Code injection attack analysis detection method and system

By constructing API feature stack frames and a list of floating memory pages, combined with stack backtracking and ETW HOOK techniques, abnormal behavior in the Windows operating system can be monitored in real time, solving the problem of detecting code injection attacks and achieving effective identification and protection against malicious code.

CN120781349BActive Publication Date: 2025-12-23INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510809068.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-12-23
Estimated Expiration
2045-06-17

AI Technical Summary

Technical Problem

Existing technologies are insufficient for effectively analyzing and detecting code injection attacks in Windows host environments, especially when faced with diverse, covert, and complex attack methods.

Method used

By constructing a list of API feature stack frames and a list of floating memory pages, and combining stack backtracking and ETW HOOK techniques, abnormal behavior in the Windows operating system can be monitored in real time. Memory page feature stack frames can be extracted and compared to identify code injection attacks.

Benefits of technology

It enables real-time detection of code injection attacks, effectively counters new injection techniques, and improves the ability to identify and protect against malicious code.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120781349B_ABST
    Figure CN120781349B_ABST
Patent Text Reader

Abstract

The application discloses a code injection attack analysis and detection method and system, and belongs to the technical field of computer network security, and the method comprises the steps of: reproducing a known code injection attack under a Windows monitoring environment, and constructing an API feature stack frame list; monitoring cross-process memory page allocation of a target program, and constructing a floating memory page list; based on the API feature stack frame list and the floating memory page list, performing code injection attack analysis and detection on the target program; and using ETW log monitoring technology to realize asynchronous monitoring of memory page permission modification operations, and regarding abnormal permission modification behavior on the floating memory page as illegal behavior. The application can realize real-time monitoring of abnormal behavior detection code injection attack behavior in a Windows operating system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer network security, and particularly relates to a code injection attack analysis and detection method and system. BACKGROUND

[0002] Windows host security refers to a comprehensive protection system for protecting the software and hardware of servers, terminals and other computing devices and data from attacks or leaks through technical and management measures. With the evolution of computer system security protection technology, code injection attacks have become one of the most threatening attack methods in the Windows host environment. Attackers can bypass traditional security protection mechanisms (such as firewalls and signature scanning) by implanting malicious code into the memory space of a legitimate process, and achieve malicious purposes such as privilege escalation and data theft. Currently, code injection attack technology is evolving towards diversification, concealment and complexity, and has become a common attack method used by advanced persistent threat organizations. Due to the high danger of code injection attack technology, how to effectively analyze and detect code injection attack behavior is a problem to be solved. SUMMARY

[0003] In view of the above problems, the present application provides a code injection attack analysis and detection method and system, which can monitor and detect code injection attack behavior in real time in the Windows operating system.

[0004] To achieve the above purpose, the specific technical scheme adopted by the present application is as follows:

[0005] A code injection attack analysis and detection method, the method comprising:

[0006] reproducing known code injection attacks in a Windows monitoring environment, and constructing an API feature stack frame list, the API feature stack frame list comprising: a feature stack frame of a benign API function and a feature stack frame of an abnormal API function;

[0007] monitoring the cross-process memory page allocation of the target program, and constructing a floating memory page list;

[0008] obtaining the memory page corresponding to the abnormal error information triggering the target program, and extracting the memory page feature stack frame if the memory page is located in the floating memory page list;

[0009] iterating and comparing the memory page feature stack frame in the API feature stack frame list to obtain the code injection attack detection result of the target program.

[0010] Further, the API feature stack frame list is constructed by reproducing known code injection attacks in a Windows monitoring environment, comprising:

[0011] Reproduce known code injection attacks under the Windows monitoring environment, and build API return address content feature list by capturing binary code features at the return address of the thread execution function;

[0012] For the API return address content feature list, use stack backtracking technology to backtrack the corresponding function stack frame and return address information upwards to build the API stack frame feature list.

