Malicious program defense method and device and storage medium
By employing behavior chain analysis and dynamic recognition algorithms, the method enhances the identification of malicious programs, addressing the limitations of single behavior detection and improving defense effectiveness against unknown threats.
Patent Information
- Application Number
- CN202510438614.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-07-15
AI Technical Summary
The prior art cannot accurately identify whether an unknown program is a malicious program, resulting in poor defense effects and inability to effectively distinguish between malicious behavior and normal behavior.
By obtaining the behavioral characteristics of the program when running, using the program behavioral characteristics evaluation library to match, calculate the first risk assessment value, and obtain the behavioral characteristic information of the behavior chain when the preset conditions are met, input the dynamic behavior recognition algorithm model to calculate the second risk assessment value, judge whether the program is a malicious program, and handle it when it is confirmed to be a malicious program.
It improves the accuracy of identification of unknown programs, enhances the defense effect of malicious programs, and can more comprehensively evaluate program behavior patterns, reduces false alarm rates and missed rates.
Smart Images

Figure CN120316773A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer security technology. Specifically, it relates to a method, device, and storage medium for defending against malicious programs. Background Art
[0002] With the rapid development of computer technology, the security threats of malicious programs (such as viruses, Trojans, worms, etc.) to computer systems and networks are increasing day by day. Malicious programs can not only steal user data, damage system files, but also spread through the network, causing serious impacts on a large number of users. Therefore, developing effective malicious program detection and defense technologies has become an important topic in the field of information security.
[0003] Existing technologies usually rely on the detection of single behaviors and cannot comprehensively evaluate the behavior patterns of programs. Malicious programs may evade single-point detection by dispersing behaviors, resulting in missed reports. For example, some malicious programs may perform multiple seemingly normal behaviors during runtime, but the combination of these behaviors is significantly malicious. Single-point detection methods are difficult to identify such complex behavior patterns. Although the dynamic analysis methods in existing technologies can detect the behaviors during program runtime, they usually only focus on single behaviors and lack comprehensive analysis of behavior chains, resulting in insufficient recognition ability for complex behavior patterns. For example, some malicious programs may perform a series of behaviors during runtime. Individually, these behaviors may not be obvious, but when combined, they are significantly malicious. There are high false positive rates and missed report rates in identifying malicious programs, and it is impossible to accurately distinguish malicious behaviors from normal behaviors.
[0004] Regarding the problem in related technologies that unknown programs cannot be accurately identified as malicious programs, resulting in poor defense effects against unknown programs, no effective solutions have been proposed yet. Summary of the Invention
[0005] The main purpose of this application is to provide a method, device, and storage medium for defending against malicious programs to solve the problem in related technologies that unknown programs cannot be accurately identified as malicious programs, resulting in poor defense effects against unknown programs.
[0006] To achieve the above object, according to one aspect of the present application, a method for defending against malicious programs is provided. The method includes: obtaining the running behavior during program operation; matching the running behavior with a program behavior feature evaluation library to obtain a first risk assessment value, where the program behavior feature evaluation library is a database storing the behaviors during program operation and their corresponding risk assessment information; in the case where the first risk assessment value reaches a first preset condition, obtaining the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain; inputting the behavior feature information of each behavior in the behavior chain into a dynamic behavior recognition algorithm model to calculate a second risk assessment value of the behavior chain; judging whether the program is a malicious program according to the second risk assessment value; and in the case where the program is a malicious program, processing the malicious program.
[0007] Further, after matching the running behavior with the program behavior feature evaluation library to obtain the first risk assessment value, the method further includes: in the case where the first risk assessment value reaches a second preset condition, determining that the program is a malicious program; and processing the malicious program.
[0008] Further, the construction steps of the program behavior feature evaluation library are as follows: determining a plurality of monitoring points and a plurality of monitoring target behaviors corresponding to each monitoring point; obtaining sample data, where the sample data includes malicious program sample data and normal program sample data; calculating the number of times each monitoring target behavior occurs in the malicious program sample data; calculating the number of times each monitoring target behavior occurs in the normal program sample data; determining the risk assessment information of each monitoring target behavior according to the number of times each monitoring target behavior occurs in the malicious program sample data and the number of times each monitoring target behavior occurs in the normal program sample data; and constructing a program behavior feature evaluation library based on each monitoring target behavior and the risk assessment information of each monitoring target behavior.
[0009] Further, matching the running behavior with the program behavior feature evaluation library to obtain the first risk assessment value includes: extracting the behavior feature information of the running behavior; determining the matching degree between the running behavior and the behaviors in the program behavior feature evaluation library according to the behavior feature information of the running behavior, the behaviors in the program behavior feature evaluation library, and their corresponding risk assessment information; and obtaining the first risk assessment value according to the matching degree.
[0010] Further, before obtaining the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain in the case where the first risk assessment value reaches the first preset condition, the method further includes: obtaining the behavior data during program operation, where the behavior data includes records of a plurality of behaviors during program operation; extracting the behavior feature information of each behavior in the behavior data, where the behavior feature information of each behavior includes at least behavior context information; and constructing a behavior chain according to the behavior context information of each behavior in the behavior data.
[0011] Further, inputting the behavioral characteristic information of each behavior in the behavior chain into the dynamic behavior recognition algorithm model to calculate the second risk assessment value of the behavior chain includes: the dynamic behavior recognition algorithm model calculates the risk assessment value of each behavior in the behavior chain according to the behavioral characteristic information of each behavior in the behavior chain; setting corresponding weights for each behavior in the behavior chain; and calculating the second risk assessment value of the behavior chain based on the risk assessment value of each behavior in the behavior chain and the weight of each behavior in the behavior chain.
[0012] Further, in the case where the program is a malicious program, handling the malicious program includes: determining the behavior pattern of the malicious program; taking a preset method to handle the malicious program according to the behavior pattern of the malicious program, the behavioral characteristic information of each behavior in the behavior chain, and the second risk assessment value; recording the processing result information of the malicious program; and outputting the processing result information.
[0013] According to another aspect of the present application, there is provided a defense device for malicious programs, characterized by including: a first acquisition unit for acquiring the running behavior during program operation; a matching unit for matching the running behavior with a program behavior characteristic evaluation library to obtain a first risk assessment value, where the program behavior characteristic evaluation library is a database storing the behaviors during program operation and their corresponding risk assessment information; a second acquisition unit for acquiring the behavior chain of the running behavior and the behavioral characteristic information of each behavior in the behavior chain when the first risk assessment value reaches a first preset condition; a calculation unit for inputting the behavioral characteristic information of each behavior in the behavior chain into a dynamic behavior recognition algorithm model to calculate the second risk assessment value of the behavior chain; a judgment unit for judging whether the program is a malicious program according to the second risk assessment value; and a first processing unit for handling the malicious program when the program is a malicious program.
[0014] Further, the device includes: a determination unit for determining that the program is a malicious program when the first risk assessment value reaches a second preset condition after matching the running behavior with the program behavior characteristic evaluation library to obtain a first risk assessment value; and a second processing unit for handling the malicious program.
