag value of "1" indicates that the data in the corresponding LBA has been read. In this way, each status flag only occupies one bit, which requires less space and is easy to implement.

[0077] In this way, since ransomware attacks require reading the data at the address protected by snapshot area X02 before data encryption can be performed to launch the ransomware attack, all LBAs that have been attacked by ransomware will leave data reading records on the LBA bitmap. Based on the LBA bitmap, LBAs suspected of being attacked by ransomware can be quickly located to perform subsequent data recovery operations, prevent data damage or loss, and ensure the data security and reliability of storage system X00.

[0078] The following is combined Figure 4 The example shown illustrates the working principle of the data recovery device 100 for protection against ransomware attacks.

[0079] like Figure 4 As shown, storage area X01 of storage system X00 stores protected data blocks A, B, and C. Storage system X00 creates global snapshots of all protected data blocks A, B, and C at certain time intervals (such as intervals on the order of seconds, but not limited to this). In this example, refer to... Figure 4 As shown in (4a), the storage system X00 creates a global snapshot Snapshot1 for all protected data blocks A, B, and C at time t1. Global snapshot Snapshot1 records the mapping relationship between LBAs and PBAs of data blocks A, B, and C through snapshot area metadata. In response, the ransomware-resistant data recovery device 100 also creates a matching LBA bitmap M1 for global snapshot Snapshot1. LBA bitmap M1 records the data read records for each LBA protected by global snapshot Snapshot1. For example, the LBA bitmap M1 can use status flags to represent the data read records of the corresponding LBAs. For instance, for any LBA protected by global snapshot Snapshot1, if the data in that LBA has been read after time t1, the status flag matching that LBA in LBA bitmap M1 is set to "1"; if the data in that LBA has not been read since time t1, the status flag matching that LBA in LBA bitmap M1 is set to "0". Understandably, the value of the status flag can also be any number or symbol other than "0" and "1". In other words, the value of the status flag only needs to be indicative information that can distinguish between the two states of "data has been read" and "data has not been read".

[0080] In this example, Figure 4 As shown in (4b), after creating global snapshot Snapshot1 and before creating the next global snapshot Snapshot2, if the receiving module 101 of the data recovery device 100 provided in this embodiment receives read operation instructions OP1 and OP2 for LBA:0x0000 and LBA:0x001 shown in (4b) and write operation instruction OP3 for LBA:0x0002 from the upper-layer application, then the device 100 can perform the following operations in response to OP1, OP2, and OP3:

[0081] According to the address mapping table of storage area X01, OP1 and OP2 are passed to the corresponding PBA:0x012D and PBA:0x012E for execution, respectively. Then, the processing module 102 of the ransomware-resistant data recovery device 100 can set the values ​​of the status flags of LBA:0x0000 and LBA:0x0001 in the LBA bitmap M1 to "1" to indicate that the data in these two LBAs has been read.

[0082] Furthermore, when processing module 102 performs the write operation requested by OP3 on LBA:0x0002, it first checks the status flag of LBA:0x0002 in LBA bitmap M1. If the value of the status flag is "0", that is, LBA:0x0002 has not been read since time t1, it can be determined that the current OP3 is an overwrite write or an append write. Then, processing module 102 can search for the PBA mapped to LBA:0x0002 in memory area X01 (it may be the PBA where the current data block C is located: 0x0200, or it may be another free PBA: 0x0203) to perform the write operation and obtain a new data block C'.

[0083] Next, as Figure 4As shown in (4c), if the receiving module 101 receives a write operation instruction OP4 from the upper-layer application for LBA:0x0001, the processing module 102 will check that LBA:0x0001 has a record that has been read in the LBA bitmap M1. Then, the processing module 102 will perform a redirect write, writing the data block B′ requested by OP4 to PBA:0x0202. Then, PBA:0x0202 is the redirect address of LBA:0x0001, and the data block B is still retained in PBA:0x012E, which was originally mapped to LBA:0x0001. Furthermore, after the data block B′ is written to PBA:0x0202, the creation module 103 of the data recovery device 100 for ransomware attack prevention will create an IO snapshot IO_Snapshot B′ for the data block B′ separately. This IO snapshot IO_Snapshot B′ is used to record the mapping relationship between LBA:0x0001 and PBA:0x0202. Furthermore, the creation module 103 generates a PBA chain structure corresponding to LBA:0x0001 based on the timing relationship between the global snapshot Snapshot1 and the IO snapshot IO_Snapshot B′. The PBA chain structure represents the sequential timing relationship between PBA:0x0202, corresponding to LBA:0x0001 in the global snapshot Snapshot1, and the PBAs redirected by LBA:0x0001 in all IO snapshots. For example, based on the timing relationship between the global snapshot Snapshot1 and the IO snapshot IO_Snapshot B′, the PBA chain structure corresponding to LBA:0x0001 is: "PBA:0x012E in global snapshot Snapshot1 → PBA:0x0202 in IO snapshot IO_Snapshot B′".

