Data processing method and apparatus

By introducing transparent cache areas and protected areas into the file system, redirecting data operation requests to shadow files, and syncing them to the original files after passing security verification, the file operation performance problems caused by existing security software when intercepting malware is solved, and efficient file operation and security protection is achieved.

WO2025107641A1PCT designated stage expired Publication Date: 2025-05-30HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/102622
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-29
Filing Date
2024-06-28
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

When existing security software intercepts and detects malware, it needs to intercept file operations in real time, resulting in file reading and writing blocking, affecting performance.

Method used

By introducing transparent cache and protected areas into the file system, the application's data operation request is redirected to the shadow file, and the modified files are only synchronized to the original file after passing security verification, thereby avoiding real-time interception and pausing file operations.

Benefits of technology

It realizes the ability to block the harmful behavior of malware to files while improving file operation performance, avoiding file reading and writing blocking, and ensuring normal operation of the file system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024102622_30052025_PF_FP_ABST
    Figure CN2024102622_30052025_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a data processing method and apparatus, relating to the field of cloud computing. The data processing method comprises: setting a transparent cache area which is transparent to a user and a user application program, wherein the transparent cache area is isolated from a protected area, the protected area is used for storing an original file, the transparent cache area is used for storing a shadow file, and the shadow file is a copy of the original file; redirecting, to the shadow file corresponding to the original file in the transparent cache area, a modification operation on the original file of the protected area in a data operation request of the application program, to obtain a modified file; and then determining that the modified file has passed security verification and then synchronizing same to the protected area. Thus, when performing security verification and other detection on the shadow file, a computing device can still access the original file in the protected area without affecting the normal operation of a file system, and only files that have passed the security verification can be synchronized to the protected area. Therefore, the file operation performance is improved while blocking malware from damaging files.
Need to check novelty before this filing date? Find Prior Art

Description

Data processing method and device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 24, 2023, with application number 202311600657.7 and application name “A method, device and other equipment for data processing”, and the Chinese patent application filed with the State Intellectual Property Office on February 29, 2024, with application number 202410231614.4 and application name “Data processing method and device”, all contents of which are incorporated by reference into this application. Technical Field

[0002] The embodiments of the present application relate to the field of cloud computing, and in particular to a data processing method and device. Background Art

[0003] After invading a user's system, malware encrypts one or more files. The malware user then demands money or other financial benefits from the user, often in exchange for providing a decryption key. To prevent files from being encrypted by ransomware, users can use security software to scan the system for malicious file signatures and identify encrypted file characteristics, thereby detecting and blocking malware and reducing or eliminating the potential harm.

[0004] Existing security software typically intercepts file creation and modification operations in real time and inspects the file contents. If the file contents contain malicious characteristics, the software is blocked from further operations. Therefore, security software must intercept and pause file operations in real time, allowing or blocking execution only after the inspection is complete. This blocks file read and write operations, impacting file operation performance.

[0005] Summary of the Invention

[0006] The present application provides a data processing method and device, thereby improving file operation performance while blocking malicious software from causing harm to files.

[0007] In a first aspect, the present application provides a data processing method for use with a computing device including a file system, wherein the file system includes a transparent cache area and a protected area. The transparent cache area is transparent to the application and is isolated from the protected area. The protected area is used to store original files, and the transparent cache area is used to store shadow files, which are copies of the original files. In the data processing method, a data operation request from the application is first obtained. When the data operation request includes a modification operation on the original file in the protected area, the shadow file corresponding to the original file is modified according to the data operation request to obtain the modified file. Then, the modified file is synchronized to the protected area after confirming that the modified file has passed security verification.

[0008] Based on the above data processing method, while a computing device performs security verification and other checks on the shadow file in the transparent cache, it can still perform operations such as accessing the original file in the protected area, without blocking file reading and writing and affecting the normal operation of the file system. At the same time, data operation requests to modify the original file are redirected to the shadow file. Only modified files that pass security verification can be synchronized with the original file in the protected area, thus protecting the protected area from malware. This improves file operation performance while blocking malware from damaging files.

[0009] As a possible implementation, when a data operation request includes a modification operation on the original file, the computing device redirects the modification operation to the shadow file. Instead of performing the modification operation on the original file in the protected area, the computing device performs the modification operation on the shadow file in the transparent cache area to obtain the modified file. In this way, the computing device redirects the modification operation on the original file in the protected area to the shadow file, preventing the application from directly modifying the original file in the protected area. Because the protected area and the transparent cache area are isolated from each other, even if the application's modification operation on the shadow file contains malware, it cannot affect the original file in the protected area, thereby ensuring the security of the original file.

[0010] As a possible implementation, the computing device redirects modification operations to the shadow file through sector linking. This minimizes disk space occupied by newly added file content and minimizes the time required to move subsequent files from the transparent cache to the protected area, thereby improving file operation performance.

[0011] Optionally, before redirecting file modifications to the original file, the computing device also needs to create a shadow file in the transparent cache. The computing device creates a copy of the original file in the transparent cache, which serves as the shadow file corresponding to the original file. The shadow file's sector pointer points to the original sector where the original file resides. This way, when a data operation request does not involve a modification, access to the original file still points to the original sector. Only a new file needs to be created in the transparent cache, without copying the file data in the original sector, thereby ensuring file operation performance.

[0012] Optionally, when a data operation request includes a modification operation, the computing device creates a new sector to store the new data generated by the modification operation and modifies the shadow file's sector pointer to point to the new sector. Thus, when a data operation request involves a modification operation, access to the original file is redirected to the shadow file in the transparent cache area via a sector link, thereby ensuring the security of the protected file.

