Instrumentation-based Behavior Monitoring Method and System

By inserting preset instrumentation instructions into the host detection module and switching to ROOT mode, the problem of abnormalities in the virtual machine environment affecting behavior monitoring is solved, and a stable behavior monitoring function is realized.

CN112463288BActive Publication Date: 2025-06-24BEIJING QIHOOD TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201910849585.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-09-09
Publication Date
2025-06-24
Estimated Expiration
2039-09-09

AI Technical Summary

Technical Problem

When an abnormality occurs in the virtual machine environment, the existing virtual machine-based behavior monitoring method will cause the security detection module to fail to operate normally, affecting the behavior monitoring function.

Method used

The monitoring list generated by the virtual machine detection module is obtained through the host detection module, and preset instrumentation instructions are inserted for the address to be monitored, and switch to ROOT mode during the execution of the instrumentation instruction to query relevant data information, and perform detection tasks to realize behavior monitoring.

Benefits of technology

This enables the instrumentation operation and behavior monitoring functions to be implemented by the host detection module, reducing the impact of virtual machine environment abnormalities on behavior monitoring and improving security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112463288B_ABST
    Figure CN112463288B_ABST
Patent Text Reader

Abstract

The present invention discloses a behavior monitoring method and system based on instrumentation. Among them, the method includes: a host detection module obtains a monitoring list generated by a virtual machine detection module through a first virtual machine exit event triggered by a virtual machine call instruction; for each monitored address included in the monitoring list, determines the memory location corresponding to the monitored address, and inserts a preset instrumentation instruction into the memory location; when the host detection module detects a second virtual machine exit event triggered by the execution process of the preset instrumentation instruction, queries data information related to the execution process of the preset instrumentation instruction according to the second virtual machine exit event; performs a detection task according to the queried data information to achieve behavior monitoring. This method enables the instrumentation operation and the behavior monitoring function to be implemented by the host detection module, so that when the virtual machine environment is abnormal due to various external reasons, the impact caused by the abnormality of the virtual machine environment can be minimized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular, to a behavior monitoring method and system based on instrumentation. Background Art

[0002] A virtual machine (VM) refers to a complete computer system that is software-simulated with complete hardware system functions and runs in a completely isolated environment. In the prior art, it is possible to use a virtual machine to detect malicious behaviors and thus detect threat sources. For example, a sandbox environment can be constructed through virtual machine technology for security detection. Additionally, during the process of security detection, it is usually necessary to perform instrumentation operations on specific instructions to monitor the execution process of these instructions.

[0003] However, the inventors found that the above-mentioned methods in the prior art have at least the following drawbacks during the implementation of the present invention: In the behavior monitoring method based on a virtual machine, the behavior monitoring function can only be realized through a security detection module set inside the virtual machine. Once the virtual machine environment becomes abnormal due to various external reasons, the security detection module will be unable to operate normally, thereby affecting the behavior monitoring function. Summary of the Invention

[0004] In view of the above problems, the present invention is proposed to provide a behavior monitoring method and system based on instrumentation that can overcome or at least partially solve the above problems.

[0005] According to one aspect of the present invention, there is provided a behavior monitoring method based on instrumentation, including:

[0006] The host detection module obtains a monitoring list generated by the virtual machine detection module through a first virtual machine exit event triggered by a virtual machine call instruction;

[0007] For each monitored address included in the monitoring list, determine the memory location corresponding to the monitored address, and insert a preset instrumentation instruction into the memory location;

[0008] When the host detection module detects a second virtual machine exit event triggered by the execution process of the preset instrumentation instruction, query data information related to the execution process of the preset instrumentation instruction according to the second virtual machine exit event;

[0009] Execute a detection task according to the queried data information to implement behavior monitoring.

[0010] According to another aspect of the present invention, there is provided a behavior monitoring system based on instrumentation, including:

[0011] A host detection module and a virtual machine detection module; wherein, the host detection module further includes:

[0012] A first exit unit, adapted to obtain a monitoring list generated by the virtual machine detection module through a first virtual machine exit event triggered by a virtual machine call instruction;

[0013] An instrumentation unit, adapted to respectively determine a memory location corresponding to each monitored address included in the monitoring list, and insert a preset instrumentation instruction into the memory location;

[0014] A second exit unit, adapted to query data information related to the execution process of the preset instrumentation instruction according to the second virtual machine exit event when the host detection module detects a second virtual machine exit event triggered by the execution process of the preset instrumentation instruction;

[0015] A monitoring unit, adapted to execute a detection task according to the queried data information to implement behavior monitoring.

[0016] According to another aspect of the present invention, there is provided an electronic device, including: a processor, a memory, a communication interface, and a communication bus, and the processor, the memory, and the communication interface complete communication with each other through the communication bus;

[0017] The memory is used to store at least one executable instruction, and the executable instruction causes the processor to execute the operations corresponding to the above-mentioned instrumentation-based behavior monitoring method.

[0018] According to still another aspect of the present invention, there is provided a computer storage medium, in which at least one executable instruction is stored, and the executable instruction causes the processor to execute the operations corresponding to the above-mentioned instrumentation-based behavior monitoring method.

[0019] According to the instrumentation-based behavior monitoring method and system disclosed in the present invention, the host detection module can obtain the monitoring list generated by the virtual machine detection module, and perform instrumentation operations according to the monitored addresses included therein and their corresponding memory locations; correspondingly, when the host detection module detects a virtual machine exit event triggered by the execution process of the preset instrumentation instruction, it switches to the ROOT mode and queries the data information related to the execution process of the preset instrumentation instruction, thereby executing the detection task and implementing behavior monitoring. It can be seen that through the method in the present invention, the instrumentation operation and the behavior monitoring function can be implemented by the host detection module, so that when the virtual machine environment is abnormal due to various external reasons, the impact caused by the virtual machine environment abnormality can be minimized. In addition, since the core code for analyzing behavior monitoring is located in the host detection module, the security risks caused by attacks on the virtual machine environment can be prevented, thereby improving security.

[0020] The above description is only an overview of the technical solution of the present invention. In order to understand the technical means of the present invention more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present invention more obvious and understandable, the specific embodiments of the present invention are specifically exemplified below. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0022] Figure 1 shows a schematic flowchart of a behavior monitoring method based on instrumentation according to an embodiment of the present invention;

[0023] Figure 2 shows a schematic flowchart of a behavior monitoring method based on instrumentation according to another embodiment of the present invention;

[0024] Figure 3 shows a system structure diagram of a behavior monitoring system based on instrumentation provided by another embodiment of the present invention;

[0025] Figure 4 shows a schematic structural diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0026] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.

[0027] Figure 1 shows a schematic flowchart of a threat detection method based on a virtual machine according to an embodiment of the present invention. As Figure 1 shown, the method includes:

[0028] Step S110: The host detection module obtains a monitoring list generated by the virtual machine detection module through a first virtual machine exit event triggered by a virtual machine call instruction.

[0029] Specifically, after the virtual machine detection module generates a monitoring list, it triggers a first virtual machine exit event by executing a virtual machine call instruction. Correspondingly, the host detection module is switched to the root mode, so that it can obtain and change the status information such as the register values of the virtual machine processor, and then obtain the monitoring list generated by the virtual machine detection module.

[0030] Step S120: For each monitored address included in the monitoring list, determine the memory location corresponding to the monitored address, and insert a preset instrumentation instruction into the memory location.

[0031] Among them, the monitoring list usually contains multiple monitored addresses, and each monitored address can be a guest linear address (the guest is the client implemented through the virtual machine and is controlled by the host). To perform the instrumentation operation, it is necessary to first determine the memory location corresponding to the monitored address and insert a preset instrumentation instruction into the memory location. Among them, the preset instrumentation instruction can be a virtual machine privilege instruction and / or an interrupt instruction.

[0032] Step S130: When the host detection module detects a second virtual machine exit event triggered by the execution process of the preset instrumentation instruction, query the data information related to the execution process of the preset instrumentation instruction according to the second virtual machine exit event.

