信息网络安全 ›› 2019, Vol. 19 ›› Issue (9): 71-75.doi: 10.3969/j.issn.1671-1122.2019.09.015

• • 上一篇    下一篇

一种局域网中基于SSD的防范勒索软件攻击技术

殷明1, 贾世杰2,3   

  1. 1.公安部第一研究所,北京 100048
    2.中国科学院信息工程研究所信息安全国家重点实验室,北京 100195
    3.中国科学院数据与通信保护研究教育中心,北京 100195
  • 收稿日期:2019-07-15 出版日期:2019-09-10 发布日期:2020-05-11
  • 作者简介:

    作者简介:殷明(1979—),男,湖南,副研究员,硕士,主要研究方向为网络安全技术;贾世杰(1989—),男,山东,助理研究员,博士,主要研究方向为网络与系统安全。

A Technology to Prevent Ransomware Attacks Based on Solid State Drives in LAN

Ming YIN1, Shijie JIA2,3   

  1. 1. First Research Institute of the Ministry of Public Security of PRC, Beijing 100048, China
    2. State Key Laboratory of Information Security, Institute of Information Engineering, CAS, Beijing 100195, China
    3. Data Assurance and Communication Security Research Center, CAS, Beijing 100195, China
  • Received:2019-07-15 Online:2019-09-10 Published:2020-05-11

摘要:

为了缓解局域网中勒索软件造成的影响,文章提出了一种基于固态硬盘(SSD)的防范技术,将部署大容量SSD的主机作为服务器,利用网络驱动器映射技术分享给局域网中的其他主机。文章利用固态存储设备数据非原位更新、修改垃圾回收等策略进行数据备份,提出二分查找法进行数据恢复。原型系统实验结果显示,文中方案可以快速有效地恢复被勒索软件攻击的数据,并且对SSD读写性能的影响很小。

关键词: 勒索软件, SSD, 局域网, 数据备份, 数据恢复

Abstract:

In order to alleviate the impact of ransomware in LAN, this paper proposes a SSD-based defense technology, which uses a host with a large-capacity SSD as a server, and uses network drive mapping technology to share with other hosts in the LAN to further utilize the solid state. Moreover, this paper utilized the out-of-place of the SSD and modified garbage collection for data backup, and a binary search method is proposed for data recovery. The experimental results of the prototype system show that this scheme can recover the data attacked by the ransomware quickly and effectively, and its impact of the read and write performance is samll.

Key words: Ransomware, SSD, LAN, data backup, data recovery

中图分类号: