Detection method and apparatus, medium, and program product
Through the file quantity detection and encryption matrix analysis of backup files, combined with the time series anomaly detection model and classifier, the ransomware attack problem in the existing technology that cannot detect binary structure backup files is solved, and virus encryption detection of common format backup files is realized, which improves detection efficiency and accuracy.
Patent Information
- Application Number
- PCT/CN2024/109419
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-29
- Filing Date
- 2024-08-02
- Publication Date
- 2025-07-03
AI Technical Summary
Existing ransomware detection methods cannot accurately detect ransomware attacks on backup data, especially backup files of binary structures, and cannot rely on conventional file structure information, resulting in inaccurate detection.
By detecting the file volume of backup files, generating an encryption matrix and classifying it, using the time series exception detection model and classifier, virus encryption detection of common format backup files is realized, and backup files are avoided parsing.
Virus encryption detection of unresolvable backup files is realized, which improves detection efficiency and accuracy, and reduces dependence on backup file parsing.
Smart Images

Figure CN2024109419_03072025_PF_FP_ABST
Abstract
Description
A detection method, device, medium and program product
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 29, 2023, with application number 202311856164.X and application name “A detection method, device, medium and program product”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of storage, and in particular to a detection method, device, medium, and program product. Background Art
[0003] Ransomware is a type of malware that encrypts user data locally on a user's computer using strong encryption algorithms such as AES and RSA, making it impossible to recover or access the data unless a ransom is paid to obtain the key. The goal is to extort money. If the ransom is not paid within a specified timeframe, the files and data will be permanently lost. Currently, ransomware attacks are frequent and cause economic losses amounting to hundreds of billions of dollars. Therefore, given the explosive growth of the ransomware industry, further research on ransomware attack detection is urgently needed to reduce data loss and the resulting economic losses.
[0004] Currently, existing ransomware attack detection methods rely heavily on structural information such as the file's header, middle, and tail. However, binary backup files are binary structured data formed by the backup software stacking multiple files. They do not contain complete file structure information in a conventional sense. The data describing the file stacking rules is stored in a separate encrypted metadata file. Therefore, existing ransomware attack detection methods cannot accurately detect ransomware attacks on backup data and can only detect regular files.
[0005] Summary of the Invention
[0006] The present application provides a detection method, device, medium, and program product for performing virus encryption detection on backup files in a common format, thereby improving the security of backup storage.
[0007] In view of this, in a first aspect, the present application provides a detection method, comprising: first, obtaining a first backup file to be detected, where the first backup file can be a backup file in any format; after obtaining the first backup file, detecting the file size of the first backup file to obtain a first detection result, where the first detection result indicates that the file size of the first backup file is abnormal; then, based on the first detection result, performing an abnormal encryption detection on the first backup file to obtain a second detection result. The abnormal encryption detection is used to perform virus encryption detection on backup files in a common format, and the obtained second detection result indicates that the first backup file is encrypted by a virus.
[0008] The embodiment of the present application can perform virus encryption detection on backup files in a general format based on the detection of the file size of the backup files. It can not only detect the parsed backed up files, but also detect the unparseable backup files. Therefore, it no longer relies on the parsing of the backup files and has the ability to perform virus encryption detection on the internal data of backup files in a general format.
[0009] In a possible implementation, the aforementioned detecting the first backup file to obtain the first detection result may include: detecting the first backup file using a file volume anomaly detection model to obtain the first detection result.
[0010] In the embodiment of the present application, the file size of the backup file can be detected. By detecting whether the file size of the backup file has increased abnormally, a preliminary judgment can be made as to whether the backup file may have been attacked by encryption by a virus, thereby providing a basis for subsequent abnormal encryption detection.
[0011] In a possible implementation, the aforementioned abnormal encryption detection of the first backup file based on the first detection result may include: if the first detection result is that the data volume of the first backup file exceeds a preset value, then performing abnormal encryption detection on each second backup file in the first backup file through a time series anomaly detection model, where the first backup file includes multiple second backup files; if the first detection result is that the data volume of the first backup file does not exceed the preset value, then performing abnormal encryption detection on X second backup files in the first backup file through a time series anomaly detection model, where X is a positive integer.
[0012] In an embodiment of the present application, based on whether the file size of the first backup file has increased abnormally, it is possible to select all or part of the second backup files in the first backup file for abnormal encryption detection, and when the file size of the first backup file has not increased abnormally, only part of the second backup files may be detected, thereby reducing the amount of files to be detected and thus improving detection efficiency.
[0013] In a possible implementation, the aforementioned abnormal encryption detection of the first backup file may include: generating an encryption matrix of the second backup file based on the second backup file, the encryption matrix including the encryption status of the second backup file; classifying the encryption matrix through a first classifier to obtain a first classification result, the first classification result including a normal encryption matrix and an abnormal encryption matrix; calculating an encryption score of the second backup file based on the first classification result, the encryption score indicating the abnormality of the encryption matrix; performing abnormal encryption detection on the time series through a time series anomaly detection model to obtain a second detection result, the time series including the encryption scores of multiple second backup files.