[0015] Further, the construction steps of the program behavior feature evaluation library in the matching unit are as follows: a first determination module for determining a plurality of monitoring points and a plurality of monitored target behaviors corresponding to each monitoring point; an acquisition module for acquiring sample data, where the sample data includes malicious program sample data and normal program sample data; a first calculation module for calculating the number of occurrences of each monitored target behavior in the malicious program sample data; a second calculation module for calculating the number of occurrences of each monitored target behavior in the normal program sample data; a second determination module for determining the risk assessment information of each monitored target behavior according to the number of occurrences of each monitored target behavior in the malicious program sample data and the number of occurrences of each monitored target behavior in the normal program sample data; and a construction module for constructing a program behavior feature evaluation library based on each monitored target behavior and the risk assessment information of each monitored target behavior.
[0016] Further, the matching unit includes: an extraction module for extracting the behavior feature information of the running behavior; a third determination module for determining the matching degree between the running behavior and the behaviors in the program behavior feature evaluation library according to the behavior feature information of the running behavior, the behaviors in the program behavior feature evaluation library, and the corresponding risk assessment information; and a fourth determination module for obtaining a first risk assessment value according to the matching degree.
[0017] Further, the device includes: a third acquisition unit for acquiring the behavior data during program operation before acquiring the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain when the first risk assessment value reaches a first preset condition, where the behavior data includes records of a plurality of behaviors during program operation; an extraction unit for extracting the behavior feature information of each behavior in the behavior data, where the behavior feature information of each behavior includes at least behavior context information; and a construction unit for constructing a behavior chain according to the behavior context information of each behavior in the behavior data.
[0018] Further, the calculation unit includes: a third calculation module for calculating the risk assessment value of each behavior in the behavior chain by the dynamic behavior recognition algorithm model according to the behavior feature information of each behavior in the behavior chain; a setting module for setting a corresponding weight for each behavior in the behavior chain; and a fourth calculation module for calculating the second risk assessment value of the behavior chain based on the risk assessment value of each behavior in the behavior chain and the weight of each behavior in the behavior chain.
[0019] Further, the first processing unit includes: a fifth determination module for determining the behavior pattern of the malicious program; a processing module for processing the malicious program in a preset manner according to the behavior pattern of the malicious program, the behavior feature information of each behavior in the behavior chain, and the second risk assessment value; a recording module for recording the processing result information of the malicious program; and an output module for outputting the processing result information.
[0020] According to another aspect of the present application, there is also provided a computer-readable storage medium. The computer-readable storage medium includes an executable program stored therein. When the executable program runs, it controls the device where the computer-readable storage medium is located to execute the above-mentioned malicious program defense method.
[0021] According to another aspect of the present application, there is also provided an electronic device, including: a memory storing an executable program; a processor for running the program. When the program runs, it executes the above-mentioned malicious program defense method.
[0022] According to another aspect of the present application, there is also provided a computer program product, including computer instructions. The computer instructions are characterized in that when executed by a processor, they implement the steps of the above-mentioned malicious program defense method.
[0023] In the embodiments of the present application, by obtaining the running behavior during program operation; matching the running behavior with the program behavior feature evaluation library to obtain a first risk assessment value, where the program behavior feature evaluation library is a database storing the behaviors during program operation and their corresponding risk assessment information; in the case where the first risk assessment value reaches a first preset condition, obtaining the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain; inputting the behavior feature information of each behavior in the behavior chain into the dynamic behavior recognition algorithm model to calculate a second risk assessment value of the behavior chain; judging whether the program is a malicious program according to the second risk assessment value; in the case where the program is a malicious program, processing the malicious program, thereby solving the technical problem that it is impossible to accurately identify whether an unknown program is a malicious program, resulting in a poor defense effect against unknown programs. In the present application, by obtaining the running behavior during program operation, first matching the running behavior with the constructed program behavior feature evaluation library, in the case where the matching result meets the first preset condition, obtaining the behavior chain of the running behavior, calculating the second risk assessment value of the behavior chain, and judging whether the program is a malicious program according to the second risk assessment value, the accuracy of identifying malicious programs is improved. If it is a malicious program, the malicious program is processed, thereby achieving the technical effect of strengthening the defense effect against unknown programs. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The drawings constituting a part of the present application are used to provide a further understanding of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings: Figure 1 Shows a hardware structure block diagram of a computer terminal for implementing the malicious program defense method; Figure 2 Is a flowchart of an optional malicious program defense method according to an embodiment of the present application; Figure 3 It is a schematic diagram of an optional malicious program defense device provided according to an embodiment of the present application; Figure 4 Schematic diagram of an optional electronic device according to an embodiment of the present application. Detailed implementation manners
[0025] In order to enable those skilled in the art to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0026] It should be noted that the terms "first", "second", etc. in the description and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0027] Embodiment 1 According to an embodiment of the present application, a method embodiment for defending against malicious programs is further provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.
[0028] The method embodiment provided in the first embodiment of the present application can be executed on a mobile terminal, a computer terminal or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing the malicious program defense method is shown. As Figure 1As shown, the computer terminal 10 (or mobile device) may include one or more processors 102 (illustrated as 102a, 102b, ……, 102n in the figure) (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown in, or have a different configuration from Figure 1 that shown.
[0029] It should be noted that the above one or more processors 102 and / or other data processing circuits are generally referred to as "data processing circuits" herein. The data processing circuit may be embodied in whole or in part as software, hardware, firmware, or any combination thereof. In addition, the data processing circuit may be a single independent processing module, or be incorporated in whole or in part into any one of other elements in the computer terminal 10 (or mobile device). As involved in the embodiments of the present application, the data processing circuit is a processor control (such as the selection of a variable resistance terminal path connected to an interface).
[0030] The memory 104 may be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the malicious program defense method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned malicious program defense method. The memory 104 may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories may be connected to the computer terminal 10 through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0031] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0032] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables the user to interact with the user interface of the computer terminal 10 (or mobile device).
[0033] Under the above operating environment, this application provides a defense method for malicious programs as Figure 2 shown. Figure 2 It is a flowchart of the defense method for malicious programs according to Embodiment 1 of this application.
[0034] Step S201, obtain the running behavior when the program is running.
[0035] Optionally, a monitoring tool can be used to obtain the running behavior when the program is running in real time. The monitoring tool can be a sandbox environment, a behavior monitoring tool, a system call monitoring tool, etc. The above-mentioned running behavior refers to the specific operations and activities shown by the program during execution. The running behavior can include file operation behaviors, such as creating files, deleting files, modifying files, etc.; the running behavior can also include network communication behaviors, such as connecting to an external server, sending data, receiving data, etc.; the running behavior can also include registry operation behaviors, such as modifying registry entries, creating registry entries, deleting registry entries, etc.; the running behavior can also include system call behaviors, such as creating processes, terminating processes, loading dynamic link libraries, etc. The running behavior occurs in real time. By monitoring these behaviors, potential malicious behaviors can be discovered in a timely manner. By analyzing the combination of multiple running behaviors (behavior chain), the behavior pattern of the program can be evaluated more comprehensively, so as to identify malicious programs more accurately.
[0036] Step S202, match the running behavior with the program behavior feature evaluation library to obtain a first risk assessment value, where the program behavior feature evaluation library is a database that stores the behaviors of the program during running and their corresponding risk assessment information.