[0013] As one possible implementation, a data operation request can include a new file operation. The computing device redirects the file path of the newly created file to the file path of the shadow file. This way, when the computing device subsequently needs to access the newly created file, it accesses the file path of the original file, thereby accessing the shadow file through file path redirection. This achieves file path mapping without the application being aware of it, improving the user experience.

[0014] As a possible implementation, the data operation request may include a file open operation. The computing device receives a data operation request that instructs the user to open an original file. If a corresponding shadow file exists for the original file, the shadow file is opened. If no corresponding shadow file exists for the original file, the original file is directly opened, and a file handle may be recorded for tracking.

[0015] As one possible implementation, a data operation request can include a file deletion or file move operation. The computing device performs the file deletion or file move operation on the shadow file, obtaining the modified file and adding a mark to the original file. Upon determining that the modified file passes security verification, the computing device performs the file deletion or file move operation on the marked original file. This way, until the modified file passes security verification, the original file remains stored in the protected area, providing a file snapshot point for rapid file or system recovery.

[0016] As a possible implementation method, when a shadow file is modified, the computing device detects whether the modified file has ciphertext features or malicious program features. If not, it determines that the modified file passes the security verification.

[0017] Optionally, the computing device determines that the modified file has passed security verification when the modified file does not contain ciphertext features or malware features, and the time since the modification operation has reached a preset threshold. This allows the computing device to still access the original file while performing ciphertext features or malware feature detection on the shadow file, enabling concurrent file access and malware detection, and improving file operation performance.

[0018] In a second aspect, the present application provides a data processing device comprising a transceiver module and a processing module. The transceiver module is configured to receive data operation requests sent by an application, wherein the data operation requests include modification operations on original files in a protected area. The processing module is configured to modify a shadow file corresponding to the original file in accordance with the data operation request, thereby obtaining a modified file. The processing module is further configured to determine whether the modified file passes security verification and synchronize the modified file to the protected area.

[0019] As a possible implementation manner, the processing module is specifically used to redirect the modification operation to the shadow file to modify the shadow file to obtain the modified file.

[0020] Optionally, the processing module is specifically configured to redirect the modification operation to the shadow file by way of sector linking.

[0021] As a possible implementation method, before redirecting the modification operation to the shadow file through sector linking, the processing module is also used to: create a copy of the original file in the transparent cache area; the copy is the shadow file corresponding to the original file, and the sector pointer of the shadow file points to the original sector where the original file is located.

[0022] As a possible implementation manner, the processing module is further configured to: create a new sector to store new data generated by the modification operation; and modify the sector pointer of the shadow file to point to the new sector.

[0023] As a possible implementation manner, the data operation request includes a new file operation, and the processing module is further configured to redirect the file path of the new file to the file path of the shadow file.

[0024] As a possible implementation manner, the data operation request includes a file opening operation, and the processing module is further configured to: open a shadow file when a corresponding shadow file exists for the original file.

[0025] As a possible implementation method, the data operation request includes a file deletion operation or a file move operation, and the processing module is also used to: perform the file deletion or file move operation on the shadow file; add a mark to the original file; when it is determined that the modified file passes the security verification, perform the file deletion or file move operation on the original file carrying the mark.

[0026] As a possible implementation method, the processing module is specifically used to: when the shadow file is modified, detect whether the modified file has ciphertext features or malicious program features; when the modified file does not have ciphertext features or malicious program features, determine that the modified file passes security verification.

[0027] Optionally, the processing module is specifically configured to: determine that the modified file passes security verification when the modified file does not have ciphertext features or malicious program features and the time after the modification operation is performed reaches a preset threshold.

[0028] As a possible implementation manner, the data processing device may further include other modules for executing the operation steps of the data processing method described in the first aspect.

[0029] Regarding the technical principles and beneficial effects of the second aspect, please refer to the relevant description of the first aspect mentioned above, and no further details will be given here.

[0030] In a third aspect, a computing device is provided, comprising a processor and a memory. The processor of the computing device is configured to execute instructions stored in the memory of the computing device, so that the computing device executes the data processing method described in any possible implementation of the first aspect.

[0031] In a fourth aspect, a computer program product is provided, which includes a computer program or instructions, and when the computer program or instructions are executed on a computer, causes the computer to execute the data processing method described in any possible implementation of the first aspect.

[0032] In a fifth aspect, a computer-readable storage medium is provided. The computer-readable storage medium includes a computer program or instructions that, when executed on a computer, causes the computer to execute the data processing method described in any possible implementation of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] FIG1 is a schematic diagram of the architecture of a distributed system provided by this application;

[0034] FIG2 is a schematic diagram of the structure of a service node provided by this application;

[0035] FIG3 is a schematic diagram of the structure of a new technology file system provided by this application;

[0036] FIG4 is a flow chart of a data processing method provided by the present application;

[0037] FIG5 is a flow chart of a detection and arbitration step provided by the present application;

[0038] FIG6 is a schematic diagram of a flow chart of another detection and arbitration step provided by the present application;

[0039] FIG7 is a schematic diagram of a process for creating a new file provided by this application;

[0040] FIG8 is a schematic diagram of a process for opening a file provided by the present application;

[0041] FIG9 is a schematic diagram of a file modification process provided by this application;

[0042] FIG10 is a schematic diagram of a file deletion process provided by the present application;

[0043] FIG11 is a schematic diagram of a file movement process provided by the present application;

[0044] FIG12 is a schematic structural diagram of a data processing device provided by the present application;

[0045] FIG13 is a schematic diagram of the structure of a computing device provided by the present application;

[0046] FIG14 is a schematic diagram of the structure of a computing device cluster provided by this application;

[0047] FIG15 is a schematic diagram of a structure of a network connection between computing devices provided by the present application. DETAILED DESCRIPTION

[0048] The data processing method provided in the embodiment of the present application can be applied to the file system scenario in the storage field. The following is a brief introduction to the technologies that may be involved in this application.