[0084] Similarly, such as Figure 4 As shown in (4d), if a write operation instruction OP5 is subsequently received for LBA:0x0001, based on a similar write principle, a redirection write will be performed on the data block B1 requested by OP5 in another PBA, such as PBA:0x0204, and an IO snapshot IO_Snapshot B1 will be created separately for data block B1. Then, the PBA chain structure corresponding to LBA:0x0001 will be appended as: "PBA:0x012E in global snapshot Snapshot1 → PBA:0x0202 in IO snapshot IO_Snapshot B' → PBA:0x0204 in IO snapshot IO_Snapshot B1".

[0085] In this example, if no ransomware is detected during the processing of all the aforementioned I / O operation instructions OP1 to OP5, then all I / O operations performed according to OP1 to OP5 can be considered normal I / O operations. In this case, storage area X01 contains both dirty data and clean data. Dirty data refers to data that has been modified but not yet written back to persistent storage, such as data blocks C' and B' mentioned above. Clean data refers to data that has been modified and written back to persistent storage, such as data blocks A, B, and C.

[0086] In this example, such as Figure 4 As shown in (4d), if the aforementioned data block B1 is the encrypted result of data block B′, and the write operation instruction OP4 is a ransomware attack attempting to overwrite data block B′ with data block B1, then after executing the above... Figure 4 Following the write operation shown in (4d), the storage system X00 or its protection program will detect and block the ransomware attack. Subsequently, the ransomware attack-protected data recovery device 100 will be triggered to perform a data recovery operation. For example, the data recovery operation process is as follows:

[0087] Recovery module 104 searches for all LBAs in LBA bitmap M1 with a status flag of "1" (meaning they have been read). The LBA of the data block under ransomware attack must be among them. This identifies LBA:0x0000 and LBA:0x001. Next, it searches the PBA chains for LBA:0x0000 and LBA:0x001 respectively, and based on the temporal relationships within these PBA chains, finds the PBA in each chain that is closest to the current ransomware attack time (excluding the PBA that was attacked). Therefore, the PBA closest to the current ransomware attack timestamp in the PBA chain of LBA:0x0000 is 0x012D, and the PBA closest to the current ransomware attack time in the PBA chain of LBA:0x0001 is 0x0202.

[0088] Therefore, the recovery module 104 determines the latest recovery points as 0x012D:A and 0x0201:B'. Then, based on the determined recovery points, a snapshot rollback is performed, which can recover data blocks A and B' for all LBAs suspected of being under ransomware attacks. Other LBAs that have not been under ransomware attacks store data normally and do not require data recovery operations.

[0089] Thus, in this embodiment, the ransomware-resistant data recovery device introduces IO snapshots of individual data blocks to record all changes to the protected data blocks in storage area X01 between two adjacent global snapshots. This is beneficial in two ways: firstly, it helps to deal with ransomware attacks that occur during this period, avoiding data loss due to data recovery based solely on the latest global snapshot; secondly, since the IO snapshot is not global (the entire file, file system, or even volume), but only records the data blocks that have been written, it can reduce the burden on snapshot area X02 in high-frequency write scenarios, thereby improving the performance of storage system X00. Furthermore, since ransomware attacks are characterized by reading data before performing encryption, the ransomware-resistant data recovery device in this embodiment can exclude normal write operations such as overwrite and append writes based on LBA bitmaps. These normal write operations will not interfere with the data recovery process against ransomware attacks, resulting in high data recovery efficiency and accuracy.

[0090] It should be noted that for scenarios involving high-frequency (e.g., second-level) snapshot creation, such as financial systems like stock / securities trading systems and bank call detail record systems, online service systems like e-commerce and social platforms, online gaming systems, monitoring of IoT devices like industrial equipment or smart homes, and real-time database transaction logs, snapshots need to be created at second-level or even shorter intervals. Furthermore, the data reading frequency in these scenarios is extremely low, but the data security requirements are high. However, ransomware attacks require reading the data protected at the address of snapshot area X02 before encryption can be performed. Therefore, in this embodiment, the LBA bitmap can effectively identify all LBAs suspected of being subjected to ransomware attacks. Thus, for any LBA recorded in the snapshot, if it is read after the snapshot is created, a read record is generated in the bitmap corresponding to the snapshot. LBAs with read records can be prevented from having their data modified or deleted, thereby improving data security.