[0037] Optionally, the above-mentioned program behavior feature evaluation library is constructed based on a large amount of sample data, and a large amount of behaviors and the risk assessment information corresponding to the behaviors are stored in the program behavior feature evaluation library.
[0038] For example, the specific steps to match the running behavior with the program behavior feature evaluation library can be as follows: Compare whether the behavior type of the running behavior is the same as that in the program behavior feature evaluation library: If the running behavior is "file operation", then find all the behavior features of the "file operation" type in the program behavior feature evaluation library; For the matched behavior type, further compare whether the behavior targets are the same: If the target of the running behavior is "create an.exe file in the %SystemRoot%\system32 path", then find the behavior features in the program behavior feature evaluation library whose target path is %SystemRoot%\system32 and the file type is.exe; Compare whether the frequency of the running behavior is the same as the frequency range of the corresponding behavior feature in the program behavior feature evaluation library: If the frequency of the running behavior is "create 5 files per minute", then find the behavior features in the program behavior feature evaluation library whose frequency range includes "5 times per minute"; Compare whether the context information of the running behavior is the same as the context information of the corresponding behavior feature in the program behavior feature evaluation library: If the running behavior occurs "within 10 minutes after system startup", then find the behavior features in the program behavior feature evaluation library whose context is "within 10 minutes after system startup".
[0039] According to the above matching results, calculate the matching degree between the running behavior and the behavior feature in the evaluation library. The matching degree can be a value between 0 and 1, indicating the similarity of the match. Based on the matching degree, the first risk assessment value can be obtained. The calculation method of the matching degree can include: Simple matching: If the behavior type, target, frequency, and context are exactly the same, the matching degree is 1, otherwise it is 0; Weighted matching: According to the importance of the behavior type, target, frequency, and context, different weights are assigned respectively to calculate the weighted matching degree.
[0040] For example, match the running behavior "create file C:\Windows\System32\example.exe" with the program behavior feature evaluation library. There is a behavior in the program behavior feature evaluation library with the following behavior features: Behavior identification number: 001; Behavior description: Create file; Behavior type: File operation; Behavior target: %SystemRoot%\system32\*.exe; Risk assessment value: 90.
[0041] The matching process is as follows: Behavior type matching degree: 1.0 (fully matched); Behavior target matching degree: 1.0 (fully matched); Behavior frequency matching degree: 1.0 (fully matched); Behavior context matching degree: 1.0 (fully matched).
[0042] Then the first risk assessment value of the running behavior "create file C:\Windows\System32\example.exe" is calculated to be 90.
[0043] Step S203, when the first risk assessment value meets the first preset condition, obtain the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain.
[0044] Optionally, the above first preset condition means that the first risk assessment value is lower than the preset high-risk threshold. Specifically, when the first risk assessment value is higher than a high-risk threshold (for example, higher than 90), the behavior is determined to be a high-risk behavior and can be directly considered a malicious behavior, and handling measures need to be taken immediately. When the first risk assessment value is lower than this high-risk threshold, the first preset condition is met, and it is necessary to further obtain the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain for more detailed analysis.
[0045] For example, the high-risk threshold is set to 90, and the first preset condition is that the first risk assessment value is lower than 90. If the first risk assessment value is 95, which is higher than the high-risk threshold, it is determined to be a high-risk behavior and considered a malicious behavior, and immediate handling is required. If the first risk assessment value is 85, which is lower than this high-risk threshold, the first preset condition is met, and further analysis is needed.
[0046] Optionally, the above behavior chain of the running behavior refers to an ordered sequence of a series of behaviors during program operation organized according to the order of occurrence and context relationship. The behavior chain reflects the behavior pattern of the program, and by analyzing the behavior chain, the potential maliciousness of the program can be evaluated more comprehensively. The behavior feature information of each behavior in the above behavior chain can include behavior type, behavior target, behavior frequency, and behavior context information, etc.
[0047] Step S204, input the behavior feature information of each behavior in the behavior chain into the dynamic behavior recognition algorithm model, and calculate the second risk assessment value of the behavior chain.
[0048] Optionally, the above dynamic behavior recognition algorithm model can comprehensively consider a series of behaviors (behavior chain) during program operation and evaluate the potential maliciousness of these behaviors. Inputting the behavior feature information of each behavior in the behavior chain into the dynamic behavior recognition algorithm model can comprehensively consider the risk assessment value and its weight of each behavior in the behavior chain, so as to calculate the second risk assessment value of the behavior chain. The weight can be dynamically adjusted according to the position of the behavior in the behavior chain, the frequency of the behavior, and the context information of the behavior.
[0049] Step S205: Determine whether the program is a malicious program according to the second risk assessment value.
[0050] For example, if the second risk assessment value exceeds a preset threshold (such as 85), the program is considered a malicious program.
[0051] Step S206: Process the malicious program in the case where the program is a malicious program.
[0052] Optionally, after confirming that the program is a malicious program, flexible processing measures can be taken according to the behavior pattern and the risk assessment value. The processing methods for malicious programs can be isolation, deletion, cleaning, system repair, terminating the process, or uploading the sample to a security analysis platform, etc. The processing results can be recorded and output during the process of processing the malicious program.
[0053] The malicious program defense method provided by the embodiments of the present application obtains the running behavior during program operation; matches the running behavior with the program behavior feature evaluation library to obtain the first risk assessment value, where the program behavior feature evaluation library is a database storing the behaviors during program operation and their corresponding risk assessment information; in the case where the first risk assessment value meets the first preset condition, obtains the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain; inputs the behavior feature information of each behavior in the behavior chain into the dynamic behavior recognition algorithm model to calculate the second risk assessment value of the behavior chain; determines whether the program is a malicious program according to the second risk assessment value; and processes the malicious program in the case where the program is a malicious program, thereby solving the technical problem that it is impossible to accurately identify whether an unknown program is a malicious program, resulting in a poor defense effect on the unknown program. In the present application, the running behavior during program operation is obtained. First, the running program is matched with the constructed program behavior feature evaluation library. In the case where the matching result meets the first preset condition, the behavior chain of the running behavior is obtained, the second risk assessment value of the behavior chain is calculated, and it is determined whether it is a malicious program according to the second risk assessment value, improving the accuracy of identifying malicious programs. If it is a malicious program, the malicious program is processed, thus achieving the technical effect of strengthening the defense effect on unknown programs.
[0054] Optionally, in the malicious program defense method provided in the embodiments of the present application, after matching the running behavior with the program behavior feature evaluation library to obtain the first risk assessment value, the method includes: First step, when the first risk assessment value reaches the second preset condition, determine that the program is a malicious program.
[0055] Optionally, when the first risk assessment value reaches the second preset condition, the system can directly determine that the program is a malicious program without further analyzing the behavior chain. This fast determination mechanism can save time and computing resources while improving the system's response speed. The second preset condition means that the first risk assessment value reaches a specific high-risk threshold. When this threshold is exceeded, the system can relatively surely determine that the program is a malicious program. This threshold is usually a relatively high value, such as 90 or higher, indicating that the behavior has a high degree of maliciousness.