[0049] (1) File system

[0050] A file system is the method and data structure used by an operating system to identify files on storage devices (such as disks, solid-state drives, etc.) or partitions, that is, the method used to organize files on storage devices. The software structure responsible for managing and storing file information in an operating system (OS) is called a file management system, or file system for short. A file system typically consists of three parts: the file system interface, a collection of software for manipulating and managing objects, and objects and their attributes. From a system perspective, a file system organizes and allocates space on file storage devices, is responsible for file storage, and protects and retrieves stored files. Specifically, a file system is responsible for creating files for users, storing, reading, modifying, and dumping files, controlling file access, and revoking files when they are no longer in use.

[0051] Common file systems include the File Allocation Table (FAT), the New Technology File System (NTFS), and the Extended File System (EXT). Taking NTFS as an example, NTFS uses a special data structure called the Master File Table (MFT) to store metadata about files and directories. Each file has an entry in the MFT that contains metadata such as the file name, size, creation time, and modification time. This entry also contains a pointer to the sector where the file data resides.

[0052] (2) Sector Link

[0053] A sector is the smallest physical storage unit on a disk, typically 512 bytes in size. A disk has many concentric tracks, which are divided into several equal arc segments, forming the disk's sectors. When the head reads or writes data from the disk, it does so in sectors. The concept of sectors applies not only to traditional mechanical hard drives, but also to modern non-volatile memory (NVM) technologies such as solid-state drives (SSDs). A block is the smallest unit of file system access. A block consists of multiple sectors, typically eight consecutive sectors, forming a 4-kilobyte (KB) block.

[0054] A sector link is a type of file link. Links point to data blocks within a file. That is, when an application accesses a file in the file system, it accesses the file's data through the link. For example, a hard link creates multiple file names in the file system that point to the data blocks of the same file. These file names are considered equivalent in the file system because they point to the same data blocks. When creating a hard link, the new file name and the original file name both point to the same data blocks. Therefore, if one file name is deleted, the file data still exists in the file system because it is still referenced by the other file names. Hard links can only be created within the same file system because they must point to the same data blocks. A soft link is a special file that contains a path to another file. For example, soft links are considered different files in the file system because they point to different data blocks. If the original file is deleted, the soft link becomes invalid because the file path it points to no longer exists. Soft links can span different file systems because they are simply paths to another file.

[0055] (3) Copy-on-write (COW)

[0056] Copy-on-write is an optimization strategy in computer programming. The core idea is that if multiple callers simultaneously request the same resource (such as memory or data storage on disk), they will all obtain the same pointer to the same resource. Only when a caller attempts to modify the contents of the resource will the system actually make a private copy for that caller, while the original resource remains unchanged for other callers.

[0057] The present application provides a data processing method, in particular, a "data processing method for redirecting modification operations on an original file to a shadow file in a transparent cache area." The data processing method can be applied to a computing device including a file system, wherein the file system includes a transparent cache area and a protected area. The transparent cache area is transparent to the application program, and the transparent cache area and the protected area are isolated from each other. In the process of the data processing method, a data operation request of the application program is first obtained. When the data operation request includes a modification operation on the original file in the protected area, the shadow file corresponding to the original file is modified according to the operation request to obtain the modified file. Then, it is determined that the modified file passes the security verification and the modified file is synchronized with the original file.

[0058] Based on the above data processing method, while a computing device performs security verification and other checks on the shadow file in the transparent cache, it can still perform operations such as accessing the original file in the protected area, without blocking file reading and writing and affecting the normal operation of the file system. At the same time, data operation requests to modify the original file are redirected to the shadow file. Only modified files that pass security verification can be synchronized with the original file in the protected area, thus protecting the protected area from malware. This improves file operation performance while blocking malware from damaging files.

[0059] The implementation of the embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0060] Figure 1 is a schematic diagram of the architecture of a distributed system provided herein. As shown in Figure 1 , distributed system 100 includes a computing server cluster 110, a storage server cluster 120, a management server cluster 130, a network device cluster 140, and a user terminal 150. Computing server cluster 110, storage server cluster 120, and management server cluster 130 each communicate with user terminal 150 via network device cluster 140.

[0061] The computing server cluster 110 includes one or more computing servers (two computing servers, namely, computing server 111 and computing server 112 , are shown in FIG1 , but are not limited to two computing servers).

[0062] Computing servers, such as servers and desktop computers, serve as computing resources in distributed system 100 and are used to generate and deploy computing resources based on user needs based on virtualization technology. At the hardware level, a computing server is equipped with a processor and memory (not shown in Figure 1). The computing server's computing functions are implemented by the processor running programs in the memory. The computing server can also read and write data to and from the various storage servers in storage server cluster 120 based on user needs.

[0063] The storage server cluster 120 includes one or more storage servers (two storage servers, storage server 121 and storage server 122 , are shown in FIG1 , but the present invention is not limited to two storage servers).

[0064] The storage server serves as a storage resource in the distributed system 100, such as a server, desktop computer, or storage array controller, hard disk frame, etc., and is used to provide logical disk storage, semi-structured data storage, and integrated backup services for the cloud virtual machines in the distributed system 100. In terms of hardware, the storage server is provided with a network card, a processor, and a memory. The processor in the storage server is used to process data from outside the storage server. The network card is used to control the access process of the memory, such as the control of address signals, data signals, and various command signals, so that the storage server can provide the memory as a storage resource to the user. The memory is used to store data and may include memory and / or a hard disk. Memory refers to an internal memory that directly exchanges data with the processor. The memory can read and write data quickly at any time and serves as a temporary data storage for the operating system or other running programs. Unlike memory, the hard disk reads and writes data slower than memory and is usually used to store data persistently.