[0014] In the embodiment of the present application, the detection of backup files can be converted into the detection of the encryption matrix of the backup files. Therefore, there is no need to parse the backup files first and then detect the parsed files. Abnormal encryption detection can be performed on both unparseable and parseable backup files, and it is no longer dependent on the parsing of the backup files, thereby realizing abnormal encryption detection of backup files in a general format.
[0015] In one possible implementation, the aforementioned generation of an encryption matrix for the second backup file based on the second backup file may include: performing feature extraction on the second backup file based on N sampling points of the second backup file to obtain M bytes of feature data for each sampling point, where M and N are positive integers; calculating eigenvalues of the M bytes of feature data, where the eigenvalues represent the encryption status of the feature data in the second backup file; and generating an encryption matrix based on the N eigenvalues, where the encryption matrix includes the N eigenvalues.
[0016] In a possible implementation, the aforementioned generation of an encryption matrix based on N eigenvalues may include: calculating the multidimensional channel value corresponding to the eigenvalue according to a dimensionality increase formula; mapping the second backup file into a space-filling curve to obtain the coordinates of each byte of data in the second backup file; and generating an encryption matrix based on the N multidimensional channel values and coordinates, wherein each element in the encryption matrix includes the multidimensional channel value and the corresponding coordinates.
[0017] In an embodiment of the present application, the eigenvalues can be converted into multi-dimensional channel values according to the dimensionality-raising formula, and the encrypted matrix can be displayed in the form of a picture in combination with the space-filling curve, so as to more intuitively display the encryption status of the encrypted matrix.
[0018] In one possible implementation, the aforementioned calculation of the encryption score of the second backup file based on the first classification result may include: if the first classification result is an abnormal encryption matrix, setting the value of the encryption score to a specific value; if the first classification result is a normal encryption matrix, dividing the encryption matrix into Y encryption sub-matrices, where Y is a positive integer; and calculating the encryption score based on the Y encryption sub-matrices.
[0019] In one possible implementation, the aforementioned calculation of the encryption score based on the Y encrypted sub-matrices may include: classifying the Y encrypted sub-matrices through a second classifier to obtain Y second classification results; calculating a sub-matrix ratio based on the number of normal encrypted sub-matrices and the number of abnormal encrypted sub-matrices in the Y second classification results; and using the sub-matrix ratio as the encryption score.
[0020] In a possible implementation, the aforementioned detection of the time series to obtain the second detection result may include: combining multiple encryption scores to obtain the time series; and detecting the time series using a time series anomaly detection model to obtain the second detection result.
[0021] In a second aspect, the present application provides a detection device, comprising:
[0022] A first detection module is configured to detect the first backup file and obtain a first detection result, wherein the first detection result indicates that the number of files in the first backup file is abnormal;
[0023] The second detection module is used to perform abnormal encryption detection on the first backup file based on the first detection result to obtain a second detection result. The abnormal encryption detection is used to perform virus encryption detection on the backup file in a general format. The second detection result indicates that the first backup file is encrypted by a virus.
[0024] In a possible implementation, the first detection module is specifically configured to detect the first backup file using a file volume anomaly detection model to obtain a first detection result.
[0025] In one possible implementation, the second detection module is specifically used to: if the first detection result is that the data volume of the first backup file exceeds a preset value, then perform abnormal encryption detection on each second backup file in the first backup file through a time series anomaly detection model, and the first backup file includes multiple second backup files; if the first detection result is that the data volume of the first backup file does not exceed the preset value, then perform abnormal encryption detection on X second backup files in the first backup file through a time series anomaly detection model, where X is a positive integer.
[0026] In one possible implementation, the second detection module is specifically configured to: generate an encryption matrix for the second backup file based on the second backup file, the encryption matrix including the encryption status of the second backup file; classify the encryption matrix using a first classifier to obtain a first classification result, the first classification result including a normal encryption matrix and an abnormal encryption matrix; calculate an encryption score for the second backup file based on the first classification result, the encryption score representing the abnormality of the encryption matrix; perform abnormal encryption detection on the time series using a time series anomaly detection model to obtain a second detection result, the time series including the encryption scores of multiple second backup files.
[0027] In one possible implementation, the second detection module is specifically used to: perform feature extraction on the second backup file based on N sampling points of the second backup file to obtain M bytes of feature data for each sampling point, where M and N are positive integers; calculate the eigenvalues of the M bytes of feature data, where the eigenvalues represent the encryption status of the feature data in the second backup file; and generate an encryption matrix based on the N eigenvalues, where the encryption matrix includes the N eigenvalues.
[0028] In one possible implementation, the second detection module is specifically used to: calculate the multidimensional channel value corresponding to the eigenvalue according to the dimensionality increase formula; map the second backup file into a space-filling curve to obtain the coordinates of each byte of data in the second backup file; generate an encryption matrix based on N multidimensional channel values and coordinates, and each element in the encryption matrix includes a multidimensional channel value and a corresponding coordinate.
