A ransomware countermeasure, system, device, medium, and product
Patent Information
- Application Number
- CN202610793200.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-03
- Publication Date
- 2026-09-29
AI Technical Summary
但该防范方法并不能做到很及时的查杀勒索软件,虽然使用诱饵文件能够发现勒索软件的行为,但确认恶意进程,准确排查到勒索软件本体,并对所有相关的恶意进程和文件进行查杀仍然需要一定时间,勒索软件往往并不期待完全加密所有文件,而是采用尽可能破坏的策略,在时间差内实现对足够的目标文件的加密,以达成目的
[0017]相对于现有技术,本发明实施例提供的一种勒索病毒对抗方法、系统、设备、介质及产品,该方法通过先基于监测目录真实文件属性生成高亲和度诱饵模板与诱饵文件,并按模板预设数量完成基础布饵,再在监测到诱饵被加密时触发预设速率的诱饵泛洪投放,同时实时采集加密速率并动态调整投放速率,最后满足停止条件时停止投放并清除诱饵。本发明可以克服现有诱饵方案防御不及时的弊端,实现对已知和未知勒索软件的精准捕获与高效对抗,同时兼顾系统资源的合理利用,提升勒索病毒对抗的时效性与可靠性。
Smart Images

Figure CN122845170A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method, system, device, medium and product for combating ransomware. Background Technology
[0002] Despite the increasing adoption of more efficient encryption mechanisms and cryptocurrencies, ransomware remains one of the most dangerous cybersecurity attacks. Ransomware employing asymmetric key technology ensures that the decryption key remains solely in the hands of the attacker. More efficient encryption mechanisms further increase the danger of ransomware, partly due to the speed of the algorithms, which shortens the useful time for detectors to trigger user and / or mitigation measures, and partly due to the strength of the encryption, making the process irreversible without the key. Furthermore, cryptocurrencies provide a reliable means to monetize attacks and protect their anonymity, which also contributes to the growth in the number of ransomware attacks.
[0003] Traditional ransomware detection methods rely on analyzing malicious executable files to identify ransomware characteristics. However, with the widespread use of code obfuscation techniques, detection methods have incorporated behavioral analysis, focusing on monitoring runtime behavior such as system call sequences and read / write operations. For instance, in process-level monitoring, any running process with a trust score exceeding a maximum threshold is considered malicious activity. Behavioral-based detection is highly effective against known threats but ineffective against unknown ransomware samples.
[0004] Because ransomware attacks user files, existing technologies have introduced deceptive solutions based on file decoys. These file decoys (or fake files) can be created automatically or manually and placed throughout the network. The ransomware's file encryption behavior is detected by detecting these decoy files. For example, Chinese patent CN106096397A proposes a ransomware prevention method and system. This involves constructing at least one decoy file that conforms to the ransomware's encryption type and inserting it into the existing file sequence of the disk to be protected. It then checks whether the decoy file has changed, and if so, prevents preset operations on the disk to be protected. However, this prevention method cannot detect and remove ransomware very quickly. Although using decoy files can detect ransomware behavior, confirming the malicious process, accurately locating the ransomware itself, and eliminating all related malicious processes and files still takes time. Ransomware often does not aim to completely encrypt all files, but rather employs a strategy of destruction as much as possible, encrypting a sufficient number of target files within a time difference to achieve its goal. Summary of the Invention
[0005] The purpose of this invention is to provide a ransomware countermeasure method, system, device, medium, and product that can reduce the effective destruction time window of ransomware, thereby continuously reducing the efficiency of ransomware in encrypting real files during the attack process, and thus reducing the risk of data loss.