[0091] For example, after completing the data recovery operation, the data recovery device 100 for ransomware attack prevention needs to delete the PBAs whose timestamps are after the recovery point from the PBA chain if the PBA used as the recovery point is in the snapshot area X02 mapping table. This ensures the consistency of the mapping relationship in the storage area X01, the snapshot area X02 and the related PBA chains, and prevents adverse effects on subsequent operation execution.

[0092] For example, after completing the data recovery operation, the processing module 102 of the ransomware-resistant data recovery device 100 can reclaim all snapshots (including global snapshots and IO snapshots) according to a preset snapshot reclamation strategy. The snapshot reclamation strategy can indicate that snapshot reclamation operations are triggered under conditions such as the snapshot number reaching the upper limit, snapshot expiration (the validity period can be set, such as 7 days or 30 days), insufficient storage space, or an excessively long snapshot chain. Furthermore, according to the snapshot reclamation strategy, when performing snapshot reclamation operations, priority can be given to deleting snapshots created earlier, deleting snapshots older than a specified time, and deleting snapshots that have not been used for a long time. In this way, the reclaimed snapshots can reduce the occupation of storage space. In this example, any LBA in storage area X01 may be protected by global snapshots and multiple IO snapshots. Therefore, if all snapshots of this LBA are reclaimed, the LBA loses the protection of these snapshots, and all PBAs mapped to this LBA in these snapshots will also be released one by one. These PBAs are marked as free in storage area X01, waiting for garbage space reclamation.

[0093] For example, to avoid filling up the space, the processing module 102 also configures an aging process strategy for IO snapshots and LBA bitmaps to ensure the consistency of information between the IO snapshots and LBA bitmaps and the data stored in storage area X01. The aging process strategy may include, after a global snapshot is deleted, resetting the status flag matching the LBA in the LBA bitmap to an unread state, as the LBA loses the protection of the deleted snapshot. In some examples, the aging process strategy may also include deleting the IO snapshots cascaded with the LBA, that is, all IO snapshots that record the LBA.

[0094] In this embodiment, compared to related technologies that rely on global snapshots for data recovery from ransomware attacks, the performance advantage of the ransomware attack recovery device 100 provided in this embodiment is reflected in Table 2 below. That is, during the period between two global snapshots, if the number of LBAs read and written to storage area X01 is m, and each LBA is written n times, then the performance of the ransomware attack recovery device 100 for different operations is shown in Table 2 below:

[0095] Table 2

[0096]

[0097] As shown in Table 2, compared with traditional technologies that rely on global snapshots for data recovery, the ransomware-resistant data recovery device 100 does not incur significant overhead when handling operations such as reading, writing, deleting, snapshot recycling, and snapshot rollback, and it has higher data recovery efficiency when dealing with ransomware attacks.

[0098] The following describes the system architecture or scenarios in which the data recovery device 100 for preventing ransomware attacks provided in this embodiment can be applied.

[0099] For example, the data recovery device 100 for preventing ransomware attacks can be applied to, for example... Figure 5 The storage system architecture shown in Figure (5a) participates in the implementation of the data protection function (snapshot feature) of storage system X00. In this example, storage system X00 is divided into production area X03 and snapshot area X02, each with its own logical volume and storage area (X011, X011). The logical volume is responsible for maintaining the mapping between LBA and PBA, as well as addressing, garbage collection, wear leveling, and other features. The storage area (X011, X011) provides physical blocks indexed by PBA and is the actual location where data is stored. In this way, the data recovery device 100 for ransomware attacks can be implemented as part of the software functions of the logical volume. That is, when the host side (the device deploying the upper-layer application) requests to write data to storage system X00, the logical volume is responsible for converting the LBA indicated by the request into a PBA. The data recovery device 100 for ransomware attacks performs snapshot operations (such as checking whether the LBA is protected by snapshots and creating cascading IO snapshots), and finally writes the data to the specified PBA in storage area X011. Furthermore, for CoW snapshots, when creating a snapshot, the protected data must be copied to the storage area X012 corresponding to snapshot area X02.

