Malicious software analysis system and method
Through a variety of collection and integration of malware samples and threat intelligence, combined with automated analysis and multi-dimensional verification, executable defense measures are generated, which solves the problems of lagging threat intelligence updates and insufficient analysis reports in the existing technology, and achieves efficient malware analysis and rapid defense.
Patent Information
- Application Number
- CN202511013206.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2045-07-23
AI Technical Summary
The existing malware analysis system has lag in threat intelligence updates, lack of multi-dimensional verification mechanisms, and the generated analysis reports fail to generate executable defense measures, resulting in missed detection of new malware and delayed emergency responses.
A variety of collection methods are used to obtain malware samples and threat intelligence, and analysis results are generated through automated analysis tools combined with multi-dimensional verification methods, and executable defense measures are generated, including sample collection module, threat intelligence integration module, automated analysis module and result verification module.
It improves the update speed of threat intelligence, improves the detection efficiency of new malware, reduces the false alarm rate, shortens the deployment time of defense measures, and improves the accuracy of high-risk malware sample judgment.
Smart Images

Figure CN120524486A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of malware analysis, and in particular to a malware analysis system and method. Background Art
[0002] Malware can pose a serious threat to computer systems and devices. Once on a computing system or device, malware can lead to the loss of personal, financial, or other sensitive information. Malware's widespread presence is due in part to the range and diversity of malware variants, which can take the form of viruses, worms, Trojans, keyloggers, spyware, adware, and ransomware. With each new type constantly emerging, malware analysis systems are essential for their analysis and processing.
[0003] When existing malware analysis systems are running, threat intelligence updates lag behind and operate independently from the sample analysis process, making it impossible to guide analysis strategies in real time, resulting in the omission of new malware. The output of a single analysis tool in the malware analysis system contains false positives and lacks a multi-dimensional verification mechanism. Moreover, the analysis reports generated by traditional malware analysis systems only present technical data and do not generate executable defense measures. Users need to manually convert rules, resulting in delays in emergency response. Summary of the Invention
[0004] The purpose of the present invention is to provide a malware analysis system and method to solve the problems of malware analysis systems in the prior art, such as delayed threat intelligence updates, lack of multi-dimensional verification mechanisms, and failure to generate executable defense measures.
[0005] In order to achieve the above-mentioned objectives, the present invention provides a malware analysis system, which includes: a sample collection module for collecting malware samples using multiple collection methods and storing the malware samples; a threat intelligence integration module for collecting threat intelligence using multiple platforms, and integrating and storing the threat intelligence; an automated analysis module for generating automated analysis results of malware based on stored malware samples and stored threat intelligence using automated analysis tools, combining analysis processes with automated processes; a result verification module for performing credibility verification on the automated analysis results based on the automated analysis results using a selected verification method and combining multiple verification indicators; and a report generation module for generating corresponding defense measures based on the automated analysis results, and generating a malware analysis report by combining the automated analysis results with the corresponding defense measures.
[0006] Optionally, integrating the threat intelligence includes: performing standardization processing based on the heterogeneous data of the threat intelligence to generate standardized threat intelligence; performing correlation analysis based on the standardized threat intelligence and the malware samples to generate correlation analysis results; and dynamically updating the threat intelligence library based on the correlation analysis results to achieve integration of threat intelligence.
[0007] Optionally, the analysis process includes static analysis, dynamic analysis, and behavioral analysis, wherein the static analysis includes: analyzing the file structure of malware samples and threat intelligence; extracting suspicious character strings based on the file structure; detecting and analyzing the encryption algorithm and hash value of the suspicious character strings; Based on the encryption algorithm and hash value, the signature of known malware is matched.
[0008] Optionally, the dynamic analysis includes: running the malware sample in a sandbox environment; monitoring the running of the malware sample and recording the running behavior; and analyzing the system API called by the malware based on the running behavior.
[0009] Optionally, the behavior analysis includes: using a rule engine to detect abnormal behavior during the operation of the malware sample; and matching with a threat intelligence library based on the abnormal behavior.
[0010] Optionally, the automated process includes: building an automated analysis pipeline to perform static analysis, dynamic analysis, and behavioral analysis in sequence; using multi-threading or multi-nodes to process the malware samples in parallel; and using a task scheduler to set the priority of malware sample analysis based on the danger level of the malware samples.
[0011] Optionally, the use of automated analysis tools, combined with analysis processes and automated processes, generates automated analysis results of malware, including: using a packer identification tool to determine whether the malware sample is protected by a packer, and combining a cryptographic analysis method to determine whether the malware sample is a hard-coded key; when the malware sample is protected by a packer and is a hard-coded key, triggering dynamic analysis; running the malware sample in a sandbox environment, and when a process injection chain is captured, confirming persistence behavior and triggering behavioral analysis; matching the persistence behavior with the threat intelligence library to generate automated analysis results of the malware sample.