[0065] The management server cluster 130 includes one or more management servers (two management servers, namely, management server 131 and management server 132 , are shown in FIG1 , but the present invention is not limited to two management servers).

[0066] The management server is used to manage all computing services, shared storage, and networks of the entire distributed system 100, and provides users or administrators with an application program interface (API) for managing the entire node. In this application, the distributed system 100 can provide the program product of this application to users by providing an accessible application program interface.

[0067] Network device cluster 140 includes one or more switches and routers. As shown in Figure 1, in this embodiment, network device cluster 140 includes router 141, switch 142, switch 143, switch 144, and switch 145. User terminal 150 is connected to router 141 via the Internet. Router 141 is further connected to switch 143 via switch 142. Switch 143 is connected to each computing server in computing server cluster 110. Switch 144 is connected to each computing server in computing server cluster 110 and each storage server in storage server cluster 120. Switch 145 is connected to each computing server in computing server cluster 110, each storage server in storage server cluster 120, and each management server in management server cluster 130.

[0068] Optionally, the number and type of switches included in network device cluster 140 can be adjusted based on the requirements of distributed system 100. Switches 142, 143, 144, and 145 can be switches with different functions. For example, switch 142 can be a core switch, while switches 143, 144, and 145 can be switches for managing specific network segments. For example, switch 142 can be a core switch, switch 143 can be an internal and external switching segment switch, switch 144 can be a storage segment switch, and switch 145 can be a management segment switch.

[0069] The user terminal 150 includes one or more user terminals ( FIG. 1 shows two user terminals, namely, the user terminal 151 and the user terminal 152 , but the present invention is not limited to two user terminals). The user terminal includes interfaces and applications required for accessing the distributed system 100 .

[0070] It is worth noting that Figure 1 is only a schematic diagram and should not be understood as a limitation of the present application. Any computing device with a file system can apply the data processing method provided in the present application. The computing device can be any device in the distributed system 100, or it can be an independent computing device in a non-distributed system. On the other hand, the above-mentioned distributed system 100 can also include other devices or other architectures, which are not drawn in Figure 1. For example, the computing server cluster 110, storage server cluster 120 and management server cluster 140 in Figure 1 are hardware-separated devices. In a possible embodiment, the computing server cluster 110, storage server cluster 120 and management server cluster 140 can also be different servers divided using hardware resources belonging to the same device on hardware.

[0071] The computing servers, storage servers, etc. in the above-mentioned distributed system 100 provided in this application can be nodes in the cloud platform. Based on the equipment of the distributed system 100 as shown in Figure 1, the distributed system 100 implements the functions of nodes such as computing nodes and storage nodes based on software as a service (SaaS), platform as a service (PaaS), and infrastructure as a service (IaaS), and provides services (such as computing services, storage services, and network services) to the user terminal 150 through the node. The node can be a service node (such as a computing node and a storage node) in the cloud obtained by virtualizing the resources (such as computing resources and storage resources) of the distributed system 100.

[0072] For example, as shown in Figure 2, the computing server cluster 110, storage server cluster 120, and / or management server cluster 140 in the distributed system 100 are virtualized into a service node. This service node runs an operating system, which in turn runs applications, filter drivers, detection and arbitration programs, a file system, and the like. The file system includes a transparent cache area and a protected area. The transparent cache area is transparent to the application and is isolated from the protected area. The protected area includes one or more original files, and the transparent cache area includes one or more shadow files corresponding to the original files.

[0073] Applications are used to send data operation requests to the file system. Data operation requests can include creating a new file, opening a file, modifying a file, deleting a file, or moving a file.

[0074] The file system perceives the data operation request for the original file through the filter driver, and redirects the operation to the shadow file in the transparent cache area to obtain the modified file.

[0075] The detection and arbitration program is used to detect the modified files and operations to determine whether the modified files pass the security verification.

[0076] The file system is also used to synchronize modified files in the transparent cache area with original files in the protected area.

[0077] As shown in Figure 3, using NTFS as an example, the protected area is used to store the original file, which includes the MFT and data content. The transparent cache area is used to store the shadow file corresponding to the original file in the protected area, that is, a copy of the original file. The MFT contains the file's metadata and pointers to the sectors where the file data is located. The shadow file in the transparent cache area is simply the MFT of a newly created basic file, and its file data still points to the sector pointers of the original file. Only when file data is modified does the file system create a new sector to store the new data, and the shadow file's original sector pointer is replaced with the new sector pointer.

[0078] The file system redirects the modification operation of the original file to the shadow file through sector linking. For example, sector A of the original file is linked to sector C. When the data operation request indicates to modify the file data of the original file stored in sector A, since sector A is linked to sector C, the modification operation is redirected to sector C through the sector link. Then the file system performs the modification operation on the copy of the original file stored in sector C (i.e., the shadow file).

[0079] It is worth noting that the above Figures 2 and 3 are only schematic diagrams and should not be understood as limitations on the present application. The virtual nodes of the distributed system 100 may also include other structures that are not drawn in Figures 2 or 3.

[0080] Next, the data processing method provided by this embodiment will be described in detail with reference to the accompanying drawings.