[0100] The data recovery device 100 for ransomware attacks can be applied to, for example... Figure 5 The storage system architecture shown in Figure (5b) employs a real-time RoW snapshot mechanism. Storage system X00 is divided into a production area X03 and a snapshot area X02, each with its own logical volume. However, snapshot area X02 does not require a separate snapshot storage area; data in both production area X03 and snapshot area X02 is stored in storage area X02. Snapshot area metadata only maintains the mapping relationship between LBAs and PBAs for protected data. The read / write logic of production area X00 determines the actual PBA where the data is stored based on the snapshot metadata. If the PBA to be written is protected by the snapshot, production area X03 will find an available PBA to write the data to.

[0101] In some possible implementations, the ransomware-resistant data recovery device 100 can be deployed on production storage devices (main memory), especially suitable for flash memory storage (which inherently possesses RoW capabilities). In some possible implementations, the ransomware-resistant data recovery device 100 can be implemented as software, possibly encapsulated as a separate tool, microservice, API, component, plugin, or module, as a value-added feature to the main memory's ransomware protection capabilities, thereby enhancing the product competitiveness of the main memory.

[0102] Next, based on the content described above, a data recovery method for preventing ransomware attacks provided by embodiments of this application will be introduced. It is understood that this method is proposed based on the content described above, and some or all of its content can be found in the description above.

[0103] Please see Figure 6 , Figure 6 This is a flowchart illustrating a data recovery method for preventing ransomware attacks provided in an embodiment of this application. It is understood that this method can be executed by any device, equipment, platform, or device cluster with computing and processing capabilities. For ease of understanding and explanation, this embodiment uses... Figure 2 The example shown is executed on the computing device 10, but it is not limited to this. Figure 6 As shown, the method may include:

[0104] S601 receives a write operation instruction for the first logical address LBA in the memory area.

[0105] In this embodiment, the computing device can receive write operation instructions issued by an upper-layer application (such as a file system). The write operation instructions may include the operation type and the first logical address (LBA) involved.

[0106] For example, the first LBA is one of the LBAs protected by snapshots in the storage system. At the current moment when a write operation is received, the first LBA may be protected by multiple snapshots. These snapshots can be global snapshots of all protected LBAs in the storage system, or they can be individual IO snapshots of the first LBA (that is, mainly recording the mapping relationship between the first LBA and the corresponding PBA, without recording the mapping relationship of other LBAs). At the current moment, these snapshots all belong to the historical snapshots of the first LBA. For ease of distinction, the snapshot with the latest timestamp among these historical snapshots is also called the first snapshot in this article. The first snapshot is used to record the mapping relationship between the first LBA and the first PBA.

[0107] Furthermore, in this example, the PBAs mapped to the first LBA in the historical snapshot can be arranged according to the timestamp order of the historical snapshot to which the PBA belongs, forming a PBA chain of the first LBA, thereby reflecting the changes that have occurred on the first LBA.

[0108] In addition, the first LBA also has a status flag to indicate whether the data in the first LBA has been read. For example, the status flag can be the status flag configured in the LBA bitmap above. The principle of the LBA bitmap representing the data read record of the LBA can be found in the above description of the LBA bitmap in the data recovery device 100 for ransomware attack prevention, and will not be repeated here.

[0109] S602, if the status flag indicates that the data in the first LBA has been read, then a write operation instruction is executed in the second PBA, where the second PBA is the redirection address of the first LBA.

[0110] In this embodiment, the computing device first queries the value of the status flag of the first LBA according to the write operation instruction. If it is determined that the data in the first LBA has been read, the computing device performs a redirected write operation. That is, the write operation instruction is executed on an available PBA (second PBA) in the storage system to avoid overwriting the data on the first PBA.

[0111] S603, create a second snapshot for the second PBA, and add the second PBA to the PBA chain according to the timestamp order of the second snapshot and the historical snapshot.

[0112] In this example, the computing device also creates a separate IO snapshot, or second snapshot, for the second PBA to record the mapping relationship between the first LBA and the second PBA.

[0113] Next, the computing device adds the second PBA to the PBA chain of the first LBA according to the timestamp order of the second snapshot and the historical snapshot. Since the first PBA is the PBA with the closest timestamp to the current moment in the PBA chain before the second PBA is added, the second PBA is appended after the first PBA in the PBA chain. In this way, suspected ransomware attacks occurring on each LBA can be characterized by the PBA chain.

[0114] S604, if it is determined that the write operation instruction is one of the actions of carrying out a ransomware attack, determine the first PBA whose timestamp is closest to the second PBA from the PBA chain, and perform a data recovery operation from the first PBA.

