Code Detection Method, Device, System, Equipment and Storage Medium

By obtaining and comparing the running memory code hash value of the target application in the virtual machine memory, the problems of small detection range and poor detection of Trojans in the prior art are solved, and a wider and more effective code integrity detection is achieved.

CN113886825BActive Publication Date: 2025-07-01INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111155705.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-29
Publication Date
2025-07-01
Estimated Expiration
2041-09-29

AI Technical Summary

Technical Problem

In the prior art, the number of files or file content comparisons are mainly based on the source code and the code running on the server. The detection range is small and the detection effect of Trojans and other files is poor.

Method used

To detect the integrity and security of the running memory code by obtaining the running memory code associated with the target application in the virtual machine memory, compute its hash value, and compare it with the hash value of the source memory code.

Benefits of technology

The detection range has been expanded, the detection effect of Trojans and other files has been improved, and the safe operation of the application has been effectively guaranteed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113886825B_ABST
    Figure CN113886825B_ABST
Patent Text Reader

Abstract

The present disclosure provides a code detection method, apparatus, system, device, and storage medium, which can be applied to the financial field, the computer technology field, and the information security field. The method includes: obtaining the running memory code associated with a target application in the virtual machine memory, where the target application runs based on the running memory code; processing the running memory code to generate running memory code information corresponding to the running memory code, where the running memory code information includes the first hash value of each first bytecode file in the running memory code; detecting the running memory code information according to the source memory code information corresponding to the source memory code, and outputting a detection result corresponding to the running memory code, where the source memory code information includes the second hash value of each second bytecode file in the source memory code, and the source memory code includes the initial running memory code of the target application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the fields of finance, computer technology, and information security, and more particularly to a code detection method, apparatus, system, device, medium, and program product. Background Art

[0002] The problem of software integrity protection has become particularly important in the current situation where computer network viruses, malicious codes, and Trojan programs are rampant. Many of these types of network attacks take advantage of the current lack of effective means to provide integrity protection for software, enabling attackers to modify the code part of a software that is basically semantically or behaviorally correct or at least non-malicious into a wrong or even malicious version.

[0003] In the process of implementing the inventive concept of the present disclosure, the inventors found that there are at least the following problems in the related art: In the related art, the detection mainly based on comparing the number of files or the content of files of the source code and the code running on the server, the detection range is small, and the detection effect on files such as Trojans is poor. Summary of the Invention

[0004] In view of the above problems, the present disclosure provides a code detection method, apparatus, system, device, medium, and program product.

[0005] According to a first aspect of the present disclosure, there is provided a code detection method, including:

[0006] Obtaining running memory code associated with a target application in a virtual machine memory, wherein the target application runs based on the running memory code;

[0007] Processing the running memory code to generate running memory code information corresponding to the running memory code, wherein the running memory code information includes a first hash value of each first bytecode file in the running memory code;

[0008] Detecting the running memory code information according to source memory code information corresponding to source memory code, and outputting a detection result corresponding to the running memory code, wherein the source memory code information includes a second hash value of each second bytecode file in the source memory code, and the source memory code includes the initial running memory code of the target application.

[0009] According to an embodiment of the present disclosure, the obtaining the running memory code associated with the target application in the virtual machine memory includes:

[0010] Deploying a target plug-in in the target application;

[0011] Obtain the above-mentioned running memory code in the virtual machine memory regularly through the above-mentioned target plug-in according to a preset time interval.

[0012] According to an embodiment of the present disclosure, the processing of the above-mentioned running memory code to generate running memory code information corresponding to the above-mentioned running memory code includes:

[0013] Scan each of the above-mentioned first bytecode files in the above-mentioned running memory code in sequence, and output the above-mentioned first hash value corresponding to each of the above-mentioned first bytecode files.

[0014] According to an embodiment of the present disclosure, the above-mentioned code detection method further includes:

[0015] Before the above-mentioned target application runs, obtain the above-mentioned source memory code to be deployed;

[0016] Process the above-mentioned source memory code to generate the above-mentioned source memory code information corresponding to the above-mentioned source memory code.

[0017] According to an embodiment of the present disclosure, the processing of the above-mentioned source memory code to generate the above-mentioned source memory code information corresponding to the above-mentioned source memory code includes:

[0018] Scan each of the above-mentioned second bytecode files in the above-mentioned source memory code in sequence, and output the above-mentioned second hash value corresponding to each of the above-mentioned second bytecode files.

