Process Detection Method, Device, Storage Medium, and Computer Device

By obtaining and analyzing the process's system call number and permission information, identifying and intercepting illegal escalation of power and socket communication tampering, the security risk problem of terminal devices is solved and the system's security is improved.

CN113836529BActive Publication Date: 2025-07-18GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202111046247.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-06
Publication Date
2025-07-18
Estimated Expiration
2041-09-06

AI Technical Summary

Technical Problem

The existing terminal devices lack effective restrictions on process permission management, resulting in extremely high security risks and are easily exploited by hackers for illegally raising rights and tampering with system settings.

Method used

By obtaining the system call number of the target process and its corresponding execution permissions, the original and set permission information are obtained, and the target process is intercepted based on this information, and illegal escalation of power or socket communication information tampering.

Benefits of technology

It effectively reduces the security risks of terminal devices, promptly intercepts illegal power-raising behaviors and exploits socket protocol vulnerabilities, and improves the security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113836529B_ABST
    Figure CN113836529B_ABST
Patent Text Reader

Abstract

The present application discloses a process detection method, device, storage medium, and computer device. The method includes: obtaining a system call number of a target process, obtaining an execution permission corresponding to the system call number, where the target process is a process of an application program in an execution state; if the execution permission indicates that the target process has the function of modifying process permissions, obtaining the original permission information and the set permission information of the target process; and performing an interception process on the target process based on the original permission information and the set permission information. By adopting the present application, when an illegal privilege escalation behavior is detected, the target process is intercepted in a timely manner, reducing the security risk of the terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security detection, and more particularly, to a process detection method, apparatus, storage medium, and computer device. Background Art

[0002] An application (APP) is a computer program in a terminal device, and its basic unit during execution is a process. Existing terminal devices do not restrict the relevant permissions of processes, making them extremely vulnerable to exploitation by hackers. For example, worms, Trojan viruses can be implanted, and system code can be maliciously modified, posing a very high security risk. Summary of the Invention

[0003] This application provides a process detection method, apparatus, storage medium, and computer device, which can solve the technical problem of how to improve the security risk of terminal devices.

[0004] In a first aspect, an embodiment of this application provides a process detection method, which includes:

[0005] Obtain the system call number of a target process, and obtain the execution permission corresponding to the system call number, where the target process is a process of an application program in an execution state;

[0006] If the execution permission indicates that the target process has the function of modifying process permissions, then obtain the original permission information and the set permission information of the target process;

[0007] Based on the original permission information and the set permission information, perform an interception process on the target process.

[0008] In a second aspect, an embodiment of this application provides a process detection method, which includes:

[0009] Obtain the system call number of a target process, where the target process is a process of an application program in an execution state;

[0010] If the system call number is a call number with socket call permission, then obtain the socket type that the target process needs to create during execution, and obtain the socket usage permission of the target process;

[0011] Based on the socket type and the socket usage permission, perform an interception process on the target process.

[0012] In a third aspect, an embodiment of this application provides a process detection apparatus, including:

[0013] An execution permission acquisition module, configured to obtain the system call number of a target process, and obtain the execution permission corresponding to the system call number, where the target process is a process of an application program in an execution state;

[0014] A process permission acquisition module, configured to acquire the original permission information and the set permission information of a target process if the execution permission indicates that the target process has the function of modifying process permissions;

[0015] An interception module, configured to perform interception processing on the target process based on the original permission information and the set permission information.

[0016] In a fourth aspect, an embodiment of the present application provides a process detection device, including:

[0017] A call number acquisition module, configured to acquire the system call number of a target process, where the target process is a process of an application program in an execution state;

[0018] A permission acquisition module, configured to acquire the socket type that the target process needs to create during execution and the socket usage permission of the target process if the system call number is a call number with socket call permissions;

[0019] An interception module, configured to perform interception processing on the target process based on the socket type and the socket usage permission.

[0020] In a fifth aspect, an embodiment of the present application provides a storage medium storing a computer program, and the computer program is adapted to be loaded and executed by a processor to perform the steps of the above method.

[0021] In a sixth aspect, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and the processor executes the program to implement the steps of the above method.

[0022] In the embodiments of the present application, by acquiring the original permission information and the set permission information of a process in an execution state, and then performing interception processing on the target process based on the original permission information and the set permission information to intercept the target process in time when an illegal privilege escalation behavior is detected, thereby reducing the security risk of the terminal device; it is also possible to acquire the socket type that the target process needs to create during execution and the socket usage permission of the target process, and then perform interception processing on the target process based on the socket type and the socket usage permission to intercept the target process in time when it is detected that a security vulnerability is exploited, thereby reducing the security risk of the terminal device. Description of the Drawings

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative efforts.

[0024] Figure 1 A flowchart of a process detection method provided by an embodiment of the present application;

[0025] Figure 2 A flowchart of a process detection method provided by an embodiment of the present application;

[0026] Figure 3 A flowchart of a process detection method provided by an embodiment of the present application;

[0027] Figure 4 A flowchart of a process detection method provided by an embodiment of the present application;

[0028] Figure 5 A flowchart of a process detection method provided by an embodiment of the present application;

[0029] Figure 6 A flowchart of a process detection method provided by an embodiment of the present application;

[0030] Figure 7 A structural diagram of a process detection device provided by an embodiment of the present application;

[0031] Figure 8 A structural diagram of a process detection device provided by an embodiment of the present application;

[0032] Figure 9 A structural diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners

[0033] To make the features and advantages of the present application more obvious and understandable, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.

[0034] When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims. The flowcharts shown in the drawings are only illustrative and not necessarily executed in the order shown. For example, some steps are parallel and there is no strict sequence in logic, so the actual execution order can be variable. In addition, the terms "first", "second", "third", "fourth", "fifth", "sixth", "seventh", "eighth" are only for the purpose of distinction and should not be construed as a limitation of the present disclosure.