[0081] The steps of the data processing method provided in this application are executed by a device in a computing server or storage server in the distributed system 100, or by a node virtualized from the distributed system 100. Both the physical device and the virtualized node can be considered as a computing device. Next, with reference to FIG4 , the data processing method provided in the embodiment of this application will be described using a computing device as an example.

[0082] Step 401: The application sends a data operation request.

[0083] The application responds to user operations or sends data operation requests to the file system according to the application's own data needs during operation.

[0084] As a possible implementation manner, the data operation request includes operations such as opening a file, creating a new file, modifying a file, deleting a file, or moving a file.

[0085] Step 402: When the data operation request includes a modification operation on the original file in the protected area, the file system modifies the shadow file corresponding to the original file according to the data operation request to obtain a modified file.

[0086] When the data operation request includes a modification operation on the original file, the file system redirects the modification operation to the transparent cache area, that is, modifies the shadow file corresponding to the original file according to the data operation request, thereby redirecting the modification operation to the shadow file corresponding to the original file in the transparent cache area.

[0087] As a possible implementation manner, the data operation request may also include operations such as opening a file, creating a new file, deleting a file, or moving a file.

[0088] Optionally, when operations such as opening a file, creating a new file, deleting a file, or moving a file make substantial modifications to file data, the file system redirects the modification operation to the shadow file in the transparent cache area using sector links, so as to modify the shadow file corresponding to the original file according to the data operation request and obtain the modified file.

[0089] Optionally, when operations such as opening a file, creating a new file, deleting a file, or moving a file do not substantially modify the file data, the file system gives priority to accessing the shadow file if a corresponding shadow file exists for the original file, and accesses the original file if no corresponding shadow file exists for the original file.

[0090] When the file system accesses the original file, it records the file handle for tracking.

[0091] Whether the data operation request includes a substantial modification to the original file can be determined by the filter driver analyzing the data operation request. For example, the filter driver obtains the data operation request sent by the application and determines the file to be created, modified, deleted, or moved based on the data identifier (e.g., address, key-value pair identifier, etc.) contained in the data operation request.

[0092] For the specific steps of the above-mentioned operations such as opening a file, creating a new file, deleting a file, or moving a file, please refer to Figures 7 to 11 and related steps, which will not be repeated here.

[0093] Step 403: The file system determines that the modified file passes security verification.

[0094] When the file system determines that the modified file does not have ciphertext features or malicious program features, it determines that the modified file passes the security verification.

[0095] As a possible implementation, whether the modified file has ciphertext features or malicious program features is detected by a detection and arbitration program and then notified to the file system.

[0096] Optionally, as shown in FIG5 , the detection and arbitration program can immediately traverse the transparent cache area when the shadow file is modified, or periodically traverse the transparent cache area to perform ciphertext feature detection on the files in the transparent cache area (such as shadow files). When the files in the transparent cache area do not have ciphertext features, it is determined that the modified files have passed the security verification. The ciphertext feature detection can be based on a variety of methods such as the consistency of the ciphertext random entropy value to detect whether the file meets the ciphertext feature and improve the detection rate.

[0097] For example, when the file in the transparent cache does not have ciphertext features and reaches a preset threshold, it is determined that the modified file passes the security verification and the application continues to run.

[0098] For example, if a file in the transparent cache contains ciphertext features, the modified file is determined to have failed security verification, the shadow file synchronization with the original file is stopped, and an alert is issued. The alert can be sent or displayed to the user via voice, text, or an image. If the user confirms to continue the operation after receiving the alert, the file system proceeds to step 404 according to the user's instructions.

[0099] Optionally, as shown in FIG6 , the detection and arbitration program may traverse the transparent cache area to perform malicious program feature detection on files in the transparent cache area (such as shadow files). When there are no malicious program features in the files in the transparent cache area, it is determined that the modified file passes the security verification.

[0100] For example, when the file in the transparent cache area does not have malicious program features, it is determined that the modified file passes the security verification and the application continues to run.

[0101] For example, if a file in the transparent cache contains malware characteristics, the modified file is determined to have failed security verification, the malware is terminated, and an alert is issued. The alert may be sent or displayed to the user in the form of voice, text, or images.

[0102] In some possible implementations, the detection and arbitration program can simultaneously detect ciphertext features and malicious file features. The detection method is a combination of the above-mentioned ciphertext features and malicious program features, which will not be described in detail here.

[0103] Step 404: The file system synchronizes the modified file to the protected area.

[0104] As a possible implementation method, after determining that the modified file passes the security verification, the file system synchronizes the modified file to the original file in the protected area through sector links.

[0105] Based on the above data processing method, while a computing device performs security verification and other checks on the shadow file in the transparent cache, it can still perform operations such as accessing the original file in the protected area, without blocking file reading and writing and affecting the normal operation of the file system. At the same time, data operation requests to modify the original file are redirected to the shadow file. Only modified files that pass security verification can be synchronized with the original file in the protected area, thus protecting the protected area from malware. This improves file operation performance while blocking malware from damaging files.

[0106] The above text provides an overall description of the data processing method in conjunction with Figures 4-6. Next, in conjunction with Figures 7-11, the specific processing flow of the file system modifying the shadow file corresponding to the original file according to the data operation request in different file operation scenarios to obtain the modified file is described.

[0107] As shown in Figure 7, in the scenario of creating a new file, the file system obtains the data operation request sent by the application, and determines through a filter driver (such as a file filter driver) that the data operation request includes a new file operation. After the file system creates the original file in the path specified by the data operation request, it determines whether there is a shadow file corresponding to the original file (such as C:\dir\file). If there is a shadow file corresponding to the original file, the file system returns a message to the application that the file already exists. After the file system first determines whether the shadow file exists, it determines whether the original file exists. If the original file exists, the file system returns a message to the application that the file already exists. If the original file does not exist, the file system redirects the new file path to the path of the shadow file (such as C:\cached\dir\file, where cached represents a hidden whitelist folder, i.e., a transparent cache area), and the data of the new file is written to the shadow file.