[0006] To achieve the above objectives, the present invention provides a method for combating ransomware, comprising: A bait template is generated based on the attribute information of each file in the monitoring directory, and a bait file is generated based on the bait template. Deploy bait files according to the preset number of bait files for each bait template; When the decoy file is detected to be encrypted, the decoy file is deployed according to the preset pre-deployment rate; The rate at which the decoy file is encrypted is obtained in real time, and the release rate of the decoy file is adjusted based on the rate at which the decoy file is encrypted. The decoy file is then released again according to the adjusted release rate. When the preset stopping conditions are met, the deployment of bait files will stop and the deployed bait files will be cleared.
[0007] Optionally, the step of acquiring the encryption rate of the decoy file in real time, adjusting the decoy file deployment rate based on the encryption rate, and continuing to deploy the decoy file according to the adjusted deployment rate includes: The number of encrypted decoy files per unit time is obtained at a preset sampling period, which is used as the encryption rate of the decoy files; Based on the rate at which the decoy file is encrypted, a linear regression model of the decoy file encryption rate is established to predict the rate at which the decoy file is encrypted. Adjust the decoy file delivery rate based on the predicted rate at which the decoy files are encrypted.
[0008] Optionally, the step of generating a decoy template based on the attribute information of each file in the monitoring directory, and generating a decoy file based on the decoy template, includes: Extract attribute information from each file in the monitoring directory; The attribute information is vectorized to obtain the feature vectors of each file; The feature vectors are clustered using the affinity propagation algorithm. The files corresponding to the cluster centers are determined as decoy file templates, and decoy files are generated based on the decoy templates.
[0009] Optionally, the naming of the decoy file is determined based on the filename of the decoy template and a dictionary.
[0010] Optionally, the number of bait files deployed for each bait template is determined based on the total file size of the cluster to which the bait file template belongs.
[0011] Optionally, the attribute information includes file name, file size, file type, file creation date, file last opened date, and file modification date.
[0012] Optionally, the stopping condition includes at least one of the following: The detection rate at which the decoy file is encrypted drops to zero and remains so for a preset duration; Alternatively, it can be confirmed that the ransomware process has been terminated.
[0013] To achieve the above objectives, the present invention also provides a ransomware countermeasure system, comprising: The bait file generation module is used to generate a bait template based on the attribute information of each file in the monitoring directory, and to generate a bait file based on the bait template. The first bait file delivery module is used to deliver bait files according to the preset number of bait files for each bait template; The second bait file delivery module delivers the bait file according to a preset pre-delivery rate when it detects that the bait file is encrypted. The third decoy file delivery module acquires the encryption rate of the decoy file in real time, adjusts the delivery rate of the decoy file based on the encryption rate, and continues to deliver the decoy file according to the adjusted delivery rate. The stop-attack module stops deploying decoy files and clears the deployed decoy files when the preset stop conditions are met.
[0014] To achieve the above objectives, the present invention also provides a ransomware countermeasure device, comprising: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the ransomware countermeasure method as described above.
[0015] To achieve the above objectives, the present invention also provides a computer-readable storage medium storing a computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to execute the ransomware countermeasure method described in any of the above claims.
[0016] To achieve the above objectives, the present invention also provides a computer program product, including a computer program / instruction that, when executed by a processor, implements the ransomware countermeasure method as described in any of the above claims.