[0013] Further, the floating memory page list is constructed by monitoring the cross-process memory page allocation of the target program, comprising:

[0014] Trigger the monitoring logic when the process handle acquisition operation occurs between non-parent and child processes, and obtain the corresponding memory page allocation function and memory permission modification function;

[0015] Use ETW HOOK technology to hijack all memory permission query behaviors of the memory permission query function on the floating memory page, and return the permission when the memory page is allocated;

[0016] Use ETW HOOK technology to monitor and hijack the memory page allocation function, and remove the permission when the memory page is allocated in the case that the corresponding memory page object of the memory operation exists the permission when the memory page is allocated, and record the information related to the memory page object;

[0017] According to the information related to the memory page object, a floating memory page list is constructed.

[0018] Further, the memory page corresponding to the exception error information of the target program is obtained, comprising:

[0019] Register a VEH exception handling function with the operating system, which is used to monitor illegal access behaviors of all memory pages;

[0020] When a memory page is triggered to report an exception error due to insufficient permissions, execute the VEH exception handling function to obtain exception-related information; wherein the exception-related information includes: memory address triggering the exception and event code triggering the exception;

[0021] Obtain the memory page corresponding to the exception error information of the target program through the event code triggering the exception.

[0022] Further, it is judged whether the memory page is located in the floating memory page list, comprising:

[0023] Based on the memory address triggering the exception, traverse in the floating memory page list to determine whether the memory page is located in the floating memory page list.

[0024] Further, the memory page feature stack frame is extracted, comprising:

[0025] applying an API tracing algorithm to the memory page, and in the process of analyzing the execution source of the memory page in combination with stack backtracking technology, performing CRC characteristic value calculation on the multi-byte content of the location of the return address in each layer of stack space;

[0026] obtaining a memory page characteristic stack frame based on the CRC characteristic value.

[0027] Further, the memory page characteristic stack frame is compared and traversed in the API characteristic stack frame list to obtain a code injection attack analysis detection result of the target program, including:

[0028] If the comparison result is a characteristic stack frame of a benign API function, it is considered as normal business;

[0029] If it is a characteristic stack frame of an abnormal API function, it is considered as known abnormal injection behavior;

[0030] If the API characteristic stack frame list does not record the memory page characteristic stack frame, it is considered as a new type of abnormal injection behavior.

[0031] Further, in the case of considering known abnormal injection behavior, the method further comprises:

[0032] Implementing asynchronous monitoring of memory page permission modification operations by using ETW log monitoring technology, and considering abnormal permission modification behavior of a floating memory page as illegal behavior.

[0033] A code injection attack analysis detection system, the system comprising:

[0034] An API characteristic stack frame list construction module for constructing an API characteristic stack frame list by reproducing known code injection attacks in a Windows monitoring environment, the API characteristic stack frame list including: characteristic stack frames of benign API functions and characteristic stack frames of abnormal API functions;

[0035] A behavior monitoring module for constructing a floating memory page list by monitoring cross-process memory page allocation of a target program;

[0036] An execution detection module for obtaining a memory page corresponding to abnormal error information triggering a target program, and extracting a memory page characteristic stack frame in the case that the memory page is located in the floating memory page list; and comparing and traversing the memory page characteristic stack frame in the API characteristic stack frame list to obtain a code injection attack detection result of the target program.

[0037] An electronic device, comprising: a processor and a memory storing computer program instructions; the processor executes the computer program instructions to implement the code injection attack analysis detection method of any one of the preceding claims.

[0038] Compared with the prior art, the present application has at least the following beneficial effects.

[0039] The present application researches the technical principle of the process injection attack analysis and detection method in the Windows environment, summarizes the composition of the basic injection chain in the injection technology, and on this basis, proposes a floating memory page execution behavior monitoring method and an API tracing method based on stack backtracking. The present application integrates the two methods, designs and implements a kernel mode driver prototype tool, and aims to realize real-time process injection behavior monitoring. Since the present application is a whitelist form of monitoring scheme, it can effectively cope with the emergence of new injection methods. BRIEF DESCRIPTION OF DRAWINGS

[0040] Figure 1 is the overall flowchart of the method.

[0041] Figure 2 is the flowchart of the floating memory page analysis and detection algorithm. DETAILED DESCRIPTION

[0042] In order to enable the persons skilled in the art to better understand the technical solutions in the embodiments of the present application, and enable the purposes, features and advantages of the present application to be more apparent and easy to understand, the present application is further described in detail below with reference to the drawings and embodiments.