[0012] Optionally, the verification method includes an expert verification method, a cross-validation method and a historical data verification method, and the verification indicators include accuracy, completeness and timeliness. The selected verification method is combined with multiple verification indicators to perform credibility verification on the automated analysis results, including: using the verification console to retrieve the automated analysis results, and comparing them with the ATT&CK technical library to generate the verification results of the expert verification method; using multiple automated analysis tools to automatically analyze the malware samples from multiple sources to generate multiple groups of automated analysis results, and comparing the multiple groups of automated analysis results to obtain the verification results of the cross-validation method; using a historical database to retrieve the matching results of the automated analysis results and historical data, and combining with a similarity algorithm to generate the verification results of the historical data verification method; mapping the verification results of the expert verification method, the cross-validation method and the historical data verification method to corresponding verification indicators, and using a comprehensive credibility model to calculate the credibility verification score; if the credibility verification score exceeds a preset threshold, the automated analysis result is assessed as high credibility; if the credibility verification score does not exceed the preset threshold, the automated analysis result is assessed as low credibility.
[0013] Optionally, generating a malware analysis report includes: generating basic information of the sample based on the malware sample; generating automated analysis results based on the results of static analysis, dynamic analysis and behavioral analysis; generating the correlation between the malware sample and the threat intelligence based on the correlation analysis results; generating corresponding malware defense measures based on the correlation; integrating the basic information, automated analysis results, correlation and defense measures to generate a malware analysis report.
[0014] On the other hand, the present invention provides a malware analysis method, which includes: collecting malware samples using multiple collection methods and storing the malware samples; collecting threat intelligence using multiple platforms, and integrating and storing the threat intelligence; based on the stored malware samples and stored threat intelligence, using automated analysis tools, combining analysis processes and automated processes, to generate automated analysis results of the malware; based on the automated analysis results, using a selected verification method, combined with multiple verification indicators, to verify the credibility of the automated analysis results; and based on the automated analysis results, generating corresponding defense measures, and combining the automated analysis results with the corresponding defense measures to generate a malware analysis report.
[0015] Through the above technical solution, the present invention improves the update speed of threat intelligence and the detection efficiency of new malware through dynamic analysis and correlation analysis of the threat intelligence integration module and pipeline design of the automated analysis module; reduces the false alarm rate and improves the accuracy of high-risk malware sample judgment through the expert verification method, cross-validation method and historical data verification method of the result verification module; and achieves the purpose of significantly shortening the deployment time of defense measures and reducing the amount of manual operation through the correlation between the report generation module and the defense measures.
[0016] Other features and advantages of the present invention will be described in detail in the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The accompanying drawings are used to provide a further understanding of the embodiments of the present invention and constitute a part of the specification. Together with the following detailed description, they are used to explain the embodiments of the present invention, but do not constitute a limitation of the embodiments of the present invention. In the accompanying drawings: Figure 1 It is a schematic diagram of the process of a malware analysis system of the present invention; Figure 2 It is a flowchart of threat intelligence integration in the present invention; Figure 3 is a schematic diagram of a process for generating automated analysis results of malware in the present invention; Figure 4 It is a schematic diagram of the process of performing credibility verification on the automated analysis results in the present invention; Figure 5 It is a schematic diagram of the process of generating a malware analysis report in the present invention; Figure 6 This is a schematic diagram of the process of a malware analysis method of the present invention. Figure 1 ; Figure 7 This is a schematic diagram of the process of a malware analysis method of the present invention. Figure 2 . DETAILED DESCRIPTION
[0018] The following describes the specific implementation of the embodiment of the present invention in detail with reference to the accompanying drawings. It should be understood that the specific implementation described herein is only used to illustrate and explain the embodiment of the present invention and is not used to limit the embodiment of the present invention.
[0019] It should be noted that the acquisition, transmission, storage, use, and processing of data in the technical solution of this application are in compliance with the relevant provisions of laws and regulations. In the embodiments of this application, certain software, components, models, and other existing solutions in the industry may be mentioned. These should be considered as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solution of this application, but it does not mean that the applicant has or will necessarily use such solutions.
[0020] Please refer to Figure 1 An embodiment of the present invention provides a malware analysis system, which includes: a sample collection module, which is used to collect malware samples using multiple collection methods and store the malware samples; a threat intelligence integration module, which is used to collect threat intelligence using multiple platforms, and integrate and store the threat intelligence; an automated analysis module, which is used to generate automated analysis results of the malware based on the stored malware samples and the stored threat intelligence using automated analysis tools, combining analysis processes with automated processes; a result verification module, which is used to perform credibility verification on the automated analysis results based on the automated analysis results using a selected verification method and combining multiple verification indicators; and a report generation module, which is used to generate corresponding defense measures based on the automated analysis results, and generate a malware analysis report by combining the automated analysis results with the corresponding defense measures.