[0029] In one possible implementation, the second detection module is specifically configured to: if the first classification result is an abnormal encryption matrix, set the value of the encryption score to a specific value; if the first classification result is a normal encryption matrix, divide the encryption matrix into Y encryption sub-matrices, where Y is a positive integer; and calculate the encryption score based on the Y encryption sub-matrices.
[0030] In one possible implementation, the second detection module is specifically configured to: classify Y encrypted submatrices using a second classifier to obtain Y second classification results; calculate a submatrix ratio based on the number of normal encrypted submatrices and the number of abnormal encrypted submatrices in the Y second classification results; and use the submatrix ratio as an encryption score.
[0031] In a possible implementation, the second detection module is specifically configured to: combine multiple encryption scores to obtain a time series; and detect the time series using a time series anomaly detection model to obtain a second detection result.
[0032] In a third aspect, the present application provides a detection device, which includes: a processor, a memory, an input / output device, and a bus; the memory stores computer instructions; when the processor executes the computer instructions in the memory, the memory stores computer instructions; when the processor executes the computer instructions in the memory, it is used to implement any one of the implementation methods of the first aspect.
[0033] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium having computer instructions stored therein; when the computer instructions are executed on a computer, the computer is caused to execute the method described in the possible implementation of the first aspect.
[0034] In a fifth aspect, an embodiment of the present application provides a computer program product. The computer program product includes a computer program or instructions, which, when executed on a computer, causes the computer to execute the method described in the possible implementation of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] FIG1 is a framework diagram of a backup storage system provided by this application;
[0036] FIG2 is a flowchart of a process for detecting backup files in a common format;
[0037] FIG3 is a schematic diagram of a flow chart of a detection method provided by the present application;
[0038] FIG4 is a schematic diagram of a process for detecting abnormal encryption of backup files;
[0039] FIG5 is a flow chart of an abnormal encryption detection method provided by the present application;
[0040] FIG6 is a schematic diagram of a process for generating an encryption matrix based on a backup file;
[0041] FIG7 is a schematic diagram of a process for generating an encryption matrix according to an encryption matrix and filling rules;
[0042] FIG8 is a schematic structural diagram of a detection device provided by the present application;
[0043] FIG9 is a schematic structural diagram of another detection device provided in this application. DETAILED DESCRIPTION
[0044] The following will describe the technical solutions in the embodiments of this application in conjunction with the drawings in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.
[0045] The following is an introduction to the backup storage system framework on which this application is based.
[0046] Referring to FIG. 1 , the present application provides a backup storage system 100 . The backup storage system 100 includes a controller 110 and a storage disk 120 . The controller 110 includes a read module 111 and a backup file ransomware detection framework 112 . The read module 111 in the controller 110 can retrieve a backup file in a common format from the storage disk 120 and transmit the retrieved backup file in the common format to the backup file ransomware detection framework 112 . The backup file ransomware detection framework 112 can perform ransomware encryption detection on the backup file, or can perform other virus encryption detection on the backup file, without limitation.
[0047] It should be noted that, in actual applications, the backup file in the universal format obtained by the reading module 111 is not necessarily obtained from the storage disk 120, but may also be obtained from a database or other storage device. The above description should not be used as a limitation on the embodiments of the present application.
[0048] It is worth noting that Figure 1 is only a schematic diagram of a system architecture provided by an embodiment of the present application. The positional relationship between the devices, components, modules, etc. shown in the figure does not constitute any limitation. For example, in Figure 1, the reading module 111 is an internal module relative to the controller 110. In other cases, the reading module 111 can also be placed outside the controller 110.
[0049] Based on the above system framework, the following is an introduction to the process framework diagram for detecting backup files in a common format.
[0050] Figure 2 is a flowchart for testing backup files in a common format. This process framework includes a backup file volume anomaly detection module and a backup internal encryption anomaly detection module. The backup file volume anomaly detection module is used to detect whether the backup file volume has increased abnormally. Based on the detection results obtained by the backup file volume anomaly detection module, the internal data of the backup file is further tested for encryption anomalies. If the backup file volume has not increased abnormally, the backup internal encryption anomaly detection module can test some backup files. Otherwise, the backup internal encryption anomaly detection module can test all backup files to obtain a test result, which includes both normal backup files and abnormal backup files.
[0051] A normal backup file indicates that the backup file has not been encrypted by a virus, while an abnormal backup file indicates that the backup file has been encrypted by a virus. The backup internal encryption anomaly detection module can be further divided into format-aware detection and format-unaware detection. Format-aware detection detects encryption anomalies in parseable backup files, while format-unaware detection detects encryption anomalies in unparseable backup files. The backup internal encryption anomaly detection module can detect both parseable and unparseable backup files, enabling detection of backup files in common formats.
[0052] Existing encryption detection methods primarily rely on structural information such as the file's header, middle, and tail. However, binary backup files are composed of multiple files stacked together, lacking comprehensive file information in the conventional sense. Furthermore, data describing the file stacking patterns is stored in a separate, encrypted metadata file. Therefore, existing encryption detection methods cannot directly and accurately detect binary backup files. Instead, they rely on parsing the backup files, restoring them to their original data, and then performing encryption detection on the original data.