[0035] The process detection method and process detection device disclosed in the embodiments of the present application can be applied to the field of security detection, such as system protection of terminal devices, security scanning of application programs, etc. The process detection device can include, but is not limited to, intelligent interactive tablets, mobile phones, personal computers, laptop computers and other intelligent terminals.

[0036] In the embodiments of the present application, the process detection device can obtain the original permission information and set permission information of the process in the execution state, and then perform an interception process on the target process based on the original permission information and the set permission information to intercept the target process in time when an illegal privilege escalation behavior is detected; it can also obtain the socket type required to be created during the execution of the target process and the socket usage permission of the target process, and then perform an interception process on the target process based on the socket type and the socket usage permission, that is, identify whether the socket communication information between the target process and other processes is tampered with. If it is detected that the socket communication information is tampered with, it indicates that the security vulnerability of the socket protocol is exploited, so as to intercept the target process in time when it is detected that the security vulnerability is exploited.

[0037] The following will be combined with Figures 1 to 6 , and a detailed introduction will be given to the process detection method provided by the embodiments of the present application.

[0038] Since application programs can apply for some sensitive permissions, such as CAP_SETUID, CAP_SETGID, etc., these permissions have the ability to modify the process permissions, and the terminal device will regard the execution process of the application program with sensitive permissions as a secure process and will not intercept its execution process. If a third-party application program with unknown security risks applies for sensitive permissions, such as a malicious application implanted by a hacker, since the terminal device does not restrict the application program with sensitive permissions, the execution process of the third-party application program can achieve the purpose of tampering with the system settings, core code, security mechanism, etc. of the terminal device by increasing the process permissions, making the terminal device at a very high security risk.

[0039] Please refer to Figure 1 , which provides a schematic flowchart of a process detection method for an embodiment of this application. As Figure 1 shown, the method may include the following steps S101 to step S103.

[0040] S101, obtain the system call number of the target process, and obtain the execution permission corresponding to the system call number, where the target process is the process of the application program in the execution state.

[0041] Specifically, the terminal device responds to the execution instruction of the application program, executes the application program, and at the same time obtains the anchor address corresponding to the system input anchor of the application program, and then sets a hook function at this anchor address, so that when the application program executes to the system input anchor, it jumps to execute this hook function. It should be noted that this hook function is the process detection step defined in this embodiment.

[0042] When the application program is executing, it creates a process to execute the program code in the application program; the system call number is the identification information of the system call, and the system call is a set of subroutines used to implement system functions. The process of the application program realizes system functions through system calls. Exemplarily, the process of the application program sends a service request to the operating system through a system call to obtain the services provided by the operating system, thereby realizing the functions of the application program. It should be noted that different system calls can implement different system functions. Specifically, different system calls have different execution permissions.

[0043] The terminal device responds to the execution instruction of the application program, executes the application program, and uses the process generated by the application program as the target process, then obtains the system call number of the system call currently requested by the target process in the process structure of the target process, and then obtains the execution permission corresponding to the system call number.

[0044] It should be noted that the process structure of the process stores the system call number of the system call currently requested by the process, the original permission information of the process, and the set permission information set by the system call.

[0045] Optionally, the terminal device may first obtain the security status of the terminal device. If the terminal device is not in a security protection state, the process detection step is directly ended; if the terminal device is in a security protection state, the process detection step is executed. Or rather, the terminal device may first detect whether the terminal device is locked. If the terminal device is not locked, the process detection step is directly ended; if the terminal device is locked, the process detection step is executed. Exemplarily, the terminal device stores a boot file of the terminal device, and the boot file may be a cmdline file. Then, the boot status value of the terminal device is obtained in the boot file, and the boot status value may be an android.verifiedbootstate value. If the boot status value is orange (device unlocked status value), it is determined that the terminal device is not in a security protection state, or rather, it is determined that the terminal device is not in a locked state.

[0046] S102. If the execution permission indicates that the target process has the function of modifying process permissions, obtain the original permission information and the set permission information of the target process.

[0047] Specifically, the execution permission with the ability to modify process permissions may be the CAP_SETUID permission or the CAP_SETGID permission.

[0048] After the terminal device obtains the execution permission corresponding to the system call number, compare the execution permission corresponding to the system call number with the CAP_SETUID permission, and compare the execution permission corresponding to the system call number with the CAP_SETGID permission. If the execution permission corresponding to the system call number matches any one of the CAP_SETUID permission or the CAP_SETGID permission, it is determined that the execution permission corresponding to the system call number has the function of modifying process permissions, and then the original permission information and the set permission information of the target process are obtained in the process structure of the target process.

[0049] It should be noted that the original permission information of the target process is the process permission of the target process. The set permission information of the target process refers to the process permission of the target process that the system call currently called by the target process intends to set.

[0050] S103. Based on the original permission information and the set permission information, perform an interception process on the target process.

[0051] Specifically, the terminal device determines whether the target process has an illegal privilege elevation behavior based on the original permission information and the set permission information. If the target process has an illegal privilege elevation behavior, an interception process is performed on the target process.

[0052] In the embodiment of the present application, by obtaining the original permission information and the set permission information of a process in the execution state, and then intercepting the target process based on the original permission information and the set permission information, the target process can be intercepted in a timely manner when an illegal privilege escalation behavior is detected, thereby reducing the security risk of the terminal device.

[0053] Please refer to Figure 2 , which is a schematic flow chart of a process detection method provided by the embodiment of the present application. As Figure 2 shown, the method may include the following steps S201 to step S206.

[0054] S201, obtain the system call number of the target process, where the target process is the process of an application program in the execution state.

[0055] Specifically, in response to the execution instruction of the application program, the terminal device executes the application program, and takes the process generated by the application program as the target process, and then obtains the system call number of the system call currently requested by the target process in the process structure of the target process.

[0056] S202, if the system call number matches any sample call number in the call number set, obtain the execution permission corresponding to the system call number.