[0056] Second step, process the malicious program.
[0057] Optionally, after confirming that the program is a malicious program, flexible processing measures can be taken according to the behavior pattern and risk assessment value. The processing methods for malicious programs can be isolation, deletion, cleaning, system repair, terminating the process, or uploading the sample to a security analysis platform, etc. The processing results can be recorded and output during the process of processing malicious programs.
[0058] In summary, by the above steps, by setting the second preset condition, when the first risk assessment value reaches the high-risk threshold, the program can be quickly determined to be a malicious program and processing measures can be taken. This mechanism can effectively improve the system's response speed and security, especially when dealing with high-risk behaviors.
[0059] Optionally, in the malicious program defense method provided in the embodiments of the present application, the construction steps of the program behavior feature evaluation library are as follows: First step, determine multiple monitoring points and multiple monitoring target behaviors corresponding to each monitoring point.
[0060] Optionally, the above-mentioned monitoring points refer to specific locations or behavior types that need to be particularly concerned about and monitored during the program's operation. For example, file operations, network communications, registry operations, etc. The multiple monitoring target behaviors corresponding to each monitoring point refer to the specific behaviors that need to be monitored at this monitoring point. For example, at the file operation monitoring point, the monitoring target behaviors may include creating files, deleting files, modifying files, etc. By determining multiple monitoring points and monitoring target behaviors, the comprehensiveness of monitoring is ensured, and various key behaviors during the program's operation can be covered.
[0061] For example, determine three monitoring points. Monitoring point 1 is for file operations, and the corresponding monitored target behaviors are creating files, deleting files, and modifying files; monitoring point 2 is for network communication, and the corresponding monitored target behaviors are connecting to external servers, sending data, and receiving data; monitoring point 3 is for registry operations, and the corresponding monitored target behaviors are modifying registry entries, creating registry entries, and deleting registry entries.
[0062] In the second step, obtain sample data, where the sample data includes malicious program sample data and normal program sample data.
[0063] Optionally, the above sample data includes malicious program sample data and normal program sample data, which are used to train and verify the program behavior feature evaluation library. The malicious program sample data can be behavior data obtained from known malicious programs such as Trojans, viruses, and worms. The normal program sample data can be behavior data obtained from common normal programs such as office software, chat tools, and input methods.
[0064] In the third step, calculate the number of times each monitored target behavior occurs in the malicious program sample data.
[0065] Optionally, by counting the number of times each monitored target behavior occurs in the malicious program sample data, the occurrence frequency of each behavior in the malicious program can be understood.
[0066] For example, the monitored target behavior "create file" occurred 100 times in the malicious program sample data. The monitored target behavior "connect to external server" occurred 80 times in the malicious program sample data.
[0067] In the fourth step, calculate the number of times each monitored target behavior occurs in the normal program sample data.
[0068] For example, the monitored target behavior "create file" occurred 10 times in the normal program sample data. The monitored target behavior "connect to external server" occurred 5 times in the normal program sample data.
[0069] In the fifth step, determine the risk assessment information for each monitored target behavior based on the number of times each monitored target behavior occurs in the malicious program sample data and the number of times each monitored target behavior occurs in the normal program sample data.
[0070] Optionally, calculate the risk assessment information for each behavior based on the number of times each monitored target behavior occurs in the malicious program sample data and the normal program sample data. The risk assessment information is a value between 0 and 100, indicating the potential maliciousness of the behavior.
[0071] For example, the behavior of "creating a file" occurs 100 times in malicious programs and 10 times in normal programs, and the risk assessment value may be 90. The behavior of "connecting to an external server" occurs 80 times in malicious programs and 5 times in normal programs, and the risk assessment value may be 85.
[0072] Step 6: Based on each monitored target behavior and the risk assessment information of each monitored target behavior, construct a program behavior feature evaluation library.
[0073] In summary, through the above steps, an accurate and reliable program behavior feature evaluation library can be constructed, which can effectively support the detection and defense of malicious programs.
[0074] Optionally, in the malicious program defense method provided in the embodiments of the present application, matching the running behavior with the program behavior feature evaluation library to obtain the first risk assessment value includes: Step 1: Extract the behavior feature information of the running behavior.
[0075] Optionally, the above behavior feature information may include behavior type, behavior target, behavior frequency, behavior context, etc. The behavior type may be file operation, network communication, registry operation, etc. The behavior target may be the specific file path, registry item, network address, etc. of the operation. The behavior frequency may be the frequency of the behavior occurrence. The behavior context may be the time, environment, etc. when the behavior occurs. Extracting the behavior feature information of the running behavior can provide basic data for subsequent matching and risk assessment.
[0076] For example, the behavior feature information of the running behavior is: the behavior type is file operation, the behavior target is C:\Windows\System32\example.exe, the behavior frequency is 1 time / minute, and the behavior context is within 10 minutes after system startup.
[0077] Step 2: According to the behavior feature information of the running behavior, the behaviors in the program behavior feature evaluation library and their corresponding risk assessment information, determine the matching degree between the running behavior and the behaviors in the program behavior feature evaluation library.
[0078] Optionally, the matching process may include: behavior type matching: comparing whether the behavior type of the running behavior is consistent with the behavior type in the evaluation library; behavior target matching: comparing whether the behavior target of the running behavior is consistent with the behavior target in the evaluation library; behavior frequency matching: comparing whether the behavior frequency of the running behavior is consistent with the behavior frequency in the evaluation library; behavior context matching: comparing whether the behavior context of the running behavior is consistent with the behavior context in the evaluation library. According to the above matching results, calculate the matching degree between the running behavior and the behavior in the evaluation library. The matching degree may be a value between 0 and 1, indicating the similarity of the matching.
[0079] For example, the matching process of the behavior characteristic information of the running behavior in the first step with the behaviors in the program behavior characteristic evaluation library is as follows: Behavior type matching degree: 1.0 (fully matched); Behavior target matching degree: 1.0 (fully matched); Behavior frequency matching degree: 1.0 (fully matched); Behavior context matching degree: 1.0 (fully matched); Assume the weights are 0.4, 0.3, 0.2, and 0.1 respectively, then the matching degree is: matching degree = 1.0×0.4 + 1.0×0.3 + 1.0×0.2 + 1.0×0.1 = 1.0.
[0080] In the third step, according to the matching degree, obtain the first risk assessment value.
[0081] According to the above matching result, the matching degree is 1.0. Obtain the risk assessment value 90 of the matched behavior from the program behavior characteristic evaluation library as the first risk assessment value.
[0082] In summary, through the above steps, the running behavior can be matched with the program behavior characteristic evaluation library, and the risk assessment value of the behavior can be obtained through the matching degree, realizing the quantitative assessment of risks.
[0083] Optionally, in the malicious program defense method provided in the embodiments of the present application, before obtaining the behavior chain of the running behavior and the behavior characteristic information of each behavior in the behavior chain when the first risk assessment value reaches the first preset condition, the method includes: In the first step, obtain the behavior data during program operation, where the behavior data includes records of multiple behaviors during program operation.