[0019] According to an embodiment of the present disclosure, the detection of the above-mentioned running memory code information according to the source memory code information corresponding to the source memory code, and outputting the detection result corresponding to the above-mentioned running memory code includes:

[0020] Compare each of the above-mentioned second hash values in the above-mentioned source memory code information with each of the above-mentioned first hash values in the above-mentioned running memory code information, and output a first abnormal comparison result;

[0021] Generate the above-mentioned detection result according to the above-mentioned first abnormal comparison result.

[0022] According to an embodiment of the present disclosure, the above-mentioned running memory code information further includes first class name information of each of the above-mentioned first bytecode files, and the above-mentioned source memory code information further includes second class name information of each of the above-mentioned second bytecode files;

[0023] The detection of the above-mentioned running memory code information according to the source memory code information corresponding to the source memory code, and outputting the detection result corresponding to the above-mentioned running memory code further includes:

[0024] Compare each of the above-mentioned second-class name information in the source memory code information with each of the first-class name information in the running memory code information, and output the second abnormal comparison result;

[0025] Generate the above-mentioned detection result according to the above-mentioned first abnormal comparison result and the above-mentioned second abnormal comparison result.

[0026] The second aspect of the present disclosure provides a code detection device, including:

[0027] A runtime code scanning subsystem, configured to obtain the running memory code associated with the target application in the virtual machine memory, where the target application runs based on the running memory code; and process the running memory code to generate running memory code information corresponding to the running memory code, where the running memory code information includes the first hash value of each first bytecode file in the running memory code;

[0028] A tampering detection subsystem, configured to detect the running memory code information according to the source memory code information corresponding to the source memory code, and output a detection result corresponding to the running memory code, where the source memory code information includes the second hash value of each second bytecode file in the source memory code, and the source memory code includes the initial running memory code of the target application.

[0029] According to an embodiment of the present disclosure, the above-mentioned code detection device further includes:

[0030] A source code scanning subsystem, configured to obtain the source memory code to be deployed before the target application runs; and process the source memory code to generate the source memory code information corresponding to the source memory code.

[0031] The third aspect of the present disclosure provides a code detection system, including:

[0032] A first acquisition module, configured to obtain the running memory code associated with the target application in the virtual machine memory, where the target application runs based on the running memory code;

[0033] A first processing module, configured to process the running memory code to generate running memory code information corresponding to the running memory code, where the running memory code information includes the first hash value of each first bytecode file in the running memory code;

[0034] A detection module, configured to detect the above-mentioned running memory code information according to source memory code information corresponding to a source memory code, and output a detection result corresponding to the above-mentioned running memory code, where the above-mentioned source memory code information includes second hash values of each second bytecode file in the above-mentioned source memory code, and the above-mentioned source memory code includes an initial running memory code of the above-mentioned target application.

[0035] A fourth aspect of the present disclosure provides an electronic device, including: one or more processors; a memory for storing one or more programs, where when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the above-mentioned code detection method.

[0036] A fifth aspect of the present disclosure further provides a computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the above-mentioned code detection method.

[0037] A sixth aspect of the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above-mentioned code detection method is implemented. Description of the Drawings

[0038] Through the following description of the embodiments of the present disclosure with reference to the drawings, the above-mentioned content and other objects, features and advantages of the present disclosure will become clearer. In the drawings:

[0039] Figure 1 Schematically shows an application scenario diagram of the code detection method according to an embodiment of the present disclosure;

[0040] Figure 2 Schematically shows a flowchart of the code detection method according to an embodiment of the present disclosure;

[0041] Figure 3 Schematically shows a structural block diagram of the code detection device according to an embodiment of the present disclosure;

[0042] Figure 4 Schematically shows a structural block diagram of the code detection device according to an embodiment of the present disclosure;

[0043] Figure 5 Schematically shows a structural block diagram of the code detection device according to an embodiment of the present disclosure;

[0044] Figure 6 Schematically shows a structural block diagram of the code detection device according to an embodiment of the present disclosure;

[0045] Figure 7 Schematically shows a structural block diagram of the code detection system according to an embodiment of the present disclosure; and

[0046] Figure 8 A block diagram of an electronic device implementing a code detection method according to an embodiment of the present disclosure is schematically shown. Detailed implementation manners

[0047] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, numerous specific details are set forth in order to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is obvious that one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily obscuring the concepts of the present disclosure.

