A code signature verification method based on computer memory forensics technology
By verifying PE file signatures in memory based on kernel pool marking scanning technology and Volatility forensics framework, the problems of inaccurate code signature verification and insufficient system compatibility in the existing technology are solved, and valid code signature verification for Windows 10 64-bit system is realized.
Patent Information
- Application Number
- CN202111069279.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-13
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2041-09-13
AI Technical Summary
The prior art is difficult to effectively verify code signatures in computer memory, especially in the face of Rootkit attacks, the results are not accurate enough and lack compatibility with different operating systems.
Using kernel pool marking scanning technology, the memory dump file is obtained through the Volatility forensics framework, PE files are identified and reconstructed, and their code signatures are verified to prevent Rootkit attacks. It is suitable for Windows 10 64-bit systems.
It realizes that the PE file verification results in memory are closer to the real situation, preventing Rootkit from hiding, and is suitable for different versions of Windows operating systems, and the results are more accurate and compatible.
Smart Images

Figure CN113761595B_ABST
Abstract
Description
Technical Field:
[0001] The present invention relates to a code signature verification method based on computer memory forensics technology, which has good applications in the field of computer memory forensics and is mainly used for reconstructing security events and detecting untrusted files in memory. Background Art:
[0002] Computer forensics technology is a basic step in network security emergency response. Abnormal or unauthorized operations performed by malware in a computer system can be detected by analyzing the system's disk drive or memory. Memory forensics, as a branch of computer forensics, refers to finding, extracting, and analyzing volatile evidence from a computer's physical memory and pagefile. The method is to obtain a memory dump file through hardware interfaces, software acquisition, virtual machine snapshots, etc., save it to the disk, and use dedicated software (such as Volatility Framework) for analysis to reconstruct relevant security events. In recent years, due to the memoryization and stealth of network attack techniques, attackers no longer store key digital evidence on disks and are easily deceived by Rootkit attacks during real-time system detection. Therefore, memory forensics technology targeting memory has gradually become more and more important.
[0003] Microsoft Authenticode is a code signature standard used to digitally sign PE files for Windows systems, including executable files (with the extension.exe), dynamic link libraries (.dll), and drivers (.sys), etc. Based on the Public Key Cryptography Standards (PKCS) and X.509v3 digital certificates, the code-signed file is bound to the identity of the software publisher, and the integrity of the file is guaranteed. Code signing includes a digital certificate and the signature hash value of the file. Code signing technology helps to establish trust in computer software, can authenticate the software publisher, and ensure the integrity of the code by verifying the digital signature provided in the software. However, there are also some weaknesses in the use of code signing, such as the lack of protection on the client side, poor management of the publisher's secret key, and the certificate authority issuing certificates to shell companies. Although only a small number of malware executed in a computer utilize code signing, there are still documented events, such as Stuxnet, megacortex, etc. Therefore, PE files containing code signing should be a priority consideration in the file system forensics process. Summary of the Invention:
[0004] To assist forensic analysts in preferentially checking and verifying PE files containing code signatures in memory, the present invention discloses a code signature verification method based on computer memory forensic technology.
[0005] For this purpose, the present invention provides the following technical solutions:
[0006] A code signature verification method based on computer memory forensic technology, the method comprising the following steps:
[0007] Step 1: Obtain a dump file of the computer's physical memory through a hardware interface or software;
[0008] Step 2: Load the memory dump file into the Volatility forensic framework and find the matching operating system version and configuration file, determine the system version kernel according to the configuration file, and identify the memory layout of the memory dump file;
[0009] Step 3: Use the pool tag scanning technique to scan the file objects in the memory;
[0010] Step 4: Reconstruct the PE file in the memory based on the file object;
[0011] Step 5: Verify the PE file and the code signature.
[0012] Preferably, in step 1, to obtain a dump file of the computer's physical memory through a hardware interface or software, the specific steps are as follows:
[0013] Step 1-1: Determine whether the target system is a virtual machine. If so, take a snapshot file; if not, proceed to step 1-2;
[0014] Step 1-2: Determine whether the target system is in a running state. If not, check the hibernation file, crash dump, and paging file in the disk. If the target system is in a running state, proceed to step 1-3;
[0015] Step 1-3: Determine whether the operation permission of the target system is available. If the permission is available, generate a dump file by running software; otherwise, obtain the memory dump file through the hardware interface method.
