Malware escape behavior detection method based on higher-order functions and dependent algebra
By constructing a high-order function dependency matrix and function summary, and analyzing the function call relationship and dependency relationship of malware, the problem of difficulty in identifying complex malware in existing technologies is solved, and efficient malware detection is achieved.
Patent Information
- Application Number
- CN202511114414.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-11
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-08-11
AI Technical Summary
Existing malware detection methods have difficulty effectively identifying variants of complex malware and new types of malware, and machine learning-based detection solutions lack a deep understanding of the internal behavioral hierarchy and dependencies of malware, resulting in high false alarm rates and low detection efficiency.
By constructing a high-order function dependency matrix and function summary, the function call relationship, data flow and control flow in the malware code are analyzed, and the dependency algebra theory is used to identify the critical path. Perturbations are injected into the critical path to determine whether the malware has successfully escaped.
It achieves accurate analysis of malware and rapid extraction of key paths, significantly improving analysis efficiency and accuracy and enhancing the detector's detection capabilities.
Smart Images

Figure CN120611377B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of functional programming and program analysis, and in particular to a malware escaping behavior detection method based on high-order functions and dependency algebra. Background Art
[0002] Currently, malware detection methods typically rely on signature detection or behavioral analysis techniques. However, as malware becomes increasingly sophisticated, these traditional detection methods are easily bypassed, especially when malware can adapt itself to the target environment.
[0003] In recent years, malware evasion has become a new research area. The goal is to engineer adversarial examples that allow malware to bypass detectors and evade detection by creating specialized input data. These adversarial examples subtly perturb the malware's behavior, preventing detection systems from correctly identifying malicious activity. However, current mainstream malware detection techniques rely primarily on feature matching or shallow behavioral analysis, which presents significant limitations. Traditional methods are often limited to identifying fixed patterns within known malware and have limited detection capabilities for variants or new malware. While machine learning-based detection solutions can handle unknown samples, they lack a deep understanding of the malware's internal behavioral hierarchies and dependencies, resulting in high false positive rates and low detection efficiency.
[0004] To this end, the present invention proposes a malware evasion behavior detection method based on high-order functions and dependency algebra. Summary of the Invention
[0005] The purpose of the present invention is to provide a malware escape behavior detection method based on high-order functions and dependency algebra. By constructing a high-order function dependency matrix and function summary, it can accurately analyze the function call relationship, data flow and control flow in the malware code. Compared with traditional static analysis methods, it can quickly extract the critical path of malware.
[0006] According to a first aspect of the present invention, to achieve the above-mentioned purpose, the present invention provides the following technical solution: a malware escaping behavior detection method based on higher-order functions and dependency algebra, comprising the following steps:
[0007] Receiving source code of the malware that failed to escape, analyzing dependencies between functions in the source code based on dependency algebra theory, and constructing a set used in the analysis process, wherein the dependencies include data dependencies, control dependencies, and parameter dependencies;
[0008] The dependency relationship generates a corresponding function summary through a high-order function, constructs a high-order function dependency matrix based on the function summary, and calculates the dependency strength weight;
[0009] By analyzing the instantiated function summary through inter-procedural analysis, the dependency strength weight is updated according to the instantiated function summary, and the high-order function dependency matrix is updated;
[0010] According to the updated dependency strength weights, the key dependency paths of several high-order dependency matrices are identified. Perturbations are injected into each key dependency path to determine whether the malware that previously failed to escape successfully escapes. If it succeeds, this key dependency path is recorded and output.
[0011] Furthermore, the source code of the malware that failed to escape is received. Based on dependency algebra theory, the dependency relationships between functions in the source code are analyzed, and a set used in the analysis process is constructed. The dependency relationships include data dependency, control dependency, and parameter dependency, as follows:
[0012] (21) Statically analyze the functions, data flows, and control flows of the malware, and analyze the data dependencies, control dependencies, and parameter dependencies between functions in the source code;
[0013] (22) Construct the set used in the analysis process, including the matrix element set , dependent type collection , the dependent type set of matrix element e , variable collection during function call , Function Summary .
[0014] Furthermore, we analyze the data dependency, control dependency, and parameter dependency between functions in the source code, as follows:
[0015] (31) Data dependency analysis: Analyze the usage of function return values and the transfer path of non-parameter data between functions;
[0016] (31.1) Check each function one by one to see if there is a function call inside it. If not, it means that this function does not have data or control dependencies on other functions. Jump to step (33.3). If so, continue to analyze the next step.
[0017] (31.2) For each called function, check whether the current function uses the return value of the called function. If not, jump to the next step. If yes, it means that the current function data depends on the called function. For each case where the current function data depends on the called function, check whether it exists first. For the current function, Is the matrix element e of the called function, if any, then Add to If not in the set, generate a matrix element set And the Set as current function, Set as the called function, then Add to In the collection;
[0018] (31.3) Check whether the current function passes its own generated data to the called function. If not, jump to the next step. If yes, it means that the called function depends on the current function in terms of data. For each case where the called function depends on the current function in terms of data, check whether it exists first. is the called function, Is the matrix element e of the current function, if any, then Add to If not in the set, generate a matrix element set And the Set as the called function, Set as the current function, then Add to In the collection;
[0019] (32) Control dependency analysis: Analyze the impact of control structures on other function calls;
[0020] (32.1) Check whether there is a control structure inside the current function. If not, it means that there is no control dependency of the current function to other functions. Jump to step (33). If there is, continue analysis.