[0053] To solve the current problems, this application proposes a detection method that no longer relies on parsing backup files and can perform abnormal encryption detection on backup files in a common format.
[0054] The following is an introduction to the method flow provided in this application in combination with the aforementioned system architecture and process framework diagram.
[0055] Referring to FIG3 , a flow chart of a detection method provided in the present application is shown as follows.
[0056] 301. Obtain a first backup file;
[0057] Before detecting the first backup file, one or more first backup files may be obtained. The first backup files may be obtained from a backup storage system or a database, and the details are not limited here.
[0058] 302. Detect the first backup file to obtain a first detection result.
[0059] After obtaining one or more first backup files, the file size of the first backup files may be detected, and a first detection result may be used to preliminarily determine whether the first backup files have been attacked by encryption by a virus.
[0060] Typically, when a virus attacks a backup file, it creates one or more encrypted copies, causing an abnormal increase in the number of backup files. By detecting this abnormal increase in the number of backup files, we can preliminarily determine whether the backup file has been attacked by a virus encryption attack. Furthermore, based on the backup file size detection results, we can further perform abnormal encryption detection on specific backup files, avoiding the need to perform abnormal encryption detection on all backup files at once, thereby reducing detection costs.
[0061] The data volume of the first backup file can be detected using a file volume anomaly detection model to determine whether the file volume of the first backup file has increased sharply, thereby obtaining a first detection result. The file volume anomaly detection model can be a machine learning-based model, such as a deep learning model based on t-distribution learning, or a neural network model, the specific details of which are not limited herein.
[0062] Furthermore, the first detection result can be obtained by analyzing the timing characteristics of the first backup file. Since a virus attack will back up multiple backup files, causing the timing characteristics of the backup files to change, the timing characteristics of the first backup file can be analyzed to determine whether the backup file size is abnormal.
[0063] 303. Perform an abnormal encryption detection on the first backup file based on the first detection result to obtain a second detection result.
[0064] After the first backup file is initially detected, the first backup file can be further detected for abnormal encryption based on the first detection result. The abnormal encryption detection can perform virus encryption detection on backup files in a general format. The second detection result obtained indicates that the first backup file is encrypted by a virus.
[0065] The virus that encrypts the backup files may be a ransomware virus or other viruses that maliciously encrypt files, and the specifics are not limited here.
[0066] Optionally, when the first detection result indicates that the data volume of the first backup file exceeds a preset value, each second backup file in the first backup file may be subjected to anomaly encryption detection using the time series anomaly detection model, where the first backup file includes multiple second backup files. When the first detection result indicates that the data volume of the first backup file does not exceed the preset value, X second backup files in the first backup file may be subjected to anomaly encryption detection using the time series anomaly detection model, where X is typically less than the total number of second backup files.
[0067] In an embodiment of the present application, the number of backup files to be checked for abnormal encryption can be selected based on the preliminary detection result of the first backup file. When the preliminary detection result of the first backup file is that the file quantity of the first backup file is normal, only part of the second backup files in the first backup file can be checked for abnormal encryption, thereby reducing the workload of abnormal encryption detection and improving detection efficiency.
[0068] Taking t-distribution learning as an example, we can use t-distribution learning to analyze the file size of historical backup files and the confidence interval of the average file size of historical backup files. If the file size of the first backup file is within the confidence interval, we can preliminarily determine that the file size of the first backup file is normal, and we can extract 50 second backup files from the first backup file for abnormal encryption detection, because the first backup file includes multiple second backup files. Otherwise, we preliminarily determine that the file size of the first backup file is abnormal, and we can perform abnormal encryption detection on each second backup file in the first backup file.
[0069] Optionally, abnormal encryption detection is performed on each second backup file in the first backup file, or on X second backup files. An encryption matrix for the second backup file can be generated based on the second backup file, an encryption score for the encryption matrix can be calculated, and multiple encryption scores can be combined to form a time series. Abnormal encryption detection is then performed on the time series to obtain a second detection result. A schematic diagram of the process for abnormal encryption detection of backup files is shown in Figure 4.
[0070] The encryption matrix is generated based on the characteristic data of the second backup file. By calculating the eigenvalues of the characteristic data, which indicate the encryption status of the second backup file, the encryption matrix includes multiple eigenvalues, i.e., the encryption status of the second backup file. Thus, by analyzing the encryption matrix, an abnormal encryption detection result for the second backup file can be obtained.
[0071] Specifically, the encryption matrix can be classified using a first classifier to obtain a first classification result, which includes a normal encryption matrix and an abnormal encryption matrix. Based on the first classification result, an encryption score of the encryption matrix can be calculated. A time series anomaly detection model can be used to perform anomaly encryption detection on the time series to obtain a second detection result.
[0072] Among them, the time series anomaly detection model can be an isolation forest anomaly detection algorithm to analyze the time series, and can also adopt various models based on machine learning, such as K-means clustering algorithm, support vector machine, long short-term memory network or recurrent neural network, etc., which are not limited here.