[0115] In this embodiment, since ransomware attacks require reading data first, then encrypting it and writing it back to the storage system, if the computing device recognizes that the write operation instruction executed in S602 is one of the actions of a ransomware attack (i.e., the write operation instruction is used to write back the encrypted data), the computing device can find the first PBA in the PBA chain whose timestamp is closest to the second PBA and whose timestamp is earlier than the second PBA. Then, the first PBA is used as the recovery point to perform a data recovery operation. That is, performing a data recovery operation means using the first snapshot corresponding to the first PBA as the latest clean copy to obtain the data on the first PBA.

[0116] In this way, if a write operation instruction for the first LBA is received between two global snapshot creations, since it is a redirected write operation, it avoids overwriting the data on the PBA previously mapped to the first LBA. Snapshot protection and PBA chain recording are performed for the PBAs involved in the current redirected write operation. Therefore, if the current redirected write operation is a normal operation, the newly created second snapshot will be the latest clean copy reflecting the newly written data. If the redirected write operation is part of a ransomware attack, a recovery point can be quickly determined from the PBA chain. This method avoids data loss during data recovery, improves the reliability of data recovery, and because a separate (non-global) snapshot is created for the newly written data between two global snapshots, it occupies very little storage space, avoiding a significant burden on the storage system.

[0117] The data recovery method for preventing ransomware attacks provided in this embodiment will be described in detail below with reference to the accompanying drawings.

[0118] For example, Figure 7A The diagram shown is a flowchart illustrating a data recovery method for preventing ransomware attacks provided in this embodiment. Compared to... Figure 6 The process shown is... Figure 7A A more detailed process step is shown. For example... Figure 7A As shown, this method may include:

[0119] S701 creates a first global snapshot for the protected LBA according to a preset snapshot creation strategy.

[0120] In this step, the computing device can periodically create global snapshots for the protected LBAs of the storage system, resulting in a first global snapshot. The first global snapshot records the mapping relationship between each protected LBA and its corresponding PBA, and the first LBA is mapped to a third PBA in the first global snapshot. For example, the principle of creating a global snapshot can be found in the explanation of creating a global snapshot (Snapshot 1) in the section on the data recovery device 100 for ransomware attacks mentioned above, and will not be repeated here.

[0121] S702, based on the timestamp order of the first global snapshot and the historical snapshot, adds the third PBA to the PBA chain.

[0122] In this embodiment, the computing device can add the third PBA to the PBA chain of the first LBA according to the timestamp order of the first global snapshot and all historical snapshots of the first LBA, so as to record the changes that occur on the first LBA. For example, the PBA chain can be implemented as a hash chain, but is not limited thereto.

[0123] S703 receives read operation instructions for the first LBA.

[0124] In this step, the computing device can receive a read operation instruction from an upper-layer application, which includes the operation type of the instruction and the first LBA involved.

[0125] S704 executes a read operation instruction in the first PBA and sets the status flag of the first LBA to the state that data has been read.

[0126] In this step, the computing device can look up the first PBA mapped to the first LBA in the memory area address mapping table of the storage system, and then execute the read operation instruction in the first PBA. The status flag of the first LBA in the LBA bitmap is then set to the state that data has been read, such as setting it to "1".

[0127] For example, in addition to using a bitmap-configured status flag to record LBA data read records, LSM trees, Bloom filters, or compressed bitmaps can also be used to generate LBA data read records.

[0128] In this way, all LBAs suspected of being subjected to ransomware attacks are indicated by their status flags.

[0129] S705 receives a write operation instruction for the first logical address LBA in the memory area.

[0130] In this example, step S705 is similar to the execution principle of S601 in the above example, and will not be described again.

[0131] S706, if the status flag indicates that the data in the first LBA has not been read, then search for the target PBA mapped by the first LBA in the storage area.

[0132] In this step, the computing device, based on the write operation instruction, first queries the value of the status flag of the first LBA. If it is determined that the data in the first LBA has not been read, then the write operation instruction is likely a normal overwrite or append instruction. Therefore, the computing device can locate the target PBA mapped to the first LBA in the storage area of ​​the storage system to perform the corresponding write operation. It can be understood that the target PBA can be the first PBA or a usable PBA other than the first PBA.

[0133] S707 executes a write operation instruction on the target PBA.

[0134] S708, if the status flag indicates that the data in the first LBA has been read, then a write operation instruction is executed in the second PBA, where the second PBA is the redirection address of the first LBA.

[0135] S709, create a second snapshot for the second PBA, and add the second PBA to the PBA chain according to the timestamp order of the second snapshot and the historical snapshot.