[0108] The file system redirects the newly created file path to the shadow file path by mapping the original file path to the shadow file path. For example, the file system maps C:\dir\file to C:\cached\dir\file.

[0109] As shown in Figure 8, in the file open scenario, the file system receives a data operation request sent by the application and determines, through a filter driver (e.g., a file filter driver), that the data operation request includes a file open operation. If a shadow file corresponding to the original file exists, the file system opens the shadow file for access. If the shadow file corresponding to the original file does not exist, the file system opens the original file for access.

[0110] For example, the file system determines whether a shadow file corresponding to the original file exists based on the mapping method between the original file and the shadow file. For example, if the original file's path is C:\dir\file, the file system determines whether a shadow file corresponding to the original file exists in the transparent cache based on C:\cached\dir\file. If a shadow file corresponding to the original file exists in the transparent cache, the file system opens the shadow file based on C:\cached\dir\file. If a shadow file corresponding to the original file does not exist in the transparent cache, the file system opens the original file based on C:\dir\file and records the file handle for tracking.

[0111] As shown in Figure 9, in a file modification scenario, the file system obtains the data operation request sent by the application, and determines through a filter driver (such as a file filter driver) that the data operation request includes a modification operation. The file system redirects the modification operation to the shadow file by means of sector linking, that is, the sector corresponding to the existing data of the original file points to the shadow file, and sets the sector to read-only. In this way, when the file system performs a modification operation according to the data operation request, it will perform the modification operation on the shadow file. Among them, the sector pointed to by the original file can be a sector written by the filter driver (such as a disk filter driver) when the file system hook perceives the file modification.

[0112] For example, the file system performs a modification operation on the original file such as C:\dir\file based on a data operation request. The file system determines whether the shadow file corresponding to the original file exists based on the mapping method between the original file and the shadow file. If the shadow file C:\cached\dir\file corresponding to the original file does not exist in the transparent cache, the file system creates a shadow file corresponding to the original file and sets the sector corresponding to the original file to read-only. If the shadow file C:\cached\dir\file corresponding to the original file exists in the transparent cache, the sector corresponding to the original file is set to read-only, and a new sector is created to save the new data generated by the modification operation, and the sector pointer of the shadow file is modified to point to the new sector.

[0113] In some possible embodiments, the modified file is a small file (eg, less than 1 byte) and does not have independent data sectors, so the file system directly copies the entire original file to the transparent cache as a new shadow file.

[0114] In some possible embodiments, the modified file is newly added data, and the file system stores the newly added data in a new sector corresponding to the shadow file.

[0115] In some possible embodiments, the modified file is a modification of the original file, and the file system performs copy-on-write (COW) to copy the original file to a new sector corresponding to the shadow file and then modify the data in the new sector.

[0116] As shown in Figure 10, in the file deletion scenario, the file system obtains the data operation request sent by the application and determines through a filter driver (such as a file filter driver) that the data operation request includes a file deletion operation. The file system performs a file deletion operation on the shadow file corresponding to the original file to obtain the modified file, and adds a mark to the original file and hides it. The mark is used to indicate that the original file has been deleted. When it is determined that the deleted file passes the security verification, for example, when the time threshold is reached after the operation, the file system performs a file deletion operation on the original file carrying the mark and clears the mark.

[0117] For example, the file system deletes the original file such as C:\dir\file based on the data operation request. The file system determines whether the shadow file corresponding to the original file exists based on the mapping method between the original file and the shadow file. If the shadow file C:\cached\dir\file corresponding to the original file exists in the transparent cache area, the file system deletes the shadow file corresponding to the original file. If the original file still exists after deleting the shadow file, the file system adds a mark to the original file and hides it. If the shadow file C:\cached\dir\file corresponding to the original file does not exist in the transparent cache area, determine whether the original file exists. If the original file exists, the file system adds a mark to the original file and hides it. If the original file does not exist, the file system fails to delete the original file.

[0118] As shown in Figure 11, in the file moving scenario, the file system obtains the data operation request sent by the application and determines through a filter driver (such as a file filter driver) that the data operation request includes a file moving operation. The file system performs the file moving operation on the shadow file corresponding to the original file to obtain the modified (moved) file, and adds a mark to the original file and hides it. The mark is used to indicate that the original file has been moved. When it is determined that the file has passed the security verification after the move, for example, when the time threshold is reached after the operation, the file system performs a deletion operation on the original file carrying the mark and clears the mark.

[0119] For example, the file system moves the original file such as C:\dir\file according to the data operation request, and the file system determines whether the shadow file corresponding to the original file exists based on the mapping method between the original file and the shadow file. If the shadow file C:\cached\dir\file corresponding to the original file exists in the transparent cache area, the file system moves the shadow file corresponding to the original file. If the original file still exists after moving the shadow file, the file system adds a mark to the original file and hides it. If the shadow file C:\cached\dir\file corresponding to the original file does not exist in the transparent cache area, determine whether the original file exists. If the original file exists, the file system creates the shadow file after the move, adds a mark to the original file and hides it. If the original file does not exist, the file system fails to move the original file.

[0120] To support the data processing method shown in FIG4 provided herein, the present application further provides a data processing device 1200, which can be used to implement the service node functionality in the data processing method shown in FIG4. As shown in FIG12 , the data processing device 1200 includes a transceiver module 1210 and a processing module 1220.