[0033] Among them, during the execution process of the preset instrumentation instruction, a second virtual machine exit event will be triggered, causing the host detection module to switch to the root mode again, so that it can obtain and change the status information such as the register values of the virtual machine processor, and then query the data information related to the execution process of the preset instrumentation instruction.

[0034] Step S140: Execute a detection task according to the queried data information to implement behavior monitoring.

[0035] Specifically, according to the queried data information, it is possible to obtain information related to the execution environment of the preset instrumentation instruction, so as to facilitate monitoring of related behaviors according to the execution environment.

[0036] It can be seen that through the method in the present invention, the instrumentation operation and the behavior monitoring function can be implemented by the host detection module, so that when the virtual machine environment is abnormal due to various external reasons, the impact caused by the virtual machine environment abnormality is minimized. In addition, since the core code for analyzing behavior monitoring is located in the host detection module, it is possible to prevent security risks caused by attacks on the virtual machine environment, thereby improving security.

[0037] For ease of understanding, the following uses a specific example to describe in detail the specific implementation details of the above method in the present invention. Among them, the method in the present invention runs in a distributed cluster server sandbox and is used to perform real-time advanced threat detection tasks on target sample files. Specifically, the present invention is implemented based on the virtual machine monitor (VMM, Hypervisor) of the full virtualization mode virtual machine management software in the host operating system (Host OS, Dom-0, Linux) kernel on the server side. Among them, the server host runs in a virtual machine sandbox isolation environment to execute the target sample file task. At the same time, the client driver module (belonging to the virtual machine detection module) loaded in the virtual machine operating system (also called the guest operating system, Guest OS, Dom-U, Windows) kernel and the global detection module (belonging to the host detection module) loaded in the host operating system (Dom-0) kernel cooperate to achieve real-time monitoring of the activity behaviors of the target task process, and to achieve real-time collection and recording of task activity behaviors and abnormal events. Among them, the behavior detection in the present invention includes, but is not limited to, tasks of sensitive and abnormal behaviors such as vulnerability exploitation, kernel privilege escalation, highly suspicious environmental damage, information theft, persistence, concealment, propagation, and infection. The method in this embodiment is mainly implemented by the global detection module located in the host operating system kernel and the client driver module located in the virtual machine operating system kernel. Among them, the global detection module is also called the host detection module and is usually one; the client driver module is also called the virtual machine detection module and is usually multiple (located in different virtual machines respectively), so as to achieve a "one-to-many" management relationship.

[0038] Among them, the global detection module is implemented based on the virtual machine monitor component of the full virtualization mode virtual machine management software in the host operating system kernel. The code of the global detection module is integrated into the virtual machine management software source code. The modified and recompiled virtual machine management software module is installed in the server-side Linux operating system and is loaded and initialized synchronously with the host operating system kernel when the server is powered on. When the power-on initialization is completed, the global detection module will reside in the host operating system kernel and is not affected by operations such as virtual machine instance creation, startup, shutdown, and destruction. By hooking the virtual machine physical memory management and responding to the virtual machine control interface, when the virtual machine management software starts and shuts down the virtual machine, the global detection module initializes and associates the detection point data structure and object of a specific virtual machine. The global detection module implements the detection function according to the pre-information data provided by the client driver module, and the pre-information data is collected by the client driver module in the guest operating system. In addition, there are auxiliary modules such as a log processing module, a virtual machine scheduling module, and a task control module in the host operating system environment to assist the global detection module in implementing the detection function.

[0039] The client driver module is located in the virtual machine operating system kernel and is a kernel-mode driver loaded in the target guest operating system kernel. The client driver module is loaded and initialized after the guest operating system starts, and its life cycle ends when the virtual machine operating system shuts down. When the loading and initialization are completed, the client driver module collects pre-information data in the guest operating system according to the configuration information provided by the auxiliary component, including but not limited to operating system version information, key data structure definitions and member offsets, key system data or object addresses, key system function addresses, specific monitoring code block addresses, etc. In addition, the virtual machine detection module can also execute some detection functions that cannot be implemented in the external virtual machine manager component, including but not limited to various system event notifications, filter drivers, etc. The detection functions implemented inside the virtual machine realize the output of detection information through the instant communication between the global detection module and the client driver module.

[0040] Figure 2 FIG. shows a schematic diagram of a behavior monitoring method based on instrumentation provided by another embodiment of the present invention. As Figure 2 shown, the method includes the following steps:

[0041] Step S200: The virtual machine detection module obtains a list of key system function addresses and a list of preset monitoring code block addresses, and generates a monitoring list according to the list of key system function addresses and the list of preset monitoring code block addresses.

[0042] Specifically, when the virtual machine environment starts up and is completed, the virtual machine detection module is loaded and initialized. The virtual machine detection module is responsible for operations such as collecting pre-data information. According to the operating system version and kernel module version information, a list of key system function addresses and a list of specific monitoring code block addresses are obtained. Key system functions include but are not limited to: key functions in the system service descriptor table (SSDT), important exported functions of kernel modules, and important unexported functions that need to be located by instruction matching calculation. A specific monitoring code block refers to: a code block with historical vulnerabilities in the system module, which monitors when an instruction is executed and makes conditional judgments according to register and memory contexts, and can accurately identify the corresponding exploitation behavior for historical vulnerabilities. Accordingly, a monitoring list is generated according to the list of key system function addresses and the list of preset monitoring code block addresses. In addition, the virtual machine detection module can further determine the initially started target process, the process started by the target process or injected by the target process, and the process that loads the file released by the target process as the processes to be monitored, and thus add the processes to be monitored to the monitoring list. And, the monitoring list can be dynamically updated, and the updated monitoring list is transmitted to the host detection module through the instant communication function.

[0043] In addition, the virtual machine detection module can also store the instructions at the location where each address in the critical system function address list and the specific monitoring code block address list is located according to a preset policy and initialize the trampoline interval. This trampoline interval (i.e., jump interval) is used to jump back to the original function for execution. Of course, the operation of initializing the trampoline interval can also be implemented by the host detection module, and the present invention does not limit this.

[0044] Step S210: The host detection module obtains the monitoring list generated by the virtual machine detection module through the first virtual machine exit event triggered by the virtual machine call instruction.

[0045] Specifically, after the virtual machine detection module generates the monitoring list, it triggers the first virtual machine exit event by executing the virtual machine call instruction. Correspondingly, the host detection module is switched to the root mode, so that it can obtain and change the status information such as the register values of the virtual machine processor, and then obtain the monitoring list generated by the virtual machine detection module. Among them, the instant communication function between the virtual machine detection module and the host detection module is realized by triggering the virtual machine exit event. The specific implementation details of the instant communication function will be described in detail later and will not be elaborated here.

[0046] Among them, the host detection module is located in the virtual machine monitor component of the host operating system kernel, and the virtual machine detection module is located in the guest machine implemented by the virtual machine; one host detection module corresponds to one or more virtual machine detection modules.

[0047] Step S220: For each monitored address included in the monitoring list, determine the memory location corresponding to the monitored address and insert a preset staking instruction into the memory location.

[0048] Specifically, for each monitored address included in the monitoring list, the memory page where the monitored address is located is determined as the target memory page, the offset position corresponding to the monitored address is determined in the target memory page, and the offset position is determined as the memory location corresponding to the monitored address. In addition, for the convenience of data recovery, when inserting a preset staking instruction into the memory location, the original instruction corresponding to the memory location is further determined, and the original instruction is stored in association with the memory location; among them, when the monitoring operation is completed, data recovery is performed according to the original instruction.

[0049] During specific implementation, the host detection module allocates and initializes a monitoring address information array according to the address list of the addresses to be monitored in the monitoring list. This initialized monitoring address information array is used to store each address to be monitored in the form of an array. Among them, each address to be monitored can be a guest linear address (GLA). The host detection module inserts specific instructions, such as virtualization-related privilege instructions or interrupt instructions, at the offset position corresponding to the memory page where each guest linear address in the monitoring address information array is located according to a preset policy. In addition, the original instruction that is overwritten is stored before inserting the new instruction for data recovery when the monitoring function is turned off.