[0016] Preferably, in step 2, to load the memory dump file into the Volatility forensic framework and find the matching operating system version and configuration file, the specific steps are as follows:
[0017] Step 2-1: Find and parse the kernel debug data block _KDDEBUGGER_DATA64;
[0018] Step 2-2: Find and parse the build string to obtain the major version number, minor version number, and service pack level of the operating system;
[0019] Step 2-3 imports the kernel symbol file according to the version number.
[0020] Preferably, in step 3, the pool tag scanning technology is used to scan the file objects in the memory. The specific steps are as follows:
[0021] Step 3-1 scans the kernel address space in the memory;
[0022] Step 3-2 determines whether the content of the memory address is "File", whether the BlockSize is within the valid range, and whether the PoolType is NonePaged. If the above three conditions are met, the file object is output. If any of the above conditions is not met, the next address is scanned;
[0023] Step 3-3 returns the file object handle.
[0024] Preferably, in step 4, the PE file in the memory is reconstructed based on the file object. The specific process is as follows:
[0025] Step 4-1 first initializes the binary file f as the carrier of the PE file;
[0026] Step 4-2 obtains the _CONTROL_AREA structure through the SectionObjectPointer member of the file object, and obtains the _SUBSECTION structure at the offset of 0x48;
[0027] Step 4-3 obtains the PTE that records the information of each page in the memory through the SubsectionBase of the _SUBSECTION structure;
[0028] Step 4-4 writes the PTE pages with Valid and Transition flag bits into the binary file f.
[0029] Preferably, in step 5, the PE file and the code signature are verified. The specific process is as follows:
[0030] Step 5-1 checks the integrity of the PE file;
[0031] Step 5-2 checks whether the PE file contains a digital certificate;
[0032] Step 5-3 verifies the code signature by embedding the certificate and the certificate in the directory.
[0033] Beneficial effects:
[0034] 1. The present invention is a code signature verification method based on computer memory forensics technology. It mainly analyzes the computer's physical memory, can effectively resist kernel Rootkit hiding technology, and the analysis results are closer to the real situation of the attack.
[0035] 2. Traditional methods obtain the file object _FILE_OBJECT by traversing process handles and are easily deceived by Rootkit hiding attacks. The technology of scanning file objects based on kernel pool tags used in the present invention can prevent attackers from using anti-forensics technologies such as modifying the handle table to hide malicious files, and the results are more accurate.
[0036] 3. Previous verification code signature methods only targeted the 32-bit system of the Windows 7 platform. The present invention can target the 64-bit systems of different versions of Windows 10 and has good applicability and compatibility for current popular operating systems. Brief Description of the Drawings:
[0037] Figure 1 It is a flowchart of obtaining a memory dump file in an embodiment of the present invention.
[0038] Figure 2 It is a flowchart of scanning file objects based on kernel pool tags in an embodiment of the present invention.
[0039] Figure 3 It is a flowchart of the PE file verification module in an embodiment of the present invention.
[0040] Figure 4 It is a flowchart of the code signature verification module in an embodiment of the present invention. Detailed Embodiment:
[0041] In order to clearly and completely describe the technical solutions in the embodiments of the present invention, the following further details the present invention with reference to the accompanying drawings in the embodiments.
[0042] The process of step 1 for obtaining a memory dump file is as follows:
[0043] Take a Windows 7 64-bit system host as an example.
[0044] The flowchart of obtaining a memory dump file in an embodiment of the present invention is as Figure 1 shown and includes the following steps.
[0045] Step 1-1: Determine that the target operating system is not a virtual machine;
[0046] Step 1-2: Determine that the target operating system is in a running state;
[0047] In step 1-3, if the operating permission of the target operating system is available, then obtain the memory dump file of the target operating system in a software manner.
[0048] In step 2, load the memory dump file into the Volatility forensic framework and search for the matching operating system version and configuration file. Determine the system version kernel according to the configuration file and identify the memory layout of the memory dump file.