[0017] Compared to existing technologies, this invention provides a ransomware countermeasure method, system, device, medium, and product. This method first generates high-affinity decoy templates and decoy files based on the attributes of real files in the monitored directory, and completes basic decoy deployment according to a preset quantity of templates. Then, when decoys are detected to be encrypted, a flood of decoys is triggered at a preset rate. Simultaneously, the encryption rate is collected in real time and the deployment rate is dynamically adjusted. Finally, when a stopping condition is met, deployment stops and the decoys are removed. This invention overcomes the drawback of untimely defense in existing decoy schemes, achieving accurate capture and efficient countermeasures against known and unknown ransomware, while also ensuring the rational utilization of system resources, improving the timeliness and reliability of ransomware countermeasures. Attached Figure Description
[0018] To more clearly illustrate the technical solution of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a flowchart illustrating a ransomware countermeasure method provided in an embodiment of the present invention; Figure 2 This is a structural block diagram of a ransomware countermeasure system provided in an embodiment of the present invention; Figure 3 This is a structural block diagram of a ransomware countermeasure device provided in an embodiment of the present invention. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0021] See Figure 1 , Figure 1 This is a flowchart illustrating a ransomware countermeasure method provided in an embodiment of the present invention, the ransomware countermeasure method comprising steps S1 to S5: Step S1: Generate a decoy template based on the attribute information of each file in the monitoring directory, and generate a decoy file based on the decoy template; In an optional embodiment, step S1 includes steps S101 to S103: Step S101: Extract the attribute information of each file in the monitoring directory; wherein, the attribute information includes file name, file size, file type, file creation date, file last opened date, and file modification date; Step S102: The attribute information is vectorized to obtain the feature vectors of each file; Step S103: Use the affinity propagation algorithm to perform cluster analysis on the feature vector, determine the file corresponding to the cluster center as the decoy file template, and generate the decoy file according to the decoy template.
[0022] For example, firstly, the attribute information of all files in the directory to be monitored is obtained, including filename, file size, file type, file creation date, file last opened date, and file modification date. Then, attribute vector embedding is performed. Specifically, filenames are one-hot encoded using the first letter, file sizes are normalized and scaled, file types are one-hot encoded, and date types are encoded using sine and cosine functions. Then, Principal Component Analysis (PCA) is used to extract features from the embedded vectors to obtain file feature vectors with redundant features removed. Then, the Affinity Propagation (AP) algorithm is used to cluster the file feature vectors in each directory, returning K nodes representing the cluster centers. The file corresponding to each node is the decoy template file. Finally, the decoy file is generated by copying the attributes of the template file.
[0023] It is worth noting that the affinity propagation algorithm used in this embodiment of the invention can achieve better capture results for decoy files than the traditional method of sorting by fixed attributes. Traditional fixed attribute sorting only selects decoy templates based on a single / fixed attribute (such as file size or type), ignoring key features such as naming and creation time, resulting in one-sided decoy features. In contrast, the affinity propagation algorithm is based on feature vector clustering of multiple file attributes. The automatically selected cluster centers can represent the core common features of a certain type of file. The generated decoys are closer to the real file and are more easily identified by ransomware. It has adaptability and high affinity to different ransomware encryption priority sorting algorithms, ensuring that ransomware can more easily identify and encrypt decoy files first. It can also avoid the waste of system resources caused by indiscriminately generating decoys. By designing targeted decoys to maximize the attraction of ransomware's encryption computing power, it can effectively delay its encryption process of real important files, buy sufficient time for subsequent ransomware detection and treatment, and improve the accuracy and efficiency of ransomware combat.
[0024] In one alternative embodiment, the naming of the decoy file is determined based on the filename of the decoy template and a dictionary.
[0025] Example content: If the decoy template file name is "sales_data_2024.xlsx", and the preset dictionary table contains high-frequency file-related words that ransomware often prioritizes, such as "final", "v3", "update", "backup", and "Q2", then it can be combined to generate decoy file names such as "final_sales_data_2024.xlsx" and "update_sales_data_2024.xlsx".
[0026] This invention, by retaining the core filename characteristics of the decoy template and integrating high-frequency related words from the dictionary, ensures that the naming of the decoy file perfectly matches the naming habits of files in real office and business scenarios. This accurately matches the ransomware's preference for naming "high-value files," significantly increasing the probability that the decoy file will be prioritized for identification and encryption by ransomware. At the same time, the dictionary can be flexibly expanded to include different word types, adapting to file naming styles in different industries and directories, enhancing the universality and stealth of the decoy file, and further ensuring that the decoy file can effectively attract the ransomware's encryption computing power, thus buying more time for subsequent ransomware detection and removal.