[0050] Step S230: When the host detection module detects a second virtual machine exit event triggered by the execution process of a preset instrumentation instruction, query the data information related to the execution process of the preset instrumentation instruction according to the second virtual machine exit event.

[0051] Specifically, when a certain thread or process of the guest operating system executes the new instrumented instruction, the logical processor immediately triggers a VM-EXIT event for the corresponding reason to return to the ROOT mode for execution. Correspondingly, the processing function in the host detection module for processing VM-EXIT events obtains the relevant information of the execution environment at that time according to the reason for triggering the VM-EXIT and the value of the instruction pointer register, searches for the node corresponding to the address in the monitoring address information array, and then determines the data information related to the execution process of the preset instrumentation instruction.

[0052] Step S240: Execute a detection task according to the queried data information to implement behavior monitoring.

[0053] Specifically, according to the queried data information and the preset processing policy, it is judged whether the current detection task is completed by the virtual machine detection module; if so, the virtual machine detection module executes the detection task, and after the detection task is completed, it jumps to the preset jump interval address; if not, the host detection module executes the detection task, and after the detection task is completed, it jumps to the preset jump interval address.

[0054] During specific implementation, according to the preset policy, the processing function in the host detection module for processing VM-EXIT events judges whether the current trigger event processing method needs to return to the guest context to execute the detection task:

[0055] If so, the processing function modifies the instruction pointer register of the virtual machine processor to the guest context processing function address (GLA) corresponding to the currently called address, and returns to the guest context to resume execution. In addition, according to the information such as the number and type of parameters, return value type, etc. specified and stored in advance, the processing function executes the detection task in the virtual machine detection module. When the detection task is completed, the processing function calls or jumps to the corresponding jump interval address to continue executing the original function.

[0056] If not, according to the information such as the number and type of parameters specified and stored in advance, the return value type, etc., the processing function executes the detection task in the host detection module. When the detection task is completed, the processing function modifies the instruction pointer register of the virtual machine processor to the jump area address (GLA) corresponding to the currently called address, and returns to the client context to resume execution.

[0057] In addition, after executing the detection task according to the queried data information, a detection log is further output according to the detection result. Specifically, the processing function for executing the detection task determines whether the current execution context belongs to the monitored process and thread, whether the current thread is in a recordable state, and determines whether to output the detection log according to the judgment result. Specifically, the processing function parses the parameter data according to the parameter type of the currently called function and generates a detection log.

[0058] It can be seen that in this embodiment, the behavior monitoring based on instrumentation includes detection functions such as monitoring the call behavior of specified key system functions and determining the context when specific monitored code block instructions are executed. The behavior monitoring function based on instrumentation is implemented by inserting specific instructions at specified positions. This method realizes the state switching of the virtual machine processor during execution by inserting virtualization-related privilege instructions or interrupt instructions at specified memory addresses, thereby realizing behavior monitoring. According to the pre-set policy, the behavior monitoring function based on instrumentation can be executed either in the processing function of the host detection module in the host context or directed back to the processing function of the virtual machine detection module in the client context. In addition, in this embodiment, the number of monitored addresses included in the monitoring list generated by the virtual machine detection module can be dynamically updated. Correspondingly, the updated monitoring list is synchronized to the host detection module through the instant messaging function, so that the host detection module performs instrumentation and behavior monitoring operations on the updated monitoring list.

[0059] In addition, the behavior monitoring method in the present invention can also implement the following four functions, namely: two-way instant messaging function, access request processing function based on instrumentation, monitoring function of memory access behavior, and monitoring function of abnormal events of the virtual machine operating system. The following will introduce the above four functions in detail with four examples respectively:

[0060] Example 1: Two-way instant messaging function

[0061] Step 1: The virtual machine detection module initializes and collects pre-data information.

[0062] When the virtual machine environment starts up and is completed, the virtual machine detection module and the driver sub-module it contains are loaded and initialized. The virtual machine detection module collects pre-data information, including but not limited to: operating system version information, key data structure definitions and member offsets, key system data or object addresses, key system function addresses, and specific monitoring code block addresses, etc.

[0063] Step 2: The virtual machine detection module encapsulates the data information related to the threat detection process obtained in the virtual machine environment into serialized data.

[0064] Among them, the data information related to the threat detection process includes: the pre-data information collected above, and / or the threat data information related to the threat source obtained by the virtual machine detection module. In order to comply with the communication specification between the virtual machine and the host, in the present invention, the data information related to the threat detection process is encapsulated into serialized data in a predefined serialization protocol and format, and parsing operations are performed according to the serialization protocol. Among them, the serialization protocol and format define the authentication string, data type, size of the header structure, member fields, and length of the appended data, etc.

[0065] Step 3: Cache the serialized data into a predefined memory space, and store the space address of the predefined memory space in a predefined register.

[0066] Specifically, the predefined memory space includes one or more consecutive memory pages. Correspondingly, cache the serialized data into a predefined buffer, and the predefined buffer is located in the above memory pages. Store the linear address of the predefined buffer included in the above memory pages in the predefined register. Among them, the memory pages included in the predefined memory space can be multiple memory pages that are consecutive in the linear address view.

[0067] Step 4: The virtual machine detection module triggers a virtual machine exit event through a virtual machine call instruction.

[0068] Among them, the virtual machine detection module determines the call number corresponding to the data type according to the data type of the serialized data, and triggers a virtual machine exit event through the virtual machine call instruction corresponding to the call number. Accordingly, the preset register further includes a plurality of general-purpose registers respectively corresponding to different call numbers. Among them, the data type of the serialized data can be determined in combination with the client context. It can be seen that by presetting a plurality of call numbers respectively corresponding to different data types and presetting the corresponding relationship between each register and the call number, various types of information can be flexibly transmitted. In specific implementation, the call number and the linear address of the preset buffer are assigned to preset general-purpose registers such as EAX / RAX and EBX / RBX, and the VMCALL instruction is executed. Among them, when the VMCALL instruction is executed, the virtual machine processor unconditionally triggers a VM-EXIT event for the reason of VMCALL, and the processor control right temporarily returns to the ROOT environment, so that the VM-EXIT processing function in the host detection module can be executed.

[0069] Step Five: The host detection module queries the preset register according to the above virtual machine exit event to obtain and process the serialized data stored in the preset memory space.

[0070] Specifically, the virtual machine exit processing function (i.e., the VM-EXIT processing function) included in the host detection module obtains the linear address stored in the preset register and converts the linear address into a virtual machine physical address; according to the mapping relationship between the virtual machine physical address and the host physical address, the virtual machine physical address is converted into a host physical address; according to the host physical address, the serialized data stored in the preset memory space is obtained and processed. Among them, when obtaining and processing the serialized data stored in the preset memory space according to the host physical address, the physical page of the host physical address is mapped to the host operating system kernel address space to obtain a host linear address; the serialized data is read from the memory page mapped to the host operating system kernel address space. In addition, the host detection module also needs to obtain the call number of the virtual machine call instruction corresponding to the virtual machine exit event, query the general-purpose register corresponding to the obtained call number, and obtain and process the serialized data stored in the preset memory space according to the general-purpose register.

[0071] During specific implementation, the VM-EXIT handler in the host detection module obtains the call ID and the guest linear address (GLA) of the data transmission buffer according to the aforementioned assigned general-purpose registers. This handler converts the guest linear address into a guest physical address (GPA), and then, according to the mapping relationship between the guest physical address and the host physical address, converts the guest physical address into a host physical address (HPA). Then, this handler maps the physical page with the converted host physical address (HPA) in the host operating system kernel address space to obtain the host linear address (HLA, virtual address). Finally, this handler reads the buffer data from the memory page mapped to the host operating system kernel address space, parses the serialized data in a predefined protocol and format to obtain the information content of the current communication transfer, and uses the obtained information according to the policy.

[0072] In addition, further optionally, during the detection task, the virtual machine detection module also needs to send information such as detection logs to the host detection module. Similarly, the log data is serialized and encapsulated through a separately predefined call ID (Call ID) and protocol format corresponding to the log type, and the VMCALL instruction is executed to unconditionally trigger the VM-EXIT event of the VMCALL reason, so that the handler of the host detection module can parse and process the corresponding serialized data. The situations where the virtual machine detection module sends data information to the host detection module include, but are not limited to: the detection log data output by some detection functions implemented in the virtual machine detection module; the extended thread monitoring mechanism adds a new process or thread to the monitoring list; the file data released by the target process inside the virtual machine.