[0021] In an embodiment of the present invention, the sample collection module may be configured to collect malware samples using a variety of collection methods and store the malware samples.
[0022] Among them, malware samples are collected using a variety of collection methods, including network packet capture tools deployed based on border firewalls to capture malicious traffic. For example, based on DPI technology (deep packet inspection technology, which analyzes the content of network data packets byte by byte to identify the application layer protocol and application type in the data packet), abnormal traffic can be filtered and PE files (i.e., portable executable files that store program code, resources, data, and other information that can be run on Windows systems) can be extracted; lightweight virtual machines deployed based on sandbox environments can be used to run malware and collect the malicious payloads it releases; honeypot tools deployed on the network can be used to capture malware and record malware information. For example, a simulated industrial control system (e.g., a fake PLC service) can be built to attract targeted attacks; and malware samples can be obtained using public malware libraries.
[0023] In a preferred embodiment of the present invention, when storing malware samples, a distributed file system can be used to store malware samples. For example, a MinIO object storage cluster can be used (MinIO is a high-performance, open source object storage server suitable for storing unstructured data, such as pictures, videos, log files, backup data, etc.), and storage can be divided into buckets according to the sample collection time; basic information of the malware sample can be recorded, for example, the four core attributes of file name, MD5 value, file size, and collection source can be automatically extracted and stored; and labels can be added to the samples according to the collection method (for example, family, type, danger level, etc.).
[0024] In an embodiment of the present invention, the threat intelligence integration module can be used to collect threat intelligence using multiple platforms, and integrate and store the threat intelligence.
[0025] Among them, the various platforms can include public threat intelligence platforms (for example, subscribing to Pulse event streams of AlienVault OTX (an open source threat intelligence platform that allows security professionals, researchers, and enthusiasts to share, obtain, and analyze various network threat intelligence), ThreatConnect (a threat intelligence platform that deploys a single platform in the cloud or on-premises, and provides advanced analytical capabilities for threat intelligence, incident response, and security operations analysis through effective aggregation, analysis, and action to respond to complex network attacks), private threat intelligence libraries (for example, attack indicators that integrate the company's internal SIEM system), open source threat intelligence (for example, threat intelligence projects on GitHub (a hosting platform for open source and private software projects)), partner sharing (for example, sharing threat intelligence with other organizations), etc.
[0026] Please refer to Figure 2 In a preferred embodiment of the present invention, integrating threat intelligence may include: Step S110: Perform standardization processing based on the heterogeneous data of threat intelligence to generate standardized threat intelligence.
[0027] For example, key fields in heterogeneous data (such as IP addresses, domain names, and file hash values) can be extracted and forced to align with the STIX2.1 object model (STIX2.1 is a structured threat information representation, and the object model is a standard model used in the field of network security to describe, share, and exchange threat intelligence) through a standardization engine. Bundle data packets (i.e., a packaged and bundled data set) that comply with the STIX2.1 specification are generated, containing threat indicators and malware objects with unified semantics, eliminating format differences in multi-source data.
[0028] Among them, the standardization engine is a tool used to implement standardized processing. It can perform standardized operations on various data, convert data of different formats and ranges into a unified format and range, remove noise, outliers, etc. in the data, so as to improve the quality and availability of the data and facilitate subsequent analysis, storage and sharing.
[0029] Step S120: performing correlation analysis based on the standardized threat intelligence and malware samples to generate correlation analysis results.
[0030] For example, the MD5 value extracted from the static analysis of the malware sample can be compared with the hash of the File object in the threat intelligence library to match known malicious files. The domain name of the C&C server (the command and control server, also known as the master server, which is the core device used by attackers to control the compromised computer) captured by the dynamic analysis can then be matched with the domain name object in the intelligence library to trace the infrastructure of the malware attack. Finally, a STIXRelationship relationship object is generated (STIX is a structured threat information expression used to represent and exchange network threat intelligence. STIXRelationship is used to describe the relationship between different objects in STIX. For example, the STIXRelationship relationship object can be [sample]-uses-[C&C server]) to construct a threat intelligence map as the result of the association analysis.
[0031] Step S130: Based on the correlation analysis results, the threat intelligence library is dynamically updated to achieve threat intelligence integration.
[0032] For example, public intelligence sources can be polled every 5 minutes to capture only newly added or modified threat intelligence data, which is then injected into the threat intelligence library after standardization. IP / domain name IoCs can then be automatically marked as expired if there is no activity for 30 days and moved to the historical archive. Tactical intelligence can be marked as abandoned if it has not been updated for 1 year to maintain a highly active threat intelligence library (for example, the proportion of expired data is ≤5%) and ensure the timeliness of correlation analysis dependencies.