[0084] Optionally, the behavior data during program operation refers to records of various operations and activities generated during the execution of the program. These data reflect the dynamic behavior of the program and are important inputs in the malicious program detection and defense system. Monitoring tools such as sandbox environments, behavior monitoring tools, and system call monitoring tools can be used to obtain the behavior data during program operation in real time. The behavior data during program operation obtained by the monitoring tools can be recorded to form a behavior log for subsequent analysis.
[0085] For example, a program performs the following behaviors during operation: 001 - Create a file Behavior type: File operation; Behavior target: C:\Windows\System32\example.exe; Behavior frequency: 1 time / minute; Behavior context: within 10 minutes after system startup, timestamp: 10:00:00; 002 - Modify registry key Behavior type: Registry operation; Behavior target: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run; Behavior frequency: 1 time / minute; Behavior context: within 10 minutes after system startup, timestamp: 10:00:05; 003 - Connect to external server Behavior type: Network communication; Behavior target: 192.168.1.1:8080; Behavior frequency: 1 time / minute; Behavior context: within 10 minutes after system startup, timestamp: 10:00:10; 004 - Delete user file Behavior type: File operation; Behavior target: C:\Users\user\Documents\example.txt; Behavior frequency: 1 time / minute; Behavior context: within 10 minutes after system startup, timestamp: 10:00:15.
[0086] These behavior data can be recorded to form a behavior log for subsequent analysis and processing.
[0087] Second step, extract the behavior feature information of each behavior in the behavior data. Among them, the behavior feature information of each behavior includes at least behavior context information.
[0088] Optionally, the behavior feature information of each of the above behaviors can include behavior type, behavior target, behavior frequency, behavior context, etc. The extracted behavior feature information can be standardized for subsequent analysis.
[0089] For example, extract the behavior feature information of the four behaviors in the first step, such as behavior type, behavior target, behavior frequency, and behavior context.
[0090] Third step, construct a behavior chain according to the behavior context information of each behavior in the behavior data.
[0091] Optionally, the behavior chain is an ordered sequence of behaviors, reflecting the behavior pattern during program operation. Multiple behaviors can be organized into an ordered sequence of behaviors according to the behavior context information (such as timestamp) and logical relationship.
[0092] For example, based on the feature information extracted in the first and second steps, construct a behavior chain: Behavior chain = [001 → 002 → 003 → 004].
[0093] In summary, through the above three steps, an accurate and complete behavior chain can be constructed. Through the analysis of the behavior chain, the behavior pattern of the program can be evaluated more comprehensively, so as to identify malicious programs more accurately.
[0094] Optionally, in the malicious program defense method provided in the embodiments of the present application, inputting the behavior feature information of each behavior in the behavior chain into the dynamic behavior recognition algorithm model, the calculation of the second risk assessment value of the behavior chain includes: In the first step, the dynamic behavior recognition algorithm model calculates the risk assessment value of each behavior in the behavior chain according to the behavior feature information of each behavior in the behavior chain.
[0095] For example, the risk assessment values of each behavior in the behavior chain are respectively: the risk assessment value of creating a file is 90, the risk assessment value of modifying a registry key is 85, the risk assessment value of connecting to an external server is 70, and the risk assessment value of deleting user files is 80.
[0096] In the second step, set corresponding weights for each behavior in the behavior chain.
[0097] Optionally, a weight can be assigned to each behavior according to the position of the behavior in the behavior chain, the frequency of the behavior, and the context information of the behavior. The weight reflects the importance of the behavior in the behavior chain. The weight can be dynamically adjusted according to the characteristics and context information of the behavior to more accurately reflect the risk of the behavior. The weight can be obtained by preset rules or dynamically calculated by a machine learning model. For example, behaviors on the critical path may be assigned higher weights, while behaviors on the auxiliary path may be assigned lower weights.
[0098] For example, the weight assignment is as follows: the weight of creating a file is 0.4, the weight of modifying a registry key is 0.3, the weight of connecting to an external server is 0.2, and the weight of deleting user files is 0.1.
[0099] In the third step, based on the risk assessment value of each behavior in the behavior chain and the weight of each behavior in the behavior chain, calculate the second risk assessment value of the behavior chain.
[0100] For example, according to the above risk assessment values and weights, calculate the second risk assessment value of the behavior chain: Second risk assessment value = (90 × 0.4) + (85 × 0.3) + (70 × 0.2) + (80 × 0.1) = 36 + 25.5 + 14 + 8 = 83.5 In summary, through the above three steps, the second risk assessment value of the behavior chain can be calculated. By comprehensively considering the risk assessment values and weights of each behavior in the behavior chain, the overall risk of the behavior chain can be more comprehensively evaluated, thereby more accurately identifying malicious programs.
[0101] Optionally, in the malicious program defense method provided in the embodiments of the present application, when the program is a malicious program, handling the malicious program includes: The first step is to determine the behavior pattern of the malicious program.
[0102] Optionally, before handling the malicious program, the behavior pattern of the malicious program can be determined first, because under different behavior patterns, the malicious program may exhibit different risk characteristics, so different handling methods need to be selected.
[0103] For example, the steps to determine the behavior pattern of the malicious program can be as follows: Behavior feature extraction: Extract key features from the behavior chain, such as behavior type, behavior target, behavior frequency, and behavior context, etc. These feature information will be used to identify the behavior pattern; Pattern recognition: Identify specific patterns in the behavior chain through machine learning or rule engines. These patterns may match known malicious behavior patterns.
[0104] Context association: Consider the logical relationship and context information between behaviors to determine the integrity and consistency of the behavior pattern.
[0105] Through the above steps, the behavior pattern of the malicious program can be identified.
[0106] The second step is to handle the malicious program in a preset manner according to the behavior pattern of the malicious program, the behavior feature information of each behavior in the behavior chain, and the second risk assessment value.
[0107] Optionally, the above preset manner can be to isolate the malicious program: isolate the malicious program into a sandbox environment; delete malicious files; clear registry entries; terminate malicious processes; upload samples: upload the malicious program samples to the cloud security platform for further analysis, etc.
[0108] For example, the identified behavior pattern of the malicious program is: 001 - Create a malicious file: C:\Windows\System32\example.exe; 002 - Modify the system startup item: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run; 003 - Connect to an external server: 192.168.1.1:8080; 004 - Delete user file: C:\Users\user\Documents\example.txt.
[0109] The processing methods for malicious programs adopted according to the above behavior patterns are as follows: 001 - Processing method for creating malicious files: Delete malicious file C:\Windows\System32\example.exe; 002 - Processing method for modifying system startup items: Clear malicious registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run; 003 - Processing method for connecting to external servers: Isolate the malicious program in a sandbox environment to prevent further communication; 004 - Processing method for deleting user files: Terminate malicious process malware.exe to prevent it from continuing to delete files.
[0110] The third step is to record the processing result information of the malicious program.
[0111] Optionally, the type of processing measures, detailed descriptions of processing results, processing timestamps, operator information, etc. during the processing can be recorded.
[0112] The fourth step is to output the processing result information.
[0113] For example, the output processing result of the malicious program is as follows: - Delete malicious file C:\Windows\System32\example.exe; - Clear malicious registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run; - Isolate the malicious program in a sandbox environment; - Terminate malicious process malware.exe; - Processing timestamp: 2023-10-01 10:00:00; - Operator information: System automatic processing.