[0073] Among them, the host detection module is located in the virtual machine monitor component of the host operating system kernel, and the virtual machine detection module is located in the guest machine implemented by the virtual machine; one host detection module corresponds to one or more virtual machine detection modules.

[0074] It can be seen that in this example, the host detection module and the virtual machine detection module communicate by triggering the virtual machine processor state transition through virtualization privileged instructions, thereby enabling the instant communication function between the host detection module and the virtual machine detection module, and facilitating the data transmission between the two. Among them, in the function code of the virtual machine detection module, the register call number and the guest physical address are specified by assignment and the VMCALL instruction is executed, so that the virtual machine processor unconditionally triggers the VM-EXIT event of the VMCALL reason and switches to the ROOT environment to execute the corresponding processing function in the host detection module, so that the host detection module obtains the call number and the guest physical address through the aforementioned assigned register, and reads the data to be received from the guest physical memory according to the agreed protocol, thereby realizing the function of instant communication between the two ends.

[0075] Example Two: Access Request Processing Function Based on Instrumentation

[0076] Step 1: The virtual machine detection module obtains the list of critical system function addresses and the list of preset monitoring code block addresses, and generates a monitoring list according to the list of critical system function addresses and the list of preset monitoring code block addresses.

[0077] For the specific details of this step, reference can be made to S200, which will not be elaborated here.

[0078] Step 2: The host detection module obtains the monitoring list containing the addresses to be monitored generated by the virtual machine detection module through the first virtual machine exit event triggered by the virtual machine call instruction.

[0079] For the specific details of this step, reference can be made to S210, which will not be elaborated here.

[0080] Step 3: The host detection module determines the memory page corresponding to the address to be monitored as the target memory page, and copies the target memory page to obtain a mirrored memory page.

[0081] Among them, the address to be monitored mainly refers to the address included in the monitoring list, and of course it can also be an address obtained by other means. This step needs to operate on each address to be monitored separately. Specifically, before the instrumentation operation of the behavior monitoring function based on instrumentation, the host detection module allocates and copies a mirrored memory page for each memory page where the guest linear address (GLA) in the monitoring address information array is located. The data in the mirrored memory page is the same as that in the original memory page and serves as the initial backup of the original memory page. In the unactivated state, the mirrored memory page does not exist in the extended page table (EPT) of the guest machine. Among them, the monitoring address information array is an array used to store each address to be monitored.

[0082] Step 4: Insert a preset instrumentation instruction corresponding to the address to be monitored into the target memory page, and cancel the access permission of the target memory page.

[0083] Specifically, canceling the access permission of the target memory page can be achieved through the following method: Determine the page table entry corresponding to the target memory page, set the read / write bit in the page table entry to zero to cancel the read / write access permission of the target memory page, and retain the execution permission of the target memory page.

[0084] During specific implementation, the host detection module parses the 4-level page table structure from the extended page table (EPT) associated with the current domain according to the guest physical frame number (GFN) of the original memory page (i.e., the target memory page), and locates and records the page table entry (PTE) corresponding to the original memory page. When the virtual machine detection module notifies the host detection module to enable the monitoring function, the host detection module traverses each node in the monitoring address information array, and sets the read and write bits in each page table entry (PTE) stored in the previous step to zero, thereby canceling the read and write access permissions of the corresponding guest memory page and only retaining the execution permission.

[0085] Step 5: The host detection module replaces the target memory page with a mirrored memory page according to the virtual machine exit event triggered by the access request of the target memory page, and restores the access permission of the target memory page, so that the access request for the target memory page is processed according to the mirrored memory page.

[0086] Among them, the access request is triggered by a thread or process in the virtual machine operating system. Since the access permission of the target memory page has been canceled, the access request for the target memory page will trigger a second virtual machine exit event caused by the EPT-VIOLATION reason due to violating the EPT regulations, thereby causing the host detection module to switch to the root mode. In the root mode, the host detection module has the permission to obtain and change the status information such as the register values of the virtual machine processor, so that it can replace the target memory page with a mirrored memory page and restore the access permission of the target memory page in the ROOT mode. Specifically, find the page table entry of the target memory page pointed to by the access request, set the read / write bit in the page table entry to enable the read / write access permission of the target memory page; and write the page frame number value of the mirrored memory page into the page table entry to activate the mirrored memory page and make the mirrored memory page process the access request instead of the target memory page.

[0087] During specific implementation, when a certain thread of the guest operating system attempts to read from or write to the memory page where the instrumented new instruction is located (i.e., the target memory page), since the read and write access permissions of this memory page have been revoked through the extended page table (EPT) in the previous step, this access operation will cause the logical processor to trigger a VM-EXIT event with the reason of EPT VIOLATION and return to the ROOT mode for execution. The processing function in the host detection module for handling VM-EXIT events obtains the relevant information of the execution environment at that time based on the reason for triggering the VM-EXIT and the guest physical address (GPA) being accessed, and searches for the node corresponding to the address in the monitoring address information array. Then, this processing function sets the read and write bit positions of the page table entry (PTE) of the monitoring address information node to restore the read and write access permissions; at the same time, it writes the host physical page frame number (HFN) value of the previously created mirrored memory page to the page frame number value position of the page table entry (PTE) to activate the mirrored memory page, thereby replacing the accessed memory page in the guest with the mirrored memory page.

[0088] It can be seen that when the logical processor returns to execute the guest context, it will continue to execute the read and write access instructions for the target memory page, and this access instruction will be able to successfully execute the read and write access operations. However, the actual target object of the read and write access operations is the mirrored memory page, thus ensuring that the new instructions instrumented in the original memory page will not be read or overwritten. In other words, although the access instruction is directed at the target memory page, in this embodiment, after receiving the access instruction, the target memory page is replaced by the mirrored memory page by switching to the ROOT mode, so that the actual access object of this access instruction is the mirrored memory page.

[0089] In addition, further optionally, after the processing of the current access request is completed, the mirrored memory page can be restored to the target memory page again to ensure the execution of the instrumentation instruction. After activating the mirrored memory page, it further includes: setting a monitor trap flag (i.e., the MTF control flag) for the virtual machine processor. By setting the monitor trap flag, the processor triggers a virtual machine exit event due to an exception every time it executes an instruction. Correspondingly, the method in this embodiment further includes: when the access request is processed, triggering a virtual machine exit event corresponding to the monitor trap flag to cancel the monitor trap flag; and restoring the read / write bit position of the page table entry to the zero state, and restoring the page frame number value of the mirrored memory page written to the page table entry to the page frame number value of the target memory page. Thus, it can be seen that the virtual machine exit event triggered by the monitor trap flag enables the host detection module to monitor the event (or timing) when the access request is processed, and then cancel the monitor trap flag at the first time when the access request is processed, so that the target memory page is restored to the state before the access request is triggered. Specifically, when the read and write access operations are completed, due to the MTF control flag set for the virtual machine processor, the logical processor will generate a VM-EXIT event of type MONITORTRAPFLAG. The processing function of the host detection module cancels the MTF control flag of the virtual machine processor at this time, and at the same time restores the read / write bit of the previous step page table entry (PTE) to the zero state, and rewrites the host physical page frame number (HFN) of the original memory page to the page frame number value position of the page table entry (PTE), and returns to the guest context to continue execution.

[0090] Thus, it can be seen that in this embodiment, the instrumentation traces are hidden and protected, and it is possible to hide the modification traces of the instrumented memory addresses for the processes or threads inside the virtual machine. Thus, the instrumented memory addresses are protected, and the memory blocks of the newly instrumented instructions cannot be read or overwritten by any process or thread inside the virtual machine. The function of hiding and protecting the instrumentation traces in this embodiment is mainly implemented based on the extended page table (EPT) mechanism of the hardware virtualization technology. The target of hiding and protecting is based on the set of instrumentation points described in the instrumentation-based behavior monitoring function.