[0136] S710, if it is determined that the write operation instruction is one of the actions of carrying out a ransomware attack, the first PBA with the closest timestamp to the second PBA is determined from the PBA chain, and a data recovery operation is performed from the first PBA.

[0137] In this example, the execution principle of steps S708 to S709 is similar to that of steps S602 to S604 in the above example, and will not be repeated here.

[0138] Furthermore, for example, during data recovery operations, the computing device can generate a list of LBAs to be recovered, and perform data recovery operations on each logical address LBA (including the first LBA) that has suffered a ransomware attack, one by one. The data recovery operation process generally includes: for any LBA to be recovered, querying the LBA bitmap to confirm whether the first LBA has been read. If it has not been read, the PBA currently recorded in the storage area is in a clean state, no rollback is required, and the process ends. If the LBA has been read, then the PBA chain corresponding to the row where the LBA is located in the snapshot area address mapping table is searched, and then the PBA chain is traversed to find the clean PBA with the closest timestamp (including but not limited to confirming whether the copy is clean through manual confirmation, entropy detection, machine learning, etc.), which is the first PBA, and a recovery point is established. Then, the first PBA corresponding to the first LBA in the storage area address mapping table is rolled back, and in the historical snapshots of the LBAs recorded in the snapshot area, snapshots with timestamps after the first snapshot to which the first PBA belongs are deleted.

[0139] In this example, no recovery point is provided for append / overwrite operations during data recovery. After an append / overwrite operation, only the written data is retained in the storage area, which helps reduce data recovery time. Furthermore, data recovery is implemented based on the PBA chain and does not rely on the regular timestamps of global snapshots.

[0140] S711 receives a delete command for the first LBA.

[0141] In this step, the computing device can receive a deletion instruction from an upper-layer application, which includes the operation type of the instruction and the first LBA involved.

[0142] S712, if the status flag indicates that the data in the first LBA has been read, then the deletion instruction is rejected and the first PBA is kept in a valid state. A valid state means that it is not identified as a garbage collection space.

[0143] In this step, the computing device queries the status flag of the first LBA. If it has not been read, the deletion instruction is executed normally on the first PBA mapped to the first LBA (i.e., step S712A in Figure 7), which marks the first PBA as garbage collection space so that new data can be written there later (which can be an overwrite). Conversely, if the first LBA has been read, the computing device refuses to execute the deletion instruction on the first PBA mapped to the first LBA and maintains the valid state of the first PBA. The valid state means that it is not marked as garbage collection space.

[0144] In this way, by using status flags, LBAs in the data-reading state can be prevented from performing deletion operations, thereby improving the security of data storage.

[0145] For example, such as Figure 7B As shown, this method may further include the following during the execution of the steps shown in 7A above:

[0146] S713 periodically deletes historical snapshots according to a preset snapshot recycling strategy.

[0147] In this step, the computing device can periodically delete historical snapshots according to a preset snapshot recycling strategy.

[0148] For example, a snapshot reclamation policy can instruct that snapshot reclamation operations be triggered under circumstances such as reaching the snapshot limit, snapshot expiration (with a set validity period, such as 7 days or 30 days), insufficient storage space, or an excessively long snapshot chain. Furthermore, according to the snapshot reclamation policy, when performing snapshot reclamation operations, priority can be given to deleting snapshots created earlier, deleting snapshots older than a specified time, and deleting snapshots that have not been used for a long time.

[0149] For example, to avoid running out of space, users can also set retention policies for IO snapshots, such as deleting after timeout, deleting after confirming that the corresponding regular snapshot is not infected, or deleting after backup.

[0150] S714, after a historical snapshot is deleted, release the PBA recorded in the deleted historical snapshot.

[0151] In this step, any LBA in storage area X01 may be protected by a global snapshot and multiple IO snapshots. If all snapshots of the LBA are reclaimed, the LBA will lose the protection of these snapshots. All PBAs mapped by the LBA in these snapshots will also be released one by one. These PBAs are marked as free in the storage area and await garbage space reclamation.

[0152] S715 updates the corresponding status flag for the LBA recorded in the deleted historical snapshot, resetting the corresponding status flag to the data not read state.

[0153] In this step, the computing device can, according to a preset aging process strategy, after a global snapshot is deleted, the LBA protected by the deleted snapshot is lost, and the status flag matching the LBA in the LBA bitmap can be reset to an unread state. This ensures the consistency of information between the LBA bitmap, the snapshot area, and the storage area.