[0114] In summary, through the above steps, appropriate processing methods can be selected according to the behavior patterns of malicious programs. By recording and outputting the processing result information, the transparency and traceability of the processing process can be improved, ensuring that users understand the processing process and results.
[0115] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0116] Embodiment 2 The embodiment of the present application also provides a malicious program defense device. It should be noted that the malicious program defense device of the embodiment of the present application can be used to execute the malicious program defense method provided by the embodiment of the present application. The malicious program defense device provided by the embodiment of the present application will be introduced below.
[0117] According to the embodiment of the present application, there is also provided a device for implementing the above-mentioned malicious program defense method, as Figure 3 shown, the device includes: a first acquisition unit 301, a matching unit 302, a second acquisition unit 303, a calculation unit 304, a judgment unit 305, and a first processing unit 306.
[0118] Specifically, the first acquisition unit 301 is used to acquire the running behavior during program operation; The matching unit 302 is used to match the running behavior with the program behavior feature evaluation library to obtain a first risk assessment value, where the program behavior feature evaluation library is a database storing the behaviors during program operation and their corresponding risk assessment information; The second acquisition unit 303 is used to acquire the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain when the first risk assessment value reaches a first preset condition; The calculation unit 304 is used to input the behavior feature information of each behavior in the behavior chain into the dynamic behavior recognition algorithm model and calculate the second risk assessment value of the behavior chain; The judgment unit 305 is used to judge whether the program is a malicious program according to the second risk assessment value; The first processing unit 306 is used to process the malicious program when the program is a malicious program.
[0119] The malicious program defense device provided by the embodiment of the present application obtains the running behavior during program operation through the first acquisition unit 301; the matching unit 302 matches the running behavior with the program behavior feature evaluation library to obtain a first risk assessment value, where the program behavior feature evaluation library is a database storing the behaviors during program operation and their corresponding risk assessment information; the second acquisition unit 303 obtains the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain when the first risk assessment value reaches a first preset condition; the calculation unit 304 inputs the behavior feature information of each behavior in the behavior chain into the dynamic behavior recognition algorithm model to calculate the second risk assessment value of the behavior chain; the judgment unit 305 determines whether the program is a malicious program according to the second risk assessment value; the first processing unit is used to process the malicious program when the program is a malicious program, solving the problem that it is impossible to accurately identify whether an unknown program is a malicious program, resulting in a poor defense effect on the unknown program, improving the accuracy of identifying malicious programs, and achieving the effect of strengthening the defense effect on unknown programs.
[0120] Optionally, in the malicious program defense device provided by the embodiment of the present application, the device further includes: a determination unit, configured to determine that the program is a malicious program when the first risk assessment value reaches a second preset condition after matching the running behavior with the program behavior feature evaluation library; a second processing unit, configured to process the malicious program.
[0121] Optionally, in the malicious program defense device provided by the embodiment of the present application, the construction steps of the program behavior feature evaluation library in the matching unit 302 are as follows: a first determination module, configured to determine a plurality of monitoring points and a plurality of monitoring target behaviors corresponding to each monitoring point; an acquisition module, configured to acquire sample data, where the sample data includes malicious program sample data and normal program sample data; a first calculation module, configured to calculate the number of times each monitoring target behavior occurs in the malicious program sample data; a second calculation module, configured to calculate the number of times each monitoring target behavior occurs in the normal program sample data; a second determination module, configured to determine the risk assessment information of each monitoring target behavior according to the number of times each monitoring target behavior occurs in the malicious program sample data and the number of times each monitoring target behavior occurs in the normal program sample data; a construction module, configured to construct a program behavior feature evaluation library based on each monitoring target behavior and the risk assessment information of each monitoring target behavior.
[0122] Optionally, in the malicious program defense device provided in the embodiments of the present application, the matching unit 302 includes: an extraction module for extracting the behavioral feature information of the running behavior; a third determination module for determining the matching degree between the running behavior and the behaviors in the program behavior feature evaluation library according to the behavioral feature information of the running behavior, the behaviors in the program behavior feature evaluation library, and the corresponding risk assessment information; a fourth determination module for obtaining a first risk assessment value according to the matching degree.
[0123] Optionally, in the malicious program defense device provided in the embodiments of the present application, the device further includes: a third acquisition unit for acquiring the behavioral data during program operation before acquiring the behavior chain of the running behavior and the behavioral feature information of each behavior in the behavior chain when the first risk assessment value reaches a first preset condition, where the behavioral data includes records of multiple behaviors during program operation; an extraction unit for extracting the behavioral feature information of each behavior in the behavioral data, where the behavioral feature information of each behavior at least includes behavioral context information; a construction unit for constructing a behavior chain according to the behavioral context information of each behavior in the behavioral data.
[0124] Optionally, in the malicious program defense device provided in the embodiments of the present application, the calculation unit 304 includes: a third calculation module for calculating the risk assessment value of each behavior in the behavior chain according to the behavioral feature information of each behavior in the behavior chain by using a dynamic behavior recognition algorithm model; a setting module for setting corresponding weights for each behavior in the behavior chain; a fourth calculation module for calculating the second risk assessment value of the behavior chain based on the risk assessment value of each behavior in the behavior chain and the weights of each behavior in the behavior chain.
[0125] Optionally, in the malicious program defense device provided in the embodiments of the present application, the first processing unit 306 includes: a fifth determination module for determining the behavior pattern of the malicious program; a processing module for processing the malicious program in a preset manner according to the behavior pattern of the malicious program, the behavioral feature information of each behavior in the behavior chain, and the second risk assessment value; a recording module for recording the processing result information of the malicious program; an output module for outputting the processing result information.
[0126] It should be noted here that the above first acquisition unit 301, matching unit 302, second acquisition unit 303, calculation unit 304, judgment unit 305, and first processing unit 306 correspond to steps S201 to S206 in Embodiment 1. The examples and application scenarios implemented by the six units and the corresponding steps are the same, but are not limited to the content disclosed in the above Embodiment 1. It should be noted that the above modules or units can be hardware components or software components stored in a memory (for example, memory 104) and processed by one or more processors (for example, processors 102a, 102b,..., 102n). The above modules can also be part of a device and can run in the computer terminal 10 provided in Embodiment 1.
[0127] Embodiment 3 An embodiment of the present application can provide a computer terminal, and the computer terminal can be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the above computer terminal can also be replaced with a mobile terminal or other terminal devices such as an electronic device.
[0128] Optionally, in this embodiment, the above computer terminal can be located in at least one of multiple network devices in a computer network.
[0129] In this embodiment, the above computer terminal can execute the program code of the following steps in the malicious program defense method: obtain the running behavior during program operation; match the running behavior with the program behavior feature evaluation library to obtain a first risk assessment value, where the program behavior feature evaluation library is a database storing the behaviors during program operation and their corresponding risk assessment information; in the case where the first risk assessment value reaches a first preset condition, obtain the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain; input the behavior feature information of each behavior in the behavior chain into the dynamic behavior recognition algorithm model to calculate the second risk assessment value of the behavior chain; according to the second risk assessment value, determine whether the program is a malicious program; in the case where the program is a malicious program, process the malicious program.