[0057] Specifically, each sample call number included in the call number set includes, but is not limited to, SETUID, SETEUID, SETRESUID, SETGID, SETEGID, and SETRESGID. A sample call with a call number as a sample call can request the execution permission for modifying the process permission from the kernel of the operating system. The execution permission with the ability to modify the process permission can be the CAP_SETUID permission or the CAP_SETGID permission. The execution permission corresponding to the system call number is specifically the execution permission of the system call in the target process corresponding to the system call number. It should be noted that although the system call corresponding to the system call number that matches the sample call number has the ability to modify the process, in the actual call process, whether the system call requests the CAP_SETUID permission or the CAP_SETGID permission from the kernel of the operating system is determined by the target process. Specifically, the system call corresponding to the system call number can request the execution permission for modifying the process permission from the kernel of the operating system, but whether to request the execution permission for modifying the process permission cannot be obtained only based on the system call number.

[0058] The process structure of the target process stores the system call number of the system call currently called by the target process and the execution permission of the system call.

[0059] After the terminal device obtains the system call number currently called by the target process, it compares the system call number with each sample call number in the call number set. If the system call number matches any sample call number in the call number set, it determines the system call corresponding to the system call number, and then obtains the execution permission of the system call.

[0060] In the embodiment of the present application, since a process may have multiple system calls, by determining whether the system call number matches the sample call number in the call number set, system calls that may have the ability to modify the process permission are screened out among many system calls, improving the process detection speed.

[0061] S203, if the execution permission indicates that the target process has the function of modifying the process permission, obtain the original permission information and the set permission information of the target process.

[0062] Specifically, the terminal device compares the execution permission of the system call with the CAP_SETUID permission, and compares the execution permission of the system call with the CAP_SETGID permission. If the execution permission of the system call matches any one of the CAP_SETUID permission or the CAP_SETGID permission, it is determined that the execution permission of the system call has the function of modifying the process permission, and then the original permission information and the set permission information of the target process are obtained in the process structure of the target process.

[0063] It should be noted that if the execution permission of the system call does not match both the CAP_SETUID permission and the CAP_SETGID permission, the system call will be directly intercepted by the native security protection mechanism of the terminal device.

[0064] S204, based on the original permission information and the set permission information, obtain the process type of the target process.

[0065] Specifically, the process type includes a legitimate process and a malicious process, where a malicious process refers to a process that has a privilege escalation behavior.

[0066] The terminal device determines whether the process permission indicated by the original permission information is the process permission of a third-party application. Exemplarily, a third-party application may refer to an application program that is not inside the terminal device. More specifically, it is an application program other than the application programs generated by the manufacturer of the terminal device, and its security is unknown. It should be noted that the application programs inside the terminal device are application programs whose security has been verified by the terminal device or the manufacturer at the initial stage and determined to be secure.

[0067] If the process permission indicated by the original permission information is not the process permission of a third-party application, it is determined that the target process does not have an illegal privilege escalation behavior, and further determined that the process type of the target process is a legitimate process;

[0068] If the process permission indicated by the original permission information is the process permission of a third-party application, the terminal device determines whether the process permission indicated by the set permission information is a system permission. If the process permission indicated by the set permission information is not a system permission, it is determined that there is no illegal privilege escalation behavior in the target process, and further, it is determined that the process type of the target process is a legitimate process.

[0069] If the process permission indicated by the set permission information is a system permission, it is determined that there is an illegal privilege escalation behavior in the target process, and further, it is determined that the process type of the target process is a malicious process.

[0070] S205, if the process type indicates that the target process is a malicious process, intercept the target process.

[0071] Specifically, when the process type of the target process is a malicious process, the terminal device intercepts the target process.

[0072] In the embodiments of the present application, by using the original process information and the set process information to identify whether there is an illegal privilege escalation behavior in the target process, so as to determine whether the target process is a malicious process, and then intercept the malicious target process in time, thereby reducing the security risk of the terminal device.

[0073] S206, obtain the process information of the target process, and record the process information of the target process as malicious process information.

[0074] Specifically, the terminal device obtains the process information of the target process, including but not limited to the process identification number, user identification number, group identification number, original permission information, set permission information, process type, etc. The terminal device saves the obtained process information as malicious process information, so as to identify whether the process created by the application program is a malicious process according to the malicious process information when receiving the execution instruction of the application program again. If it is identified that the process created by the application program is a malicious process, the process of creating the process by the application program is directly intercepted.

[0075] Optionally, the terminal device can also send the process information to the kernel process of the terminal device through a socket, and then perform data logging at the kernel process, so as to directly intercept the creation behavior when the kernel process creates the target process corresponding to the application program. It should be noted that when receiving the creation instruction of the application program, the process is created by the kernel process to execute the application program.

[0076] In the embodiments of the present application, by using the process information of the intercepted target process as malicious process information, when the target process is created and executed again, it can be directly identified as a malicious process and intercepted, improving the process detection speed.

[0077] Please refer to Figure 3, which provides a schematic flowchart of a process detection method for an embodiment of the present application. As Figure 3 shown, the method may include the following steps S301 to S306.

[0078] S301, obtain the system call number of the target process, and obtain the execution permission corresponding to the system call number. The target process is the process of an application program in the execution state.

[0079] Specifically, refer to step S201 and step S202, which will not be elaborated here.

[0080] S302, if the execution permission indicates that the target process has the function of modifying process permissions, then obtain the original permission information and the set permission information of the target process.

[0081] Specifically, refer to step S203, which will not be elaborated here.

[0082] It should be noted that the original permission information of the target process refers to the process permission value of the target process, including at least one of the original UID (User ID) and the original GID (Group ID) of the target process; the set permission information of the target process is the process permission value of the target process that the system call currently called by the target process wants to set, including at least one of the set UID and the set GID of the target process. Both UID and GID are recorded in numerical form.

[0083] S303, obtain the original process permission value of the target process in the original permission information, and obtain the set process permission value of the target process in the set permission information.

[0084] Specifically, obtain the original process permission value of the target process, that is, obtain the original UID and the original GID of the target process, and obtain the set process permission value of the target process, that is, obtain the set UID and the set GID that the system call of the target process wants to set.

