Program processing method and device based on associated program tracking, and storage medium
By monitoring and analyzing the behavior chains of target applications and associated programs, and identifying and intercepting malicious behavior chains, the identification lag and feature acquisition limitations of malware detection in the prior art are solved, and the identification accuracy and efficiency of malicious programs are improved.
Patent Information
- Application Number
- CN202111294512.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-03
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-11-03
AI Technical Summary
The prior art has identification lag and feature acquisition limitations in malware detection, making it difficult to accurately identify information theft behaviors completed by multiple malware in collaboration.
By monitoring the execution operation behavior of the target application and its associated programs, the target behavior chain and associated behavior chain are determined, and the similarity calculation is performed based on the preset malicious behavior chain to identify whether it belongs to the malicious behavior chain, and then intercept the relevant programs.
It improves the accuracy and efficiency of malicious programs to identify a malicious program and intercept related programs when multiple programs work together to commit evil, improving the protection capabilities of information security.
Smart Images

Figure CN114021134B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer security technology, and in particular to a program processing method and device, and a storage medium based on associated program tracking. Background Art
[0002] Malware refers to applications that perform malicious tasks on computer systems. If malware is installed on a company's computer equipment, it will steal terminal information or send fraudulent information, seriously affecting the company's information security. Preventing malware from performing malicious operations on computer equipment is one of the key issues to be addressed in order to improve corporate information security.
[0003] Currently, in malware detection, malware is generally identified by targeting the feature values of files generated by malicious behavior after the software has committed malicious behavior. For example, the feature values corresponding to the malware collected in advance are compared with the feature values of local software files to identify the malware.
[0004] Although the above detection and killing system can achieve the purpose of protecting client devices to a certain extent, many malware steal information through the collaboration of multiple malware, and the feature values are generally obtained after the malicious behavior is executed. Due to the limitations of the collected malicious features, the lag in feature acquisition, and the variability of malware, it may be difficult to accurately identify all malware in a short period of time. In this case, the existing technology lacks relevant protection measures and it is difficult to stop malicious behavior in time, which poses a serious threat to computer information security. Summary of the invention
[0005] In view of this, the present application provides a program processing method and device, and a storage medium based on associated program tracking, which helps to improve the recognition accuracy and efficiency of malicious programs.
[0006] According to one aspect of the present application, a program processing method based on associated program tracing is provided, comprising:
[0007] Monitoring the execution operation behaviors of the target application and the associated programs of the target application;
[0008] Based on the execution operation behavior, determining a target behavior chain of the target application program and an associated behavior chain of the associated program;
[0009] Identify whether the target behavior chain and the associated behavior chain are malicious behavior chains;
[0010] When the target behavior chain and / or the associated behavior chain belongs to the malicious behavior chain, the target application and the associated program are intercepted.
[0011] Optionally, the associated program includes an upstream associated program and / or a downstream associated program, the target application is created and / or downloaded by executing a process of the upstream associated program, and the downstream associated program is created and / or downloaded by executing a process of the target application.
[0012] Optionally, the identifying whether the target behavior chain and the associated behavior chain belong to a malicious behavior chain specifically includes:
[0013] According to the preset malicious behavior chain, respectively determining the target similarity between the target behavior chain and the preset malicious behavior chain and the association similarity between the association behavior chain and the preset malicious behavior chain;
[0014] According to the target similarity, the associated similarity and a preset similarity condition, it is identified whether the target behavior chain and the associated behavior chain belong to the malicious behavior chain.
[0015] Optionally, the preset malicious behavior chain includes at least one malicious behavior chain sample corresponding to at least one application sample; and determining, according to the preset malicious behavior chain, the target similarity between the target behavior chain and the preset malicious behavior chain and the association similarity between the association behavior chain and the preset malicious behavior chain, specifically includes:
[0016] Determine a target malicious behavior chain sample corresponding to the target program in the preset malicious behavior chain, and an associated malicious behavior chain sample corresponding to the associated program;
[0017] Calculating the similarity between the target behavior chain and the target malicious behavior chain sample to obtain the target similarity;
[0018] The similarity between the associated behavior chain and the associated malicious behavior chain sample is calculated to obtain the associated similarity.