[0033] In a preferred embodiment of the present invention, the format of threat intelligence may include using the STIX / TAXII format to store and transmit threat intelligence. For example, the core threat intelligence library uses STIX (a standard language for representing and sharing network threat intelligence, which allows different organizations and systems to more effectively communicate and analyze network security-related information) to describe attack patterns, and distributes threat intelligence through the TAXII2.0 protocol (a protocol for standardized, trusted, and automatic network threat information exchange, which is a version of the TAXII protocol and defines a set of services and message exchanges that enable organizations to share actionable network threat information with each other). Threat intelligence can also be stored in JSON format (a lightweight data exchange format that is easy for humans to read and write, and also easy for machines to parse and generate, such as a C&C server IP list) or YAML format (a readable data serialization format used in scenarios such as configuration files and data exchange, which uses indentation and line breaks to represent data structures, has a concise format, and supports data types such as scalars, lists, and mappings).
[0034] In an embodiment of the present invention, the automated analysis module can be used to generate automated analysis results of malware based on stored malware samples and stored threat intelligence, using automated analysis tools, and combining analysis processes with automated processes.
[0035] In a preferred embodiment of the present invention, the analysis process includes static analysis, dynamic analysis and behavioral analysis, wherein static analysis may include: analyzing the file structure of malware samples and threat intelligence, for example, extracting file headers, PE structures, etc., and parsing abnormal items in the import table / export table of PE files; extracting suspicious strings based on the file structure, for example, scanning C&C domain names in ASCII / Unicode strings; detecting and analyzing the encryption algorithm and hash value of suspicious strings, for example, it can identify the function characteristics of AES-256 keys (encryption keys used by the Advanced Symmetric Encryption Standard algorithm with a 256-bit key length); matching with the characteristics of known malware based on the encryption algorithm and hash value, for example, code snippets of known malware can be matched through the YARA rule library. The YARA rule library is a collection of YARA rules based on text string and binary pattern matching. It is an open source tool for detecting malware, identifying specific file types, or finding specific patterns in files. YARA rules describe the characteristics of files by writing rules, and then apply these rules to the target file to determine whether the file contains matching characteristics.
[0036] In a preferred embodiment of the present invention, dynamic analysis may include: running malware samples in a sandbox environment, for example, running samples in a Windows 10 environment in Cuckoo Sandbox (an open source automated malware analysis system that can execute suspicious files or programs in an isolated environment and analyze the characteristics, activities, and potential hazards of malware by monitoring their behavior); monitoring the execution of malware samples and recording the execution behavior, for example, recording the creation of the malware sample process tree and registry persistence operations; analyzing system APIs called by the malware based on the execution behavior, for example, hooking 18 high-risk API call sequences such as NtCreateFile (a native API function in the Windows operating system, whose main function is to create, open, or truncate a file, directory, physical disk, volume, console buffer, mail slot, pipe, or other object).
[0037] In a preferred embodiment of the present invention, behavioral analysis may include: using a rule engine to detect abnormal behavior during the operation of malware samples. For example, the rule engine can be used to identify fileless attack features. The rule engine is a component embedded in the application, which separates business decisions from the application code and uses predefined semantic modules to write business decisions. The rules are usually expressed in an easy-to-understand manner (for example, in the form of "if...then...") and stored in a rule base; based on abnormal behavior, matching with the threat intelligence base, for example, the external IP of the malware sample can be compared with the threat intelligence base in real time and matched with it.
[0038] In a preferred embodiment of the present invention, the automated process may include: building an automated analysis pipeline to perform static analysis, dynamic analysis, and behavioral analysis in sequence, with a fixed execution sequence of "static analysis → dynamic analysis → behavioral analysis", and terminating if the preceding sequence fails; utilizing multi-threading or multi-nodes to process malware samples in parallel. For example, concurrent analysis of hundreds of samples can be achieved based on a Kubernetes cluster. A Kubernetes cluster is a set of nodes (physical machines or virtual machines) used to run containerized applications. It consists of a control plane and worker nodes. The control plane is responsible for managing and maintaining the status of the entire cluster and coordinating various resources and operations in the cluster. The worker nodes are used to run applications. The Kubernetes cluster can implement automated application deployment, expansion, failover, load balancing, and other functions, thereby improving the reliability and maintainability of the application; utilizing a task scheduler to manage analysis tasks. For example, Airflow can be used to set the priority of malware sample analysis according to the risk level of the malware sample.
[0039] Please refer to Figure 3 In a preferred embodiment of the present invention, automated analysis tools are used to combine analysis processes with automated processes to generate automated analysis results of malware, which may include: Step S210: Using a packer identification tool, determine whether the malware sample is protected by a packer, and combine cryptographic analysis methods to determine whether the malware sample is a hard-coded key.