[0027] Step S2: Deploy bait files according to the preset quantity of bait files for each bait template; It should be noted that step S2 involves deploying a preset number of decoy files before the ransomware attack occurs. The core function of these decoy files is routine monitoring and triggering alarms.
[0028] In one alternative embodiment, the number of bait files deployed for each bait template is determined based on the total file size of the cluster to which the bait file template belongs.
[0029] For example, suppose the monitoring directory yields two decoy file templates through cluster analysis. Template A belongs to a cluster containing 10 commonly used office documents with a total file size of 600KB, while template B belongs to a cluster containing 5 large design drawing files with a total file size of 1200KB. A pre-defined mapping rule of "1KB corresponds to 1 decoy file" is used. Based on this, it is determined that 600 decoy files will be deployed for template A and 1200 for template B. Then, the decoy files are deployed according to the total number of files in each cluster.
[0030] This invention determines the deployment quantity based on the total file size of the cluster to which the decoy template belongs. This maximizes the decoy's targeting and affinity for ransomware, ensuring that ransomware prioritizes identifying and encrypting the decoy. Simultaneously, it avoids the indiscriminate deployment based on a fixed number or file count, preventing ransomware from quickly encrypting the decoy and then switching to real, important files due to insufficient decoy quantity, and also preventing excessive deployment from wasting system storage and computing resources. This ensures that the decoy deployment is highly compatible with the distribution characteristics of real files and the ransomware's encryption preferences, efficiently consuming the ransomware's encryption computing power and buying more time for subsequent ransomware detection and removal.
[0031] Step S3: When the decoy file is detected to be encrypted, the decoy file is deployed according to the preset deployment rate.
[0032] It should be noted that by monitoring the modification records of the decoy files in real time, when a modification is detected, it indicates the presence of suspected ransomware. A signal to mitigate the attack can then be sent. Upon initially receiving this signal, the decoy files are flooded at a pre-set default rate, resulting in a large-scale, rapid generation of decoy files. This preset rate can be configured in advance based on system resource capacity and the intensity of common ransomware attacks.
[0033] For example, when it is detected that the basic decoy file generated based on the template in the monitoring directory is encrypted by ransomware, the countermeasure delivery instruction is immediately triggered. The system continuously generates and delivers decoy files to the monitoring directory at a pre-set flood delivery rate of 15 files / second until a new delivery rate instruction is received based on the encryption rate prediction result.
[0034] It's worth noting that traditional solutions typically proceed directly to the removal process after detecting ransomware. However, removal takes time, during which the ransomware continues to encrypt files. This invention inserts a proactive mitigation phase between "detection" and "removal," actively depleting the attacker's resources by deploying decoy files, thus buying time for removal and directly reducing losses.
[0035] Step S4: Obtain the encryption rate of the decoy file in real time, adjust the decoy file deployment rate based on the encryption rate of the decoy file, and continue to deploy the decoy file according to the adjusted deployment rate; In an optional embodiment, step S4 includes steps S401 to S403: Step S401: Obtain the number of encrypted decoy files per unit time at a preset sampling period, which is used as the rate at which the decoy files are encrypted; Step S402: Based on the rate at which the decoy file is encrypted, establish a linear regression model of the encryption rate of the decoy file to predict the rate at which the decoy file is encrypted. Step S403: Adjust the decoy file deployment rate according to the predicted rate at which the decoy file is encrypted.
[0036] Specifically, the rate at which the decoy files are deployed is adjusted, either by increasing or decreasing the rate at which the decoy files are deployed, and decoy files continue to be generated on the disk.