[0073] The encryption score of the encryption matrix can be calculated by making a preliminary judgment on the encryption matrix. According to the first classification result, the encryption score of the abnormal encryption matrix in the encryption matrix is set to a specific value, such as 1 or other values; for the normal encryption matrix in the encryption matrix, the normal encryption matrix can be further divided to obtain Y encryption sub-matrices, and the Y encryption sub-matrices are classified by the second classifier to obtain the second classification result. According to the number of normal encryption matrices and the number of abnormal encryption matrices in the second classification result, the abnormal sub-matrix ratio of the normal encryption matrix is calculated, and the abnormal sub-matrix ratio is used as the encryption score.
[0074] In an embodiment of the present application, the file size of the first backup file can be detected. Based on the detection results, all or part of the second backup file in the first backup file can be selected for abnormal encryption detection, thereby determining whether the first backup file has been attacked by virus encryption. This abnormal encryption detection method can detect backup files in a common format and no longer relies on parsing the backup files. In addition, through the layer-by-layer detection method, when the file size of the first backup file has not increased abnormally, only part of the second backup file in the first backup file needs to be detected for abnormal encryption, reducing the workload of abnormal encryption detection and thus improving detection efficiency.
[0075] After the first backup file is detected, based on the first detection result, abnormal encryption detection will be performed on all or part of the second backup files in the first backup file. The following is an example of abnormal encryption detection on one or more second backup files.
[0076] Referring to FIG5 , a flowchart of an abnormal encryption detection method provided by the present application is described below.
[0077] 501. Generate an encryption matrix based on the second backup file;
[0078] When abnormal encryption detection is performed on the second backup file in the first backup file, an encryption matrix may be generated according to the second backup file. The encryption matrix includes the encryption status of the second backup file.
[0079] Alternatively, the second backup file can be viewed as a line in a one-dimensional space. Based on the length of the second backup file, N (or n*m, where N=n*m) sampling points can be selected at equal or random intervals, where n and m represent the number of rows and columns, respectively, of the encryption matrix of the second backup file. Feature extraction is performed on the second backup file based on the obtained n*m sampling points, obtaining M bytes of feature data for each sampling point.
[0080] Optionally, based on the obtained characteristic data, a characteristic value of the M-byte characteristic data may be calculated, where the characteristic value represents the encryption status of the characteristic data in the second backup file.
[0081] Optionally, an encryption matrix may be generated according to the n*m eigenvalues, where the encryption matrix includes the n*m eigenvalues.
[0082] For example, for each sampling point, M bytes of data around each sampling point can be selected as feature data. For example, 5 bytes of data before and after the sampling point can be selected as feature data, or 4 bytes of data before and 6 bytes of data after the sampling point can be selected as feature data. The specific details are not limited here. After obtaining M bytes of feature data, a feature value of the M bytes of data can be calculated. The feature value can be an entropy value of the M bytes of data or a p-value of a chi-square test. The specific details are not limited here. The entropy value or the p-value of the chi-square test can both indicate the degree of chaos in the system, that is, the degree of encryption of the second backup file.
[0083] Optionally, an encryption matrix is generated based on the n*m eigenvalues. The obtained eigenvalues can be converted into multidimensional channel values according to a dimensionality-raising formula. The multidimensional channel values can be RGB channel values, or four-dimensional or five-dimensional channel values, the specific details of which are not limited here. Furthermore, the second backup file can be mapped to a space-filling curve to obtain the coordinates of each byte of data in the second backup file. Based on the obtained multidimensional channel values and the coordinates of each byte of data, an encryption matrix is generated, where each element in the encryption matrix includes the corresponding multidimensional channel value and the corresponding coordinates.
[0084] Each byte in the second backup file is mapped to two-dimensional space according to the filling rule. Points that are close in one-dimensional space are also close in the space-filling curve in two-dimensional space. A schematic diagram of the process for generating an encryption matrix from a backup file is shown in Figure 6, and a schematic diagram of the process for generating an encryption matrix based on the length, width, and filling rule of the encryption matrix is shown in Figure 7.
[0085] In the embodiment of the present application, by converting the acquired eigenvalues into multi-dimensional channel values and mapping the backup file into a space-filling curve, the encryption matrix is presented in the form of a picture, which can more intuitively show the encryption status of the backup file.
[0086] 502. Classify the encryption matrix using a first classifier to obtain a first classification result;
[0087] After the encryption matrix is obtained, the encryption matrix can be classified according to the classifier to obtain a classification result of the encryption matrix, so that the encryption score of the encryption matrix can be calculated according to the classification result.
[0088] Optionally, the encryption matrix can be classified using a first classifier to obtain a first classification result, which includes a normal encryption matrix and an abnormal encryption matrix. Using the first classifier to perform preliminary classification of the encryption matrix can directly filter out abnormal encryption matrices, reducing the number of encryption submatrices that need to be subsequently classified, thereby improving detection efficiency.
[0089] Optionally, according to the first classification result, the normal encryption matrix may be divided into Y encryption sub-matrices, and the Y encryption sub-matrices may be further classified by a second classifier to obtain a second classification result.
[0090] 503. Calculate an encryption score of the encryption matrix based on the first classification result;
[0091] After obtaining the classification result of the encryption matrix, an encryption score of the encryption matrix can be calculated according to the classification result. The encryption score represents the encryption status of the encryption matrix.