[0043] The code injection attack analysis and detection method of the present application, as shown in Figure 1 , comprises the following steps 100 to 400.

[0044] Step 100: Reproduce known code injection attacks in the Windows monitoring environment to build an API feature stack frame list.

[0045] The present application reproduces the attack method in the Windows monitoring environment under the condition of no external interference, observes and records the system API calling behavior and function call stack frame during the reproduction process, captures the binary code features at the return address of the thread execution function, and builds an API return address content feature list. Then, the stack backtracking technology is used to continuously backtrack the API function stack frame and return address information upwards, and an API stack frame feature list is built.

[0046] Step 200: Monitor the cross-process memory page allocation of the target program to build a floating memory page list.

[0047] The application monitors inter-process operation behavior in real time through kernel callback technology, and injects monitoring logic code into suspicious processes; monitors cross-process memory page allocation through kernel monitoring technology, and builds a floating memory page list for subsequent memory page execution behavior monitoring.

[0048] The construction of the floating memory page list mainly applies kernel monitoring technology. The kernel monitoring technology includes kernel callback technology and ETW HOOK technology. The application first uses kernel callback technology to monitor inter-process operations, and triggers monitoring logic when inter-process process handle acquisition operations occur; then uses ETW HOOK technology to hijack and monitor memory permission query functions, hijacks all memory permission query behaviors of floating memory pages, and returns memory page allocation permissions; finally, uses ETW HOOK technology to monitor and hijack memory page allocation functions and memory permission modification functions, analyzes memory page objects of memory operations, removes memory executable permissions if the memory page has executable permissions, and records detailed information of the memory page to build a floating memory page list. In the above kernel monitoring process, the application also applies a parent-child process detection algorithm to monitor only the memory page operation between non-parent-child processes, and filters the memory operation behavior between parent-child processes.

[0049] In a preferred embodiment, the construction process of the floating memory page list includes the following steps 210 to 240.

[0050] Step 210: Trigger monitoring logic when inter-process process handle acquisition operations occur between non-parent-child processes, and obtain corresponding memory page allocation functions and memory permission modification functions.

[0051] Step 220: Use ETW HOOK technology to hijack all memory permission query behaviors of the memory permission query function to floating memory pages, and return memory page allocation permissions.

[0052] Step 230: Use ETW HOOK technology to monitor and hijack the memory page allocation function, and remove the memory page allocation permission if the corresponding memory page object of the memory operation has the memory page allocation permission, and record information related to the memory page object.

[0053] Step 240: According to the information related to the memory page object, a floating memory page list is constructed.

[0054] Step 300: Based on the API feature stack frame list and the floating memory page list, code injection attack analysis and detection of the target program is performed.

[0055] The step first responds to the memory page permission abnormal error through the abnormal behavior monitoring technology, compares with the floating memory page captured by the kernel, and hooks the floating memory page at the memory page level; then uses the stack backtracking technology to extract the memory page execution function stack frame structure and compare with the API feature stack frame. If it is the feature stack frame of a benign API function, it is considered normal business; if it is the feature stack frame of an abnormal API function, it is considered known abnormal injection behavior; if the API feature stack frame list does not record the API function, it is considered a new injection behavior.

[0056] The memory page abnormal execution behavior is monitored in the following aspects:

[0057] 1) The kernel callback mechanism is used to monitor the operation behavior between processes, and the kernel-level injection technology is used to inject the monitoring module into the target process, so as to realize real-time monitoring and behavior analysis of the running state.

[0058] 2) The monitoring module registers a VEH exception handling function to the operating system to monitor illegal access behavior of all memory pages. When a memory page is triggered by insufficient permissions, the registered VEH exception handling function in the foregoing will be executed, and the exception handling function will receive exception related information, including the memory address triggering the exception and the event code triggering the exception. Whether it is a memory page permission exception is determined by the event code; then, it is determined whether the memory page triggering the exception is located in the floating memory page list constructed in the foregoing. If the address is located in the floating memory page and is a memory permission exception, the execution control flow of the memory page will be hijacked by using the memory page hook technology, and the monitoring code will be inserted. Then, the exception handling function is normally exited. The control flow is transferred to the monitoring code for execution, so as to realize control and execution monitoring of the memory page.