[0037] For example, assuming the preset sampling period is once per second and the initial decoy file deployment rate is set to 15 files / second, after detecting that the decoy file is encrypted, the number of encrypted decoy files per unit time is collected once per second. The encryption rate is 10 files / second in the first second, 12 files / second in the second second, and 14 files / second in the third second. Based on these three sets of real-time data, a linear regression model of the decoy file encryption rate is established. Through model fitting and prediction, it is found that the encryption rate will reach 18 files / second in the fifth second. To match this prediction result, the decoy file deployment rate is adjusted to 25 files / second. Subsequently, the model is continuously updated by the real-time collected encryption rate data. If the actual encryption rate in the fourth second is 16 files / second, the model corrects and predicts that the encryption rate in the sixth second will be 20 files / second, and the deployment rate is further adjusted to 30 files / second.
[0038] This invention captures the dynamic changes in the encryption rate of decoy files in real time by pre-setting a fixed sampling period, ensuring timely understanding of the ransomware's encryption pace. Simultaneously, by using a linear regression model to predict the encryption rate trend, it enables proactive responses to ransomware encryption behavior. Finally, based on the prediction results, the decoy deployment rate is dynamically adjusted. This avoids the risk of ransomware switching to real files after the decoy is quickly encrypted due to insufficient deployment, while also preventing system resource waste caused by excessive deployment. It maximizes the efficiency of the decoy in consuming ransomware's computing power, providing more time for ransomware detection and removal.
[0039] Step S5: When the preset stopping conditions are met, stop the deployment of bait files and clear the deployed bait files.
[0040] In one alternative embodiment, the stopping condition includes at least one of the following: The detection rate at which the decoy file is encrypted drops to zero and remains so for a preset duration; Alternatively, it can be confirmed that the ransomware process has been terminated.
[0041] For example, the preset duration of the stop condition is 3 seconds. After the decoy file delivery rate is dynamically adjusted to 30 files / second, the decoy file monitor continuously tracks the encryption status. It finds that the rate at which the decoy files are encrypted gradually decreases from 20 files / second to 0, and the "encryption rate of 0" state is stable and lasts for a full 3 seconds. Alternatively, the ransomware detection and processing module confirms through process detection that the ransomware main process and associated child processes have been completely terminated, and then stops the delivery of decoy files and deletes the decoy files that were delivered in excess.
[0042] The embodiments of this invention set stop conditions, which can avoid the risk of accidentally stopping the bait delivery due to the encryption rate temporarily dropping to 0 when the ransomware goes into a brief dormant state. It can also ensure timely termination after the ransomware is completely dealt with, avoiding ineffective delivery that occupies system resources. At the same time, after stopping the delivery, excess bait files are automatically cleared, which can quickly release system resources such as disk storage and CPU, preventing bait files from leaving space or interfering with normal file retrieval and management. This not only ensures the security and reliability of ransomware defense, but also improves the utilization efficiency of system resources, making the defense process free of extra redundant burden.
[0043] For example, in a specific implementation, the ransomware sample encrypts files in a folder with 200 files, using three different file priority sorting methods and employing multi-threading for simultaneous encryption.
[0044] In this embodiment of the invention, 15 decoy file templates are first generated using the affinity propagation algorithm, and the decoy files are deployed according to the total number of files in each class. When the ransomware sample is detected to have modified the decoy files, a signal generation strategy is sent: "policyid=0, speed=15", which is the default strategy, generating 15 decoy files per second. As the ransomware sample encrypts more decoy files, the system records the number of decoy files encrypted every second and builds a linear regression model of the decoy file encryption rate based on the sampled data. This model predicts when the decoy deployment rate needs to be increased, and it is continuously updated in real-time, along with the prediction results. For example, if it predicts that the decoy file encryption rate exceeds 15 per second at the 5th second, the adversarial policy "policyid=1, speed=30" is regenerated. Here, 30 represents the predicted decoy file encryption rate that might be reached at the 10th second. If the rate is reached earlier, the adversarial policy is regenerated in advance; otherwise, the rate is maintained. Finally, when the ransomware sample's encryption rate for the decoy file is detected to decrease to 0, the generation of decoy files is stopped, and any additional decoy files deployed are deleted based on the decoy file deployment records.