[0085] S304, if the original process permission value is greater than or equal to the permission threshold, and the set process permission value is less than the permission threshold, then determine that the process type of the target process is a malicious process.

[0086] Specifically, the permission threshold may be the minimum permission value of the process permissions of a third-party application, that is, 10000. Specifically, if the process permission value is greater than or equal to the permission threshold, the process permission of the target process is the process permission of a third-party application; if the process permission value is less than the permission threshold, the process permission of the target process is the system permission; it should be noted that the smaller the permission value, the higher the permission level. It should be noted that the permission threshold may also be other permission values, and this embodiment does not limit that the permission threshold must be the minimum permission value of the process permissions of a third-party application.

[0087] The terminal device compares the original UID in the original permission information with the permission threshold, and compares the original GID in the original permission information with the permission threshold; if the original UID is greater than or equal to the permission threshold, or the original GID is greater than or equal to the permission threshold, then it compares the set UID in the set permission information with the permission threshold, and compares the set GID in the set permission information with the permission threshold. If the set UID is greater than or equal to the permission threshold, or the set GID is greater than or equal to the permission threshold, it determines that the target process has an illegal privilege escalation behavior, and further determines that the process type of the target process is a malicious process.

[0088] If both the original UID and the original GID are less than the permission threshold, it directly determines that the process type of the target process is a legitimate process; if both the set UID and the set GID are greater than or equal to the permission threshold, it directly determines that the process type of the target process is a legitimate process.

[0089] In the embodiment of the present application, by comparing the original process permission value with the permission threshold, comparing the set process permission value with the permission threshold, and then identifying whether the target process has an illegal privilege escalation behavior based on the judgment result, the target process can be intercepted in time when an illegal privilege escalation behavior is detected, thereby reducing the security risk of the terminal device.

[0090] S305, if the process type indicates that the target process is a malicious process, modify the set permission information of the target process to the original permission information of the target process, and continue to execute the target process.

[0091] Specifically, when the process type of the target process is a malicious process, the terminal device modifies the set permission information of the system call currently invoked by the target process to the original permission information of the target process.

[0092] S306, if the process type indicates that the target process is a malicious process, stop executing the target process.

[0093] Specifically, when the process type of the target process is a malicious process, the terminal device directly stops executing the target process. Exemplarily, the target process can be directly killed by calling do_exit().

[0094] In the embodiment of the present application, by modifying the set permission information of the system call currently invoked by the target process to the original permission information of the target process, while avoiding illegal privilege escalation behavior, it ensures the normal operation of the application program so that the application program can implement its functions. Or by stopping the execution of the target process, the application program stops running due to an execution error, thereby avoiding illegal privilege escalation behavior and improving the security of the terminal device.

[0095] Since there are a large number of processes in the operating system of the terminal device, and the processes communicate with each other through sockets, and there are certain security vulnerabilities in the existing socket protocols, that is, by illegally tampering with the relevant information of the sockets used for communication between processes, the system memory of the terminal device is damaged, making the terminal device at extremely high security risks.

[0096] Please refer to Figure 4 , which provides a schematic flowchart of a process detection method for an embodiment of this application. As Figure 4 shown, the method may include the following steps S401 to step S403.

[0097] S401, obtain the system call number of the target process, where the target process is the process of an application program in an execution state.

[0098] Specifically, in response to an execution instruction of the application program, the terminal device executes the application program, and at the same time obtains the anchor point address corresponding to the system output anchor point of the application program, and then sets a hook function at this anchor point address, so that when the application program executes to the system input anchor point, it jumps to execute this hook function. It should be noted that this hook function is the process detection step defined in this embodiment.

[0099] When the application program is executing, it creates a process to execute the program code in the application program; the system call number is the identification information of the system call, and the system call is a set of subroutines used to implement system functions, and the process of the application program realizes system functions through system calls. Exemplarily, the process of the application program sends a service request to the operating system through the system call to obtain the services provided by the operating system, and then realizes the functions of the application program.

[0100] In response to an execution instruction of the application program, the terminal device executes the application program, and takes the process generated by the application program as the target process, and then obtains the system call number of the system call currently requested by the target process in the process structure of the target process.

[0101] It should be noted that the process structure of the process stores the system call number of the system call currently requested by the process and the original permission information of the process.

[0102] Optionally, the terminal device may first obtain the security status of the terminal device. If the terminal device is not in a security protection state, the process detection step is directly ended. If the terminal device is in a security protection state, the subsequent process detection steps are executed. Or, the terminal device may first detect whether the terminal device is locked. If the terminal device is not locked, the process detection step is directly ended. If the terminal device is locked, the process detection step is executed. Exemplarily, the terminal device stores a boot file of the terminal device, and the boot file may be a cmdline file. Then, the boot state value of the terminal device is obtained in the boot file, and the boot state value may be an android.verifiedbootstate value. If the boot state value is orange (device unlocked state value), it is determined that the terminal device is not in a security protection state, or in other words, it is determined that the terminal device is not in a locked state.

[0103] S402, if the system call number is a call number with socket call permission, obtain the socket type required to be created during the execution of the target process, and obtain the socket usage permission of the target process.

[0104] Specifically, the terminal device compares the currently obtained system call number with the call number with socket call permission. If the currently obtained system call number matches the call number with socket call permission, obtain the socket type required to be created during the execution of the target process. Specifically, it is the socket type required to be created by the system call currently invoked by the target process, and this system call is the system call corresponding to the currently obtained system call number. The terminal device obtains the socket usage permission of the target process.

[0105] It should be noted that the socket usage permission of the process is stored in the process structure of the process; when there is a call number with socket call permission, the socket type of the socket required to be created by the system call with socket call permission is also stored in the process structure of the process.

[0106] Exemplarily, the call numbers with socket call permission include but are not limited to _NR_socket.

[0107] S403, based on the socket type and the socket usage permission, perform an interception process on the target process.

[0108] Specifically, the terminal device determines whether the socket communication information between the target process and other processes is tampered with based on the socket type and the socket usage permission. If it is detected that the socket communication information is tampered with, it is determined that the target process is performing an illegal operation by taking advantage of the security vulnerability of the socket protocol, and there is a risk of maliciously damaging the system memory. Then, an interception process is performed on the target process.