[0049] In step 2-1, search for the kernel debug data block: 0xfffff78000000000L in the memory dump file;
[0050] In step 2-2, find the build string 3790.srv03_sp2_rtm.070216-1710 contained in the kernel debug data block, indicating that the target operating system is Windows 7 64-bit SP0 system.
[0051] In step 2-3, import the configuration file Win7SP0x64 of the target operating system.
[0052] In step 3, scan the file objects in the memory using the pool tag scanning technology
[0053] The flowchart of scanning the memory file object based on the pool tag scanning technology in the embodiment of the present invention is as Figure 2 shown. Specifically:
[0054] In step 3-1, scan the content of the memory kernel address space once;
[0055] The header of the pool allocation is a _POOL_HEADER structure. BlockSize is used to record the pool allocation size. In a 32-bit system, the pool allocation size is BlockSize multiplied by 8 bytes. In a 64-bit system, the pool allocation size is BlockSize multiplied by 16 bytes. PoolType is used to distinguish between paged pools and non-paged pools. Pooltag is used to uniquely mark the objects in the memory pool. The pool tag of the file object is "File". For the addresses containing the "File" tag in the scanned content, continue with the following judgment: Judge the BlockSize in the memory pool header. Since it is a 64-bit system, the pool allocation size is BlockSize multiplied by 16 bytes, and the PoolType is a non-paged pool;
[0056] In step 3-3, the file objects that pass the screening conditions are returned after the pool scan.
[0057] In step 4, reconstruct the PE file based on the file object. The specific steps are as follows:
[0058] In step 4-1, initialize the binary file f as the carrier of the PE file;
[0059] Step 4-2: The file object is in the form of a _FILE_OBJECT structure in memory. The SectionObjectPointers member in the structure stores a pointer to the _SECTION_OBJECT_POINTERS structure. The _SECTION_OBJECT_POINTERS structure contains three members: DataSectionObject, SharedCacheMap, and ImageSectionObject. Among them, the ImageSectionObject and DataSectionObject members are both used to track the memory regions of each section of the PE file. Obtain the starting position ControlArea of the _CONTROL_AREA structure through FileObject.SectionObjectPointer, and add 0x48 to the starting address of ControlArea to get the address of the _SUBSECTION structure;
[0060] Step 4-3: Obtain the PTEs of each page information through SubsectionBase of the _SUBSECTION structure;
[0061] Step 4-4: Write the PTEs with Valid and Transiton flag bits into the binary file f. A Valid flag bit of 1 indicates that this page exists in physical memory, and the physical memory address is pointed to by PageFrameNumber. When the PTE is in the Transiton state, the _MMPTE_TRANSITION structure is applied. Although the Valid flag bit is not set in the Transiton state, the page still exists in physical memory and can be obtained through the PageFrameNumber field.
[0062] Step 5: If the PE file contains a code signature, extract the digital certificate in the file and verify the credibility of the certificate, and return the verification result.
[0063] The flowchart for verifying the PE file and its code signature in the embodiments of the present invention is as Figure 2 and Figure 3 shown. The specific steps are as follows:
[0064] Step 5-1: First, define a variable pe_rebuilt with a default value of False to mark whether the PE file is successfully reconstructed. Judge whether the file object is correct. Extract the PE file from the memory based on the correct file object, and then continue to judge whether the PE file has missing pages. If there are no missing pages, judge whether the PE file type is DataSectionObject or ImageSectionObject. If it is of the ImageSectionObject type, use the enumeration method to restore the default loading base address of the PE file until the checksum of the PE file is successfully verified. If the reconstruction is successful, set the value of pe_rebuilt to True, and the program enters the next module to verify the signature. Otherwise, return that the reconstruction fails. If the PE file has missing pages, first judge whether the PE file can be read. If it can be read, judge whether the PE file contains an embedded signature. If there is an embedded signature, judge whether it is of the ImageSectionObject type. If so, verify whether the certificate chain in the PE header exists. If it exists, return the certificate chain verification. Otherwise, return the verification failure. If there is no embedded signature in the PE file, judge whether the directory where the file object is located is the system root directory. If so, return that it may be a signature file. Otherwise, return a non-signature file;
[0065] Step 5-2: Check whether the PE file contains a digital certificate;
[0066] Step 5-3: Judge whether the PE file contains an embedded signature. If it contains an embedded signature, calculate the hash value of the PE file and the hash value of the embedded signature. If they are equal, further perform the certificate chain verification. If the hash values are not equal, judge the value of pe_rebuilt. If it is True, return that the code signature does not match or the base address selection is incorrect. If it is False, return that the code signature does not match. If there is no embedded signature in the PE file, look for a matching hash value in the cat file in the system directory "C:\Windows\system32\catroot". If the match is successful, return that the signature verification is successful. Otherwise, verify whether the PE file path is located under the system root directory. If it is located under the root directory, return that it may be a signature file. Otherwise, continue to judge the value of pe_rebuilt. If it is True, return a non-signature file or the default base address selection is incorrect. If it is False, return a non-signature file.