[0091] In addition, this example can be combined with the behavior monitoring method in Embodiment 2 to further implement the instrumentation-based behavior monitoring function. Correspondingly, at the end of this example, the step S220 and its subsequent steps in Embodiment 2 can be further added.

[0092] Example 3. Monitoring Function of Memory Access Behavior

[0093] Step 1: The virtual machine detection module initializes and collects pre-data information, and sets a monitoring list according to the collection results.

[0094] When the virtual machine environment starts up and completes, the virtual machine detection module and the driver sub-module it contains are loaded and initialized. The virtual machine detection module collects pre-data information, including but not limited to: operating system version information, key data structure definitions and member offsets, key system data or object addresses, key system function addresses, and specific monitoring code block addresses, etc. Next, the virtual machine detection module determines the objects to be monitored and their corresponding addresses to be monitored based on the operating system version and kernel module version information. For example, the addresses and sizes of key system data or objects, specifically including: the Token member pointer of the system process associated object, the Token object of the system process associated object, the hardware abstraction layer (HAL) dispatch function table, and the relevant kernel global variables indicating the boundary between the user and kernel address spaces. Finally, a monitoring list is generated based on the above information, and this monitoring list is used to store the addresses to be monitored corresponding to each of the above objects to be monitored.

[0095] Step 2: Obtain the monitoring list set by the virtual machine detection module and the addresses to be monitored included in the monitoring list, and determine the memory page corresponding to the address to be monitored as the target memory page.

[0096] The host detection module obtains the monitoring list set by the virtual machine detection module and the addresses to be monitored included in the monitoring list through the instant messaging function. Among them, the instant messaging function is implemented by triggering a virtual machine exit event, and the specific implementation method will be described in detail later. Specifically, when implementing, the host detection module allocates and initializes a monitoring address information array according to each address to be monitored in the passed monitoring list, so as to store each address to be monitored in the form of an array, which is convenient for querying. The addresses to be monitored in the monitoring list belong to the guest physical address (GPA). For each address to be monitored, determine the memory page where the address to be monitored is located, and determine this memory page as the target memory page.

[0097] Step 3: Set the read / write bit in the page table entry corresponding to the target memory page to zero to cancel the read / write access permission of the target memory page.

[0098] This step is implemented by the host detection module. Specifically, when implementing, first, determine each address to be monitored and its corresponding target memory page according to the monitoring address information array mentioned above; then, obtain the guest page frame number (GFN) of the memory page where each guest physical address (GPA) is located, and parse the 4-level page table structure from the extended page table (EPT) associated with the current domain, locate and record the corresponding page table entry (PTE); finally, set the read and write bits in each page table entry (PTE) stored in the previous step to zero, so as to cancel the read and write access permissions of the corresponding guest memory page.

[0099] Step 4: When a virtual machine exit event triggered by the access behavior of the target memory page is detected, switch to the root mode according to the virtual machine exit event.

[0100] Specifically, when there is a process or thread in the virtual machine operating system attempting to access the target memory page, the corresponding access behavior will trigger a virtual machine exit event due to violation of the EPT regulations. In response to the virtual machine exit event, the host detection module will switch from the non-root mode to the root mode. For example, when a certain thread of the guest operating system attempts to read or write access the memory page of the instrumented new instruction, since the read and write access permissions of this memory page have been cancelled through the extended page table in the previous step, the access operation will cause the logical processor to trigger a VM-EXIT event with the reason of EPT VIOLATION and return to execute in the root mode.

[0101] Step 5: Monitor the access data information corresponding to the access behavior of the target memory page in the root mode.

[0102] Specifically, read the values of the preset registers and the guest memory data to determine the execution environment information and the access status information corresponding to the access behavior. Among them, the execution environment information includes: the process or thread executing the access, the caller function of the access behavior, the stack backtrace sequence, the malicious code block, and / or the critical register values; the access status information includes: the read access of a non-system process to the member pointer of a system process associated object, the read access to a system process associated object, the write access to the hardware abstraction layer distribution function table, and / or the write access to the relevant kernel global variable indicating the boundary between the user and kernel address spaces.

[0103] In specific implementation, when the accessed target address belongs to the monitored data and object range, according to the monitoring policy, the processing function in the host detection module determines the environment information such as the process and thread executing the access based on the relevant virtual machine processor register values and the guest memory data, and determines whether the current read and write operations are in an abnormal state, and records and outputs the abnormal state and the execution environment information. The abnormal state includes but is not limited to: the read access of a non-system process to the Token member pointer of a system process associated object, the read access to a system process associated Token object, the write access to the hardware abstraction layer (HAL) distribution function table, and the write access to the relevant kernel global variable indicating the boundary between the user and kernel address spaces. The execution environment information includes: the process, thread, caller function, necessary stack backtrace sequence, suspicious malicious code block, and critical register values executing the access.

[0104] In addition, considering that the target memory page may contain other addresses that do not need to be monitored in addition to the address to be monitored, in this embodiment, when monitoring the access data information corresponding to the access behavior of the target memory page in the root mode, the access object of the access behavior is further matched with the addresses to be monitored included in the monitoring list; if the match is successful, the access data information corresponding to the access behavior of the target memory page is monitored; if the match is unsuccessful, the root mode is exited and the client context is returned for execution. For example, since there may still be other unmonitored data or objects in the memory page where the critical system data or objects to be monitored are located, the access to these data or objects will also trigger a VM-EXIT event. Therefore, in the processing function of the host detection module, the data object address and size stored in the previous step are matched with the currently accessed target address, and the accesses that do not belong to the monitored data and object range are ignored, and the logical processor returns to the client context to continue execution.

[0105] It can be seen that the monitoring operation for the memory access behavior can be completed through the above steps. Additionally, to not affect the normal execution of the access behavior, optionally, in this embodiment, after monitoring the access data information corresponding to the access behavior of the target memory page in the root mode, it further includes: setting the read / write bit in the page table entry corresponding to the target memory page to restore the read / write access permission of the target memory page, and setting the monitor trap flag for the virtual machine processor; where the monitor trap flag is used to trigger a virtual machine exit event corresponding to the monitor trap flag when the access operation for the access behavior to the target memory page is completed. Correspondingly, the method further includes: when detecting the virtual machine exit event corresponding to the monitor trap flag, canceling the monitor trap flag and restoring the read / write bit in the page table entry to its zero state.

[0106] For example, when the detection task for the memory access behavior is completed, the processing function sets the read and write bits in the page table entry of the previous step to restore the read and write access permissions; at the same time, the processing function sets the MTF control flag of the virtual machine processor. Correspondingly, when the logical processor returns to the client context for execution, it will continue to execute the read and write access instructions for the target memory page, and the access instruction will be able to successfully perform the read and write access operations. Through the above operations, the access behavior for the target memory page can be normally implemented. When the read and write access operations are completed, since the virtual machine processor sets the MTF control flag, the logical processor will generate a VM-EXIT event of type MONITORTRAPFLAG. The processing function of the host detection module will then cancel the MTF control flag of the virtual machine processor and at the same time restore the read and write bits of the page table entry in the previous step to their zero state, and return to the client context to continue execution.

[0107] It can be seen that this method can achieve real-time monitoring of memory access behavior through virtual machine exit events: once an access behavior is executed, a virtual machine exit event will be triggered immediately, enabling the memory access behavior to be monitored immediately. This method can perform real-time monitoring on read and write access behaviors implemented for specific critical system data or object addresses of the guest operating system. The real-time monitoring function of this memory access is mainly implemented based on the extended page table mechanism of hardware virtualization technology. In addition, the real-time monitoring function of memory access can focus on the following processes to be monitored: the target process at initial startup, the processes started by the target process and injected by the target process, and the processes that load files released by the target process.

[0108] Example 4: Abnormal Event Monitoring Function of Virtual Machine Operating System

[0109] Step 1: The virtual machine detection module is initialized and pre-data information is collected.