[0092] Optionally, based on the first classification result, the encryption score of the abnormal encryption matrix is set to a specific value, which may be 1 or other specific values, which are not limited here.
[0093] Optionally, for a normal encryption matrix, a submatrix ratio λ can be calculated based on the number y1 of normal encryption submatrices and the number y2 of abnormal encryption submatrices in the second classification result, and the submatrix ratio λ is used as the encryption score of the normal encryption matrix. This submatrix ratio can be either an abnormal submatrix ratio or a normal submatrix ratio, the specific details of which are not limited here. If it is an abnormal submatrix ratio, the formula λ = Y2 / Y is satisfied. If it is a normal submatrix ratio, the formula λ = Y1 / Y is satisfied.
[0094] 504. Perform anomaly encryption detection on the time series using the time series anomaly detection model to obtain a second detection result.
[0095] After obtaining the encryption score of the encryption matrix, the encryption scores of multiple second backup files can be combined to obtain a time series. The time series is then subjected to an abnormal encryption detection through a time series anomaly detection model to obtain a second detection result, which indicates that the second backup file is encrypted by a virus.
[0096] Typically, when there are compressed files in the backup file, when classified by the first classifier, the first classification result obtained is a normal encryption matrix. However, when the encryption sub-matrix is classified by the second classifier, the compressed file may be divided into an abnormal encryption sub-matrix, thereby affecting the encryption score of the normal encryption matrix. Therefore, a time series anomaly detection model can be used to comprehensively analyze the encryption score of the backup file. Based on the analysis result, that is, the second detection result, it is determined whether the backup file has been attacked by a ransomware virus.
[0097] In an embodiment of the present application, the detection of backup files can be converted into the detection of encryption matrices, thereby no longer relying on the parsing of backup files, and abnormal encryption detection can be performed on backup files in a common format. Specifically, the feature data in the second backup file can be extracted, and the eigenvalues of multiple feature data are calculated. Based on the eigenvalues and the space-filling curve, an encryption matrix is generated. Subsequently, the encryption score of the encryption matrix can be calculated, and the multiple encryption scores can be combined to obtain a time series. The time series is then subjected to abnormal encryption detection using a time series anomaly detection model, thereby obtaining a detection result of whether the second backup file has been attacked by ransomware encryption.
[0098] The above describes the method flow provided by the present application. Based on the above method flow, the following describes the device provided by the present application.
[0099] Referring to FIG8 , a schematic diagram of the structure of a detection device provided by the present application includes:
[0100] A first detection module 801 is configured to detect the first backup file and obtain a first detection result, where the first detection result indicates that the number of files in the first backup file is abnormal;
[0101] The second detection module 802 is used to perform abnormal encryption detection on the first backup file based on the first detection result to obtain a second detection result. The abnormal encryption detection is used to perform virus encryption detection on the backup file in a general format. The second detection result indicates that the first backup file is encrypted by a virus.
[0102] In a possible implementation, the first detection module 801 is specifically configured to detect the first backup file using a file volume anomaly detection model to obtain a first detection result.
[0103] In one possible implementation, the second detection module 802 is specifically configured to: if the first detection result is that the data volume of the first backup file exceeds a preset value, then perform an abnormal encryption detection on each second backup file in the first backup file through a time series anomaly detection model, where the first backup file includes multiple second backup files; if the first detection result is that the data volume of the first backup file does not exceed the preset value, then perform an abnormal encryption detection on X second backup files in the first backup file through a time series anomaly detection model, where X is a positive integer.
[0104] In one possible implementation, the second detection module 802 is specifically configured to: generate an encryption matrix for the second backup file based on the second backup file, the encryption matrix including the encryption status of the second backup file; classify the encryption matrix using a first classifier to obtain a first classification result, the first classification result including a normal encryption matrix and an abnormal encryption matrix; calculate an encryption score for the second backup file based on the first classification result, the encryption score representing the abnormality of the encryption matrix; perform abnormal encryption detection on the time series using a time series anomaly detection model to obtain a second detection result, the time series including the encryption scores of multiple second backup files.
[0105] In one possible implementation, the second detection module 802 is specifically configured to: perform feature extraction on the second backup file based on N sampling points of the second backup file to obtain M bytes of feature data for each sampling point, where M and N are positive integers; calculate eigenvalues of the M bytes of feature data, where the eigenvalues represent the encryption status of the feature data in the second backup file; and generate an encryption matrix based on the N eigenvalues, where the encryption matrix includes the N eigenvalues.
[0106] In one possible implementation, the second detection module 802 is specifically used to: calculate the multidimensional channel value corresponding to the eigenvalue according to the dimensionality increase formula; map the second backup file into a space-filling curve to obtain the coordinates of each byte of data in the second backup file; and generate an encryption matrix based on N multidimensional channel values and coordinates, wherein each element in the encryption matrix includes a multidimensional channel value and a corresponding coordinate.