[0154] This application also provides a computing device 10. For example... Figure 8 As shown, the computing device 10 includes a bus, a processor 110, a memory 120, and a communication interface 130. The processor 110, the memory 120, and the communication interface 130 communicate with each other via the bus. The computing device 10 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 10.

[0155] A bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized into address buses, data buses, control buses, etc. For ease of representation, Figure 8 The bus 104 may be represented by a single line, but this does not mean that there is only one bus or one type of bus. The bus 104 may include a path for transmitting information between various components of the computing device 10 (e.g., memory 120, processor 110, communication interface 130).

[0156] The processor 110 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0157] Memory 120 may include volatile memory, such as random access memory (RAM). Processor 110 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0158] The memory 120 stores executable program code, which the processor 110 executes to implement the functions of the aforementioned modules A, B, and C, thereby realizing the data recovery method against ransomware attacks. In other words, the memory 120 stores instructions for executing the data recovery method against ransomware attacks.

[0159] The communication interface 103 uses transceiver modules such as, but not limited to, network interface cards and transceivers to enable communication between the computing device 10 and other devices or communication networks.

[0160] This application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.

[0161] like Figure 9 As shown, the computing device cluster includes at least one computing device 10. The memory 120 of one or more computing devices 10 in the computing device cluster may store the same instructions for executing a data recovery method to prevent ransomware attacks.

[0162] In some possible implementations, the memory 120 of one or more computing devices 10 in the computing device cluster may also store partial instructions for executing a data recovery method against ransomware attacks. In other words, a combination of one or more computing devices 10 can jointly execute instructions for executing a data recovery method against ransomware attacks.

[0163] In some possible implementations, one or more computing devices in a computing device cluster can be connected via a network. This network can be a wide area network (WAN) or a local area network (LAN), etc. Figure 10 One possible implementation is shown. For example... Figure 10 As shown, the two computing devices 10A and 10B are connected via a network. Specifically, they are connected to the network through communication interfaces in each computing device. In this possible implementation, the memory 120 in computing device 10A stores instructions for performing the functions of the receiving module 101, the processing module 102, and the creation module 103. Meanwhile, the memory 120 in computing device 10B stores instructions for performing the functions of the recovery module 104.

[0164] This application also provides another computing device cluster. The connection relationships between the computing devices in this computing device cluster can be similarly referred to... Figure 9 and Figure 10The connection method of the computing device cluster is different in that the memory 120 of one or more computing devices 10 in the computing device cluster can store the same instructions for executing data recovery methods to prevent ransomware attacks.

[0165] This application also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions, capable of running on a computing device or stored on any usable medium. When the computer program product is run on at least one computing device, it causes the at least one computing device to perform a data recovery method against ransomware attacks.

[0166] This application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store, or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct a computing device to perform a ransomware attack-resistant data recovery method.

[0167] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data recovery method for preventing ransomware attacks, characterized in that, The method includes: The system receives a write operation instruction for a first logical address (LBA) in the storage area. The first LBA has a first snapshot created. The first snapshot is a snapshot with the latest timestamp among the historical snapshots of the first LBA. The first snapshot records the mapping relationship between the first LBA and a first physical address (PBA). The first LBA has a status flag and a PBA chain. The status flag is used to indicate whether the data in the first LBA has been read. The PBA chain includes the PBAs mapped by the first LBA in the historical snapshots. The PBAs in the PBA chain are arranged in order of their respective historical snapshot timestamps. If the status flag indicates that the data in the first LBA has been read, then the write operation instruction is executed in the second PBA, where the second PBA is the redirection address of the first LBA. Create a second snapshot for the second PBA, and add the second PBA to the PBA chain according to the timestamp order of the second snapshot and the historical snapshot; If it is determined that the write operation instruction is one of the actions to carry out the ransomware attack, the first PBA whose timestamp is closest to the second PBA is determined from the PBA chain, and a data recovery operation is performed from the first PBA.

2. The method according to claim 1, characterized in that, After receiving the write operation instruction for the first logical address LBA in the memory area, the method includes: If the status flag indicates that the data in the first LBA has not been read, then the target PBA mapped by the first LBA is searched in the storage area. The target PBA is the first PBA or a PBA other than the first PBA. The write operation instruction is executed on the target PBA.

3. The method according to claim 1 or 2, characterized in that, The first LBA is a portion of the protected LBAs in the memory area. Before receiving a write operation instruction for the first logical address LBA in the memory area, the method includes: According to a preset snapshot creation strategy, a first global snapshot is created for the protected LBA. The first global snapshot is used to record the mapping relationship between each protected LBA and the corresponding PBA. The first LBA has a mapping relationship with the third PBA in the first global snapshot. The third PBA is added to the PBA chain according to the timestamp order of the first global snapshot and the historical snapshot.