[0021] (32.2) Check whether the control structure determines the call, number of calls, or order of calls to other functions. If not, jump to the next step. If so, it means that the current function data depends on the called function. For each case where the current function data depends on the called function, check whether it exists first. For the current function, Is the matrix element e of the called function, if any, then Add to If not in the set, generate a matrix element set And the Set as current function, Set as the called function, then Add to In the collection;
[0022] (33) Parameter dependency analysis: Analyze the source and transfer of function parameters;
[0023] (33.1) Determine the parameters passed to the called function and check whether the execution of the called function depends on the passed parameters. If not, jump to step (33.3). If so, it indicates that the called function parameters depend on the current function. For each case where the called function parameters depend on the current function, check whether is the called function, Is the matrix element e of the current function, if any, then Add to If not in the set, generate a matrix element set And the Set as the called function, Set as the current function, then Add to In the collection;
[0024] (33.2) Check whether the parameters used by the current function to call other functions are provided by other functions or affected by other functions. If so, it means that the current function parameters depend on the function that provides the parameters. For each case where the current function parameters depend on the function that provides the parameters, check whether there is For the current function, The matrix element e of the function that provides the parameters, if any, will be Add to If not in the set, generate a matrix element set And the Set as current function, Set to a function that provides the parameters, and then Add to In the collection;
[0025] (33.3) Check whether the parameters of the current function are provided by other functions or affected by other functions. If so, it means that the current function parameters depend on the function that provides the parameters. For each case where the current function parameters depend on the function that provides the parameters, check whether there is For the current function, For the matrix element e of other functions, if any, Add to If not in the set, generate a matrix element set And the Set as current function, Set to other functions, then Add to In collection.
[0026] Furthermore, the set used in the analysis process is constructed, including the matrix element set , dependent type collection , the dependent type set of matrix element e , variable collection during function call , Function Summary , as follows:
[0027] Matrix element collection , is a four-tuple ,in They represent the rows and columns of the dependency matrix, i.e., the starting and ending functions of the dependency relationship in the escaped malicious code. The purpose of storing rows and columns in the matrix element set is to optimize storage. The sparse matrix storage structure is used to record each non-zero dependency. is the dependency strength weight, which is used to express the criticality of the dependency path;
[0028] Dependent type collection , represents a set of dependent types, supporting multi-type superposition, where They are data dependency, control dependency, and parameter dependency;
[0029] The set of dependent types of the matrix element e ;
[0030] Variable collection during function call , which is in the form of a tuple ,in Represents a set of data-dependent variables, including all variables and related functions in the data dependency. Represents a set of parameter-dependent variables, including all variables and related functions that depend on the parameters. and Elements are stored in the form of a tuple <variable, related function>;
[0031] Function Summary , which represents the function summary generated after analyzing the dependency relationship between entities, and its form is a tuple When a formal parameter or global variable is encountered, a Expression and add to In collection.
[0032] Furthermore, the dependency relationship generates a corresponding function summary through a high-order function, and a high-order function dependency matrix is constructed based on the function summary, as follows:
[0033] (51) Specific steps for constructing a function summary:
[0034] When performing dependency analysis on a function A in a malicious code fragment, its data dependency variable set use Instead, the parameter depends on the set of variables use Instead, when adding these variables to the function summary of A, use The expression is replaced by The analysis result of calculating the dependency weight based on the function parameter corresponding to the function dependency set is: The expression represents a specific value or a function, which is instantiated when the corresponding argument is encountered. Expressions to obtain precise results;
[0035] Based on the generated function summary , calculated to correspond to the matrix elements The row is the starting point of the dependency path, and the col is the dependency path strength weight of the end point of the dependency path. , and finally perfect the dependency matrix element e to form a high-order function dependency matrix;
[0036] (52) Specific steps for calculating dependency intensity weights:
[0037] Dependency intensity weight ,in
[0038] is the data dependency strength weight, defined as:
[0039] Assumptions 、 Function A and function B respectively:
[0040]
[0041] Indicates the number of times function A passes data to function B; Indicates the maximum number of times data is passed in a single path of the program; Indicates the depth of processing of data passed from function B to function A; Indicates the maximum depth of data passed through a single path in the program; Represents a weighting factor, which is used to adjust the influence of data processing depth in the calculation of data dependency intensity weight;
[0042] is the parameter dependence intensity weight, defined as:
[0043] Assumptions 、 Function A and function B respectively:
[0044]
[0045] Indicates the number of times function A calls function B; represents the maximum number of calls of a single path in a program; represents the number of times of argument passing from function A to function B; represents the number of times of passing function as argument from function A to function B; represents the total number of arguments of all functions in a program, represents a weighting factor, which is used to adjust the degree of influence of argument passing and passing function as argument on the weight.
[0046] Further, the function summary is instantiated through inter-process analysis, the dependency strength weight is updated according to the instantiated function summary, and the high-order function dependency matrix is updated, specifically as follows:
[0047] (61) obtaining the actual argument at the function call point of the malicious code;
[0048] (62) substituting the obtained actual argument into the corresponding parameter of the called function summary, and instantiating the function summary;
[0049] (63) returning the analysis result of the instantiated function summary to the call point, and updating the dependency strength weight to according to the instantiated information, and updating the high-order function dependency matrix;
[0050] The recalculated dependency strength weight is represented as ,
[0051]
[0052] represents the number of times of actually passing data from function A to function B through analysis of the instantiated behavior; represents the maximum value of the number of times of actually passing data in a single path of a program; represents the actual level of depth of processing the data passed from B to A; represents the actual maximum depth of processing the passed data in a single path of a program; represents an influence factor, wherein the range value of the influence factor is , which is used to reflect the influence of the output of a function on other functions, if the output of function A is dependent on multiple functions, then is close to 1, if it is only used by function B, then is close to 0; , v represents a weighting factor, which is used to adjust the degree of influence of the data processing depth in the calculation of the data dependency strength weight;
[0053]
[0054] Indicates the actual number of times function A calls function B, obtained by analyzing the instantiated behavior; Indicates the maximum number of actual calls in a single path in the program; Indicates the actual number of times the parameters are passed from function A to function B; Indicates the actual number of times function A passes a function as a parameter to function B; Indicates the total number of actual parameters of all functions in the program; represents the influence factor; and is the weighting factor: Used to adjust the influence of parameter passing and function passing as parameter on weight. It is used to adjust the influence of the influence factor in the weight calculation.