[0109] In an embodiment of the present application, by obtaining the socket types required to be created during the execution of a target process and the socket usage permissions of the target process, and then intercepting the target process based on the socket types and socket usage permissions, that is, identifying whether the socket communication information between the target process and other processes is tampered with. If it is detected that the socket communication information is tampered with, it indicates that a security vulnerability in the socket protocol is exploited, so as to intercept the target process in a timely manner when a security vulnerability is detected, thereby reducing the security risk of the terminal device.

[0110] Please refer to Figure 5 , which is a schematic flow diagram of a process detection method provided by an embodiment of the present application. As Figure 5 shown, the method may include the following steps S501 to step S506.

[0111] S501, obtain the system call number of the target process, where the target process is the process of an application program in the execution state.

[0112] Specifically, refer to step S401 for details, which will not be elaborated here.

[0113] S502, if the system call number is a call number with socket call permission, obtain the socket protocol family required to be created during the execution of the target process.

[0114] Specifically, the process structure of the process stores the socket usage permissions of the process and the return value that the target process will receive when the execution is successful; when there is a call number with socket call permission, the process structure of the process also stores socket information such as the socket type required to create a socket by the system call with socket call permission and the socket protocol family to which the socket belongs.

[0115] After the terminal device obtains the system call number currently called by the target process, compare the system call number with the call number with socket call permission. If the system call number matches the call number with socket call permission, obtain the socket protocol family to which the socket created by the system call belongs in the process structure of the target process.

[0116] S503, if the socket protocol family is the same as the target socket protocol family, obtain the socket type in the system call corresponding to the system call number, and obtain the socket usage permissions of the target process.

[0117] Specifically, the target socket protocol family includes but is not limited to the AF_NETLINK protocol family.

[0118] After the terminal device obtains the socket protocol family to which the socket to be created by the system call belongs, it compares the socket protocol family with the target socket protocol family. If the socket protocol family matches the target socket protocol family, it obtains the socket type of the socket to be created by the system call corresponding to the system call number in the process structure of the target process, and the socket usage permission of the target process in the process structure of the target process.

[0119] In the embodiment of the present application, since there are multiple system calls in a process, by determining whether the system call number matches the call number with socket call permission, the system calls that may exploit socket security vulnerabilities are screened out among many system calls, improving the process detection speed; since the protocol families to which the sockets belong are different, and the sockets of non-target socket protocol families do not have socket security vulnerabilities, by determining whether the socket protocol family matches the target socket protocol family, the system calls that may exploit socket security vulnerabilities are further screened out among the system calls obtained by the foregoing screening, improving the process detection speed.

[0120] S504, based on the socket type and the socket usage permission, obtain the process type of the target process.

[0121] Specifically, the process type includes a legitimate process and a malicious process, where the malicious process refers to a process that has a privilege escalation behavior.

[0122] The terminal device determines whether the target process has the usage permission of the socket type required for the system call of the target process. If the target process has the usage permission of this socket type, it is determined that the target process does not have the behavior of illegally tampering with socket communication information, and further it is determined that the process type of the target process is a legitimate process; if the target process does not have the usage permission of this socket type, it is determined that the target process has the behavior of illegally tampering with socket communication information, and further it is determined that the process type of the target process is a malicious process.

[0123] In the embodiment of the present application, by the socket type required for the system call of the target process and the socket usage permission of the target process, it is identified whether there is an illegal tampering behavior of socket communication information in the target process, so as to determine whether the target process is a malicious process, and then the malicious target process is intercepted in time, thereby reducing the security risk of the terminal device.

[0124] S505, if the process type indicates that the target process is a malicious process, obtain the return address of the target process, and modify the return value on the return address to an error value.

[0125] Specifically, when the process type of the target process is a malicious process, the terminal device obtains the return address of the target process, and then modifies the return value on the return address to an error value, so that the target process stops executing due to an incorrect return value (equivalent to an incorrect execution). Exemplarily, if the legitimate return value of the target process is "1", the return value on the return address is modified to a value or character inconsistent with "1", such as "0" or "err".

[0126] Optionally, the terminal device can also directly kill the target process by calling do_exit().

[0127] In the embodiment of the present application, by stopping the execution of the target process, the application stops running due to an execution error, thereby avoiding illegal privilege escalation behavior and improving the security of the terminal device.

[0128] S506, obtain the process information of the target process, and record the process information of the target process as malicious process information.

[0129] Specifically, the terminal device obtains the process information of the target process, including but not limited to the process identification number, user identification number, group identification number, original permission information, set permission information, process type, etc. The terminal device saves the aforementioned obtained process information as malicious process information, so as to, when receiving an execution instruction of the application again, identify whether the process created by the application is a malicious process according to the malicious process information. If it is identified that the process created by the application is a malicious process, the process of creating the process by the application is directly intercepted.

[0130] Optionally, the terminal device can also send the process information to the kernel process of the terminal device through a socket, and then perform data logging at the kernel process, so as to directly intercept the creation behavior when the kernel process creates the target process corresponding to the application. It should be noted that when receiving a creation instruction of the application, the process is created by the kernel process to execute the application.

[0131] In the embodiment of the present application, by taking the process information of the intercepted target process as malicious process information, when the target process is created and executed again, it is directly identified as a malicious process and the target process is intercepted, improving the process detection speed.

[0132] Please refer to Figure 6 , which shows a schematic flowchart of a process detection method provided by an embodiment of the present application. As Figure 6 shown, the method may include the following steps S601 to S605.

[0133] S601, obtain the system call number of the target process, where the target process is the process of an application in an execution state.

[0134] For details, please refer to step S401, which will not be elaborated here.

[0135] S602, if the system call number has socket call permission, obtain the original permission information of the target process.

[0136] Specifically, after the terminal device obtains the system call number currently called by the target process, it compares the system call number with the system call number with socket call permission. If the system call number matches the system call number with socket call permission, the original permission information of the target process is obtained from the process structure of the target process.