[0045] In summary, the ransomware countermeasure method provided by this invention first generates high-affinity decoy templates and decoy files based on the real file attributes of the monitored directory, and completes basic decoy deployment according to a preset number of templates. Then, when the decoys are detected to be encrypted, a flood of decoys is triggered at a preset rate. Simultaneously, the encryption rate is collected in real time and the deployment rate is dynamically adjusted. Finally, when a stopping condition is met, the deployment stops and the decoys are removed. This invention achieves its countermeasures through three stages: detection, mitigation, and removal. By discovering ransomware behavior clues during the detection process, a mitigation process is added to counteract the ransomware's destructive behavior. By adaptively generating decoy files through real-time monitoring of the decoy file's encryption status, the number of files encrypted by the ransomware is minimized, buying time for final confirmation and removal. This overcomes the shortcomings of existing decoy solutions in terms of untimely defense, achieving accurate capture and efficient countermeasures against known and unknown ransomware, while also ensuring reasonable utilization of system resources, thus improving the timeliness and reliability of ransomware countermeasures.
[0046] See Figure 2 , Figure 2 This is a structural block diagram of a ransomware countermeasure system provided in an embodiment of the present invention. The ransomware countermeasure system includes: The bait file generation module 21 is used to generate a bait template based on the attribute information of each file in the monitoring directory, and to generate a bait file based on the bait template. The first bait file delivery module 22 is used to deliver bait files according to the preset number of bait files for each bait template; The second bait file delivery module 23, when detecting that the bait file is encrypted, delivers the bait file according to a preset pre-delivery rate; The third bait file delivery module 24 acquires the encryption rate of the bait file in real time, adjusts the delivery rate of the bait file based on the encryption rate of the bait file, and continues to deliver the bait file according to the adjusted delivery rate. The stop-counter module 25 stops deploying decoy files and clears deployed decoy files when the preset stop conditions are met.
[0047] In one optional embodiment, the decoy file generation module 21 is configured to: Extract attribute information from each file in the monitoring directory; The attribute information is vectorized to obtain the feature vectors of each file; The feature vectors are clustered using the affinity propagation algorithm. The files corresponding to the cluster centers are determined as decoy file templates, and decoy files are generated based on the decoy templates.
[0048] In one optional embodiment, the third bait delivery module 24 is configured to: The number of encrypted decoy files per unit time is obtained at a preset sampling period, which is used as the encryption rate of the decoy files; Based on the rate at which the decoy file is encrypted, a linear regression model of the decoy file encryption rate is established to predict the rate at which the decoy file is encrypted. Adjust the decoy file delivery rate based on the predicted rate at which the decoy files are encrypted.
[0049] It should be noted that the ransomware countermeasure system provided in this embodiment of the invention is used to execute all the process steps of the ransomware countermeasure method in the above embodiment. The working principles and beneficial effects of the two are one-to-one, so they will not be described again.
[0050] See Figure 3 , Figure 3 This is a structural block diagram of a ransomware countermeasure device provided in an embodiment of the present invention. The ransomware countermeasure device includes a processor 31, a memory 32, and a computer program stored in the memory 32 and executable on the processor 31. When the processor 31 executes the computer program, it implements the steps in the various ransomware countermeasure method embodiments described above, for example...
[0051] For example, the computer program can be divided into one or more modules / units, which are stored in the memory 32 and executed by the processor 31 to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the ransomware countermeasure device.
[0052] The ransomware countermeasure device may include, but is not limited to, a processor 31 and a memory 32. Those skilled in the art will understand that the schematic diagram is merely an example of a ransomware countermeasure device and does not constitute a limitation on the ransomware countermeasure device. It may include more or fewer components than illustrated, or combine certain components, or different components. For example, the ransomware countermeasure device may also include input / output devices, network access devices, buses, etc.
[0053] The processor 31 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor. The processor 31 is the control center of the ransomware countermeasure device, connecting all parts of the ransomware countermeasure device via various interfaces and lines.