[0048] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0049] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0050] In the case of using expressions such as "at least one of A, B, and C, etc.", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).

[0051] In the related art, code integrity protection schemes are mainly based on comparing the number of files or the content of files of the source memory code and the code running on the server. However, a large number of Trojan files exist in the form of memory code in the application server. Therefore, corresponding landing files cannot be found in the server, resulting in the failure of the file-based code integrity protection scheme.

[0052] In view of this, the inventors found that the running memory code in the virtual machine memory of the server can be exported, and its hash value can be calculated. At the same time, the hash value corresponding to the source memory code is compared with the hash value of the running memory code, so as to determine whether there is malicious information such as Trojan files in the running memory code in the server.

[0053] Accordingly, embodiments of the present disclosure provide a code detection method, apparatus, system, device, medium, and program product. The method includes: obtaining running memory code associated with a target application in a virtual machine memory, where the target application runs based on the running memory code; processing the running memory code to generate running memory code information corresponding to the running memory code, where the running memory code information includes a first hash value of each first bytecode file in the running memory code; detecting the running memory code information according to source memory code information corresponding to source memory code, and outputting a detection result corresponding to the running memory code, where the source memory code information includes a second hash value of each second bytecode file in the source memory code, and the source memory code includes the initial running memory code of the target application.

[0054] It should be noted that the code detection method, apparatus, system, device, and storage medium provided by the present disclosure can be applied to the financial field. For example, it can be used in financial institutions such as banks, and can also be used in any field other than the financial field, such as hospitals. Therefore, the application fields of the code detection method, apparatus, system, device, and storage medium provided by the present disclosure are not limited.

[0055] Figure 1 Schematically shows an application scenario diagram of the code detection method according to an embodiment of the present disclosure.

[0056] As Figure 1 shown, the application scenario 100 according to this embodiment may include a network 104 and multiple servers 105. The network 104 is used to provide a medium for communication links between terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0057] Users can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to run the target application, etc.

[0058] The terminal devices 101, 102, 103 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.

[0059] The server 105 may be a server providing various services. For example, it executes the target application requested by the user using the terminal devices 101, 102, 103, and may also execute detection processing on the running memory code and feedback the processing result (such as the detection result generated according to the target application requested by the user for the server 105 to execute, such as the detection result shows that the user's target application includes a malicious memory trojan, maliciously added or tampered class files, etc.) to the terminal device.

[0060] It should be noted that the code detection method provided by the embodiments of the present disclosure can generally be executed by the server 105. Correspondingly, the code detection device provided by the embodiments of the present disclosure can generally be set in the server 105. The code detection method provided by the embodiments of the present disclosure can also be executed by a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, 103 and / or the server 105. Correspondingly, the code detection device provided by the embodiments of the present disclosure can also be set in a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, 103 and / or the server 105.

[0061] It should be understood that Figure 1 the numbers of terminal devices, networks, and servers in

[0062] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 1 The following will be based on Figures 2 to 6 the scenarios described below, and will describe in detail the code detection method of the disclosed embodiments through

[0063] Figure 2 FIG. schematically shows a flowchart of the code detection method according to an embodiment of the present disclosure.

[0064] As Figure 2 shown, the code detection method of this embodiment includes operations S210 to S230.

[0065] In operation S210, the running memory code associated with the target application in the virtual machine memory is obtained, where the target application runs based on the running memory code.

[0066] In operation S220, the running memory code is processed to generate running memory code information corresponding to the running memory code, where the running memory code information includes the first hash value of each first bytecode file in the running memory code.

[0067] In operation S230, the running memory code information is detected according to the source memory code information corresponding to the source memory code, and a detection result corresponding to the running memory code is output, where the source memory code information includes the second hash value of each second bytecode file in the source memory code, and the source memory code includes the initial running memory code of the target application.

[0068] According to an embodiment of the present disclosure, bytecode is a binary file containing an execution program, consisting of a sequence of operation code (op) codes or data pairs, and is an intermediate code.

[0069] According to an embodiment of the present disclosure, a hash value may refer to mapping a binary value of any length to a smaller binary value of a fixed length by using a hash algorithm. Among them, both the first hash value and the second hash value may include a Message Digest 5 (MD5) value, a Secure Hash Algorithm 1 (SHA-1) value, etc.