[0040] For example, the Packer Identification Tool (PEiD) can be used to detect abnormal entry point offsets and section table overlaps (for example, the .text and .data sections overlap) of malware samples, match the signature rules of the executable file compression tool, and determine that the malware sample is protected by a packer. Then, by converting the machine language (binary code) into assembly language code, the fixed hexadecimal value at the offset abnormality is located, and combined with the encryption API call pattern, it is confirmed to be a hard-coded key.
[0041] Step S220: When the malware sample is protected by a packer and has a hard-coded key, dynamic analysis is triggered.
[0042] For example, when two high-risk features, namely, malware packing (to evade analysis) and hard-coded keys (evidence of C&C encrypted communication), are detected, the automated process generates dynamic analysis instructions, carrying the C&C server web address extracted by static analysis as a monitoring parameter, triggering the dynamic analysis process.
[0043] Step S230: Run the malware sample in a sandbox environment. When a process injection chain is captured, confirm the persistence behavior and trigger behavioral analysis.
[0044] For example, you can run samples in an isolated Windows 10 environment, forcibly enable network blocking rules to block all outbound traffic, force malware samples to activate alternative attack chains, and expose the behavior patterns of malware samples in real restricted networks through environmental restrictions; capture the process injection chain of the attack chain, use the CAPE malware analysis platform, and use hooking technology to capture the call sequence of a series of high-risk APIs called by malware during operation, analyze the high-risk API sequence, and identify the behavior patterns, functional characteristics and attack intentions of the malware; release the counterfeit file and call the function in the application programming interface to set the hidden attribute, and the registry startup item ensures that the malware sample runs automatically after the system restarts. Combined with the file hidden attribute, long-term residence and concealment are achieved. The released counterfeit file is the execution target of the application programming interface function in the injection chain, proving that the injection behavior serves persistence.
[0045] Step S240: Match the persistent behavior with the threat intelligence library to generate automated analysis results of the malware sample.
[0046] For example, the memory dump of the process injection chain can be extracted to find the reverse shell instruction flow (that is, the controlled end actively initiates a connection to the control end to establish an interactive command line session, through which the attacker can execute commands on the target host and control a series of ordered instruction sets of the target system). The captured C&C server web address is compared with the threat intelligence library in real time (for example, hitting activities that match the attacker's technical means described in the STIX format and associating API organizations). The MD5 value of the released counterfeit file collides with the new type of malicious program formed by the mutation of known malware, and the malware sample is traced back to its lineage.
[0047] In an embodiment of the present invention, the result verification module can be used to perform credibility verification on the automated analysis results based on the automated analysis results using a selected verification method in combination with multiple verification indicators.
[0048] In a preferred embodiment of the present invention, the verification method may include an expert verification method, a cross-validation method, and a historical data verification method, and the verification indicators may include accuracy, completeness, and timeliness.
[0049] Among them, the expert verification method is to use the web console to have security experts manually verify the automated analysis results; the cross-validation method is to use other analysis tools to generate analysis results and compare and verify them with the automated analysis results; the historical data verification method is based on the analysis results of historical malware samples and compares and verifies them with the automated analysis results.
[0050] Accuracy refers to the consistency between the analysis results and the actual results, and the false alarm rate of automated analysis is calculated based on the manual verification results; completeness refers to whether all preset detection dimensions (for example, files / networks / registries) are covered; timeliness refers to whether the analysis speed meets the requirements, that is, the total time taken from the statistical sample being stored to the completion of verification.
[0051] Please refer to Figure 4 In a preferred embodiment of the present invention, the reliability check of the automated analysis results is performed using a selected verification method in combination with multiple verification indicators, which may include: Step S310: Use the verification console to retrieve the automated analysis results, compare them with the ATT&CK technical library, and generate the verification results of the expert verification method.
[0052] In a preferred embodiment of the present invention, security experts can retrieve the following core data through the verification console: retrieve malware samples through dynamic analysis of screen recording clips to modify registry key data, and capture DNS tunnel request data through network traffic; then compare with the ATT&CK technical library to confirm that the registry self-startup matches the DNS protocol communication, and obtain the verification result of the expert verification method.
[0053] Step S320: Utilize multiple automated analysis tools to automatically analyze malware samples from multiple sources, generate multiple sets of automated analysis results, compare the multiple sets of automated analysis results, and obtain verification results of the cross-validation method.
[0054] In a preferred embodiment of the present invention, a variety of automated analysis tools may include the CuckooSandbox tool, which detects registry persistence behavior and determines whether it is consistent with the Sysmon log record; the CAPE extension tool, which captures the DNS tunnel API and determines whether it matches the network protocol analyzer traffic characteristics; the Volatility tool, which outputs a process tree and determines whether it is the same as the process chain recorded by the EDR terminal (i.e., the endpoint detection and response terminal, which is used to monitor and respond to security threats of endpoint devices (such as computers, servers, etc.) in real time). The above results are compared to obtain the verification result of the cross-validation method.