[0019] Optionally, the calculating the similarity between the target behavior chain and the target malicious behavior chain sample to obtain the target similarity specifically includes:
[0020] Determine each target execution operation behavior in the target behavior chain and its corresponding occurrence order;
[0021] Respectively, from the first sample execution operation behavior corresponding to each of the target malicious behavior chain samples, extract behaviors that at least partially match the target execution operation behavior and have the same occurrence order as the first target similar behavior corresponding to each of the target malicious behavior chain samples;
[0022] Calculate the first ratio of each of the first target similar behaviors to the first sample execution operation behaviors corresponding to each of the first target behaviors, and obtain the similarity between each of the target behavior chains and the target malicious behavior chain sample;
[0023] Determine the similarity corresponding to the first ratio with the largest value as the target similarity;
[0024] The calculating the similarity between the associated behavior chain and the associated malicious behavior chain sample to obtain the associated similarity specifically includes:
[0025] Determine each associated execution operation behavior in the associated behavior chain and its corresponding occurrence order;
[0026] Respectively, from the second sample execution operation behaviors corresponding to each of the associated malicious behavior chain samples, extract behaviors that at least partially match the associated execution operation behaviors and have the same occurrence order as the first associated similar behaviors corresponding to each of the associated malicious behavior chain samples;
[0027] Calculate the second ratio of each of the first associated similar behaviors to the second sample execution operation behavior corresponding to each of the first associated similar behaviors, and obtain the similarity between each of the associated behavior chains and the associated malicious behavior chain sample;
[0028] The similarity corresponding to the second ratio with the largest value is determined as the associated similarity.
[0029] Optionally, the determining, according to a preset malicious behavior chain, a target similarity between the target behavior chain and the preset malicious behavior chain and an association similarity between the association behavior chain and the preset malicious behavior chain specifically includes:
[0030] If the application sample includes the target application, determining the target malicious behavior chain sample corresponding to the target program in the preset malicious behavior chain, and the associated malicious behavior chain sample corresponding to the associated program;
[0031] If the application sample does not include the target application, the similarity between the target behavior chain and the malicious behavior chain sample is calculated to obtain the target similarity, and the similarity between the associated behavior chain and the malicious behavior chain sample is calculated to obtain the associated similarity.
[0032] Optionally, the calculating the similarity between the target behavior chain and the malicious behavior chain sample to obtain the target similarity specifically includes:
[0033] Determine each target execution operation behavior in the target behavior chain and its corresponding occurrence order;
[0034] Extracting behaviors that at least partially match the target execution operation behaviors and have the same occurrence order from the third sample execution operation behaviors corresponding to each of the malicious behavior chain samples as the second target similar behaviors corresponding to each of the malicious behavior chain samples;
[0035] Calculate the third ratio of each of the second target similar behaviors to the third sample execution operation behaviors respectively, and obtain the similarity between each of the target behavior chains and the malicious behavior chain samples;
[0036] Determine the similarity corresponding to the third ratio with the largest value as the target similarity;
[0037] The calculating the similarity between the associated behavior chain and the malicious behavior chain sample to obtain the associated similarity specifically includes:
[0038] Determine each associated execution operation behavior in the associated behavior chain and its corresponding occurrence order;
[0039] Respectively, from the fourth sample execution operation behaviors corresponding to each of the malicious behavior chain samples, extract behaviors that at least partially match the associated execution operation behaviors and have the same occurrence order as the second associated similar behaviors corresponding to each of the malicious behavior chain samples;
[0040] Calculate respectively a fourth ratio of each of the second associated similar behaviors to the fourth sample execution operation behaviors corresponding to each of the second associated similar behaviors, and obtain a similarity between each of the associated behavior chains and the malicious behavior chain sample;
[0041] The similarity corresponding to the fourth ratio with the largest value is determined as the associated similarity ratio.
[0042] Optionally, before respectively determining the target similarity between the target behavior chain and the preset malicious behavior chain and the association similarity between the association behavior chain and the preset malicious behavior chain according to the preset malicious behavior chain, the method further includes:
[0043] The preset malicious behavior chain is obtained and saved in a local preset storage location, wherein the preset malicious behavior chain is determined by a plurality of ordered behaviors obtained by parsing sensitive program operation behavior records.
[0044] According to another aspect of the present application, a program processing device based on associated program tracing is provided, comprising:
[0045] A monitoring module, used to monitor the execution operation behaviors corresponding to the target application and the associated programs of the target application;
[0046] A behavior chain determination module, used to determine the target behavior chain of the target application program and the associated behavior chain of the associated program based on the execution operation behavior;
[0047] A behavior chain identification module, used to identify whether the target behavior chain and the associated behavior chain are malicious behavior chains;
[0048] A program processing module is used to intercept the target application and the associated program when the target behavior chain and / or the associated behavior chain belong to the malicious behavior chain.
[0049] Optionally, the associated program includes an upstream associated program and / or a downstream associated program, the target application is created and / or downloaded by executing a process of the upstream associated program, and the downstream associated program is created and / or downloaded by executing a process of the target application.
[0050] Optionally, the behavior chain identification module is specifically used to:
[0051] According to the preset malicious behavior chain, respectively determining the target similarity between the target behavior chain and the preset malicious behavior chain and the association similarity between the association behavior chain and the preset malicious behavior chain;
[0052] According to the target similarity, the associated similarity and a preset similarity condition, it is identified whether the target behavior chain and the associated behavior chain belong to the malicious behavior chain.