4. The method according to any one of claims 1-3, characterized in that, Before receiving the write operation instruction for the first logical address LBA in the memory area, the method includes: Receive a read operation instruction for the first LBA; The read operation instruction is executed in the first PBA, and the status flag of the first LBA is set to the state that data has been read.

5. The method according to any one of claims 1-4, characterized in that, The method further includes: Receive the deletion instruction for the first LBA; If the status flag indicates that the data in the first LBA has been read, the deletion instruction is rejected, and the first PBA remains in a valid state, whereby a valid state refers to a state that is not identified as a garbage collection space.

6. The method according to any one of claims 1-5, characterized in that, The method further includes: According to the preset snapshot recycling strategy, the historical snapshots are deleted periodically; After a historical snapshot is deleted, release the PBA recorded in the deleted historical snapshot; For the LBAs recorded in the deleted historical snapshots, update the corresponding status flags to reset the corresponding status flags to the data not read state.

7. A data recovery device for preventing ransomware attacks, characterized in that, The device includes: A receiving module is used to receive a write operation instruction for a first logical address (LBA) in the storage area. The first LBA has a first snapshot created. The first snapshot is a snapshot with the latest timestamp among the historical snapshots of the first LBA. The first snapshot records the mapping relationship between the first LBA and a first physical address (PBA). The first LBA has a status flag and a PBA chain. The status flag is used to indicate whether the data in the first LBA has been read. The PBA chain includes the PBAs mapped by the first LBA in the historical snapshots. The PBAs in the PBA chain are arranged in the order of their respective historical snapshot timestamps. The processing module is configured to execute the write operation instruction in the second PBA if the status flag indicates that the data in the first LBA has been read, wherein the second PBA is the redirection address of the first LBA; A creation module is used to create a second snapshot for the second PBA and add the second PBA to the PBA chain according to the timestamp order of the second snapshot and the historical snapshot; The recovery module is configured to, if it is determined that the write operation instruction is one of the actions that carry out the ransomware attack, determine the first PBA whose timestamp is closest to the second PBA from the PBA chain, and perform a data recovery operation from the first PBA.

8. The apparatus according to claim 7, characterized in that, The processing module is also used for: If the status flag indicates that the data in the first LBA has not been read, then the target PBA mapped by the first LBA is searched in the storage area. The target PBA is the first PBA or a PBA other than the first PBA. The write operation instruction is executed on the target PBA.

9. The apparatus according to claim 7 or 8, characterized in that, The first LBA is a portion of the protected LBAs in the storage area, and the creation module is further configured to: According to a preset snapshot creation strategy, a first global snapshot is created for the protected LBA. The first global snapshot is used to record the mapping relationship between each protected LBA and the corresponding PBA. The first LBA has a mapping relationship with the third PBA in the first global snapshot. The third PBA is added to the PBA chain according to the timestamp order of the first global snapshot and the historical snapshot.

10. The apparatus according to any one of claims 7-9, characterized in that, The receiving module is further configured to: receive a read operation instruction for the first LBA; The processing module is further configured to execute the read operation instruction in the first PBA and set the status flag of the first LBA to the state that data has been read.

11. The apparatus according to any one of claims 7-10, characterized in that, The receiving module is further configured to: receive a deletion instruction for the first LBA; The processing module is further configured to refuse to execute the deletion instruction and maintain the valid state of the first PBA if the status flag indicates that the data in the first LBA has been read, wherein the valid state refers to the state that is not identified as a garbage collection space.

12. The apparatus according to any one of claims 7-10, characterized in that, The processing module is also used for, According to the preset snapshot recycling strategy, the historical snapshots are deleted periodically; After a historical snapshot is deleted, release the PBA recorded in the deleted historical snapshot; For the LBAs recorded in the deleted historical snapshots, update the corresponding status flags to reset the corresponding status flags to the data not read state.

13. A computing device, characterized in that, Including processor and memory; The processor is configured to execute instructions stored in the memory to cause the computing device to perform the method as described in any one of claims 1-6.

14. A computer program product containing instructions, characterized in that, When the instruction is executed by the computing device, the computing device performs the method as described in any one of claims 1-6.

15. A computer-readable storage medium, characterized in that, It includes computer program instructions, which, when executed by a computing device, cause the computing device to perform the method as described in any one of claims 1-6.