[0055] Furthermore, the dependency path of the high-order dependency matrix is identified based on the updated dependency strength weights. Perturbations are injected into this dependency path to determine whether the malware that previously failed to escape has successfully escaped. If it has successfully escaped, this dependency path is recorded to enhance the detection capabilities of related detectors. The details are as follows:
[0056] (71) Identify the key dependency paths in the high-order function dependency matrix as follows;
[0057] Calculate the dependency strength weight of the direct dependency path ;
[0058] Calculate the dependency strength weight of the indirect dependency path , the specific steps include:
[0059] Define weighting coefficients , used to reflect the direct path Relative importance among all direct paths:
[0060] Weighting coefficient
[0061] If there is a direct dependency path in the program B, C, then it is determined that there must be an indirect dependency path ,therefore:
[0062]
[0063]
[0064] Therefore, the dependency strength weight of each indirect dependency path in the program , calculated by the following formula:
[0065]
[0066]
[0067] in , ...represents all direct dependency paths that form this indirect dependency path;
[0068] Calculate all the and Then, sort them in descending order, select the first m direct dependency paths and indirect dependency paths and identify them as key dependency paths, where the value of m is customized;
[0069] (72) Inject disturbances on multiple identified critical dependency paths to determine whether the malware can attempt to escape again;
[0070] (73) If the escape is successful, the key dependency path that affects the malware’s escape effect is recorded to enhance the detector’s detection capability.
[0071] According to a second aspect of the present invention, a malware escaping behavior detection system based on higher-order functions and dependency algebra is provided, which is used to implement the malware escaping behavior detection method based on higher-order functions and dependency algebra described in the first aspect, comprising:
[0072] A program processing module is configured to receive source code of the malware that failed to escape, analyze dependencies between functions in the source code based on dependency algebra theory, and construct a related set, wherein the dependencies include data dependencies, control dependencies, and parameter dependencies;
[0073] An intra-process analysis module is used to construct a function summary using a high-order function to formally represent the dependency relationship, calculate the dependency strength weight to express the criticality of the dependency path, and construct a high-order function dependency matrix;
[0074] An interprocedural analysis module, configured to instantiate function summaries through interprocedural analysis, and update dependency strength weights based on the instantiated information, and update a high-order function dependency matrix;
[0075] The escape behavior detection module is used to identify the key dependency paths of several high-order dependency matrices based on the updated dependency strength weights, inject disturbances into each key dependency path, and determine whether the malware that previously failed to escape has successfully escaped. If it has successfully escaped, the key dependency path is recorded and output.
[0076] According to a third aspect of the present application, the present application provides a terminal device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, wherein when the processor loads and executes the computer program, the method for detecting malware escape behavior based on high-order functions and dependent algebra described in the first aspect is adopted.
[0077] According to a fourth aspect of the present application, the present application provides a storage medium containing computer executable instructions for executing the method for detecting malware escape behavior based on high-order functions and dependent algebra described in the first aspect when executed by a computer processor.
[0078] The present application has at least the following beneficial effects:
[0079] 1. The present application can accurately analyze the function call relationship, data flow and control flow in the malware code by constructing the high-order function dependent matrix and function abstract, compared with the traditional static analysis method, the present application can quickly extract the key path of the malware, especially in the case of complex function call and dependent relationship, the most critical malicious behavior path can be effectively identified, and the analysis efficiency and accuracy are significantly improved.
[0080] 2. The present application can select the most critical dependent path for further analysis and optimization by calculating the weight of the dependent strength and sorting the key path with the dependent matrix, and the effectiveness of the key dependent path on the malware escape can be verified by the perturbation injection technology (such as changing the function call order, inserting harmless operation, etc.), the success rate of escape is improved, the key dependent path affecting the effect of malware escape is recorded and monitored, and the detection ability of the related detector is enhanced.
[0081] Of course, any product implementing the present application does not necessarily need to achieve all the advantages described above at the same time. BRIEF DESCRIPTION OF DRAWINGS
[0082] Figure 1 is the flow chart of the malware escape behavior detection method based on high-order functions and dependent algebra of the present application. DETAILED DESCRIPTION
[0083] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0084] Embodiment one:
[0085] Please refer to Figure 1The present invention provides a technical solution: a malware escaping behavior detection method based on high-order functions and dependency algebra, comprising the following steps:
[0086] Receiving source code of the malware that failed to escape, analyzing dependencies between functions in the source code based on dependency algebra theory, and constructing a set used in the analysis process, wherein the dependencies include data dependencies, control dependencies, and parameter dependencies;
[0087] The dependency relationship generates a corresponding function summary through a high-order function, constructs a high-order function dependency matrix based on the function summary, and calculates the dependency strength weight;
[0088] By analyzing the instantiated function summary through inter-procedural analysis, the dependency strength weight is updated according to the instantiated function summary, and the high-order function dependency matrix is updated;
[0089] Based on the updated dependency strength weights, the key dependency paths of several high-order dependency matrices are identified. Perturbations are injected into each key dependency path to determine whether the malware that previously failed to escape successfully escapes. If it does, the key dependency path is recorded and output. The output key dependency path is mainly used to enhance the detection capabilities of related detectors.
[0090] Next, the technical solution of the present invention is further described with reference to specific embodiments:
[0091] S1, program preprocessing: receiving the source code of the malware that failed to escape, and analyzing the dependencies between functions in the source code based on dependency algebra theory, and constructing a related set, where the dependencies include data dependency, control dependency, and parameter dependency;
[0092] The specific steps of program preprocessing include:
[0093] S11, static analysis of malware functions, data flow, and control flow;
[0094] In this embodiment, the selected malicious code program fragments to be analyzed are shown in Table 1:
[0095] Table 1: Missing malicious code snippets
[0096]
[0097] Specifically:
[0098] 1. Lines 1-8: Define the download_file(url) function
[0099] Line 2: Call fetch_data(url) to get the file content → Key calls
[0100] Line 4: Conditional judgment if "secret" inurl.lower()
[0101] Line 5: Hard-coded key assignment key="malicious_key" → Red Mark
[0102] Line 6: Call decrypt_data(file_content,key) to decrypt
[0103] Line 7: Returns the processed file content
[0104] 2. Lines 10-14: Define the fetch_data(url) function
[0105] Line 11: Simulation data file_content="Simulation data"
[0106] Line 12: Save the file save_file("file.txt",file_content) → File name tags
[0107] Line 13: Returns the file contents
[0108] 3. Lines 15-20: Define the decrypt_data() function
[0109] Line 16: Directly assign decrypted_data=encrypted_data
[0110] Line 17: Conditional judgment ifkey=="malicious_key"
[0111] Line 18: Returns the forged data "decrypted data" → Core malicious behavior
[0112] Line 19: Save the file save_file("decrypted_file.txt",decrypted_data) → Added persistence operations
[0113] Line 20: return decrypted_data → Data return
[0114] 4. Lines 22-23: Define the save_file() function
[0115] Line 22: Define the function defsave_file(file_name, content): File save function
[0116] Line 23: Print information print(f"Save file {file_name}, content: {content}") → Log output ;
[0117] The core malicious behavior analysis is as follows:
[0118] 1. Conditional trigger mechanism (lines 4-6)
[0119] if"secret"inurl.lower():#Detect keywords in URL
[0120] key="malicious_key"#Hardcoded malicious key
[0121] file_content=decrypt_data(file_content,key)#Activate decryption process
[0122] Attack signature: Malicious code is activated when the URL contains a secret
[0123] Threat: Hiding malicious behavior through regular requests;
[0124] 2. Disguise decryption function (lines 16-18)
[0125] defdecrypt_data(encrypted_data,key):
[0126] decrypted_data=encrypted_data#Not actually decrypted
[0127] ifkey=="malicious_key":#Verify malicious key
[0128] return "decrypted data" #return forged data
[0129] Deceptive design:
[0130] It appears to be a decryption function, but it actually replaces data.