[0054] The memory 32 can be used to store the computer programs and / or modules. The processor 31 implements various functions of the ransomware countermeasure device by running or executing the computer programs and / or modules stored in the memory 32 and calling the data stored in the memory 32. The memory 32 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 32 may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0055] If the modules / units integrated into the ransomware anti-virus device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by the processor 31, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.
[0056] Furthermore, embodiments of the present invention also provide a computer program product, including a computer program / instruction, which, when executed by a processor, implements the ransomware countermeasure method as described in any of the above embodiments.
[0057] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A method for combating ransomware, characterized in that, include: A bait template is generated based on the attribute information of each file in the monitoring directory, and a bait file is generated based on the bait template. Deploy bait files according to the preset number of bait files for each bait template; When the decoy file is detected to be encrypted, the decoy file is deployed according to the preset pre-deployment rate; The rate at which the decoy file is encrypted is obtained in real time, and the release rate of the decoy file is adjusted based on the rate at which the decoy file is encrypted. The decoy file is then released again according to the adjusted release rate. When the preset stopping conditions are met, the deployment of bait files will stop and the deployed bait files will be cleared.
2. The ransomware countermeasure method as described in claim 1, characterized in that, The process of acquiring the encryption rate of the decoy file in real time, adjusting the decoy file deployment rate based on the encryption rate, and continuing to deploy the decoy file according to the adjusted deployment rate includes: The number of encrypted decoy files per unit time is obtained at a preset sampling period, which is used as the encryption rate of the decoy files; Based on the rate at which the decoy file is encrypted, a linear regression model of the decoy file encryption rate is established to predict the rate at which the decoy file is encrypted. Adjust the decoy file delivery rate based on the predicted rate at which the decoy files are encrypted.
3. The ransomware countermeasure method as described in claim 1, characterized in that, The process of generating a decoy template based on the attribute information of each file in the monitoring directory, and generating a decoy file based on the decoy template, includes: Extract attribute information from each file in the monitoring directory; The attribute information is vectorized to obtain the feature vectors of each file; The feature vectors are clustered using the affinity propagation algorithm. The files corresponding to the cluster centers are determined as decoy file templates, and decoy files are generated based on the decoy templates.
4. The ransomware countermeasure method as described in claim 3, characterized in that, The naming of the decoy file is determined based on the filename of the decoy template and a dictionary.
5. The ransomware countermeasure method as described in claim 3, characterized in that, The number of bait files to be deployed for each bait template is determined based on the total file size of the cluster to which the bait file template belongs.
6. The ransomware countermeasure method as described in claim 3, characterized in that, The attribute information includes file name, file size, file type, file creation date, last opened date, and file modification date.
7. The ransomware countermeasure method as described in claim 1, characterized in that, The stopping condition includes at least one of the following: The detection rate at which the decoy file is encrypted drops to zero and remains so for a preset duration; Alternatively, it can be confirmed that the ransomware process has been terminated.
8. A ransomware countermeasure system, characterized in that, include: The bait file generation module is used to generate a bait template based on the attribute information of each file in the monitoring directory, and to generate a bait file based on the bait template. The first bait file delivery module is used to deliver bait files according to the preset number of bait files for each bait template; The second bait file delivery module delivers the bait file according to a preset pre-delivery rate when it detects that the bait file is encrypted. The third decoy file delivery module acquires the encryption rate of the decoy file in real time, adjusts the delivery rate of the decoy file based on the encryption rate, and continues to deliver the decoy file according to the adjusted delivery rate. The stop-attack module stops deploying decoy files and clears the deployed decoy files when the preset stop conditions are met.
9. A ransomware countermeasure device, characterized in that, include: A processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the ransomware countermeasure method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the ransomware countermeasure method as described in any one of claims 1 to 7.
11. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the ransomware countermeasures method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Ransomware prevention method and system
CN106096397A