[0055] Step S330: using the historical database, searching for matching results between the automated analysis results and the historical data, and combining with a similarity algorithm to generate a verification result of the historical data verification method.
[0056] In a preferred embodiment of the present invention, a similarity algorithm is used to measure the degree of similarity between two or more analysis results and historical data. The verification result of the historical data verification method can be obtained through the similarity value, which can be expressed by the following formula:
[0057] Step S340: Map the verification results of the expert verification method, the verification results of the cross-validation method, and the verification results of the historical data verification method into corresponding verification indicators, and use the comprehensive credibility model to calculate the credibility verification score.
[0058] In a preferred embodiment of the present invention, when the verification results are mapped to corresponding verification indicators, security experts review key evidence based on experience (for example, dynamic analysis of screen recordings) to directly determine whether the analysis results are true, and calculate the manual confirmation true positive rate, which can be used as a contribution to accuracy verification. Experts check the coverage of preset detection items and calculate the coverage rate, which can be used as a contribution to integrity verification; the analysis results of multiple automated analysis tools are mutually verified to eliminate single-point errors, and the consistency rate of multi-tool results is calculated, which can be used as a contribution to accuracy verification; the complementary capabilities of multiple automated analysis tools discover hidden features, and the feature increment is calculated, which can be used as a contribution to integrity verification; historical patterns are used as a benchmark reference, and the similarity between samples and historical libraries is calculated, which can be used as a contribution to accuracy verification. Statistics are taken from the start of historical retrieval to the output of results, and the proportion of verification time to total verification time is calculated, which can be used as a contribution to timeliness verification.
[0059] In a preferred embodiment of the present invention, the comprehensive credibility model is a comprehensive model used to evaluate and quantify the credibility of things. It can comprehensively consider multiple different factors, dimensions or information sources, integrate these factors through specific algorithms and rules, and thus obtain an evaluation result such as a numerical value or level of the credibility of the target object.
[0060] The credibility verification score can be expressed as follows:
[0061] in, represents the accuracy contribution value, Indicates the integrity contribution value, Indicates the timeliness contribution value.
[0062] Step S350: If the credibility check score exceeds a preset threshold (eg, 80%), the automated analysis result is assessed as having high credibility; if the credibility check score does not exceed the preset threshold, the automated analysis result is assessed as having low credibility.
[0063] In an embodiment of the present invention, the report generation module may be configured to generate corresponding defense measures based on the automated analysis results, and to generate a malware analysis report by combining the automated analysis results with the corresponding defense measures.
[0064] Please refer to Figure 5 In a preferred embodiment of the present invention, generating a malware analysis report may include: Step S410: Generate basic information of the sample based on the malware sample.
[0065] In a preferred embodiment of the present invention, basic attributes of malware samples, such as file name, MD5 value, file size, and collection source, can be extracted from distributed storage. Label system information of malware samples, such as initial label and post-analysis label, can also be added.
[0066] Step S420: Generate automated analysis results based on the results of static analysis, dynamic analysis, and behavioral analysis.
[0067] In a preferred embodiment of the present invention, the integration of static analysis results may include, for example, analysis of the structure of the packed file, extracted strings (C&C server, release path), cryptographic analysis (hard-coded keys) and feature matching (YARA rule hits), etc.; the integration of dynamic analysis results may include, for example, sandbox execution (activation of DNS tunnel after network blocking), behavior monitoring (registry persistence, file operations) and API call analysis, etc.; the integration of behavior analysis results may include abnormal behavior detection (abnormal process tree entropy value, DNS traffic pattern matching) and threat intelligence matching (IP associated APT organization), so as to generate automated analysis results.
[0068] Step S430: Based on the correlation analysis results, generate the correlation between the malware sample and the threat intelligence.
[0069] In a preferred embodiment of the present invention, generating association information may include first parsing a structured threat information expression object, for example, [sample]-uses-[infrastructure: 94.130.178.23], [sample]-variant of-[malware: Emotet]; then associating with the attack organization, for example, the hacker organization TA542 (historical activities: banking Trojan distribution); and finally mapping the ATT&CK framework (registry self-start, DNS protocol communication) to generate an association between the malware sample and the threat intelligence.
[0070] Step S440: Generate corresponding malware defense measures based on the association situation.
[0071] In a preferred embodiment of the present invention, network layer defense measures are generated for the C&C server communication behavior captured by dynamic analysis. Firewall rules can be used to generate instructions to block malicious IP addresses, prohibiting terminal devices from connecting to the C&C server IP address discovered through analysis. This rule directly acts on the network exit and can immediately cut off the communication channel between the malware sample and the attacker. At the same time, specific rules are created for DNS covert tunnel behavior to block malicious domain name resolution requests, preventing malware samples from infiltrating data through the DNS protocol.