[0137] It should be noted that the original permission information of the target process refers to the process permission value of the target process, including at least one of the original UID (User ID) and the original GID (Group ID) of the target process. Both UID and GID are recorded in numerical form.

[0138] S603, if the original process permission value in the original permission information is greater than or equal to the permission threshold, obtain the socket type in the system call corresponding to the system call number, and obtain the socket usage permission of the target process.

[0139] Specifically, the permission threshold can be the minimum permission value of the process permission of a third-party application, that is, 10000. Specifically, if the process permission value is greater than or equal to the permission threshold, the process permission of the target process is the process permission of the third-party application; if the process permission value is less than the permission threshold, the process permission of the target process is the system permission; it should be noted that the smaller the permission value, the higher the permission level. It should be noted that the permission threshold can also be other permission values, and this embodiment does not limit that the permission threshold must be the minimum permission value of the process permission of a third-party application.

[0140] The terminal device determines whether the process permission indicated by the original permission information is the process permission of a third-party application. Exemplarily, a third-party application can refer to an application program that is not inside the terminal device. More specifically, it is an application program other than the application programs generated by the manufacturer of the terminal device, and its security is unknown. It should be noted that the application programs inside the terminal device are application programs whose security has been verified by the terminal device or the manufacturer at the initial stage and determined to be secure.

[0141] If the process permission indicated by the original permission information is not the process permission of a third-party application, it is determined that the target process does not have the behavior of illegally tampering with socket communication information, and further it is determined that the process type of the target process is a legal process.

[0142] If the process permission indicated by the original permission information is the process permission of a third-party application, obtain the socket type of the socket required for the system call corresponding to the system call number in the process structure of the target process, and obtain the socket usage permission of the target process in the process structure of the target process.

[0143] In the embodiment of the present application, since the process corresponding to the recognized secure application has the ability to modify socket communication information, and there are multiple system calls in a process, by determining whether the process permission of the target process has the ability to modify socket communication information, system calls that may exploit socket security vulnerabilities are screened out among numerous system calls, improving the process detection speed.

[0144] S604, if the socket type is the same as the original socket type, and the socket usage permission is different from the original socket usage permission, determine that the process type of the target process is a malicious process.

[0145] Specifically, the original socket type refers to SOCK_RAW, and the original socket usage permission refers to the CAP_NET_RAW permission. A process can damage the system memory through raw socket communication. Therefore, the terminal device restricts the process from applying for the usage permission of the raw socket.

[0146] The terminal device first compares the socket type of the socket required to be created by the system call of the target process with the original socket type. If the socket type of the required created socket does not match the original socket type, it is determined that the target process does not have a system call that exploits the socket security vulnerability, and further determine that the target process is a legitimate process.

[0147] If the socket type of the required created socket matches the original socket type, then compare the socket usage permission of the target process with the original socket usage permission. If the socket usage permission of the target process matches the original socket usage permission, it is determined that the target process does not have a system call that exploits the socket security vulnerability, and further determine that the target process is a legitimate process.

[0148] If the socket usage permission of the target process does not match the original socket usage permission, it is determined that the target process has a system call that exploits the socket security vulnerability, and further determine that the target process is a malicious process.

[0149] S605, if the process type indicates that the target process is a malicious process, intercept the target process.

[0150] Specific reference can be made to S505, which will not be elaborated here.

[0151] In the embodiment of the present application, by comparing the socket type of the socket to be created for the system call of the target process with the original socket type, and comparing the socket usage permission of the target process with the original socket usage permission, and then based on the judgment result, it is identified whether the target process has a system call that exploits a socket security vulnerability, so as to intercept the target process in time when a system call that exploits a socket security vulnerability is detected, thereby reducing the security risk of the terminal device.

[0152] The following will combine with the attached Figure 7 ~attached Figure 8 The process detection device provided in the embodiment of the present application will be introduced in detail. It should be noted that the attached Figure 7 ~attached Figure 8 The process detection device is used to execute the method of the embodiment of the present application Figures 1 to 6 shown in the embodiment. For the sake of convenience of description, only the parts related to the embodiment of the present application are shown. For the specific technical details not disclosed, please refer to the embodiment Figures 1 to 6 shown in the present application.

[0153] Please refer to Figure 7 , which is a schematic structural diagram of a process detection device provided in an embodiment of the present application. As Figure 7 shown, the process detection device 1 in the embodiment of the present application may include: an execution permission acquisition module 101, a process permission acquisition module 102, and an interception module 103.

[0154] The execution permission acquisition module 101 is used to acquire the system call number of the target process and acquire the execution permission corresponding to the system call number, where the target process is the process of an application program in the execution state;

[0155] The process permission acquisition module 102 is used to acquire the original permission information and the set permission information of the target process if the execution permission indicates that the target process has the function of modifying the process permission;

[0156] The interception module 103 is used to perform interception processing on the target process based on the original permission information and the set permission information.

[0157] In the embodiment of the present application, by acquiring the original permission information and the set permission information of the process in the execution state, and then performing interception processing on the target process based on the original permission information and the set permission information, so as to intercept the target process in time when an illegal privilege elevation behavior is detected, thereby reducing the security risk of the terminal device.

[0158] Optionally, the execution permission acquisition module 101 is specifically used for:

[0159] If the system call number matches any sample call number in the call number set, the execution permission corresponding to the system call number is acquired.

[0160] Optionally, the interception module 103 is specifically configured to:

[0161] Obtain the process type of the target process based on the original permission information and the set permission information;

[0162] If the process type indicates that the target process is a malicious process, intercept the target process.

[0163] Optionally, the interception module 103 is specifically configured to:

[0164] Obtain the original process permission value of the target process in the original permission information, and obtain the set process permission value of the target process in the set permission information;

[0165] If the original process permission value is greater than or equal to the permission threshold and the set process permission value is less than the permission threshold, determine that the process type of the target process is a malicious process.