[0121] The transceiver module 1210 is configured to obtain a data operation request from an application program. For example, the transceiver module 1210 is configured to execute step 401 as shown in FIG4 .

[0122] The processing module 1220 is configured to modify the shadow file corresponding to the original file according to the data operation request to obtain a modified file when the data operation request includes a modification operation on the original file in the protected area. For example, the processing module 1220 is configured to execute step 402 as shown in FIG4 .

[0123] The processing module 1220 is further configured to determine whether the modified file passes the security verification and synchronize the modified file to the protected area. For example, the processing module 1220 is configured to execute step 403 as shown in FIG4 .

[0124] As a possible implementation manner, the processing module 1220 is specifically configured to: when the data operation request includes a modification operation on the original file, redirect the modification operation to the shadow file to modify the shadow file and obtain a modified file.

[0125] As a possible implementation manner, the processing module 1220 is specifically configured to redirect the file path of the newly created file to the file path of the shadow file.

[0126] As a possible implementation manner, the modification operation includes file modification, and the processing module 1220 is specifically configured to redirect the modification operation to the shadow file by means of sector linking.

[0127] As a possible implementation, the processing module 1220 is further configured to: create a copy of the original file in the transparent cache area; the copy serves as a shadow file corresponding to the original file, and a sector pointer of the shadow file points to the original sector where the original file is located.

[0128] As a possible implementation manner, the processing module 1220 is specifically used to: create a new sector to store new data generated by the modification operation; and modify the sector pointer of the shadow file to point to the new sector.

[0129] As a possible implementation method, the modification operation includes deleting a file or moving a file. The processing module 1220 is specifically used to: perform the operation of deleting a file or moving a file on the shadow file to obtain a modified file; add a mark to the original file; when it is determined that the modified file passes the security verification, perform the operation of deleting a file or moving a file on the original file carrying the mark.

[0130] As a possible implementation method, the processing module 1220 is specifically used to: when the shadow file is modified, detect whether the modified file has ciphertext features or malicious program features; when the modified file does not have ciphertext features or malicious program features, determine that the modified file passes security verification.

[0131] As a possible implementation, the processing module 1220 is specifically configured to determine that the modified file passes security verification when the modified file does not have ciphertext features or malicious program features and the time after the modification operation reaches a preset threshold.

[0132] The transceiver module 1210 and the processing module 1220 can be implemented in software or hardware. For example, the implementation of the transceiver module 1210 will be described below using the transceiver module 1210 as an example. Similarly, the implementation of the processing module 1220 can refer to the implementation of the transceiver module 1210.

[0133] As an example of a software functional unit, the transceiver module 1210 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Furthermore, the computing instance may be one or more. For example, the transceiver module 1210 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including one data center or multiple geographically close data centers. Typically, a region may include multiple AZs.

[0134] Similarly, multiple hosts / virtual machines / containers running the code can be distributed within the same virtual private cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Cross-region communication between two VPCs within the same region, or between VPCs in different regions, requires a communication gateway within each VPC to interconnect the VPCs.

[0135] As an example of a hardware functional unit, the transceiver module 1210 may include at least one computing device, such as a server. Alternatively, the transceiver module 1210 may be implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0136] The multiple computing devices included in the transceiver module 1210 can be distributed in the same region or in different regions. The multiple computing devices included in the transceiver module 1210 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the transceiver module 1210 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of servers, ASICs, PLDs, CPLDs, FPGAs, GALs, and other computing devices.

[0137] It should be noted that, in other embodiments, any module in the transceiver module 1210 or the processing module 1220 can be used to execute any step in the data processing method, and the steps that the transceiver module 1210 and the processing module 1220 are responsible for implementing can be specified as needed. The full functions of the data processing device 1200 are realized by respectively implementing different steps in the data processing method through the transceiver module 1210 and the processing module 1220.

[0138] This application also provides a computing device 1300. As shown in Figure 13, computing device 1300 includes a bus 1302, a processor 1304, a memory 1306, and a communication interface 1308. Processor 1304, memory 1306, and communication interface 1308 communicate with each other via bus 1302. Computing device 1300 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in computing device 1300.

[0139] Bus 1302 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, among others. Buses may be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG13 shows a single line, but this does not imply a single bus or type of bus. Bus 1302 may include a path for transmitting information between various components of computing device 1300 (e.g., memory 1306, processor 1304, and communication interface 1308).

[0140] The processor 1304 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0141] The memory 1306 may include volatile memory, such as random access memory (RAM). The processor 1304 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0142] The memory 1306 stores executable program codes, and the processor 1304 executes the executable program codes to respectively implement the functions of the various modules included in the aforementioned data processing device 1200, thereby implementing the data processing method. In other words, the memory 1306 stores instructions for executing the data processing method.

[0143] Alternatively, the memory 1306 stores executable codes, and the processor 1304 executes the executable codes to respectively implement the functions of the aforementioned service nodes, thereby implementing the data processing method. In other words, the memory 1306 stores instructions for executing the data processing method.

[0144] The communication interface 1308 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 1300 and other devices or a communication network.

[0145] Considering that the data processing method provided in this application is applied to the distributed system 100, the infrastructure of the distributed system 100, such as the computing server cluster 110 and the storage server cluster 120, typically includes multiple computing devices. Therefore, this application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.

[0146] As shown in Figure 14, the computing device cluster includes at least one computing device 1300. The memory 1306 in one or more computing devices 1300 in the computing device cluster may store the same instructions for executing the data processing method.

[0147] In some possible implementations, the memory 1306 of one or more computing devices 1300 in the computing device cluster may also store partial instructions for executing the data processing method. In other words, the combination of one or more computing devices 1300 can jointly execute the instructions for executing the data processing method.