[0110] When the virtual machine environment starts up successfully, the virtual machine detection module and the driver sub-module it contains are loaded and initialized. The virtual machine detection module collects pre-data information, including but not limited to: operating system version information, definitions of key data structures and member offsets, addresses of key system data or objects, addresses of key system functions, and addresses of specific monitoring code blocks, etc. In addition, the virtual machine detection module obtains the function address of the key function for operating system kernel exception handling (i.e., the exception handling function) according to the operating system version and kernel module version information.

[0111] Step 2: Through the first virtual machine exit event triggered by a virtual machine call instruction, obtain the function address of the exception handling function provided by the virtual machine detection module.

[0112] Specifically, according to the instant messaging function at both ends, the virtual machine detection module and the host detection module can communicate instantaneously. Correspondingly, the function address of the key function for operating system kernel exception handling determined in the previous step is passed to the host detection module. The host detection module sets this function address for runtime monitoring through instrumentation operations.

[0113] Step 3: Insert preset instrumentation code for the function address; among them, the preset instrumentation code is used to monitor when the exception handling function is executed.

[0114] Among them, the preset instrumentation code is used to monitor when the exception handling function is executed. The preset instrumentation code can be implemented in various forms. For example, it can be in the form of a probe. In addition, when the number of exception handling functions is multiple, corresponding preset instrumentation code needs to be inserted for the function address of each exception handling function respectively.

[0115] Step 4: When a second virtual machine exit event triggered by the execution process of the exception handling function is detected, switch to the root mode according to the second virtual machine exit event.

[0116] Specifically, by setting the execution logic of the preset instrumentation code, when the exception handling function is executed, the second virtual machine exit event can be triggered through the preset instrumentation code. Accordingly, the host detection module switches to the root mode according to the second virtual machine exit event. In the root mode, the host detection module can obtain and change the status information such as the register values of the virtual machine processor.

[0117] For example, when a blue screen-like exception event occurs inside the virtual machine operating system, according to the code logic of the operating system kernel module, the kernel collects the blue screen context information and calls and executes the relevant exception handling function. When a certain thread of the guest operating system executes the instrumented new instruction, the logical processor immediately triggers the VM-EXIT event for the corresponding reason and returns to the root mode for execution, entering the processing function of the host detection module, so as to monitor the exception event through the processing function of the host detection module.

[0118] Step 5: Obtain the event information of the exception event related to the exception handling function in the root mode.

[0119] Since the status information such as the register values of the virtual machine processor can be obtained and changed in the root mode, the host detection module can determine the event information of the exception event related to the exception handling function based on the obtained status information. Among them, the event information of the exception event related to the exception handling function includes: various information such as the occurrence time of the exception event, the cause of the exception event, and the execution environment information when the exception event occurs. For example, the processing function in the host detection module obtains the blue screen context information through register values such as ESP / RSP and the guest memory data, and records and outputs it.

[0120] It can be seen that this example can perform real-time monitoring on the blue screen event of the guest operating system (i.e., the virtual machine operating system). The exception monitoring function of the guest operating system performs instrumentation monitoring on the system functions responsible for handling the operating system blue screen event. When the guest operating system has a blue screen, the system kernel will call the aforementioned function to collect system exception information and handle the exception.

[0121] In summary, the above method in this embodiment can implement multiple functions, and this method has at least the following advantages:

[0122] (1) The host detection module is implemented based on the global virtual machine monitor, so that the core code of the detection engine is implemented at the global virtual machine monitor layer. This can simplify the functions of the virtual machine detection module inside the virtual machine, isolate the core code of the detection engine from the virtual machine environment, ensure that the abnormal state of the virtual machine environment will no longer affect the normal execution of the detection function, and minimize the impact of the detection engine on the virtual machine environment. Moreover, since the core code of the detection engine is located at the global virtual machine monitor layer rather than in the virtual machine detection module, malicious processes with environment detection behaviors will not be able to steal the key data and code of the detection engine.

[0123] (2) Through the virtualization technology based on the processor, this solution also realizes the function of hiding and protecting the instrumentation traces of the detection module, making it more difficult for malicious code inside the virtual machine to detect the instrumentation points deployed by the detection module including hooks. At the same time, the modification of the address of the instrumented function by malicious code inside the virtual machine will not affect the detection function of the instrumentation points of the detection module itself, thus ensuring the continuous effectiveness of the threat detection function.

[0124] (3) The clustered distributed threat detection system itself depends on specific virtual machine management software to implement services such as virtual machine management, scheduling, and basic support in the server host. The threat detection implementation solution based on the virtual machine monitor organically combines the software intermediate layer of the virtual machine management software and the threat detection function module, simplifies the multi-level separation structure that originally relied on mechanisms such as nested virtualization, and greatly improves the hardware working performance consumption of the virtual machine environment and the host physical server environment. In addition, through the threat detection implementation solution based on the global virtual machine monitor, the data transfer path in the middle and later stages during task detection can be significantly shortened at the same time, and the parallel detection efficiency of virtual machines in the sandbox cluster will also be significantly improved.

[0125] In summary, compared with traditional virtual machine-based detection methods, the advantages of this solution are as follows: Based on the global virtual machine monitor component, the dynamic threat detection engine function is implemented through processor-based virtualization technology, providing strong guarantees for detecting threat behaviors during runtime in terms of detection effectiveness, detection performance, and detection reliability. The virtual machine detection module performs pre-information collection tasks inside the virtual machine. The host detection module obtains pre-information by communicating and interacting with the virtual machine detection module at the virtual machine monitor layer located in the host kernel, and performs functions such as detection point instrumentation, memory monitoring, privileged instruction monitoring, and execution flow control and transfer at the virtual machine monitor layer. The core detection function is located in the host operating system kernel outside the virtual machine, realizing the mutual isolation of the core code of the detection engine and the virtual machine environment. Relying on the VM-EXIT mechanism and extended page table mechanism based on processor-based virtualization technology, key functions such as two-way instant communication, instrumentation-based behavior monitoring, hiding and protection of instrumentation traces, real-time monitoring of memory access, and exception monitoring of the guest operating system can be achieved.

[0126] Figure 3 FIG. shows the system structure diagram of a behavior monitoring system based on instrumentation provided by another embodiment of the present invention, as Figure 3 shown, the system includes: a host detection module 31 and a virtual machine detection module 32; wherein, the host detection module 31 further includes:

[0127] A first exit unit 311, adapted to obtain a monitoring list generated by the virtual machine detection module through a first virtual machine exit event triggered by a virtual machine call instruction;

[0128] An instrumentation unit 312, adapted to determine the memory location corresponding to each monitored address included in the monitoring list respectively, and insert a preset instrumentation instruction into the memory location;

[0129] A second exit unit 313, adapted to query data information related to the execution process of the preset instrumentation instruction according to the second virtual machine exit event when the host detection module detects a second virtual machine exit event triggered by the execution process of the preset instrumentation instruction;

[0130] A monitoring unit 314, adapted to perform a detection task according to the queried data information to achieve behavior monitoring.

[0131] Optionally, the preset instrumentation instruction includes: a virtual machine privileged instruction and / or an interrupt instruction.

[0132] Optionally, the virtual machine detection module is further adapted to:

[0133] Obtain a list of key system function addresses and a list of preset monitoring code block addresses;

[0134] Generate the monitoring list according to the list of key system function addresses and the list of preset monitoring code block addresses.

[0135] Optionally, the virtual machine detection module is further adapted to: determine the processes to be monitored as the target process that is initially started, the processes started by the target process or injected by the target process, and the processes that load the files released by the target process; add the processes to be monitored to the monitoring list.

[0136] Optionally, the instrumentation unit is specifically adapted to: determine the memory page where the address to be monitored is located as the target memory page, determine the offset position corresponding to the address to be monitored in the target memory page, and determine the offset position as the memory position corresponding to the address to be monitored.

[0137] Optionally, the instrumentation unit is specifically adapted to: determine the original instruction corresponding to the memory position, and store the original instruction in association with the memory position; wherein, after the monitoring operation is completed, data recovery is performed according to the original instruction.