[0166] Optionally, the interception module 103 is specifically configured to:

[0167] Modify the set permission information of the target process to the original permission information of the target process, and continue to execute the target process; or,

[0168] Stop executing the target process.

[0169] Optionally, please refer to Figure 7 , the process detection device 1 further includes: a recording module 104.

[0170] The recording module 104 is configured to obtain the process information of the target process and record the process information of the target process as malicious process information.

[0171] Please refer to Figure 8 , which provides a schematic structural diagram of a process detection device for an embodiment of the present application. As Figure 8 shown, the process detection device 2 of the embodiment of the present application may include: a call number acquisition module 201, a permission acquisition module 202, and an interception module 203.

[0172] The call number acquisition module 201 is configured to obtain the system call number of the target process, where the target process is the process of an application program in an execution state;

[0173] The permission acquisition module 202 is configured to, if the system call number is a call number with socket call permission, obtain the socket type required to be created during the execution of the target process and obtain the socket usage permission of the target process;

[0174] The interception module 203 is configured to intercept the target process based on the socket type and the socket usage permission.

[0175] In an embodiment of the present application, by obtaining the socket types required to be created during the execution of the target process and the socket usage permissions of the target process, and then intercepting the target process based on the socket types and socket usage permissions, that is, identifying whether the socket communication information between the target process and other processes has been tampered with. If it is detected that the socket communication information has been tampered with, it indicates that a security vulnerability in the socket protocol has been exploited, so as to intercept the target process in a timely manner when a security vulnerability is detected, thereby reducing the security risk of the terminal device.

[0176] Optionally, the interception module 203 is specifically configured to:

[0177] Based on the socket types and socket usage permissions, obtain the process type of the target process;

[0178] If the process type indicates that the target process is a malicious process, intercept the target process.

[0179] Optionally, the interception module 203 is specifically configured to:

[0180] If the socket type is the same as the original socket type and the socket usage permissions are inconsistent with the original socket usage permissions, determine that the process type of the target process is a malicious process.

[0181] Optionally, the permission acquisition module 202 is specifically configured to:

[0182] If the system call number is a call number with socket call permission, obtain the socket protocol family required to be created during the execution of the target process;

[0183] If the socket protocol family is the same as the target socket protocol family, obtain the socket type in the system call corresponding to the system call number, and obtain the socket usage permissions of the target process.

[0184] Optionally, the permission acquisition module 202 is specifically configured to:

[0185] If the system call number is a call number with socket call permission, obtain the original permission information of the target process;

[0186] If the original process permission value in the original permission information is greater than or equal to the permission threshold, obtain the socket type in the system call corresponding to the system call number, and obtain the socket usage permissions of the target process.

[0187] Optionally, the interception module 203 is specifically configured to:

[0188] Obtain the return address of the target process and modify the return value on the return address to an error value.

[0189] Optionally, the process detection device 2 further includes: a recording module 204.

[0190] A recording module 204 is configured to obtain process information of a target process and record the process information of the target process as malicious process information.

[0191] An embodiment of the present application further provides a storage medium, which can store multiple program instructions. The program instructions are suitable for being loaded and executed by a processor to perform the method steps of the embodiments as described above. Figures 1 to 6 For the specific execution process, reference can be made to Figures 1 to 6 the specific description of the embodiments as shown. Details are not described herein again.

[0192] Please refer to Figure 9 , which is a schematic structural diagram of a computer device provided by an embodiment of the present application. As Figure 9 shown, the computer device 1000 may include: at least one processor 1001, at least one memory 1002, at least one network interface 1003, at least one input / output interface 1004, at least one communication bus 1005, and at least one display unit 1006. Among them, the processor 1001 may include one or more processing cores. The processor 1001 connects various parts within the entire computer device 1000 through various interfaces and lines, and executes various functions of the terminal 1000 and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 1002, and by calling data stored in the memory 1002. The memory 1002 may be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. Optionally, the memory 1002 may further be at least one storage device located far from the aforementioned processor 1001. Among them, the network interface 1003 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The communication bus 1005 is used to implement connection communication between these components. As Figure 9 shown, the memory 1002, as a storage medium of a terminal device, may include an operating system, a network communication module, an input / output interface module, and a process detection program.

[0193] In Figure 9 the computer device 1000 as shown, the input / output interface 1004 is mainly used to provide an input interface for users and access devices, and obtain data input by users and access devices.

[0194] In one embodiment.

[0195] The processor 1001 may be used to call the process detection program stored in the memory 1002 and specifically perform the following operations:

[0196] Obtain the system call number of the target process, and obtain the execution permission corresponding to the system call number. The target process is the process of the application program in the execution state;

[0197] If the execution permission indicates that the target process has the function of modifying process permissions, obtain the original permission information and the set permission information of the target process;

[0198] Based on the original permission information and the set permission information, perform an interception process on the target process.

[0199] Optionally, when the processor 1001 executes to obtain the execution permission corresponding to the system call number, the following operations are specifically performed:

[0200] If the system call number matches any sample call number in the call number set, obtain the execution permission corresponding to the system call number.

[0201] Optionally, when the processor 1001 executes to perform an interception process on the target process based on the original permission information and the set permission information, the following operations are specifically performed:

[0202] Based on the original permission information and the set permission information, obtain the process type of the target process;

[0203] If the process type indicates that the target process is a malicious process, perform an interception process on the target process.

[0204] Optionally, when the processor 1001 executes to obtain the process type of the target process based on the original permission information and the set permission information, the following operations are specifically performed:

[0205] Obtain the original process permission value of the target process in the original permission information, and obtain the set process permission value of the target process in the set permission information;

[0206] If the original process permission value is greater than or equal to the permission threshold and the set process permission value is less than the permission threshold, determine that the process type of the target process is a malicious process.

[0207] Optionally, when the processor 1001 executes to perform an interception process on the target process, the following operations are specifically performed:

[0208] Modify the set permission information of the target process to the original permission information of the target process, and continue to execute the target process; or,

[0209] Stop executing the target process.