[0070] According to an embodiment of the present disclosure, when detecting code, obtain the running memory code associated with the target application from the memory in the virtual machine, generate a corresponding first hash value according to each first bytecode file in the running memory code, and compare and analyze the first hash value with the second hash value of the second bytecode file corresponding to the first bytecode file in the source memory code information, so as to judge whether the first bytecode file and the second bytecode file in the virtual machine are the same detection result.

[0071] According to an embodiment of the present disclosure, when the detection result indicates that the two are the same, it indicates that there is no malicious code in the second bytecode file, and the malicious code includes but is not limited to malicious memory trojans, maliciously added or modified class files, etc.

[0072] According to an embodiment of the present disclosure, when the detection result indicates that the two are different, it indicates that there is malicious code in the second bytecode file.

[0073] According to an embodiment of the present disclosure, by obtaining the running memory code when the target application is running, processing the running memory code, generating running memory code information including the first hash value of each first bytecode file in the running memory code, and detecting the running memory code information through the source memory code information including the second hash value of each second bytecode file in the source memory code, and outputting the detection result, the technical means of detecting the running code information during runtime through the originally deployed source memory code information can perform real-time monitoring on inserted malicious memory trojans, maliciously added or modified class files, solve the technical problems in the related art that mainly compare the number of files or the content of files for the source code and the code running on the server, the detection range is small, and the detection effect on files such as trojans is poor, thereby expanding the detection range, improving the detection effect on files such as trojans, and effectively ensuring the secure operation of the application.

[0074] According to an embodiment of the present disclosure, obtaining the running memory code associated with the target application in the virtual machine memory may include the following operations.

[0075] Deploy the target plug-in in the target application. According to a preset time interval, regularly obtain the running memory code in the virtual machine memory through the target plug-in.

[0076] According to embodiments of the present disclosure, the target plug-in may include, but is not limited to, an access module. The access module may include a JavaAgent access module.

[0077] According to embodiments of the present disclosure, the function of the JavaAgent access module includes attaching the engine to the running target application. The JavaAgent can be bound to the target application to be detected by adding Agent parameters at startup or by using an attached process during the running of the application.

[0078] According to embodiments of the present disclosure, processing the running memory code to generate running memory code information corresponding to the running memory code may include the following operations.

[0079] Scan each first bytecode file in the running memory code in sequence, and output a first hash value corresponding to each first bytecode file.

[0080] According to embodiments of the present disclosure, since the number of first bytecode files in the running memory code is large, before detection, each first bytecode file in the running memory code needs to be calculated to obtain a first hash value corresponding to each first bytecode file, so as to facilitate subsequent detection and analysis of the first hash value and the second hash value.

[0081] According to embodiments of the present disclosure, the above code detection method may further include the following operations.

[0082] Before the target application runs, obtain the source memory code to be deployed. Process the source memory code to generate source memory code information corresponding to the source memory code.

[0083] According to embodiments of the present disclosure, processing the source memory code to generate source memory code information corresponding to the source memory code may include the following operations.

[0084] Scan each second bytecode file in the source memory code in sequence, and output a second hash value corresponding to each second bytecode file.

[0085] According to embodiments of the present disclosure, since the number of second bytecode files in the source memory code is large, before detection, each second bytecode file in the source memory code needs to be calculated to obtain a second hash value corresponding to each second bytecode file, so as to facilitate subsequent detection and analysis of the first hash value and the second hash value. According to embodiments of the present disclosure, detecting the running memory code information according to the source memory code information corresponding to the source memory code and outputting a detection result corresponding to the running memory code may include the following operations.

[0086] Compare each second hash value in the source memory code information with each first hash value in the running memory code information, and output a first abnormal comparison result. Generate a detection result based on the first abnormal comparison result.

[0087] According to an embodiment of the present disclosure, the first abnormal comparison result may indicate that the first hash value is inconsistent with the second hash value. In other words, the first bytecode file corresponding to the first hash value contains malicious information. For example, the first bytecode file has been maliciously added and / or modified by others.

[0088] According to an embodiment of the present disclosure, the above detection result may further include a first normal comparison result, where the first normal comparison result may indicate that the first hash value is consistent with the second hash value. In other words, there is no malicious information in the first bytecode file corresponding to the first hash value.

[0089] According to an embodiment of the present disclosure, the running memory code information may further include first class name information of each first bytecode file, and the source memory code information may further include second class name information of each second bytecode file.