[0131] Activate only if key matches malicious_key
[0132] Harm: Substituting legitimate data for malicious content
[0133] 3. Persistence operation (line 12)
[0134] save_file("file.txt",file_content)#Save the received file
[0135] File name mark: fixedly use file.txt as the storage path
[0136] Forensic clues: File system remnants can be used as detection indicators;
[0137] S12, analyze data dependency, control dependency, and parameter dependency, and construct related sets;
[0138] S13, build collection ,T, 、 、 , their meanings are as follows:
[0139] ①Matrix element set , is a four-tuple ,in They represent the rows and columns of the dependency matrix, i.e., the starting point function and the end point function of the dependency relationship in the escaped malicious code;
[0140] ②Dependent type collection ,in They are data dependency, control dependency, and parameter dependency;
[0141] ③The dependent type set of matrix element e ;
[0142] ④Variable collection during function call , which is in the form of a tuple ,in Represents a set of data-dependent variables, including all variables and related functions in the data dependency. Represents a set of parameter-dependent variables, including all variables and related functions that depend on the parameters. and Elements are stored in the form of a tuple <variable, related function>;
[0143] ⑤Function Summary , which represents the function summary generated after analyzing the dependency relationship between entities. Its form is a tuple When a formal parameter or global variable is encountered, a Expression and add to In the collection;
[0144] Dependency intensity weight ,in
[0145] is the data dependency strength weight, defined as:
[0146] by 、 Take function A and function B as examples respectively
[0147]
[0148] Indicates the number of times A transfers data to B. Indicates the maximum number of times data is passed in a single path of the program. Indicates the depth of processing of data passed from B to A. Indicates the maximum depth of data passed through a single path in the program. Weighting factor, which adjusts the influence of data processing depth in the calculation of data dependency intensity weight;
[0149] is the parameter dependence intensity weight, defined as:
[0150] by 、 Take function A and function B as examples respectively
[0151]
[0152] Indicates the number of times A calls B, Indicates the maximum number of calls to a single path in the program; Indicates the number of parameter transfers from A to B. Indicates the number of times A passes the function as a parameter to B; Indicates the total number of parameters of all functions in the program, Weighting factors are used to adjust the influence of parameter passing and function passing as parameters on weights;
[0153] S2. Intra-procedural analysis: Select each function in the code in turn and use it as the current analysis object. Check the dependencies within the function, update the corresponding set results, and then generate a function summary for the function. Function parameters and global variables are represented by specific symbols and used as parameters of the current function summary, so that actual parameters can be substituted for instantiation later.
[0154] S21. Select the first function in the escaped malicious code fragment as the function to be analyzed;
[0155] S22. Analyze the functional dependency types.
[0156] The functional dependency types include: data dependency, control dependency and parameter dependency;
[0157] S221. The analysis corresponding to data dependency is:
[0158] S2211. Check whether there is a function call inside the function. If not, it means that there is no data dependency or control dependency of the function on other functions. Jump to S2233. If there is, continue analysis.
[0159] S2212. For each called function, check whether the current function uses the return value of the called function; if not, jump to the next step; if yes, it means that the current function data depends on the called function, and for each case, check whether it exists first. For the current function, Is the matrix element e of the called function, if any, then Add to If not, a matrix element set is generated. And the Set as current function, Set as the called function, then Add to middle;
[0160] S2213, check whether the current function passes its own generated data (excluding parameters) to the called function. If not, jump to the next step. If yes, it means that the called function depends on the current function in terms of data. For each case, check whether it exists first. is the called function, Is the matrix element e of the current function, if any, then Add to If not, a matrix element set is generated. And the Set as the called function, Set as the current function, then Add to middle;
[0161] S222, the analysis corresponding to the control dependency is:
[0162] S2221, check whether there is a control structure (such as a judgment statement and a loop statement) inside the function. If not, it means that there is no control dependency of this function on other functions, jump to S223, if yes, continue analysis;
[0163] S2222, check whether these control structures determine the calling, calling times or calling order of other functions. If not, jump to the next step. If yes, it means that the current function data depends on the called function. For each case, check whether it exists first. For the current function, Is the matrix element e of the called function, if any, then Add to If not, a matrix element set is generated. And the Set as current function, Set as the called function, then Add to middle;
[0164] S223, the corresponding analysis of parameter dependence is:
[0165] S2231, determine the parameters passed to the called function, check whether the execution of the called function depends on these parameters, if not, jump to S2233, if yes, it means that the called function parameters depend on the current function, for each case, check whether it exists is the called function, Is the matrix element e of the current function, if any, then Add to If not, a matrix element set is generated. And the Set as the called function, Set as the current function, then Add to middle;
[0166] S2232, check whether the parameters used by the current function to call other functions are provided by other functions or affected by other functions. If so, it means that the current function parameters depend on the function that provides the parameters. For each case, check whether For the current function, The matrix element e of the function that provides the parameters, if any, will be Add to If not, a matrix element set is generated. And the Set as current function, Set to a function that provides the parameters, and then Add to middle;
[0167] S2233, check whether the parameters of the current function are provided by other functions or affected by other functions. If so, it means that the parameters of the current function depend on the function that provides the parameters. For each case, check whether For the current function, For the matrix element e of other functions, if any, Add to If not, a matrix element set is generated. And the Set as current function, Set to other functions, then Add to middle;
[0168] S23, determine whether all statements have been analyzed. If not, go to S22 to continue analyzing. If all statements have been analyzed, go to S24;
[0169] S24, according to the function Summary of Set Generating Functions ;
[0170] The specific steps to generate a function summary include:
[0171] S241, for function parameters and global variables, which cannot determine the final information due to function calls, use specific symbols ( and other Greek letters) and then generate a The expression will generate The expression is used as a parameter in the current function summary so that the actual parameter can be substituted later to update the analysis result;
[0172] Hypothetical variables is a function Formal parameters or global variables, in the When adding these variables to the function summary, use The expression is replaced by The result of calculating the dependency weights based on the function parameters corresponding to the function dependency set is: An expression can represent a specific value or a function, which is instantiated when the corresponding argument is encountered. expression to obtain accurate results.