[0130] Optionally, the above computer terminal can execute the program code of the following steps in the malicious program defense method: after matching the running behavior with the program behavior feature evaluation library to obtain a first risk assessment value, the method includes: in the case where the first risk assessment value reaches a second preset condition, determine that the program is a malicious program; process the malicious program.
[0131] Optionally, the above computer terminal may execute the program code for the following steps in the malicious program defense method: The steps for constructing a program behavior feature evaluation library are as follows: Determine a plurality of monitoring points and a plurality of monitored target behaviors corresponding to each monitoring point; Obtain sample data, where the sample data includes malicious program sample data and normal program sample data; Calculate the number of occurrences of each monitored target behavior in the malicious program sample data; Calculate the number of occurrences of each monitored target behavior in the normal program sample data; Determine the risk assessment information of each monitored target behavior based on the number of occurrences of each monitored target behavior in the malicious program sample data and the number of occurrences of each monitored target behavior in the normal program sample data; Construct a program behavior feature evaluation library based on each monitored target behavior and the risk assessment information of each monitored target behavior.
[0132] Optionally, the above computer terminal may execute the program code for the following steps in the malicious program defense method: Matching the running behavior with the program behavior feature evaluation library to obtain a first risk assessment value includes: Extracting the behavior feature information of the running behavior; Determining the matching degree between the running behavior and the behaviors in the program behavior feature evaluation library according to the behavior feature information of the running behavior, the behaviors in the program behavior feature evaluation library, and their corresponding risk assessment information; Obtaining the first risk assessment value according to the matching degree.
[0133] Optionally, before obtaining the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain when the first risk assessment value reaches a first preset condition, the method includes: Obtaining the behavior data during program operation, where the behavior data includes records of multiple behaviors during program operation; Extracting the behavior feature information of each behavior in the behavior data, where the behavior feature information of each behavior at least includes behavior context information; Constructing a behavior chain according to the behavior context information of each behavior in the behavior data.
[0134] Optionally, the above computer terminal may execute the program code for the following steps in the malicious program defense method: Inputting the behavior feature information of each behavior in the behavior chain into a dynamic behavior recognition algorithm model to calculate a second risk assessment value of the behavior chain includes: The dynamic behavior recognition algorithm model calculates the risk assessment value of each behavior in the behavior chain according to the behavior feature information of each behavior in the behavior chain; Setting corresponding weights for each behavior in the behavior chain; Calculating the second risk assessment value of the behavior chain based on the risk assessment value of each behavior in the behavior chain and the weight of each behavior in the behavior chain.
[0135] Optionally, the above computer terminal may execute the program code of the following steps in the method for defending against malicious programs: When the program is a malicious program, handling the malicious program includes: determining the behavior pattern of the malicious program; according to the behavior pattern of the malicious program, the behavior characteristic information of each behavior in the behavior chain, and the second risk assessment value, handling the malicious program in a preset manner; recording the processing result information of the malicious program; and outputting the processing result information.
[0136] Optionally, Figure 4 is a structural block diagram of an electronic device according to an embodiment of the present application. As Figure 4 shown, the electronic device may include: one or more ( Figure 4 only one is shown in the figure) processors 402, a memory 404, a storage controller, and a peripheral interface, wherein the peripheral interface is connected to a radio frequency module, an audio module, and a display.
[0137] Among them, the memory may be used to store software programs and modules, such as the program instructions / modules corresponding to the method and device for defending against malicious programs in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the above-mentioned method for defending against malicious programs. The memory may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely set relative to the processor, and these remote memories may be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, an enterprise internal network, a local area network, a mobile communication network, and combinations thereof.
[0138] The processor may call the information and application programs stored in the memory through a transmission device to execute the above steps in the method for defending against malicious programs.
[0139] By adopting the embodiments of the present application, a solution for defending against malicious programs is provided. By obtaining the running behavior during program operation; matching the running behavior with a program behavior characteristic evaluation library to obtain a first risk assessment value, wherein the program behavior characteristic evaluation library is a database storing the behaviors during program operation and their corresponding risk assessment information; when the first risk assessment value reaches a first preset condition, obtaining the behavior chain of the running behavior and the behavior characteristic information of each behavior in the behavior chain; inputting the behavior characteristic information of each behavior in the behavior chain into a dynamic behavior recognition algorithm model to calculate a second risk assessment value of the behavior chain; judging whether the program is a malicious program according to the second risk assessment value; and when the program is a malicious program, handling the malicious program, thereby solving the technical problem that it is impossible to accurately identify whether an unknown program is a malicious program, resulting in a poor defense effect against unknown programs, and achieving the technical effect of strengthening the defense effect against unknown programs.
[0140] Those of ordinary skill in the art can understand that Figure 4 the structure shown is only illustrative, and the electronic device can also be a smart phone (such as, a tablet computer, a personal digital assistant, and terminal devices such as Mobile Internet Devices (MIDs), PADs, etc.). Figure 4 It does not limit the structure of the above-mentioned electronic device. For example, the electronic device may further include more or fewer components (such as a network interface, a display device, etc.) than those shown Figure 4 in the figure, or have a different configuration from that shown Figure 4 in the figure.
[0141] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium. The storage medium may include: a flash drive, a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk, an optical disk, etc.
[0142] Embodiment 4 An embodiment of the present application further provides a storage medium. Optionally, in this embodiment, the above storage medium can be used to store the program code executed by the malicious program defense method provided in the first embodiment above.
[0143] Optionally, in this embodiment, the above storage medium can be located in any one of the computer terminals in the computer terminal group in the computer network, or in any one of the mobile terminals in the mobile terminal group.
[0144] Optionally, in this embodiment, the storage medium is set to store program code for performing the following steps: obtaining the running behavior during program operation; matching the running behavior with a program behavior feature evaluation library to obtain a first risk assessment value, where the program behavior feature evaluation library is a database storing the behaviors during program operation and their corresponding risk assessment information; in the case where the first risk assessment value reaches a first preset condition, obtaining the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain; inputting the behavior feature information of each behavior in the behavior chain into a dynamic behavior recognition algorithm model to calculate a second risk assessment value of the behavior chain; judging whether the program is a malicious program according to the second risk assessment value; and in the case where the program is a malicious program, processing the malicious program.
[0145] Optionally, the storage medium is further configured to store program code for performing the following steps: after matching the running behavior with the program behavior feature evaluation library to obtain a first risk assessment value, the method includes: when the first risk assessment value reaches a second preset condition, determining that the program is a malicious program; processing the malicious program.
[0146] Optionally, the storage medium is further configured to store program code for performing the following steps: the steps for constructing the program behavior feature evaluation library are as follows: determining a plurality of monitoring points and a plurality of monitoring target behaviors corresponding to each monitoring point; obtaining sample data, where the sample data includes malicious program sample data and normal program sample data; calculating the number of times each monitoring target behavior occurs in the malicious program sample data; calculating the number of times each monitoring target behavior occurs in the normal program sample data; determining the risk assessment information of each monitoring target behavior according to the number of times each monitoring target behavior occurs in the malicious program sample data and the number of times each monitoring target behavior occurs in the normal program sample data; constructing a program behavior feature evaluation library based on each monitoring target behavior and the risk assessment information of each monitoring target behavior.