[0053] Optionally, the preset malicious behavior chain includes at least one malicious behavior chain sample corresponding to at least one application sample; the behavior chain identification module is specifically used to:
[0054] Determine a target malicious behavior chain sample corresponding to the target program in the preset malicious behavior chain, and an associated malicious behavior chain sample corresponding to the associated program;
[0055] Calculating the similarity between the target behavior chain and the target malicious behavior chain sample to obtain the target similarity;
[0056] The similarity between the associated behavior chain and the associated malicious behavior chain sample is calculated to obtain the associated similarity.
[0057] Optionally, the behavior chain identification module is specifically used to:
[0058] Determine each target execution operation behavior in the target behavior chain and its corresponding occurrence order; respectively, in the first sample execution operation behavior corresponding to each target malicious behavior chain sample, extract the behavior that at least partially matches the target execution operation behavior and has the same occurrence order as the first target similar behavior corresponding to each target malicious behavior chain sample; respectively calculate the first ratio of each first target similar behavior to the first sample execution operation behavior corresponding to each of the first target similar behaviors, and obtain the similarity between each target behavior chain and the target malicious behavior chain sample; determine the similarity corresponding to the first ratio with the largest value as the target similarity; and,
[0059] Determine each associated execution operation behavior in the associated behavior chain and its corresponding occurrence order; respectively, in the second sample execution operation behavior corresponding to each of the associated malicious behavior chain samples, extract the behavior that at least partially matches the associated execution operation behavior and has the same occurrence order as the first associated similar behavior corresponding to each of the associated malicious behavior chain samples; respectively calculate the second proportion of each of the first associated similar behaviors to the respective corresponding second sample execution operation behavior, and obtain the similarity between each of the associated behavior chains and the associated malicious behavior chain samples; determine the similarity corresponding to the second proportion with the largest value as the associated similarity.
[0060] Optionally, the behavior chain identification module is specifically used to:
[0061] If the application sample includes the target application, determining the target malicious behavior chain sample corresponding to the target program in the preset malicious behavior chain, and the associated malicious behavior chain sample corresponding to the associated program;
[0062] If the application sample does not include the target application, the similarity between the target behavior chain and the malicious behavior chain sample is calculated to obtain the target similarity, and the similarity between the associated behavior chain and the malicious behavior chain sample is calculated to obtain the associated similarity.
[0063] Optionally, the behavior chain identification module is specifically used to:
[0064] Determine each target execution operation behavior in the target behavior chain and its corresponding occurrence order; respectively, in the third sample execution operation behavior corresponding to each of the malicious behavior chain samples, extract the behavior that at least partially matches the target execution operation behavior and has the same occurrence order as the second target similar behavior corresponding to each of the malicious behavior chain samples; respectively calculate the third ratio of each of the second target similar behavior to the corresponding third sample execution operation behavior, and obtain the similarity between each of the target behavior chains and the malicious behavior chain samples; determine the similarity corresponding to the third ratio with the largest value as the target similarity; and,
[0065] Determine each associated execution operation behavior in the associated behavior chain and its corresponding occurrence order; respectively, in the fourth sample execution operation behavior corresponding to each of the malicious behavior chain samples, extract the behavior that at least partially matches the associated execution operation behavior and has the same occurrence order as the second associated similar behavior corresponding to each of the malicious behavior chain samples; respectively calculate the fourth ratio of each of the second associated similar behaviors to the corresponding fourth sample execution operation behavior, and obtain the similarity between each of the associated behavior chains and the malicious behavior chain samples; determine the similarity corresponding to the fourth ratio with the largest value as the associated similarity ratio.
[0066] Optionally, the device further comprises:
[0067] A malicious behavior chain acquisition module is used to obtain the preset malicious behavior chain before determining the target similarity between the target behavior chain and the preset malicious behavior chain and the association similarity between the association behavior chain and the preset malicious behavior chain according to the preset malicious behavior chain, and save the preset malicious behavior chain in a local preset storage location, wherein the preset malicious behavior chain is determined by multiple ordered behaviors obtained by parsing sensitive program operation behavior records.
[0068] According to another aspect of the present application, a storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the program processing method based on associated program tracking is implemented.
[0069] According to another aspect of the present application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the above-mentioned program processing method based on associated program tracking when executing the program.
[0070] By means of the above technical scheme, the present application provides a program processing method and device based on associated program tracking, and a storage medium, which monitor the execution operation behaviors of the target application and the associated program, determine the target behavior chain of the target application and the associated behavior chain of the associated program, thereby identifying the target behavior chain and the associated behavior chain, and intercepting the target application and the associated program when at least one of them is identified as a malicious behavior chain. Compared with the prior art method of independently identifying the feature values of each program file, the embodiment of the present application can track and identify multiple associated programs during program execution, which not only improves the efficiency of identifying malicious programs, but also, in the case of multiple programs working together to do evil, as long as one malicious program is identified, other related malicious programs can be discovered immediately, thereby improving the accuracy of identifying related programs.