[0067] The above is a detailed introduction to the embodiments of the present invention in combination with the accompanying drawings. The specific implementation manners herein are only used to help understand the method of the present invention. For those of ordinary skill in the art in this technical field, according to the idea of the present invention, various changes and modifications can be made within the specific implementation manners and application scope. Therefore, this specification of the present invention should not be construed as a limitation to the present invention.
Claims
1. A code signature verification method based on computer memory forensics technology, characterized in that The method includes the following steps: Step 1: Obtain the dump file of the computer's physical memory through a hardware interface or software; Step 2: Load the memory dump file into the Volatility forensic framework, search for the matching operating system version and configuration file, determine the system version kernel according to the configuration file, and identify the memory layout of the memory dump file; Step 3: Use the pool tag scanning technology to scan the file objects in the memory; Step 4: Reconstruct the PE file in the memory based on the file object. The specific process is as follows: Step 4-1 First, initialize the binary file f as the carrier of the PE file; Step 4-2 Obtain the _CONTROL_AREA structure through the SectionObjectPointer member of the file object, and obtain the _SUBSECTION structure at the offset of 0x48; Step 4-3 Obtain the PTE that records the information of each memory page through the SubsectionBase of the _SUBSECTION structure; Step 4-4 Write the PTE pages with Valid and Transition flag bits into the binary file f; Step 5: Verify the PE file and the code signature.
2. The code signature verification method based on computer memory forensics technology according to claim 1, wherein In Step 1, to obtain the dump file of the computer's physical memory through a hardware interface or software, the specific steps are as follows: Step 1-1 Determine whether the target system is a virtual machine. If so, take a snapshot file. If not, proceed to Step 1-2; Step 1-2 Determine whether the target system is in a running state. If not, check the hibernation file, crash dump, and paging file on the disk. If the target system is in a running state, proceed to Step 1-3; Step 1-3 Determine whether the operation permission of the target system is available. If the permission is available, generate a dump file by running the software. Otherwise, obtain the memory dump file through the hardware interface method.
3. The code signature verification method based on computer memory forensics technology according to claim 1, characterized in that, In Step 2, to load the memory dump file into the Volatility forensic framework and search for the matching operating system version and configuration file, the specific steps are as follows: Step 2-1 Search for and parse the kernel debug data block _KDDEBUGGER_DATA64; Step 2-2 Search for and parse the build string to obtain the major version number, minor version number, and service pack level of the operating system; Step 2-3 Import the kernel symbol file according to the version number.
4. The code signature verification method based on computer memory forensics technology according to claim 1, wherein In Step 3, to use the pool tag scanning technology to scan the file objects in the memory, the specific steps are as follows: Step 3-1 Scan the kernel address space of the memory; Step 3-2 Determine whether the content of the memory address is "File", whether the BlockSize is within the valid range, and whether the PoolType is NonePaged. If the above three conditions are met, output the file object. If any of the above conditions is not met, scan the next address; Step 3-3 Return the file object handle.
5. The code signature verification method based on computer memory forensics technology according to claim 1, wherein In Step 5, to verify the PE file and the code signature, the specific process is as follows: Step 5-1 Check the integrity of the PE file; Step 5-2 Check whether the PE file contains a digital certificate; Step 5-3 Verify the code signature by comparing the embedded certificate with the certificate in the directory.
Citation Information
Patent Citations
Software testing and evaluation method based on cloud computation technology
CN108255716A
Malicious program recognition method and device, storage medium and electronic equipment
CN113010268A