[0090] According to an embodiment of the present disclosure, when detecting the running memory code information according to the source memory code information corresponding to the source memory code, the operations for outputting the detection result corresponding to the running memory code may further include the following.

[0091] Compare each second class name information in the source memory code information with each first class name information in the running memory code information, and output a second abnormal comparison result. Generate a detection result based on the first abnormal comparison result and the second abnormal comparison result.

[0092] According to an embodiment of the present disclosure, the second abnormal comparison result may indicate that each second class name information in the source memory code information is different from each first class name information in the running memory code information. In other words, the second abnormal comparison result may indicate that the first bytecode file corresponding to the first class name information has been maliciously added and / or modified by others.

[0093] According to an embodiment of the present disclosure, the above detection result may further include a second normal result, where the second normal result may indicate that each second class name information in the source memory code information is the same as each first class name information in the running memory code information.

[0094] Based on the above code detection method, the present disclosure also provides a code detection system. The following will be combined with Figures 3 to 6 Describe the system in detail.

[0095] Figure 3 Schematically shows a structural block diagram of a code detection device according to an embodiment of the present disclosure.

[0096] As Figure 3 shown, the code detection device 300 may include a runtime code scanning subsystem 310 and a tampering detection subsystem 320.

[0097] The runtime code scanning subsystem 310 is configured to obtain the runtime memory code associated with the target application in the virtual machine memory, where the target application runs based on the runtime memory code; and process the runtime memory code to generate runtime memory code information corresponding to the runtime memory code, where the runtime memory code information includes the first hash value of each first bytecode file in the runtime memory code.

[0098] The tampering detection subsystem 320 is configured to detect the runtime memory code information according to the source memory code information corresponding to the source memory code, and output a detection result corresponding to the runtime memory code, where the source memory code information includes the second hash value of each second bytecode file in the source memory code, and the source memory code includes the initial runtime memory code of the target application.

[0099] According to an embodiment of the present disclosure, by obtaining the runtime memory code of the target application during runtime, processing the runtime memory code to generate runtime memory code information including the first hash value of each first bytecode file in the runtime memory code, and detecting the runtime memory code information through the source memory code information including the second hash value of each second bytecode file in the source memory code and outputting the detection result, the technique of detecting the runtime code information through the source memory code information deployed originally can perform real-time monitoring on inserted malicious memory trojans and maliciously added or tampered class files, solving the technical problem in the related art that mainly based on comparing the number of files or the content of files in the source code and the code running on the server, the detection scope is small and the detection effect on files such as trojans is poor, thereby expanding the detection scope, improving the detection effect on files such as trojans, and effectively ensuring the secure operation of the application.

[0100] As Figure 3 shown, the above-mentioned code detection device 300 may further include a source code scanning subsystem.

[0101] The source code scanning subsystem 330 is configured to obtain the source memory code to be deployed before the target application runs; and process the source memory code to generate source memory code information corresponding to the source memory code.

[0102] Figure 4 Schematically shows a structural block diagram of a code detection device according to an embodiment of the present disclosure.

[0103] As Figure 4As shown in the figure, the above-mentioned runtime code scanning subsystem 310 may include an access module 311, a bytecode dump module 312, and a first information uploading module 313. The access module 311 may include a JavaAgent access module.

[0104] According to an embodiment of the present disclosure, the function of the JavaAgent access module may include attaching the engine to the running target application. The JavaAgent can be bound to the target application to be detected by adding Agent parameters at startup or by using an attached process during the application's running process.

[0105] According to an embodiment of the present disclosure, the bytecode dump module 312 uses the proxy engine bound by the access module 311 to dump the running memory code in the virtual machine memory at regular intervals.

[0106] According to an embodiment of the present disclosure, the function of the first information uploading module 313 may include transmitting the information of the running memory code obtained and calculated by the bytecode dump module 312 for subsequent detection and analysis.

[0107] Figure 5 The structural block diagram of the code detection device according to an embodiment of the present disclosure is schematically shown.

[0108] As Figure 5 shown, the above-mentioned tampering detection subsystem 320 may include a tampering analysis module 321.

[0109] According to an embodiment of the present disclosure, the function of the tampering analysis module 321 may include receiving the second hash value, the second class name information, and receiving the first hash value and the first class name information transmitted by the runtime code scanning subsystem. Since various malicious information such as viruses and Trojans need to be loaded and executed by the class loader of the application after modifying the first class name information or adding new code, by comparing the first class name information of the running memory code running in the virtual machine memory with the second class name information of the source memory code, malicious information in the code can be effectively monitored.