[0107] In one possible implementation, the second detection module 802 is specifically configured to: if the first classification result is an abnormal encryption matrix, set the value of the encryption score to a specific value; if the first classification result is a normal encryption matrix, divide the encryption matrix into Y encryption sub-matrices, where Y is a positive integer; and calculate the encryption score based on the Y encryption sub-matrices.
[0108] In one possible implementation, the second detection module 802 is specifically configured to: classify the Y encrypted sub-matrices using a second classifier to obtain Y second classification results; calculate a sub-matrix ratio based on the number of normal encrypted sub-matrices and the number of abnormal encrypted sub-matrices in the Y second classification results; and use the sub-matrix ratio as an encryption score.
[0109] In a possible implementation, the second detection module 802 is specifically configured to: combine multiple encryption scores to obtain a time series; and detect the time series using a time series anomaly detection model to obtain a second detection result.
[0110] Please refer to FIG9 , which is a schematic structural diagram of another detection device provided in the present application, as described below.
[0111] The detection device may include a processor 901 and a memory 902. The processor 901 and the memory 902 are interconnected via a circuit. The memory 902 stores program instructions and data.
[0112] The memory 902 stores program instructions and data corresponding to the steps in FIG. 3 and FIG. 5 .
[0113] The processor 901 is configured to execute the method steps performed by the model determination apparatus shown in FIG. 3 and FIG. 5 .
[0114] Optionally, the model determination device may further include a transceiver 903 for receiving or sending data.
[0115] A computer-readable storage medium is also provided in an embodiment of the present application. The computer-readable storage medium stores a program, which, when executed on a computer, enables the computer to execute the steps of the method described in the embodiments shown in the aforementioned Figures 3 and 5.
[0116] An embodiment of the present application also provides a computer program product, which, when executed on a computer, enables the computer to execute the method steps described in the embodiment shown in FIG. 3 or FIG. 5 .
[0117] It should also be noted that the device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment. In addition, in the drawings of the device embodiments provided in this application, the connection relationship between the modules indicates that there is a communication connection between them, which can be specifically implemented as one or more communication buses or signal lines.
[0118] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0119] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0120] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0121] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0122] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0123] The terms "first," "second," "third," "fourth," and the like (if any) in the specification and claims of this application and in the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions, e.g., a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0124] Finally, it should be noted that the above is only a specific implementation method of the present application, but the protection scope of the present application is not limited to this. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the protection scope of the present application.
Claims
1. A detection method, characterized in that, Including: Detecting a first backup file to obtain a first detection result, where the first detection result indicates an abnormal situation of the number of files in the first backup file; According to the first detection result, performing abnormal encryption detection on the first backup file to obtain a second detection result, where the abnormal encryption detection is used to detect virus encryption of backup files in a general format, and the second detection result indicates the situation of the first backup file being encrypted by the virus.
2. The method according to claim 1, wherein The detecting the first backup file to obtain a first detection result includes: Detecting the first backup file through a file volume anomaly detection model to obtain the first detection result.
3. The method according to any one of claims 1 or 2, characterized in that The performing abnormal encryption detection on the first backup file according to the first detection result includes: If the first detection result is that the data volume of the first backup file exceeds a preset value, performing the abnormal encryption detection on each second backup file in the first backup file through a time series anomaly detection model, where the first backup file includes multiple second backup files; If the first detection result is that the data volume of the first backup file does not exceed the preset value, performing the abnormal encryption detection on X second backup files in the first backup file through the time series anomaly detection model, where X is a positive integer.
4. The method according to claim 3, wherein The performing abnormal encryption detection on the first backup file includes: Generating an encryption matrix of the second backup file according to the second backup file, where the encryption matrix includes the encryption status of the second backup file; Classifying the encryption matrix through a first classifier to obtain a first classification result, where the first classification result includes a normal encryption matrix and an abnormal encryption matrix; Calculating an encryption score of the second backup file according to the first classification result, where the encryption score represents the abnormal situation of the encryption matrix; Performing the abnormal encryption detection on a time series through the time series anomaly detection model to obtain the second detection result, where the time series includes encryption scores of multiple second backup files.
5. The method according to claim 4, wherein The generating the encryption matrix of the second backup file according to the second backup file includes: Performing feature extraction on the second backup file according to N sampling points of the second backup file to obtain M-byte feature data of each sampling point, where M and N are positive integers; Calculating a feature value of the M-byte feature data, where the feature value represents the encryption situation of the feature data in the second backup file; Generating the encryption matrix according to N feature values, where the encryption matrix includes the N feature values.
6. The method according to claim 5, characterized in that, The generating the encryption matrix according to N feature values includes: Calculating a multi-dimensional channel value corresponding to the feature value according to a dimensionality increase formula; Mapping the second backup file to a space filling curve to obtain coordinates of data of each byte in the second backup file; Generating the encryption matrix according to N multi-dimensional channel values and the coordinates, where each element in the encryption matrix includes the multi-dimensional channel value and the corresponding coordinate.