[0173] In this embodiment, according to the above steps S22-S23, it can be concluded that for the download_file function, its dependent type set is , whose data depends on the set of variables };
[0174] Parameter dependent variable set };
[0175] Set its data dependent variables use Instead, the parameter depends on the set of variables use Instead, generate a function summary for the function , the matrix elements e with the download_file function as the starting point of dependence are:
[0176]
[0177]
[0178] In this embodiment, according to the above steps S22-S23, it can be concluded that for the fetch_data function,
[0179] Its dependent type collection , whose data depends on the set of variables , whose parameters depend on the set of variables }, parameter dependent variable set use Instead, generate a function summary for the function , the matrix element e with fetch_data function as the starting point of dependence has
[0180] In this embodiment, according to the above steps S22-S23, it can be concluded that for the decrypt_data function, its dependent type set is , its data dependency type set
[0181] }
[0182] Parameter dependent variable set }, its data dependent variable set use Instead, the parameter depends on the set of variables use Instead, generate a function summary for the function , the matrix elements e that depend on the decrypt_data function are:
[0183]
[0184]
[0185] In this embodiment, according to the steps S22-S23 above, for the save_file function, its dependency type set , its data dependency variable set }
[0186] , its parameter dependency type set , the data dependency variable set is replaced by , the function summary of the function is generated , the matrix element e with the save_file function as the dependency starting point is:
[0187]
[0188]
[0189] S242, in the steps S22-S23 above, the values of each variable required for calculating the dependency strength weight are calculated, and the dependency strength weight :
[0190]
[0191]
[0192] In this example, let download_file be A, fetch_data be B, decrypt_data be C, and save_file be E, take , and the dependency strength weight
[0193]
[0194]
[0195] , and the dependency strength weight
[0196]
[0197]
[0198]
[0199]
[0200]
[0201]
[0202] Therefore, the elements in the high-order function dependency matrix constructed according to the missing malicious code fragment analysis include:
[0203]
[0204]
[0205]
[0206]
[0207]
[0208]
[0209]
[0210] S3. Inter-process analysis: As the dynamic running of the program, its function parameters, return values and the like may be updated, therefore, for the function call statement of the missing malicious code, the information of the actual argument at the call point is substituted into the function summary of the called function, then the instantiated summary result is transmitted back to the call point according to the correspondence between the formal argument and the actual argument, and the called function is analyzed according to the instantiated information;
[0211] The steps of the inter-process analysis include:
[0212] S31. Acquiring the actual argument at the function call point of the missing malicious code;
[0213] S32. Substituting the acquired actual argument into the corresponding parameter of the called function summary, and instantiating the function summary;
[0214] S33. Transmitting the analysis result of the instantiated function summary back to the call point, and updating the dependency strength weight to according to the instantiated information, and updating the high-order function dependency matrix;
[0215] S4. Escape behavior detection: According to the updated dependency strength weight, the key dependency path of the high-order dependency matrix is recognized, and the disturbance is injected on the recognized key dependency path, so that the previously failed malicious software successfully escapes, finally the key dependency path affecting the escape effect of the malicious software is recorded, the detection ability of the related detector is enhanced, and the process ends.
[0216] The steps of the escape behavior detection include:
[0217] S41. Recognizing the key dependency path in the high-order function dependency matrix, which is specifically as follows:
[0218] The recaculated dependency strength weight is represented as ,
[0219]
[0220] Indicates the number of times A actually transfers data to B by analyzing the instantiation behavior. Indicates the maximum number of times data is actually transferred in a single path of the program. Indicates the actual level depth of processing of data passed from B to A. Indicates the actual maximum depth of data passed through a single path in the program. Influence factor : This is a new factor introduced after instantiation, reflecting the influence of function output on other functions. If the output of A is relied upon by multiple functions (such as global variables or key parameters), then Close to 1, if only used by B, then Close to 0, ,v is a weighting factor, which is used to adjust the influence of data processing depth in the calculation of data dependency intensity weight;
[0221]
[0222] Indicates the actual number of times A calls B, obtained by analyzing the behavior after instantiation. Indicates the maximum number of actual calls in a single path in the program. Indicates the actual number of times the parameters from A to B are passed. Indicates the actual number of times A passes the function as a parameter to B, Indicates the total number of actual parameters of all functions in the program; represents the influence factor, and is the weighting factor: Used to adjust the influence of parameter passing and function passing as parameter on weight. It is used to adjust the influence of the influence factor in the weight calculation.
[0223] In this example, when the program is running dynamically, the program fragment is analyzed according to steps S21-S23 to obtain the actual variable set of each function. , follow the steps of S24 and substitute it into the function summary of the corresponding function to obtain the instantiated information, and thereby update the dependency strength weight and the high-order function dependency matrix.