[0110] As Figure 5 shown, the above-mentioned tampering detection subsystem 320 may further include an information display module 322.

[0111] The information display module 322 may display the detection results analyzed and detected by the tampering analysis module 321. For example, it may display the newly added classes and tampered classes in the tampered running memory code to remind the developers.

[0112] According to an embodiment of the present disclosure, the bytecode dump module 312 in the runtime code scanning subsystem 310 may also calculate the first class name information of each first bytecode file, so as to facilitate the tampering detection subsystem 320 to detect and analyze the second class name information and the first class name information in the source memory code information.

[0113] Figure 6 Schematically shows a structural block diagram of a code detection device according to an embodiment of the present disclosure.

[0114] As Figure 6 shown, the source code scanning subsystem 330 may include a code scanning module 331 and a second information uploading module 332.

[0115] According to an embodiment of the present disclosure, the code scanning module 331 may obtain the source memory code of the target application to be deployed, scan all the second bytecode files in the source memory code, and calculate the second hash value and the second class name information corresponding to each second bytecode file.

[0116] According to an embodiment of the present disclosure, the second information uploading module 332 may transmit the first hash value and the first class name information of all the second bytecode files in the source memory code calculated by the code scanning module 331 to the tampering detection subsystem 320 for subsequent detection and analysis.

[0117] According to an embodiment of the present disclosure, what the source code scanning subsystem 330 transmits is the initial class baseline information. What the runtime code scanning subsystem 310 transmits is the class information that is running in real time in the virtual machine memory, where the class information may include a hash value and class name information.

[0118] Based on the above code detection method, the present disclosure also provides a code detection system. The following will be combined with Figure 7 to describe this system in detail.

[0119] Figure 7 Schematically shows a structural block diagram of a code detection system according to an embodiment of the present disclosure.

[0120] As Figure 7 shown, the code detection system 700 of this embodiment may include a first acquisition module 710, a first processing module 720, and a detection module 730.

[0121] The first acquisition module 710 is used to acquire the running memory code associated with the target application in the virtual machine memory, where the target application runs based on the running memory code. In one embodiment, the first acquisition module 710 may be used to perform the operation S210 described above, which will not be elaborated here.

[0122] The first processing module 720 is used to process the running memory code to generate running memory code information corresponding to the running memory code. The running memory code information includes the first hash value of each first bytecode file in the running memory code. In one embodiment, the first processing module 720 may be used to perform the operation S220 described above, which will not be elaborated here.

[0123] The detection module 730 is used to detect the running memory code information according to the source memory code information corresponding to the source memory code, and output a detection result corresponding to the running memory code. The source memory code information includes the second hash value of each second bytecode file in the source memory code, and the source memory code includes the initial running memory code of the target application. In one embodiment, the detection module 730 may be used to perform the operation S230 described above, which will not be elaborated here.

[0124] According to an embodiment of the present disclosure, by obtaining the running memory code during the running of the target application, processing the running memory code to generate running memory code information including the first hash value of each first bytecode file in the running memory code, and detecting the running memory code information through the source memory code information including the second hash value of each second bytecode file in the source memory code, and outputting the detection result, the technical means of detecting the running code information during running through the source memory code information deployed originally can monitor malicious memory trojans inserted, maliciously added or tampered class files in real time, solve the technical problems in the related art that mainly based on comparing the number of files or the content of files of the source code and the code running on the server, the detection range is small, and the detection effect on files such as trojans is poor, thereby expanding the detection range, improving the detection effect on files such as trojans, and effectively ensuring the safe running of the application.

[0125] According to an embodiment of the present disclosure, the first acquisition module 710 may include a deployment unit and an acquisition unit.

[0126] The deployment unit is used to deploy the target plugin into the target application.

[0127] The acquisition unit is used to regularly acquire the running memory code in the virtual machine memory through the target plugin according to a preset time interval.

[0128] According to an embodiment of the present disclosure, the first processing module 720 may include a first processing unit.

[0129] The first processing unit is used to sequentially scan each first bytecode file in the running memory code and output the first hash value corresponding to each first bytecode file.

[0130] According to an embodiment of the present disclosure, the above code detection system 700 may further include a second acquisition module and a second processing module.

[0131] The second acquisition module is configured to acquire the source memory code to be deployed before the target application runs.