[0147] Optionally, the storage medium is further configured to store program code for performing the following steps: matching the running behavior with the program behavior feature evaluation library to obtain a first risk assessment value includes: extracting the behavior feature information of the running behavior; determining the matching degree between the running behavior and the behaviors in the program behavior feature evaluation library according to the behavior feature information of the running behavior, the behaviors in the program behavior feature evaluation library, and their corresponding risk assessment information; obtaining the first risk assessment value according to the matching degree.
[0148] Optionally, the storage medium is further configured to store program code for performing the following steps: before obtaining the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain when the first risk assessment value reaches a first preset condition, the method includes: obtaining the behavior data during program operation, where the behavior data includes records of a plurality of behaviors during program operation; extracting the behavior feature information of each behavior in the behavior data, where the behavior feature information of each behavior at least includes behavior context information; constructing a behavior chain according to the behavior context information of each behavior in the behavior data.
[0149] Optionally, the storage medium is further configured to store program code for performing the following steps: inputting the behavior feature information of each behavior in the behavior chain into the dynamic behavior recognition algorithm model, and calculating a second risk assessment value of the behavior chain, including: the dynamic behavior recognition algorithm model calculates the risk assessment value of each behavior in the behavior chain according to the behavior feature information of each behavior in the behavior chain; setting corresponding weights for each behavior in the behavior chain; and calculating the second risk assessment value of the behavior chain based on the risk assessment value of each behavior in the behavior chain and the weight of each behavior in the behavior chain.
[0150] Optionally, the storage medium is further configured to store program code for performing the following steps: in the case that the program is a malicious program, processing the malicious program includes: determining the behavior pattern of the malicious program; taking a preset method to process the malicious program according to the behavior pattern of the malicious program, the behavior feature information of each behavior in the behavior chain, and the second risk assessment value; recording the processing result information of the malicious program; and outputting the processing result information.
[0151] The present application also provides a computer program product, which is suitable for executing a program for the steps of the malicious program defense method when executed on a data processing device.
[0152] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments.
[0153] In the above embodiments of the present application, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0154] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0155] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0156] In addition, in each embodiment of the present application, each functional unit can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0157] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The foregoing storage medium includes: various media that can store program codes such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs.
[0158] The above is only the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A defense method for malicious programs, characterized in that, Including: Obtain the running behavior during program operation; Match the running behavior with a program behavior feature evaluation library to obtain a first risk assessment value, where the program behavior feature evaluation library is a database storing the behaviors during program operation and their corresponding risk assessment information; When the first risk assessment value reaches a first preset condition, obtain the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain; Input the behavior feature information of each behavior in the behavior chain into a dynamic behavior recognition algorithm model, and calculate a second risk assessment value of the behavior chain; Judge whether the program is a malicious program according to the second risk assessment value; When the program is a malicious program, process the malicious program.
2. The method according to claim 1, characterized in that, After matching the running behavior with the program behavior feature evaluation library to obtain a first risk assessment value, the method includes: When the first risk assessment value reaches a second preset condition, determine that the program is a malicious program; Process the malicious program.
3. The method according to claim 1, characterized in that, The construction steps of the program behavior feature evaluation library are as follows: Determine multiple monitoring points and multiple monitoring target behaviors corresponding to each monitoring point; Obtain sample data, where the sample data includes malicious program sample data and normal program sample data; Calculate the number of times each monitoring target behavior occurs in the malicious program sample data; Calculate the number of times each monitoring target behavior occurs in the normal program sample data; Determine the risk assessment information of each monitoring target behavior according to the number of times each monitoring target behavior occurs in the malicious program sample data and the number of times each monitoring target behavior occurs in the normal program sample data; Based on each monitoring target behavior and the risk assessment information of each monitoring target behavior, construct the program behavior feature evaluation library.
4. The method according to claim 3, characterized in that, Matching the running behavior with the program behavior feature evaluation library to obtain a first risk assessment value includes: Extract the behavior feature information of the running behavior; According to the behavior feature information of the running behavior, the behaviors in the program behavior feature evaluation library and their corresponding risk assessment information, determine the matching degree between the running behavior and the behaviors in the program behavior feature evaluation library; Obtain the first risk assessment value according to the matching degree.
5. The method according to claim 1, characterized in that Before obtaining the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain when the first risk assessment value reaches a first preset condition, the method includes: Obtain the behavior data during program operation, where the behavior data includes records of multiple behaviors during program operation; Extract the behavior feature information of each behavior in the behavior data, where the behavior feature information of each behavior at least includes behavior context information; Construct the behavior chain according to the behavior context information of each behavior in the behavior data.
6. The method according to claim 5, wherein Inputting the behavior feature information of each behavior in the behavior chain into a dynamic behavior recognition algorithm model and calculating a second risk assessment value of the behavior chain includes: The dynamic behavior recognition algorithm model calculates the risk assessment value of each behavior in the behavior chain according to the behavior feature information of each behavior in the behavior chain; Set corresponding weights for each behavior in the behavior chain; Based on the risk assessment value of each behavior in the behavior chain and the weight of each behavior in the behavior chain, calculate the second risk assessment value of the behavior chain.
7. The method according to claim 1, wherein When the program is a malicious program, handling the malicious program includes: Determine the behavior pattern of the malicious program; According to the behavior pattern of the malicious program, the behavior feature information of each behavior in the behavior chain, and the second risk assessment value, handle the malicious program in a preset manner; Record the processing result information of the malicious program; Output the processing result information.
8. A defense device for malicious programs, characterized in that, Including: The first acquisition unit is used to acquire the running behavior during program operation; The matching unit is used to match the running behavior with the program behavior feature evaluation library to obtain the first risk assessment value, where the program behavior feature evaluation library is a database storing the behaviors during program operation and their corresponding risk assessment information; The second acquisition unit is used to acquire the behavior chain of the running behavior and the behavior feature information of each behavior in the behavior chain when the first risk assessment value reaches a first preset condition; The calculation unit is used to input the behavior feature information of each behavior in the behavior chain into the dynamic behavior recognition algorithm model and calculate the second risk assessment value of the behavior chain; The judgment unit is used to judge whether the program is a malicious program according to the second risk assessment value; The first processing unit is used to handle the malicious program when the program is a malicious program.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored executable program, wherein when the executable program runs, it controls the device where the computer-readable storage medium is located to execute the defense method for malicious programs described in any one of claims 1 to 7.
10. An electronic device, characterized in that, Including: A memory storing an executable program; A processor for running the program, wherein when the program runs, it executes the defense method for malicious programs described in any one of claims 1 to 7.
11. A computer program product, comprising computer instructions, characterized in that, The computer instructions, when executed by the processor, implement the steps of the defense method for malicious programs described in any one of claims 1 to 7.
Citation Information
Patent Citations
Method and system for detecting malicious application of Android system
CN106874761A
Malicious software identification method and system
CN107742079A
Program identification method and device
CN109800569A
Malicious program detection method and device, equipment and storage medium
CN119312330A
Behavior chain analysis and abnormal association detection method
CN119484030A