[0224] In this example, the resulting updated function summary is ,
[0225] In this example, let download_file be A, fetch_data be B, decrypt_data be C, save_file be E, and , can be calculated according to the above formula:
[0226]
[0227]
[0228] Dependency intensity weight , similarly we can conclude that:
[0229]
[0230]
[0231]
[0232]
[0233]
[0234]
[0235] Therefore, after instantiation, the elements in the updated high-order function dependency matrix constructed based on the analysis of the escaped malicious code fragment include:
[0236]
[0237]
[0238]
[0239]
[0240]
[0241]
[0242]
[0243] Furthermore, the key dependency paths are identified based on the high-order function dependency matrix. The specific steps include:
[0244] Calculate the dependency strength weight of the direct dependency path ;
[0245] Calculate the dependency strength weight of the indirect dependency path , the specific steps include:
[0246] Define weighting coefficients , for each direct path (For example B), reflects the path relative importance among all direct paths;
[0247] Weighting coefficient
[0248] In this example, the intensity weights and weighting coefficients of each direct dependency path are shown in Table 2:
[0249] Table 2 Direct dependency path strength weights and weighting coefficients
[0250]
[0251] If there is a direct dependency path in the program B, C, then it is determined that there must be an indirect dependency path (Note: a loop is not an indirect dependency path), so
[0252]
[0253]
[0254] Therefore, the dependency strength weight of each indirect dependency path in the program , can be calculated by the following formula:
[0255]
[0256]
[0257] in , ...represents all direct dependency paths that form this indirect dependency path
[0258] In this example, the indirect dependency paths and their strength weights are shown in Table 3:
[0259] Table 3 Indirect dependency paths and their strength weights
[0260]
[0261] Calculate all the and After that, the system sorts the paths in descending order and selects the top m direct and indirect dependency paths as critical dependency paths. The value of m is user-defined. If you need to optimize the most critical path or evade detection, a smaller value may be more effective. If you need to perform a comprehensive analysis or optimization, a larger value may be better to cover more critical paths.
[0262] In this example, take m = 2, and the final key dependency paths are shown in Table 4:
[0263] Table 4 Key dependency paths and their strength weights
[0264]
[0265] S42. Inject perturbations on the identified key dependency paths to make the malware try to escape again;
[0266] In this example, for the key dependency path download_file→fetch_data, some meaningless branch logic and redundant data processing steps can be added to confuse the control flow and data flow; for the key dependency path download_file→decrypt_data, some intermediate variables or irrelevant function calls can be inserted to confuse the parameter passing path; for the key dependency path download_file→decrypt_data→save_file, some false calls can be added; for the key dependency path decrypt_data→download_file→fetch_data, some redundant encoding or markers can be added to the data to confuse the data flow. After perturbing the key dependency paths in the failed escaping malware, the malware can be tried to escape again, and if it fails again, the method of the present application can be used to analyze again to finally complete the escape;
[0267] S43. Record the key dependency paths that affect the effect of malware escape, and enhance the detection ability of the related detectors.
[0268] Embodiment Two
[0269] The present embodiment provides a malware escape behavior detection system based on high-order functions and dependency algebra, which is used to implement the malware escape behavior detection method based on high-order functions and dependency algebra described in embodiment one, and includes:
[0270] A program processing module is configured to receive the source code of the failed escaping malware, and based on the dependency algebra theory, analyze the dependency relationships between functions in the source code, and construct a related set, wherein the dependency relationships include data dependency, control dependency and parameter dependency;
[0271] An intra-process analysis module is configured to use high-order functions to construct function summaries to formalize the dependency relationships, calculate dependency strength weights to represent the criticality of the dependency paths, and construct a high-order function dependency matrix.
[0272] An interprocedural analysis module, configured to instantiate function summaries through interprocedural analysis, and update dependency strength weights based on the instantiated information, and update a high-order function dependency matrix;
[0273] The escape behavior detection module identifies the key dependency paths of the high-order dependency matrix based on the updated dependency strength weights, and injects perturbations on the identified key dependency paths, allowing malware that previously failed to escape to successfully escape. Finally, it records the key dependency paths that affect the malware's escape effect, enhancing the detection capabilities of related detectors.
[0274] Specifically, the above-mentioned program processing module, intra-process analysis module, inter-process analysis module and escape behavior detection module can be embedded in a computer processing system. The computer calls the above-mentioned modules to complete the delay optimization task based on the above-mentioned malware escape behavior detection method based on high-order functions and dependency algebra; the above-mentioned program processing module, intra-process analysis module, inter-process analysis module and escape behavior detection module can perform operations according to the specific steps given in the malware escape behavior detection method based on high-order functions and dependency algebra.
[0275] It should be noted that it should be understood that the division of the various modules of the above system is only a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. Moreover, these modules can all be implemented in the form of software called by processing elements; they can also all be implemented in the form of hardware; some modules can also be implemented in the form of processing elements calling software, and some modules can be implemented in the form of hardware. For example, the program processing module can be a separately established processing element, or it can be integrated into a certain chip of the above-mentioned device. In addition, it can also be stored in the memory of the above-mentioned device in the form of program code, and called and executed by a certain processing element of the above-mentioned device to perform the functions of the above-mentioned signal processing module. The implementation of other modules is similar. In addition, these modules can all or partly be integrated together, or they can be implemented independently. The processing element described here can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above modules can be completed by the hardware integrated logic circuit in the processor element or the instructions in the form of software.
[0276] For example, the above modules can be configured as one or more integrated circuits that implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more microprocessors (DSPs), or one or more field-programmable gate arrays (FPGAs). For another example, when a module is implemented by scheduling program code through a processing element, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. For another example, these modules can be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0277] Example 3:
[0278] The present invention provides a terminal device, including a memory, a processor, and a computer program stored in the memory and capable of running on the processor. The memory stores a computer program capable of running on the processor. When the processor loads and executes the computer program, the malware escape behavior detection method based on high-order functions and dependency algebra described in Example 1 is adopted.
[0279] It should be noted that the terminal device can be a computer device such as a desktop computer, a laptop computer or a cloud server, and the terminal device includes but is not limited to a processor and a memory. For example, the terminal device can also include input and output devices, network access devices and buses, etc.
[0280] Furthermore, the processor may be a central processing unit (CPU). Of course, depending on the actual usage, other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. may also be used. The general-purpose processor may be a microprocessor or any conventional processor, etc., and this application does not impose any restrictions on this.
[0281] Example 4:
[0282] The present invention provides a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform the malware escaping behavior detection method based on high-order functions and dependency algebra described in the first embodiment.
[0283] Among them, the computer program can be stored in a computer-readable medium, the computer program includes computer program code, the computer program code can be in the form of source code, object code, executable file or certain middleware, etc. The computer-readable medium includes any entity or device that can carry computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that computer-readable medium includes but is not limited to the above-mentioned components.