[0132] The second processing module is configured to process the source memory code to generate source memory code information corresponding to the source memory code.

[0133] According to an embodiment of the present disclosure, the second processing module may include a second processing unit.

[0134] The second processing unit is configured to sequentially scan each second bytecode file in the source memory code and output a second hash value corresponding to each second bytecode file.

[0135] According to an embodiment of the present disclosure, the detection module 730 may include a first comparison unit and a first generation unit.

[0136] The first comparison unit is configured to compare each second hash value in the source memory code information with each first hash value in the running memory code information and output a first abnormal comparison result.

[0137] The first generation unit is configured to generate a detection result according to the first abnormal comparison result.

[0138] According to an embodiment of the present disclosure, the running memory code information further includes first class name information of each first bytecode file, and the source memory code information further includes second class name information of each second bytecode file.

[0139] According to an embodiment of the present disclosure, the detection module 730 may further include a second comparison unit and a second generation unit.

[0140] The second comparison unit is configured to compare each second class name information in the source memory code information with each first class name information in the running memory code information and output a second abnormal comparison result.

[0141] The second generation unit is configured to generate a detection result according to the first abnormal comparison result and the second abnormal comparison result.

[0142] According to embodiments of the present disclosure, any multiple of the first acquisition module 710, the first processing module 720, and the detection module 730 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to embodiments of the present disclosure, at least one of the first acquisition module 710, the first processing module 720, and the detection module 730 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on a substrate, a system in a package, an application specific integrated circuit (ASIC), or any other reasonable manner of integrating or packaging circuits, etc., implemented by hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Alternatively, at least one of the first acquisition module 710, the first processing module 720, and the detection module 730 may be at least partially implemented as a computer program module, and when the computer program module is run, corresponding functions may be executed.

[0143] Figure 8 A block diagram of an electronic device suitable for implementing a code detection method according to an embodiment of the present disclosure is schematically shown.

[0144] As Figure 8 shown, the electronic device 800 according to an embodiment of the present disclosure includes a processor 801, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage section 808 into a random access memory (RAM) 803. The processor 801 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 801 may also include on-board memory for caching purposes. The processor 801 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0145] In the RAM 803, various programs and data required for the operation of the electronic device 800 are stored. The processor 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. The processor 801 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 802 and / or the RAM 803. It should be noted that the programs may also be stored in one or more memories other than the ROM 802 and the RAM 803. The processor 801 may also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.

[0146] According to an embodiment of the present disclosure, the electronic device 800 may further include an input / output (I / O) interface 805, and the input / output (I / O) interface 805 is also connected to the bus 804. The electronic device 800 may further include one or more of the following components connected to the I / O interface 805: an input portion 806 including a keyboard, a mouse, etc.; an output portion 807 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 808 including a hard disk, etc.; and a communication portion 809 including a network interface card such as a LAN card, a modem, etc. The communication portion 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to the I / O interface 805 as needed. A removable medium 811, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 810 as needed so that a computer program read from it can be installed into the storage portion 808 as needed.

[0147] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.

[0148] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include one or more memories other than the ROM 802 and / or RAM 803 described above and / or the ROM 802 and RAM 803.

[0149] An embodiment of the present disclosure further includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the item recommendation method provided by the embodiment of the present disclosure.

[0150] When the computer program is executed by the processor 801, it executes the above functions defined in the system / apparatus of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. can be implemented by computer program modules.

[0151] In one embodiment, the computer program can rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program can also be transmitted and distributed in the form of a signal on a network medium, and is downloaded and installed through the communication part 809, and / or installed from the removable medium 811. The program code included in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0152] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 809, and / or installed from the removable medium 811. When the computer program is executed by the processor 801, it executes the above functions defined in the system of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.

[0153] According to embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (for example, by using an Internet service provider to connect through the Internet).

[0154] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0155] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined or / and combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.

[0156] The embodiments of the present disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and these substitutions and modifications should all fall within the scope of the present disclosure.

Claims

1. A code detection method, comprising: Deploying a target plugin in a target application, and at preset time intervals, obtaining, by means of the target plugin, the running memory code associated with the target application in the virtual machine memory, wherein the target application runs based on the running memory code; Processing the running memory code to generate running memory code information corresponding to the running memory code, wherein the running memory code information includes the first hash value of each first bytecode file in the running memory code; Detecting the running memory code information according to the source memory code information corresponding to the source memory code, and outputting a detection result corresponding to the running memory code, wherein the source memory code information includes the second hash value of each second bytecode file in the source memory code, and the source memory code includes the initial running memory code of the target application; The detecting the running memory code information according to the source memory code information corresponding to the source memory code specifically includes: comparing and analyzing the first hash value of each first bytecode file in the running memory code with the second hash value of the second bytecode file corresponding to the first bytecode file in the source memory code.