[0138] Optionally, the monitoring unit is specifically adapted to: determine whether the current detection task is completed by the virtual machine detection module according to the queried data information and the preset processing strategy;

[0139] If so, the virtual machine detection module executes the detection task, and after the detection task is completed, jumps to the preset jump area address;

[0140] If not, the host detection module executes the detection task, and after the detection task is completed, jumps to the preset jump area address.

[0141] Optionally, the monitoring unit is further configured to: output a detection log according to the detection result;

[0142] Wherein, the host detection module is located in the virtual machine monitor component of the host operating system kernel, and the virtual machine detection module is located in the guest machine implemented by the virtual machine; wherein, one host detection module corresponds to one or more virtual machine detection modules.

[0143] For the specific structures and working principles of the above host detection module, virtual machine detection module and each unit, reference can be made to the descriptions of the corresponding steps in the method embodiments, which will not be elaborated here.

[0144] An embodiment of the present application provides a non-volatile computer storage medium, and the computer storage medium stores at least one executable instruction, and the computer executable instruction can execute the behavior monitoring method based on instrumentation in any of the above method embodiments.

[0145] Figure 4 FIG. 1 shows a schematic structural diagram of an electronic device according to an embodiment of the present invention. The specific embodiments of the present invention do not limit the specific implementation of the electronic device.

[0146] As Figure 4 shown, the electronic device may include: a processor 402, a communications interface 404, a memory 406, and a communication bus 408.

[0147] Among them:

[0148] The processor 402, the communications interface 404, and the memory 406 communicate with each other through the communication bus 408.

[0149] The communications interface 404 is used to communicate with network elements of other devices such as clients or other servers.

[0150] The processor 402 is used to execute the program 410, and specifically can execute the relevant steps in the embodiment of the above method for querying memory addresses.

[0151] Specifically, the program 410 may include program code, and the program code includes computer operation instructions.

[0152] The processor 402 may be a central processing unit CPU, or a specific integrated circuit ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of the present invention. One or more processors included in the electronic device may be of the same type of processor, such as one or more CPUs; or may be of different types of processors, such as one or more CPUs and one or more ASICs.

[0153] The memory 406 is used to store the program 410. The memory 406 may include a high-speed RAM memory, and may also include a non-volatile memory, such as at least one disk memory.

[0154] The program 410 is specifically used to cause the processor 402 to execute the various operations in the above method embodiments.

[0155] The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other device. A variety of general-purpose systems can also be used in conjunction with the teachings presented herein. The structure required to construct such systems will be apparent from the above description. Additionally, the present invention is not directed to any particular programming language. It should be understood that the teachings of the present invention described herein can be implemented in a variety of programming languages, and the description of a particular language above is for the purpose of disclosing the best mode of the present invention.

[0156] In the specification provided herein, numerous specific details are set forth. However, it can be understood that embodiments of the present invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0157] Similarly, it should be understood that, for the purpose of streamlining this disclosure and aiding in the understanding of one or more of the various inventive aspects, in the foregoing description of the exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together in a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the following claims, the inventive aspects lie in less than all of the features of the single foregoing disclosed embodiment. Thus, the claims following the detailed description are hereby expressly incorporated into this detailed description, with each claim standing on its own as a separate embodiment of the present invention.

[0158] Those skilled in the art will appreciate that the modules in the devices in the embodiments can be adaptively changed and disposed in one or more devices different from the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except for the fact that at least some of such features and / or processes or units are mutually exclusive, any combination can be adopted for all the features disclosed in this specification (including the accompanying claims, abstract, and drawings) and all the processes or units of any method or device so disclosed. Unless otherwise expressly stated, each feature disclosed in this specification (including the accompanying claims, abstract, and drawings) can be replaced by an alternative feature providing the same, equivalent, or similar purpose.

[0159] In addition, those skilled in the art can understand that although some embodiments described herein include certain features included in other embodiments rather than other features, the combination of features of different embodiments is meant to be within the scope of the present invention and forms different embodiments. For example, in the following claims, any one of the claimed embodiments can be used in any combination.

[0160] Each component embodiment of the present invention can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art should understand that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the staking-based behavior monitoring device according to the embodiments of the present invention. The present invention can also be implemented as a device or device program (such as a computer program and a computer program product) for executing part or all of the methods described herein. Such a program for implementing the present invention can be stored on a computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0161] It should be noted that the above embodiments illustrate rather than limit the present invention, and those skilled in the art can design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention can be implemented by means of hardware including several different elements and by means of a suitably programmed computer. In the unit claims listing several devices, several of these devices can be embodied by the same item of hardware. The use of the words first, second, and third, etc. does not denote any order. These words can be interpreted as names.

[0162] The present invention also discloses A1. A staking-based behavior monitoring method, wherein the method includes:

[0163] The host detection module obtains a monitoring list generated by the virtual machine detection module through a first virtual machine exit event triggered by a virtual machine call instruction;

[0164] For each monitored address included in the monitoring list, determine the memory location corresponding to the monitored address, and insert a preset staking instruction into the memory location;

[0165] When the host detection module detects a second virtual machine exit event triggered by the execution process of the preset instrumentation instruction, query data information related to the execution process of the preset instrumentation instruction according to the second virtual machine exit event;

[0166] Execute a detection task according to the queried data information to implement behavior monitoring.

[0167] A2. The method according to A1, wherein the preset instrumentation instruction includes: a virtual machine privilege instruction and / or an interrupt instruction.

[0168] A3. The method according to A1 or 2, wherein before the method is executed, it further includes:

[0169] The virtual machine detection module obtains a list of critical system function addresses and a list of preset monitoring code block addresses;

[0170] Generate the monitoring list according to the list of critical system function addresses and the list of preset monitoring code block addresses.

[0171] A4. The method according to any one of A1-3, wherein before the method is executed, it further includes:

[0172] The virtual machine detection module determines the initially started target process, the process started by the target process or injected by the target process, and the process that loads the file released by the target process as the processes to be monitored;

[0173] Add the processes to be monitored to the monitoring list.

[0174] A5. The method according to any one of A1-4, wherein determining the memory location corresponding to the address to be monitored includes:

[0175] Determine the memory page where the address to be monitored is located, determine the offset position corresponding to the address to be monitored in the target memory page, and determine the offset position as the memory location corresponding to the address to be monitored.

[0176] A6. The method according to any one of A1-5, wherein specifically inserting the preset instrumentation instruction into the memory location includes:

[0177] Determine the original instruction corresponding to the memory location, and store the original instruction in association with the memory location; wherein after the monitoring operation is completed, data recovery is performed according to the original instruction.

[0178] A7. The method according to any one of A1-6, wherein executing the detection task according to the queried data information includes:

[0179] Based on the queried data information and the preset processing strategy, determine whether the current detection task is completed by the virtual machine detection module;

[0180] If so, the virtual machine detection module executes the detection task, and after the detection task is completed, jumps to the preset jump area address;

[0181] If not, the host machine detection module executes the detection task, and after the detection task is completed, jumps to the preset jump area address.

[0182] A8. According to the method of any one of A1-7, wherein, after performing the detection task according to the queried data information, it further includes: outputting a detection log according to the detection result;

[0183] Wherein, the host machine detection module is located in the virtual machine monitor component of the host machine operating system kernel, and the virtual machine detection module is located in the guest machine implemented by the virtual machine; wherein, one host machine detection module corresponds to one or more virtual machine detection modules.

[0184] B9. A behavior monitoring system based on instrumentation, wherein the system includes: a host machine detection module and a virtual machine detection module; wherein, the host machine detection module further includes:

[0185] A first exit unit, adapted to obtain a monitoring list generated by the virtual machine detection module through a first virtual machine exit event triggered by a virtual machine call instruction;

[0186] An instrumentation unit, adapted to respectively determine the memory location corresponding to each monitored address included in the monitoring list, and insert a preset instrumentation instruction into the memory location;

[0187] A second exit unit, adapted to query data information related to the execution process of the preset instrumentation instruction according to the second virtual machine exit event when the host machine detection module detects a second virtual machine exit event triggered by the execution process of the preset instrumentation instruction;

[0188] A monitoring unit, adapted to perform a detection task according to the queried data information to implement behavior monitoring.