[0284] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0285] For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to the specific circumstances. When an element is referred to as being "assembled on", "installed on", "fixed on" or "set on" another element, it can be directly on the other element or there can be a central element. When an element is considered to be "connected" to another element, it can be directly connected to the other element or there can be a central element at the same time. The terms "vertical", "horizontal", "up", "down", "left", "right" and similar expressions used herein are for illustrative purposes only and are not intended to be the only embodiment.
[0286] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
[0287] Throughout this specification, references to terms such as "one embodiment," "example," or "specific example" indicate that a specific feature, structure, material, or characteristic described in conjunction with that embodiment or example is included in at least one embodiment or example of the present disclosure. In this specification, schematic representations of these terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.
Claims
1. A malware evasion behavior detection method based on high-order functions and dependency algebra, characterized by: The following steps are involved: Receiving source code of the malware that failed to escape, analyzing dependencies between functions in the source code based on dependency algebra theory, and constructing a set used in the analysis process, wherein the dependencies include data dependencies, control dependencies, and parameter dependencies; The dependency relationship generates a corresponding function summary through a high-order function, constructs a high-order function dependency matrix based on the function summary, and calculates the dependency strength weight: Specific steps to construct a function summary: When performing dependency analysis on a function A in a malicious code fragment, its data dependency variable set use Instead, the parameter depends on the set of variables use Instead, when adding these variables to the function summary of A, use The expression is replaced by The analysis result of calculating the dependency weight based on the function parameter corresponding to the function dependency set is: The expression represents a specific value or a function, which is instantiated when the corresponding argument is encountered. Expressions to obtain precise results; Based on the generated function summary , calculated to correspond to the matrix elements The row is the starting point of the dependency path, and the col is the dependency path strength weight of the end point of the dependency path. , and finally perfect the dependency matrix element e to form a high-order function dependency matrix; Specific steps for calculating dependency strength weights: Dependency intensity weight ,in is the data dependency strength weight, defined as: Assumptions 、 Function A and function B respectively: Indicates the number of times function A passes data to function B; Indicates the maximum number of times data is passed in a single path of the program; Indicates the depth of processing of data passed from function B to function A; Indicates the maximum depth of data passed through a single path in the program; Represents a weighting factor, which is used to adjust the influence of data processing depth in the calculation of data dependency intensity weight; is the parameter dependence intensity weight, defined as: Assumptions 、 Function A and function B respectively: Indicates the number of times function A calls function B; Indicates the maximum number of calls to a single path in the program; Indicates the number of times the parameters are passed from function A to function B; Indicates the number of times function A passes a function as a parameter to function B; Indicates the total number of parameters of all functions in the program, Represents a weighting factor, which is used to adjust the influence of parameter passing and function passing as parameter on the weight; By analyzing the instantiated function summary through inter-procedural analysis, the dependency strength weight is updated according to the instantiated function summary, and the high-order function dependency matrix is updated; According to the updated dependency strength weights, the key dependency paths of several high-order dependency matrices are identified. Perturbations are injected into each key dependency path to determine whether the malware that previously failed to escape successfully escapes. If it succeeds, this key dependency path is recorded and output.
2. The malware evasion behavior detection method based on higher-order functions and dependency algebra according to claim 1, characterized in that: Receive the source code of the malware that failed to escape, analyze the dependencies between functions in the source code based on dependency algebra theory, and construct a set used in the analysis process. The dependencies include data dependency, control dependency, and parameter dependency, as follows: (21) Statically analyze the functions, data flows, and control flows of the malware, and analyze the data dependencies, control dependencies, and parameter dependencies between functions in the source code; (22) Construct the set used in the analysis process, including the matrix element set , dependent type collection , the dependent type set of matrix element e , variable collection during function call , Function Summary .
3. The malware evasion behavior detection method based on higher-order functions and dependency algebra according to claim 2, characterized in that: Analyze the data dependency, control dependency, and parameter dependency between functions in the source code, as follows: (31) Data dependency analysis: Analyze the usage of function return values and the transfer path of non-parameter data between functions; (31.1) Check each function one by one to see if there is a function call inside it. If not, it means that this function does not have data or control dependencies on other functions. Jump to step (33.3). If so, continue to analyze the next step. (31.2) For each called function, check whether the current function uses the return value of the called function. If not, jump to the next step. If yes, it means that the current function data depends on the called function. For each case where the current function data depends on the called function, check whether it exists first. For the current function, Is the matrix element e of the called function, if any, then Add to If not in the set, generate a matrix element set And the Set as current function, Set as the called function, then Add to In the collection; (31.3) Check whether the current function passes its own generated data to the called function. If not, jump to the next step. If yes, it means that the called function depends on the current function in terms of data. For each case where the called function depends on the current function in terms of data, check whether it exists first. is the called function, Is the matrix element e of the current function, if any, then Add to If not in the set, generate a matrix element set And the Set as the called function, Set as the current function, then Add to In the collection; (32) Control dependency analysis: Analyze the impact of control structures on other function calls; (32.1) Check whether there is a control structure inside the current function. If not, it means that there is no control dependency of the current function to other functions. Jump to step (33). If there is, continue analysis. (32.2) Check whether the control structure determines the call, number of calls, or order of calls to other functions. If not, jump to the next step. If so, it means that the current function data depends on the called function. For each case where the current function data depends on the called function, check whether it exists first. For the current function, Is the matrix element e of the called function, if any, then Add to If not in the set, generate a matrix element set And the Set as current function, Set as the called function, then Add to In the collection; (33) Parameter dependency analysis: Analyze the source and transfer of function parameters; (33.1) Determine the parameters passed to the called function and check whether the execution of the called function depends on the passed parameters. If not, jump to step (33.3). If so, it indicates that the called function parameters depend on the current function. For each case where the called function parameters depend on the current function, check whether is the called function, Is the matrix element e of the current function, if any, then Add to If not in the set, generate a matrix element set And the Set as the called function, Set as the current function, then Add to In the collection; (33.2) Check whether the parameters used by the current function to call other functions are provided by other functions or affected by other functions. If so, it means that the current function parameters depend on the function that provides the parameters. For each case where the current function parameters depend on the function that provides the parameters, check whether there is For the current function, The matrix element e of the function that provides the parameters, if any, will be Add to If not in the set, generate a matrix element set And the Set as current function, Set to a function that provides the parameters, and then Add to In the collection; (33.3) Check whether the parameters of the current function are provided by other functions or affected by other functions. If so, it means that the current function parameters depend on the function that provides the parameters. For each case where the current function parameters depend on the function that provides the parameters, check whether there is For the current function, For the matrix element e of other functions, if any, Add to If not in the set, generate a matrix element set And the Set as current function, Set to other functions, then Add to In collection.