[0072] In a preferred embodiment of the present invention, terminal-layer defense measures are generated for the persistent residence and process behaviors discovered by behavioral analysis. EDR response commands can be used to generate commands for forcibly terminating malicious processes (for example, terminating a process named spoolv.exe (an executable file related to the print spooler. When an abnormal spoolv.exe process appears in the system, such as occupying a large amount of system resources or having an abnormal network connection, it may mean that the system has been infected)). This command can immediately terminate the running malicious activities and create registry repair instructions (for example, deleting the PrintSpooler (print background processing service in the Windows operating system, which manages print tasks) startup item), clearing the persistence mechanism established by the malware sample in the system, and ensuring that the malicious code will not be reactivated after the system is restarted. These commands can be executed directly in the terminal security system to achieve automatic repair.
[0073] In a preferred embodiment of the present invention, hunting detection rules are generated based on the unique features discovered by static analysis. YARA rules can be used to dynamically generate detection rules based on binary features. For example, a precisely matched YARA rule can be created for the hard-coded key features discovered by cryptographic analysis. The rule can be deployed to a terminal or network sensor to actively scan for variants of the same source malware code in the memory or file system, thereby enhancing the capability of continuous threat hunting.
[0074] Step S450: Integrate basic information, automated analysis results, correlation conditions, and defense measures to generate a malware analysis report.
[0075] In a preferred embodiment of the present invention, when generating a malware analysis report, one can first select a report template, for example, using a standard structure with a cover / table of contents / chapter index, and adding a "Lateral Movement Detection Recommendations" chapter based on user configuration; then, a format conversion engine is used for HTML / PDF rendering and JSON / XML output. For example, JSON analysis data is injected into a Jinja2 template (a powerful and widely used template engine for Python that allows developers to combine dynamic data with static template files to generate final text output, such as HTML web pages, configuration files, etc.); WeasyPrint (an open source library written in Python for converting HTML and CSS documents to PDF files that follows web standards and can accurately generate high-quality PDFs in accordance with the style and layout of web page designs) is used to generate a PDF with a table of contents, retaining the original data structure and adding ATT&CK mapping fields; and finally, visual charts (for example, behavior time series diagrams, threat score radar charts) are embedded.
[0076] Please refer to Figure 6 and Figure 7 , an embodiment of the present invention further provides a malware analysis method, the analysis method comprising: Step S1: Collect malware samples using multiple collection methods and store the malware samples.
[0077] Step S2: Collect threat intelligence using multiple platforms, and integrate and store the threat intelligence.
[0078] Step S3: Based on the stored malware samples and stored threat intelligence, use automated analysis tools, combine the analysis process with the automation process, and generate automated analysis results of the malware.
[0079] Step S4: Based on the automated analysis results, the reliability of the automated analysis results is verified using the selected verification method in combination with multiple verification indicators.
[0080] Step S5: Based on the automated analysis results, corresponding defense measures are generated, and a malware analysis report is generated by combining the automated analysis results and the corresponding defense measures.
[0081] Accordingly, an embodiment of the present invention provides a malware analysis system, which includes: a sample collection module for collecting malware samples using multiple collection methods and storing the malware samples; a threat intelligence integration module for collecting threat intelligence using multiple platforms, and integrating and storing the threat intelligence; an automated analysis module for generating automated analysis results of malware based on stored malware samples and stored threat intelligence, using automated analysis tools, combining analysis processes and automated processes; a result verification module for performing credibility verification on the automated analysis results based on the automated analysis results, using a selected verification method, and combining multiple verification indicators; and a report generation module for generating corresponding defense measures based on the automated analysis results, and generating a malware analysis report in combination with the automated analysis results and the corresponding defense measures. Through the above technical solution, the present invention improves the update speed of threat intelligence and the detection efficiency of new malware through dynamic analysis and correlation analysis of the threat intelligence integration module and pipeline design of the automated analysis module; reduces the false alarm rate and improves the accuracy of high-risk malware sample judgment through the expert verification method, cross-validation method and historical data verification method of the result verification module; and achieves the purpose of significantly shortening the deployment time of defense measures and reducing the amount of manual operation through the correlation between the report generation module and the defense measures.
[0082] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0083] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0084] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0085] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0086] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0087] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0088] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can be implemented using any method or technology for information storage. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change RAM (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.
[0089] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0090] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A malware analysis system, characterized in that: The analysis system comprises: A sample collection module, configured to collect malware samples using a variety of collection methods and store the malware samples; A threat intelligence integration module is used to collect threat intelligence using multiple platforms and integrate and store the threat intelligence; An automated analysis module is used to generate automated analysis results of malware based on stored malware samples and stored threat intelligence, using automated analysis tools and combining analysis processes with automated processes; a result verification module, configured to verify the credibility of the automated analysis results based on the automated analysis results using a selected verification method in combination with a plurality of verification indicators; and The report generation module is used to generate corresponding defense measures based on the automated analysis results, and to generate a malware analysis report by combining the automated analysis results with the corresponding defense measures.