7. The method according to any one of claims 4 to 6, characterized in that Calculating the encryption score of the second backup file according to the first classification result includes: If the first classification result is the abnormal encryption matrix, set the value of the encryption score to a specific value; If the first classification result is the normal encryption matrix, divide the encryption matrix into Y encryption sub-matrices, where Y is a positive integer; Calculate the encryption score according to the Y encryption sub-matrices.
8. The method according to claim 7, wherein Calculating the encryption score according to the Y encryption sub-matrices includes: Classify the Y encryption sub-matrices through a second classifier to obtain Y second classification results; Calculate the sub-matrix ratio according to the number of normal encryption sub-matrices and the number of abnormal encryption sub-matrices in the Y second classification results; Use the sub-matrix ratio as the encryption score.
9. The method according to any one of claims 4 to 8, characterized in that Detecting the time series to obtain the second detection result includes: Combine multiple encryption scores to obtain the time series; Detect the time series through the time series anomaly detection model to obtain the second detection result.
10. A detection device, characterized in that, Including: A first detection module for detecting a first backup file to obtain a first detection result, where the first detection result indicates the abnormal situation of the file quantity of the first backup file; A second detection module for performing abnormal encryption detection on the first backup file according to the first detection result to obtain a second detection result. The abnormal encryption detection is used to detect virus encryption of a backup file in a general format, and the second detection result indicates the situation where the first backup file is encrypted by the virus.
11. The device according to claim 10, characterized in that, Specifically, the first detection module is used for: Detect the first backup file through a file quantity anomaly detection model to obtain the first detection result.
12. The device according to any one of claims 10 or 11, characterized in that Specifically, the second detection module is used for: If the first detection result is that the data volume of the first backup file exceeds a preset value, perform the abnormal encryption detection on each second backup file in the first backup file through a time series anomaly detection model. The first backup file includes multiple second backup files; If the first detection result is that the data volume of the first backup file does not exceed the preset value, perform the abnormal encryption detection on X second backup files in the first backup file through the time series anomaly detection model, where X is a positive integer.
13. The device according to claim 12, wherein Specifically, the second detection module is used for: Generate an encryption matrix of the second backup file according to the second backup file, where the encryption matrix includes the encryption status of the second backup file; Classify the encryption matrix through a first classifier to obtain a first classification result, where the first classification result includes a normal encryption matrix and an abnormal encryption matrix; Calculate the encryption score of the second backup file according to the first classification result, where the encryption score represents the abnormal situation of the encryption matrix; Perform the abnormal encryption detection on the time series through the time series anomaly detection model to obtain the second detection result, where the time series includes the encryption scores of multiple second backup files.
14. The device according to claim 13, wherein Specifically, the second detection module is used for: Extract features from the second backup file according to N sampling points of the second backup file to obtain M-byte feature data for each of the sampling points, where M and N are positive integers; Calculate the eigenvalue of the M-byte feature data, where the eigenvalue represents the encryption situation of the feature data in the second backup file; Generate the encryption matrix according to the N eigenvalues, where the encryption matrix includes the N eigenvalues.
15. The device according to claim 14, characterized in that, The second detection module is specifically configured to: Calculate the multi-dimensional channel value corresponding to the eigenvalue according to the dimensionality increase formula; Map the second backup file to a space-filling curve to obtain the coordinates of the data of each byte in the second backup file; Generate the encryption matrix according to the N multi-dimensional channel values and the coordinates, where each element in the encryption matrix includes the multi-dimensional channel value and the corresponding coordinate.
16. The device according to any one of claims 13 to 15, characterized in that, The second detection module is specifically configured to: If the first classification result is the abnormal encryption matrix, set the value of the encryption score to a specific value; If the first classification result is the normal encryption matrix, divide the encryption matrix into Y encryption sub-matrices, where Y is a positive integer; Calculate the encryption score according to the Y encryption sub-matrices.
17. The device according to claim 16, characterized in that, The second detection module is specifically configured to: Classify the Y encryption sub-matrices through a second classifier to obtain Y second classification results; Calculate the sub-matrix ratio according to the number of normal encryption sub-matrices and the number of abnormal encryption sub-matrices in the Y second classification results; Use the sub-matrix ratio as the encryption score.
18. The device according to any one of claims 13 to 17, characterized in that, The second detection module is specifically configured to: Combine multiple encryption scores to obtain the time series; Detect the time series through the time series anomaly detection model to obtain the second detection result.
19. A detection device, characterized in that, Comprising: A processor and a memory, where the processor is coupled to the memory; The memory is used to store programs; The processor is configured to execute the programs in the memory so that the method described in any one of claims 1 to 9 is executed.
20. A computer-readable storage medium including instructions that, when run on a computer, cause the computer to execute the method described in any one of claims 1 to 9.
21. A computer program product containing instructions that, when run on a computer, cause the computer to execute the method described in any one of claims 1 to 9.
Citation Information
Patent Citations
Ransomware virus defense method, ransomware virus defense equipment and readable storage medium
CN113360909A
Virus defense method, electronic equipment, medium and program product
CN114925362A
Ransomware attack onset detection
US20190042744A1
Anomaly-Based Ransomware Detection for Encrypted Files
US20200042703A1
Efficient detection of ransomware attacks within a backup storage environment
US20210357504A1