[0059] 3) The API tracing algorithm is applied to the memory page, and the stack backtracking technology is used to analyze the execution source. At the same time, the CRC characteristic value of the multi-byte content of the return address in each layer of stack space is calculated to generate the feature information used for subsequent API function stack frame comparison.

[0060] 4) The API function triggered by the injection behavior is identified by comparing the stack frame information extracted by the API tracing algorithm with the API stack frame features collected in advance; and whether the API function has malicious properties is determined in combination with the behavior characteristics of the API function.

[0061] In a preferred embodiment, as shown in Figure 2 the code injection attack analysis and detection of the target program of the present application includes the following steps 310 to 340.

[0062] Step 310: register an exception handling function, which will capture all exceptions of all processes and threads of the target process for the monitored target process.

[0063] Step 320: according to the captured exception information, read the memory address triggering the exception, and judge whether the memory page triggering the exception is located in the floating memory page list constructed in the foregoing, that is, whether the floating memory page region causes the exception, if located in the floating memory page, then the next step is performed on the exception, otherwise, the exception is directly released without processing.

[0064] Step 330: use a self-defined instrumentation method to instrument the floating memory page, and the specific position of the instrumentation is provided by the exception information. The stack backtracking algorithm is executed in the instrumentation code, the source of the execution control flow is tracked, and the stack frame features are recorded.

[0065] Step 340: according to the stack frame features, judge whether there is suspicious behavior, if the execution control flow stack frame indicates that the execution source is suspicious, then trigger the exception termination module to terminate the thread execution, if it is not a suspicious source, then jump back to the original code execution position to restore the normal operation of the program.

[0066] Step 400: use the ETW log monitoring technology to realize asynchronous monitoring of the memory page permission modification operation, and regard the exception permission modification behavior of the floating memory page as illegal behavior.

[0067] The application utilizes the ETW log monitoring technology provided by the Windows kernel to realize real-time monitoring of the inter-process memory page permission modification operation. Through the monitoring mechanism at the kernel level, any illegal modification of the memory page permission by the process can be accurately detected.

[0068] Finally, it should be noted that the above implementation cases are only used to illustrate the technical solutions of the application and are not limited. Although the application is described in detail using examples, those skilled in the art should understand that the technical solutions of the application can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the application, and they should be covered in the scope of the claims of the application.

Claims

1. A code injection attack analysis detection method, characterized by, The method comprises: reproducing a known code injection attack in a Windows monitoring environment, and constructing an API feature stack frame list comprising feature stack frames of benign API functions and feature stack frames of abnormal API functions; constructing a floating memory page list by monitoring cross-process memory page allocation of the target program; obtaining a memory page corresponding to the exception error information triggered by the target program, and extracting a memory page feature stack frame when the memory page is located in the floating memory page list; performing traversal comparison of the memory page feature stack frame in the API feature stack frame list to obtain a code injection attack detection result of the target program; wherein the reproducing a known code injection attack in a Windows monitoring environment and constructing an API feature stack frame list comprises: reproducing a known code injection attack in a Windows monitoring environment, and constructing an API return address content feature list by capturing binary code features at return addresses of thread execution functions; for the API return address content feature list, using stack backtracking technology to backtrack corresponding function stack frames and return address information upwards to construct an API stack frame feature list; the constructing a floating memory page list by monitoring cross-process memory page allocation of the target program comprises: triggering monitoring logic when a process handle acquisition operation occurs between non-parent and child processes, and obtaining a memory page allocation function and a memory permission modification function; using ETW HOOK technology to hijack all memory permission query behaviors of the memory permission query function on the floating memory page, and returning the permission when the memory page is allocated; using ETW HOOK technology to monitor and hijack the memory page allocation function, and removing the permission when the memory page is allocated in the case that the memory page object of the corresponding memory operation has the permission when the memory page is allocated, and recording information related to the memory page object; constructing a floating memory page list according to the information related to the memory page object; the extracting a memory page feature stack frame comprises: applying an API tracing algorithm to the memory page, and in the process of analyzing the execution source of the memory page in combination with stack backtracking technology, performing CRC characteristic value calculation on the multi-byte content at the return address position in each layer of stack space; based on the CRC characteristic value, obtaining a memory page feature stack frame.