4. The malware evasion behavior detection method based on higher-order functions and dependency algebra according to claim 2, characterized in that: Construct the set used in the analysis process, including the matrix element set , dependent type collection , the dependent type set of matrix element e , variable collection during function call , Function Summary , as follows: Matrix element collection , is a four-tuple ,in They represent the rows and columns of the dependency matrix, i.e., the starting and ending functions of the dependency relationship in the escaped malicious code. The purpose of storing rows and columns in the matrix element set is to optimize storage. The sparse matrix storage structure is used to record each non-zero dependency. is the dependency strength weight, which is used to express the criticality of the dependency path; Dependent type collection , represents a set of dependent types, supporting multi-type superposition, where They are data dependency, control dependency, and parameter dependency; The set of dependent types of the matrix element e ; Variable collection during function call , which is in the form of a tuple ,in Represents a set of data-dependent variables, including all variables and related functions in the data dependency. Represents a set of parameter-dependent variables, including all variables and related functions that depend on the parameters. and Elements are stored in the form of a tuple <variable, related function>; Function Summary , which represents the function summary generated after analyzing the dependency relationship between entities, and its form is a tuple When a formal parameter or global variable is encountered, a Expression and add to In collection.
5. The malware evasion behavior detection method based on higher-order functions and dependency algebra according to claim 4, characterized in that: Through interprocedural analysis, the function summary is instantiated, the dependency strength weight is updated according to the instantiated function summary, and the high-order function dependency matrix is updated as follows: (51) Obtain the actual parameters at the function call point of the escaped malicious code; (52) Substitute the obtained actual parameters into the corresponding parameters of the called function summary to instantiate the function summary; (53) The summary analysis results of the instantiated function are passed back to the call point, and the dependency strength weight is updated based on the instantiated information. , and update the high-order function dependency matrix; The recalculated dependency strength weight is expressed as , Indicates the number of times function A actually passes data to function B by analyzing the instantiation behavior; Indicates the maximum number of times data is actually transferred in a single path of the program; Indicates the actual level depth of processing of data passed from B to A; Indicates the actual maximum depth of data passed through a single path in the program; Represents the influence factor, where the range of the influence factor is , used to reflect the influence of function output on other functions. If the output of function A is depended on by multiple functions, then Close to 1, if only used by function B, then Close to 0; ,v represents the weighting factor, which adjusts the influence of data processing depth in the calculation of data dependency intensity weight; Indicates the actual number of times function A calls function B, obtained by analyzing the instantiated behavior; Indicates the maximum number of actual calls in a single path in the program; Indicates the actual number of times the parameters are passed from function A to function B; Indicates the actual number of times function A passes a function as a parameter to function B; Indicates the total number of actual parameters of all functions in the program; represents the influence factor; and is the weighting factor: Used to adjust the influence of parameter passing and function passing as parameter on weight. It is used to adjust the influence of the influence factor in the weight calculation.
6. The malware evasion behavior detection method based on higher-order functions and dependency algebra according to claim 5, characterized in that: Based on the updated dependency strength weights, we identify the dependency path of the high-order dependency matrix. We inject perturbations into this dependency path to determine whether the malware that previously failed to escape has successfully escaped. If it has, we record this dependency path to enhance the detection capabilities of related detectors. The details are as follows: (61) Identify the key dependency paths in the high-order function dependency matrix as follows; Calculate the dependency strength weight of the direct dependency path ; Calculate the dependency strength weight of the indirect dependency path , the specific steps include: Define weighting coefficients , used to reflect the direct path Relative importance among all direct paths: Weighting coefficient If there is a direct dependency path in the program B, C, then it is determined that there must be an indirect dependency path ,therefore: Therefore, the dependency strength weight of each indirect dependency path in the program , calculated by the following formula: in , ...represents all direct dependency paths that form this indirect dependency path; Calculate all the and Then, sort them in descending order, select the first m direct dependency paths and indirect dependency paths and identify them as key dependency paths, where the value of m is customized; (62) Inject perturbations on multiple identified critical dependency paths to determine whether the malware can attempt to escape again; (63) If the escape is successful, the key dependency path that affects the malware’s escape effect is recorded to enhance the detector’s detection capability.
7. A malware escaping behavior detection system based on higher-order functions and dependency algebra, for implementing the malware escaping behavior detection method based on higher-order functions and dependency algebra as claimed in any one of claims 1 to 6, characterized in that: include: A program processing module is configured to receive source code of malware that failed to escape, analyze dependencies between functions in the source code based on dependency algebra theory, and construct a set used in the analysis process, wherein the dependencies include data dependencies, control dependencies, and parameter dependencies; The intra-process analysis module is used to generate corresponding function summaries from dependency relationships through high-order functions, construct a high-order function dependency matrix based on the function summaries, and calculate the dependency strength weights; An interprocedural analysis module is used to instantiate a function summary through interprocedural analysis, update a dependency strength weight according to the instantiated function summary, and update a high-order function dependency matrix; The escape behavior detection module is used to identify the key dependency paths of several high-order dependency matrices based on the updated dependency strength weights, inject disturbances into each key dependency path, and determine whether the malware that previously failed to escape has successfully escaped. If it has successfully escaped, the key dependency path is recorded and output.
8. A terminal device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that: When the processor loads and executes the computer program, the malware escaping behavior detection method based on high-order functions and dependency algebra according to any one of claims 1 to 6 is adopted.
9. A storage medium containing computer-executable instructions, characterized in that: When executed by a computer processor, the computer executable instructions are used to perform the malware evasion behavior detection method based on high-order functions and dependency algebra according to any one of claims 1 to 6.
Citation Information
Patent Citations
A system and a method for statically detecting malicious software in a container
CN110008703A
Method and system for identifying Android escape software based on function call and condition features
CN115329330A