2. The method according to claim 1, wherein, The processing the running memory code to generate running memory code information corresponding to the running memory code includes: Scanning each of the first bytecode files in the running memory code in sequence, and outputting the first hash value corresponding to each of the first bytecode files.

3. The method according to claim 1, further comprising: Before the target application runs, obtaining the source memory code to be deployed; Processing the source memory code to generate the source memory code information corresponding to the source memory code.

4. The method according to claim 3, wherein The processing the source memory code to generate the source memory code information corresponding to the source memory code includes: Scanning each of the second bytecode files in the source memory code in sequence, and outputting the second hash value corresponding to each of the second bytecode files.

5. The method according to claim 1, wherein, The outputting a detection result corresponding to the running memory code includes: When the first hash value is inconsistent with the second hash value, outputting a first abnormal comparison result; Generating the detection result according to the first abnormal comparison result.

6. The method according to claim 5, wherein, The running memory code information further includes the first class name information of each of the first bytecode files, and the source memory code information further includes the second class name information of each of the second bytecode files; The detecting the running memory code information according to the source memory code information corresponding to the source memory code and outputting a detection result corresponding to the running memory code further includes: Comparing each of the second class name information in the source memory code information with each of the first class name information in the running memory code information, and outputting a second abnormal comparison result; Generating the detection result according to the first abnormal comparison result and the second abnormal comparison result.

7. A code detection device, comprising: A runtime code scanning subsystem for deploying a target plugin to a target application and periodically obtaining, according to a preset time interval, via the target plugin, the runtime memory code associated with the target application in the virtual machine memory, wherein the target application runs based on the runtime memory code; and processing the runtime memory code to generate runtime memory code information corresponding to the runtime memory code, wherein the runtime memory code information includes the first hash value of each first bytecode file in the runtime memory code. A tampering detection subsystem for detecting the runtime memory code information according to the source memory code information corresponding to the source memory code and outputting a detection result corresponding to the runtime memory code, wherein the source memory code information includes the second hash value of each second bytecode file in the source memory code, and the source memory code includes the initial runtime memory code of the target application. The detecting the runtime memory code information according to the source memory code information corresponding to the source memory code specifically includes: comparing and analyzing the first hash value of each first bytecode file in the runtime memory code with the second hash value of the second bytecode file corresponding to the first bytecode file in the source memory code.

8. The apparatus according to claim 7, further comprising: A source code scanning subsystem for obtaining the source memory code to be deployed before the target application runs; and processing the source memory code to generate the source memory code information corresponding to the source memory code.

9. A code detection system, comprising: A first obtaining module for deploying a target plugin to a target application and periodically obtaining, according to a preset time interval, via the target plugin, the runtime memory code associated with the target application in the virtual machine memory, wherein the target application runs based on the runtime memory code; A first processing module for processing the runtime memory code to generate runtime memory code information corresponding to the runtime memory code, wherein the runtime memory code information includes the first hash value of each first bytecode file in the runtime memory code; A detection module for detecting the runtime memory code information according to the source memory code information corresponding to the source memory code and outputting a detection result corresponding to the runtime memory code, wherein the source memory code information includes the second hash value of each second bytecode file in the source memory code, and the source memory code includes the initial runtime memory code of the target application; The detecting the runtime memory code information according to the source memory code information corresponding to the source memory code specifically includes: comparing and analyzing the first hash value of each first bytecode file in the runtime memory code with the second hash value of the second bytecode file corresponding to the first bytecode file in the source memory code.

10. An electronic device, comprising: One or more processors; A storage device for storing one or more programs, Wherein, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method according to any one of claims 1 to 6.

11. A computer-readable storage medium having executable instructions stored thereon, which when executed by a processor cause the processor to execute the method according to any one of claims 1 to 6.

12. A computer program product comprising a computer program, which when executed by a processor implements the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Code integrity detection method and device, electronic terminal and readable storage medium

    CN107480068A

  • Code coverage rate processing method and device, server and storage medium

    CN111290943A