[0189] B10. According to the system of B9, wherein the preset instrumentation instruction includes: a virtual machine privilege instruction and / or an interrupt instruction.

[0190] B11. According to the system of B9 or 10, wherein the virtual machine detection module is further adapted to:

[0191] Obtain a list of critical system function addresses and a list of preset monitored code block addresses;

[0192] Generate the monitoring list according to the list of key system function addresses and the list of preset monitoring code block addresses.

[0193] B12. The system according to any one of B9 - 11, wherein the virtual machine detection module is further adapted to: determine the processes to be monitored as the target process at initial startup, the processes started by the target process or injected by the target process, and the processes that load the files released by the target process; add the processes to be monitored to the monitoring list.

[0194] B13. The system according to any one of B9 - 12, wherein the instrumentation unit is specifically adapted to:

[0195] Determine the memory page where the address to be monitored is located, determine the offset position corresponding to the address to be monitored in the target memory page, and determine the offset position as the memory location corresponding to the address to be monitored.

[0196] B14. The system according to any one of B9 - 13, wherein the instrumentation unit is specifically adapted to:

[0197] Determine the original instruction corresponding to the memory location, and store the original instruction in association with the memory location; wherein, after the monitoring operation is completed, data recovery is performed according to the original instruction.

[0198] B15. The system according to any one of B9 - 14, wherein the monitoring unit is specifically adapted to:

[0199] Judge whether the current detection task is completed by the virtual machine detection module according to the queried data information and the preset processing strategy;

[0200] If so, the virtual machine detection module executes the detection task, and after the detection task is completed, jumps to the preset jump area address;

[0201] If not, the host detection module executes the detection task, and after the detection task is completed, jumps to the preset jump area address.

[0202] B16. The system according to any one of B9 - 15, wherein the monitoring unit is further used to: output a detection log according to the detection result;

[0203] Wherein, the host detection module is located in the virtual machine monitor component of the host operating system kernel, and the virtual machine detection module is located in the guest machine implemented by the virtual machine; wherein, one host detection module corresponds to one or more virtual machine detection modules.

[0204] C17. An electronic device, comprising: a processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface complete communication with each other through the communication bus;

[0205] The memory is used to store at least one executable instruction, and the executable instruction causes the processor to execute the operations corresponding to the instrumentation-based behavior monitoring method described in any one of A1-8.

[0206] D18. A computer storage medium, in which at least one executable instruction is stored, and the executable instruction causes a processor to execute the operations corresponding to the instrumentation-based behavior monitoring method described in any one of A1-8.

Claims

1. A behavior monitoring method based on instrumentation, wherein, The method includes: The host detection module obtains a monitoring list generated by the virtual machine detection module through a first virtual machine exit event triggered by a virtual machine call instruction; For each monitored address included in the monitoring list, determine the memory location corresponding to the monitored address, and insert a preset instrumentation instruction into the memory location; When the host detection module detects a second virtual machine exit event triggered by the execution process of the preset instrumentation instruction, query data information related to the execution process of the preset instrumentation instruction according to the second virtual machine exit event; Execute a detection task according to the queried data information to implement behavior monitoring; The executing the detection task according to the queried data information includes: Judge whether the current detection task is completed by the virtual machine detection module according to the queried data information and a preset processing strategy; If so, the virtual machine detection module executes the detection task, and after the detection task is completed, jumps to a preset jump interval address; If not, the host detection module executes the detection task, and after the detection task is completed, jumps to a preset jump interval address.

2. The method according to claim 1, wherein, The preset instrumentation instruction includes: virtual machine privilege instructions and / or interrupt instructions.

3. The method according to claim 1 or 2, wherein Before the method is executed, it further includes: The virtual machine detection module obtains a list of critical system function addresses and a list of preset monitoring code block addresses; Generate the monitoring list according to the list of critical system function addresses and the list of preset monitoring code block addresses.

4. The method according to claim 1, wherein Before the method is executed, it further includes: The virtual machine detection module determines the processes to be monitored as the target process started initially, the processes started by the target process or injected by the target process, and the processes that load the files released by the target process; Add the processes to be monitored to the monitoring list.

5. The method according to claim 1, wherein, The determining the memory location corresponding to the monitored address includes: Determine the memory page where the monitored address is located as the target memory page, determine the offset position corresponding to the monitored address in the target memory page, and determine the offset position as the memory location corresponding to the monitored address.

6. The method according to claim 1, wherein The inserting the preset instrumentation instruction into the memory location specifically includes: Determine the original instruction corresponding to the memory location, and store the original instruction in association with the memory location; wherein, after the monitoring operation is completed, data recovery is performed according to the original instruction.

7. The method according to claim 1, wherein After the detection task is executed according to the queried data information, it further includes: outputting a detection log according to the detection result; Among them, the host detection module is located in the virtual machine monitor component of the host operating system kernel, and the virtual machine detection module is located in the guest machine implemented through the virtual machine; wherein, one host detection module corresponds to one or more virtual machine detection modules.

8. A behavior monitoring system based on instrumentation, wherein, The system includes: a host detection module and a virtual machine detection module; wherein, the host detection module further includes: A first exit unit, adapted to obtain a monitoring list generated by the virtual machine detection module through a first virtual machine exit event triggered by a virtual machine call instruction; The instrumentation unit is adapted to determine the memory location corresponding to each monitored address included in the monitoring list respectively, and insert a preset instrumentation instruction into the memory location. The second exit unit is adapted to, when the host detection module detects a second virtual machine exit event triggered by the execution process of the preset instrumentation instruction, query data information related to the execution process of the preset instrumentation instruction according to the second virtual machine exit event. The monitoring unit is adapted to execute a detection task according to the queried data information to implement behavior monitoring. Specifically, the monitoring unit is adapted to: Judge whether the current detection task is completed by the virtual machine detection module according to the queried data information and a preset processing strategy. If so, the virtual machine detection module executes the detection task, and after the detection task is completed, jumps to a preset jump area address. If not, the host detection module executes the detection task, and after the detection task is completed, jumps to a preset jump area address.

9. The system according to claim 8, wherein, The preset instrumentation instruction includes: a virtual machine privilege instruction and / or an interrupt instruction.

10. The system according to claim 8 or 9, wherein, The virtual machine detection module is further adapted to: Obtain a list of critical system function addresses and a list of preset monitoring code block addresses. Generate the monitoring list according to the list of critical system function addresses and the list of preset monitoring code block addresses.

11. The system according to claim 8, wherein, The virtual machine detection module is further adapted to: determine the processes to be monitored as the initially started target process, the processes started by the target process or injected by the target process, and the processes loading the files released by the target process; add the processes to be monitored to the monitoring list.

12. The system according to claim 8, wherein, Specifically, the instrumentation unit is adapted to: Determine the memory page where the monitored address is located as the target memory page, determine the offset position corresponding to the monitored address in the target memory page, and determine the offset position as the memory location corresponding to the monitored address.

13. The system according to claim 8, wherein Specifically, the instrumentation unit is adapted to: Determine the original instruction corresponding to the memory location, and store the original instruction in association with the memory location; wherein, after the monitoring operation is completed, data recovery is performed according to the original instruction.

14. The system according to claim 8, wherein The monitoring unit is further used to: output a detection log according to the detection result. Wherein, the host detection module is located in the virtual machine monitor component of the host operating system kernel, and the virtual machine detection module is located in the guest machine implemented by the virtual machine; wherein, one host detection module corresponds to one or more virtual machine detection modules.

15. An electronic device, comprising: A processor, a memory, a communication interface and a communication bus, and the processor, the memory and the communication interface complete mutual communication through the communication bus. The memory is used to store at least one executable instruction, and the executable instruction causes the processor to execute the operations corresponding to the instrumentation-based behavior monitoring method according to any one of claims 1-7.

16. A computer storage medium, in which at least one executable instruction is stored, and the executable instruction causes the processor to execute the operations corresponding to the instrumentation-based behavior monitoring method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Linux kernel lightweight structural protection method and device

    CN107203716A

  • Automatically bridging the semantic gap in machine introspection

    US20150033227A1