[0210] Optionally, after the processor 1001 executes if the target process is a malicious process, then intercept the target process, and the following operations are also performed:

[0211] Obtain the process information of the target process, and record the process information of the target process as malicious process information.

[0212] In the embodiments of the present application, by obtaining the original permission information and the set permission information of the process in the execution state, and then performing an interception process on the target process based on the original permission information and the set permission information, the target process can be intercepted in time when an illegal privilege escalation behavior is detected, thereby reducing the security risk of the terminal device.

[0213] In another embodiment.

[0214] The processor 1001 can be used to call the process detection program stored in the memory 1002, and specifically perform the following operations:

[0215] Obtain the system call number of the target process, where the target process is the process of the application program in the execution state;

[0216] If the system call number is a call number with socket call permission, obtain the socket type required to be created during the execution of the target process, and obtain the socket usage permission of the target process;

[0217] Based on the socket type and the socket usage permission, perform an interception process on the target process.

[0218] Optionally, when the processor 1001 performs an interception process on the target process based on the socket type and the socket usage permission, it specifically performs the following operations:

[0219] Based on the socket type and the socket usage permission, obtain the process type of the target process;

[0220] If the process type indicates that the target process is a malicious process, perform an interception process on the target process.

[0221] Optionally, when the processor 1001 obtains the process type of the target process based on the socket type and the socket usage permission, it specifically performs the following operations:

[0222] If the socket type is the same as the original socket type and the socket usage permission is inconsistent with the original socket usage permission, determine that the process type of the target process is a malicious process.

[0223] Optionally, when the processor 1001 performs the operation of obtaining the socket type required to be created during the execution of the target process and obtaining the socket usage permission of the target process if the system call number is a call number with socket call permission, it specifically performs the following operations:

[0224] If the system call number is a call number with socket call permission, obtain the socket protocol family required to be created during the execution of the target process;

[0225] If the socket protocol family is the same as the target socket protocol family, obtain the socket type in the system call corresponding to the system call number, and obtain the socket usage permission of the target process.

[0226] Optionally, when the processor 1001 executes if the system call number is a call number with socket call permission, obtain the socket type required to be created during the execution of the target process, and obtain the socket usage permission of the target process, the following specific operations are performed:

[0227] If the system call number is a call number with socket call permission, obtain the original permission information of the target process;

[0228] If the original process permission value in the original permission information is greater than or equal to the permission threshold, obtain the socket type in the system call corresponding to the system call number, and obtain the socket usage permission of the target process.

[0229] Optionally, when the processor 1001 executes the interception process on the target process, the following specific operations are performed:

[0230] Obtain the return address of the target process, and modify the return value at the return address to an error value.

[0231] Optionally, after the processor 1001 executes the interception process on the target process based on the socket type and the socket usage permission, the following operations are further performed:

[0232] Obtain the process information of the target process, and record the process information of the target process as malicious process information.

[0233] In the embodiments of the present application, by obtaining the socket type required to be created during the execution of the target process, and the socket usage permission of the target process, and then performing an interception process on the target process based on the socket type and the socket usage permission, that is, identifying whether the socket communication information between the target process and other processes is tampered with. If it is detected that the socket communication information is tampered with, it indicates that the security vulnerability of the socket protocol is exploited, so as to intercept the target process in time when the security vulnerability is detected, thereby reducing the security risk of the terminal device.

[0234] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.

[0235] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0236] The above is the description of a process detection method, a process detection device, a storage medium, and a device provided by the present application. For those skilled in the art, according to the idea of the embodiments of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A process detection method, characterized in that The method includes: Obtaining the system call number of the target process. If the system call number matches any sample call number in the call number set, obtaining the execution permission corresponding to the system call number, where the target process is the process of an application program in an execution state; If the execution permission indicates that the target process has the function of modifying process permissions, obtaining the original permission information and the set permission information of the target process. The original permission information is the process permission of the target process, and the set permission information refers to the process permission of the target process that the system call currently called by the target process wants to set. The original permission information and the set permission information are information in the process structure of the target process; Based on the original permission information and the set permission information, obtaining the process type of the target process; If the process type indicates that the target process is a malicious process, modifying the set permission information of the target process to the original permission information of the target process and performing an interception process on the target process.

2. The method according to claim 1, characterized in that, The obtaining the process type of the target process based on the original permission information and the set permission information includes: Obtaining the original process permission value of the target process in the original permission information and obtaining the set process permission value of the target process in the set permission information; If the original process permission value is greater than or equal to the permission threshold and the set process permission value is less than the permission threshold, determining that the process type of the target process is a malicious process.

3. The method according to claim 1, wherein After performing the interception process on the target process, it further includes: Obtaining the process information of the target process and recording the process information of the target process as malicious process information.

4. A process detection device, characterized in that including: An execution permission obtaining module, configured to obtain the system call number of the target process. If the system call number matches any sample call number in the call number set, obtaining the execution permission corresponding to the system call number, where the target process is the process of an application program in an execution state; A process permission obtaining module, configured to, if the execution permission indicates that the target process has the function of modifying process permissions, obtain the original permission information and the set permission information of the target process. The original permission information is the process permission of the target process, and the set permission information refers to the process permission of the target process that the system call currently called by the target process wants to set. The original permission information and the set permission information are information in the process structure of the target process; An interception module, configured to obtain the process type of the target process based on the original permission information and the set permission information. If the process type indicates that the target process is a malicious process, modifying the set permission information of the target process to the original permission information of the target process and performing an interception process on the target process.

5. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the process detection method according to any one of claims 1 to 3.

6. A computer device, characterized in that, including: A processor and a memory; wherein, the memory stores a computer program, and the computer program is adapted to be loaded and executed by the processor to perform the steps of the process detection method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Kernel authority management system and method of mobile terminal

    CN105701415A

  • Method and device for detecting malicious code

    CN106845223A

  • Method, device and equipment for determining program by utilizing privileged bug and storage medium

    CN111191226A

  • Malicious process detection method and device, terminal and computer readable storage medium

    CN111783091A