[0148] It should be noted that the memory 1306 in different computing devices 1300 in the computing device cluster can store different instructions, each used to execute part of the functions of the data processing apparatus 1200. In other words, the instructions stored in the memory 1306 in different computing devices 1300 can implement the functions of one or more modules included in the data processing apparatus 1200.

[0149] In some possible implementations, one or more computing devices in a computing device cluster may be connected via a network. The network may be a wide area network (WAN) or a local area network (LAN), among others. FIG. 15 illustrates one possible implementation. As shown in FIG. 15 , two computing devices 1300A and 1300B are connected via a network. Specifically, the network is connected via a communication interface in each computing device. In this type of possible implementation, the memory 1306 in the computing device 1300A stores instructions for executing the functions of one or more of the transceiver module 1210 and the processing module 1220. FIG. 15 takes the example of the memory 1306 in the computing device 1300A storing instructions for executing the functions of the transceiver module 1210. Simultaneously, the memory 1306 in the computing device 1300B stores instructions for executing the functions of one or more of the transceiver module 1210 and the processing module 1220. FIG. 15 takes the example of the memory 1306 in the computing device 1300B storing instructions for executing the functions of the processing module 1220.

[0150] It should be understood that the functionality of the computing device 1300A shown in FIG15 may also be implemented by multiple computing devices 1300. Similarly, the functionality of the computing device 1300B may also be implemented by multiple computing devices 1300.

[0151] The present application also provides a computer program product comprising instructions. The computer program product may be software or a program product comprising instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device executes the data processing method shown in FIG4 , or the steps executed by the service node in the data processing method shown in FIG4 .

[0152] The present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to perform the data processing method shown in FIG4 .

[0153] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (such as infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0154] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0155] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0156] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0157] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0158] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0159] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory, a random access memory, a magnetic disk, or an optical disk.

[0160] In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b and c can be single or multiple.

[0161] It should be noted that, in this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0162] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the protection scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A data processing method, characterized in that: The file system of the host includes a protected area and a transparent cache area, the protected area is used to store original files, the transparent cache area is used to store shadow files, and the shadow files are copies of the original files. The method includes: Acquire a data operation request sent by an application, wherein the data operation request includes a modification operation on an original file in the protected area; Modify the shadow file corresponding to the original file according to the data operation request to obtain a modified file; Determine that the modified file passes the security verification, and synchronize the modified file to the protected area.

2. The method according to claim 1, characterized in that The step of modifying the shadow file corresponding to the original file according to the data operation request to obtain a modified file includes: The modification operation is redirected to the shadow file to modify the shadow file and obtain the modified file.

3. The method according to claim 2, characterized in that The redirecting the modification operation to the shadow file comprises: The modification operation is redirected to the shadow file by means of sector linking.

4. The method according to claim 3, characterized in that Before redirecting the modification operation to the shadow file by means of sector linking, the method further includes: A copy of the original file is created in the transparent cache area; the copy is a shadow file corresponding to the original file, and a sector pointer of the shadow file points to the original sector where the original file is located.

5. The method according to claim 4, characterized in that The step of redirecting the modification operation to the shadow file by means of sector linking includes: Creating a new sector to store new data generated by the modification operation; The sector pointer of the shadow file is modified to point to the new sector.

6. The method according to any one of claims 1 to 5, characterized in that The data operation request includes a new file operation, and the method further includes: Redirect the file path of the newly created file to the file path of the shadow file.

7. The method according to any one of claims 1 to 6, characterized in that The data operation request includes an open file operation, and the method further includes: When a corresponding shadow file exists for the original file, open the shadow file.

8. The method according to any one of claims 1 to 7, characterized in that The data operation request includes a file deletion operation or a file move operation, and the method further includes: Performing an operation of deleting or moving a file on the shadow file; Adding a mark to the original file; When it is determined that the modified file passes the security verification, an operation of deleting or moving the file is performed on the original file carrying the mark.

9. The method according to any one of claims 1 to 8, characterized in that Determining that the modified file passes the security verification includes: When the shadow file is modified, detecting whether the modified file has ciphertext features or malicious program features; When the modified file does not have a ciphertext feature or a malicious program feature, it is determined that the modified file passes the security verification.

10. The method according to claim 9, characterized in that When the modified file does not have a ciphertext feature or a malicious program feature, determining that the modified file passes the security verification includes: When the modified file does not have a ciphertext feature or a malicious program feature, and the time after the modification operation is performed reaches a preset threshold, it is determined that the modified file passes the security verification.

11. A data processing device, characterized in that: include: The transceiver module is used to obtain a data operation request sent by an application program, wherein the data operation request includes a modification operation on an original file in the protected area; A processing module, used for modifying the shadow file corresponding to the original file according to the data operation request to obtain a modified file; The processing module is further used to determine that the modified file passes the security verification and synchronize the modified file to the protected area.

12. A computing device, characterized in that: including a processor and a memory; The processor is configured to execute instructions stored in the memory, so that the computing device performs the method according to any one of claims 1 to 10.

13. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device, the computing device is caused to perform the method according to any one of claims 1 to 10.

14. A computer-readable storage medium, characterized in that: The method comprises computer program instructions, and when the computer program instructions are executed by a computing device, the computing device performs the method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • File protection method and system

    CN101853363A

  • File protection method and device

    CN107871089A

  • Transparent encryption method and device, electronic equipment and storage medium

    CN115455440A

  • Method and system for protecting a computer file from a possible encryption performed by malicious code

    US20190114439A1

  • Shadow copy-based malware scanning

    US8220053B1