2. The malware analysis system according to claim 1, wherein: The integrating of the threat intelligence includes: Based on the heterogeneous data of the threat intelligence, standardization processing is performed to generate standardized threat intelligence; Performing correlation analysis based on the standardized threat intelligence and the malware sample to generate a correlation analysis result; Based on the correlation analysis results, the threat intelligence library is dynamically updated to achieve threat intelligence integration.
3. The malware analysis system according to claim 1, wherein: The analysis process includes static analysis, dynamic analysis and behavioral analysis, wherein the static analysis includes: Analyze the file structure of malware samples and threat intelligence; Extracting suspicious character strings based on the file structure; Detecting and analyzing the encryption algorithm and hash value of the suspicious character string; Based on the encryption algorithm and hash value, the signature of known malware is matched.
4. The malware analysis system according to claim 3, wherein: The dynamic analysis includes: Running the malware sample in a sandbox environment; Monitor the execution of the malware sample and record its execution behavior; Based on the running behavior, the system API called by the malware is analyzed.
5. The malware analysis system according to claim 3, wherein: The behavioral analysis includes: Utilizing a rule engine to detect abnormal behavior during the execution of the malware sample; Based on the abnormal behavior, it is matched with the threat intelligence library.
6. The malware analysis system according to claim 3, wherein: The automated process includes: Build an automated analysis pipeline to perform static analysis, dynamic analysis, and behavioral analysis in sequence; Processing the malware sample in parallel using multi-threading or multi-node; The task scheduler is used to set a priority for malware sample analysis based on the danger level of the malware sample.
7. The malware analysis system according to claim 3, wherein: The automated analysis tool is used to combine the analysis process with the automation process to generate automated analysis results of malware, including: Using a packer identification tool to determine whether the malware sample is protected by a packer, and combining cryptographic analysis methods to determine whether the malware sample contains a hard-coded key; When the malware sample is protected by a packer and has a hard-coded key, dynamic analysis is triggered; Run the malware sample in a sandbox environment, and when a process injection chain is captured, confirm the persistence behavior and trigger behavioral analysis; The persistence behavior is matched with the threat intelligence library to generate automated analysis results of the malware sample.
8. The malware analysis system according to claim 1, wherein: The verification methods include expert verification, cross-validation, and historical data verification. The verification indicators include accuracy, completeness, and timeliness. The selected verification method, combined with multiple verification indicators, is used to verify the credibility of the automated analysis results, including: Use the verification console to retrieve the automated analysis results and compare them with the ATT&CK technical library to generate verification results for the expert verification method; Utilizing multiple automated analysis tools to automatically analyze the malware samples from multiple sources, generating multiple sets of automated analysis results, and comparing the multiple sets of automated analysis results to obtain verification results using a cross-validation method; Using the historical database, searching for matching results between the automated analysis results and the historical data, and combining with a similarity algorithm to generate verification results of the historical data verification method; Mapping the verification results of the expert verification method, the verification results of the cross-validation method, and the verification results of the historical data verification method into corresponding verification indicators, and calculating the credibility verification score using a comprehensive credibility model; If the credibility check score exceeds the preset threshold, the automated analysis result is rated as high credibility; If the credibility check score does not exceed the preset threshold, the automated analysis result is assessed as low credibility.
9. The malware analysis system according to claim 1, wherein: Generating a malware analysis report includes: Based on the malware sample, generate basic information of the sample; Generate automated analysis results based on the results of static analysis, dynamic analysis, and behavioral analysis; Based on the correlation analysis results, generating a correlation between the malware sample and the threat intelligence; Based on the correlation, generate corresponding malware defense measures; Integrate the basic information, automated analysis results, correlation situations and defense measures to generate a malware analysis report.
10. A malware analysis method, characterized in that: The analysis method comprises: Collecting malware samples using multiple collection methods and storing the malware samples; Utilize multiple platforms to collect threat intelligence, and integrate and store said threat intelligence; Based on stored malware samples and stored threat intelligence, automated analysis tools are used to combine analysis processes with automated processes to generate automated analysis results of malware. Based on the automated analysis results, using a selected verification method and combining multiple verification indicators to verify the credibility of the automated analysis results; and Based on the automated analysis results, corresponding defense measures are generated, and a malware analysis report is generated by combining the automated analysis results and the corresponding defense measures.
Citation Information
Patent Citations
Malicious code detection method and system
CN106778268A
Cooperative prevention system for unknown threat detection
CN106888196A
Malicious file threat analysis platform and malicious file threat analysis method
CN110955893A
Dynamic iteration multi-engine fusion malicious code detection method and device and medium
CN114386034A
Detection and analysis method and system for threat attack
CN117254950A