2. The method of claim 1, wherein, obtaining a memory page corresponding to the exception error information triggered by the target program comprises: registering a VEH exception handling function with the operating system, the VEH exception handling function being used to monitor illegal access behaviors of all memory pages; when a memory page is triggered to report an exception error due to insufficient permissions, executing the VEH exception handling function to obtain exception related information; wherein the exception related information comprises a memory address triggering an exception and an event code triggering an exception; obtaining a memory page corresponding to the exception error information triggered by the target program through the event code triggering an exception.

3. The method of claim 2, wherein, judging whether the memory page is located in the floating memory page list comprises: based on the memory address triggering an exception, performing traversal in the floating memory page list to determine whether the memory page is located in the floating memory page list.

4. The method of claim 1, wherein, The code injection attack analysis detection result of the target program is obtained by performing the traversal comparison of the memory page feature stack frame in the API feature stack frame list, including: If the comparison result is the feature stack frame of a benign API function, it is considered as normal business; If it is the feature stack frame of an abnormal API function, it is considered as known abnormal injection behavior; If the API feature stack frame list does not record the memory page feature stack frame, it is considered as new abnormal injection behavior.

5. The method of claim 4, wherein, In the case of being considered as known abnormal injection behavior, the method further includes: The ETW log monitoring technology is used to realize asynchronous monitoring of memory page permission modification operations, and the abnormal permission modification behavior of the floating memory page is considered as illegal behavior.

6. A code injection attack analysis detection system characterized by, The system includes: An API feature stack frame list construction module is configured to construct an API feature stack frame list by reproducing known code injection attacks in a Windows monitoring environment, and the API feature stack frame list includes feature stack frames of benign API functions and feature stack frames of abnormal API functions; A behavior monitoring module is configured to construct a floating memory page list by monitoring the cross-process memory page allocation of the target program; An execution detection module is configured to obtain a memory page corresponding to abnormal error information triggering the target program, and extract a memory page feature stack frame when the memory page is located in the floating memory page list; and perform traversal comparison of the memory page feature stack frame in the API feature stack frame list to obtain a code injection attack detection result of the target program. The API feature stack frame list is constructed by reproducing known code injection attacks in a Windows monitoring environment, including: The known code injection attacks are reproduced in the Windows monitoring environment, and the API return address content feature list is constructed by capturing the binary code features at the return address of the thread execution function. For the API return address content feature list, the stack backtracking technology is used to backtrack the corresponding function stack frame and return address information upwards to construct the API stack frame feature list. The floating memory page list is constructed by monitoring the cross-process memory page allocation of the target program, including: The monitoring logic is triggered when the process handle acquisition operation occurs between non-parent and child processes, and the corresponding memory page allocation function and memory permission modification function are obtained; The ETW HOOK technology is used to hijack all memory permission query behaviors of the memory permission query function to the floating memory page, and the memory permission at the time of memory page allocation is returned; The ETW HOOK technology is used to monitor and hijack the memory page allocation function, and in the case that the memory page object of the corresponding memory operation has the memory permission at the time of memory page allocation, the memory permission at the time of memory page allocation is removed, and the information related to the memory page object is recorded; The floating memory page list is constructed according to the information related to the memory page object. The memory page feature stack frame is extracted, including: The API tracing algorithm is applied to the memory page, and in the process of analyzing the execution source of the memory page in combination with the stack backtracking technology, the CRC characteristic value of the multi-byte content at the return address position in each layer of stack space is calculated; The memory page feature stack frame is obtained based on the CRC characteristic value.

7. An electronic device, comprising: The electronic device comprises a processor and a memory storing computer program instructions; the processor executes the computer program instructions to implement the code injection attack analysis and detection method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Code injection attack detection mode based on memory forensics technology

    CN115270119A

  • Real-time shellcode detection and prevention

    US20240346145A1