[0071] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0072] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0073] Figure 1 A flowchart of a program processing method based on associated program tracking provided by an embodiment of the present application is shown;
[0074] Figure 2 A schematic diagram of a process flow of executing a program operation behavior provided by an embodiment of the present application is shown;
[0075] Figure 3 A flowchart of another program processing method based on associated program tracking provided by an embodiment of the present application is shown;
[0076] Figure 4 A schematic diagram of the structure of a program processing device based on associated program tracking provided by an embodiment of the present application is shown;
[0077] Figure 5 A schematic diagram of the structure of another program processing device based on associated program tracking provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0078] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that the embodiments and features in the embodiments of the present application can be combined with each other without conflict.
[0079] In this embodiment, a program processing method based on associated program tracking is provided, such as Figure 1 As shown, the method includes:
[0080] Step 101 : monitoring execution operation behaviors corresponding to a target application and an associated program of the target application.
[0081] In the embodiment of the present application, the operating system can monitor the program behavior of each application in the system in real time. Specifically, a function call monitoring tool can be used to track and monitor each program, and a monitoring log is formed that records the behavior records left each time the program runs, so that after monitoring the operation behavior performed by the target application, the behavior record corresponding to the target application behavior is obtained in the monitoring log. In addition, in order to reduce the system memory usage and improve the system operation efficiency, a monitoring cycle can also be set to query the program behavior in the system log according to the cycle and obtain the corresponding behavior record, which is not limited here.
[0082] It is understandable that in order to improve the efficiency of identifying malicious programs, when the monitoring system is executing programs, programs with sensitive or abnormal operating behaviors can be prioritized as target applications for identification, thereby ensuring that malicious programs can be discovered and intercepted in the first place, thereby improving the security of the operating system.
[0083] Step 102: Based on the execution operation behavior, determine the target behavior chain of the target application program and the associated behavior chain of the associated program.
[0084] Furthermore, since each program will involve various behavioral operations in the process of executing the operation behavior, such as filling in the registration form, collecting registration information, querying the network status, etc., the target application program's execution of the operation behavior corresponds to a series of behavioral operation processes, which is equivalent to a behavior chain. Based on the system monitoring information, a target behavior chain for the target application program to execute the operation behavior can be generated according to the sequence of each operation behavior. The target behavior chain records the operation information corresponding to each behavior operation in the process of the target application program executing the operation behavior.
[0085] It should be noted that each behavior operation in the above behavior chain has a post-line order. For example, a target behavior chain may include but is not limited to the following steps: the first step is to collect program process information; the second step is to select the attack process from the program process information; the third step is to inject malicious code into the attack process; the fourth step is to adjust the entry address and base address, and resume the process.
[0086] Step 103: Identify whether the target behavior chain and the associated behavior chain are malicious behavior chains.
[0087] In this embodiment, the target application can be identified as a malicious program by the execution operation behavior characteristics of the target application, wherein the execution operation behavior characteristics of the target application can be reflected by the target behavior chain, that is, the target behavior chain can be analyzed to identify whether the target application is a malicious program. Similarly, the associated behavior chain can be analyzed to identify whether the target application is a malicious program. In a specific application scenario, the target behavior chain and the associated behavior chain can be identified by the malicious behavior chain corresponding to the preset malicious behavior to determine whether the target behavior chain and the associated behavior chain meet the malicious behavior characteristics, thereby realizing the identification of the malicious behavior chain; the target behavior chain and the associated behavior chain can also be identified by the legal behavior chain corresponding to the preset legal behavior to determine whether the target behavior chain and the associated behavior chain meet the legal behavior characteristics. If not, it is determined to be a malicious behavior chain; the target behavior chain and the associated behavior chain can also be analyzed by an expert system to realize the identification of the malicious behavior chain, wherein the expert system is a malicious program identification system trained by machine learning. The identification method of the malicious behavior chain is not limited here.
[0088] Step 104: When the target behavior chain and / or the associated behavior chain belongs to the malicious behavior chain, intercept the target application and the associated program.
[0089] Furthermore, when at least one of the target behavior chain and the associated behavior chain is identified as a malicious behavior chain, it indicates that there are malicious programs in the target application and the associated program. Since the two programs are related to each other, that is, the target application and the associated program may use the other to perform malicious behavior, both programs can be identified as malicious programs and intercepted, thereby improving the security of the terminal system, and identifying the programs in an associated manner, thereby reducing the problem of low recognition accuracy caused by independent judgment of each program, and improving the accuracy of malicious program identification. Of course, the two programs can also be intercepted first, and then further identified through other means such as expert systems, so as to reduce the probability of misidentification of malicious programs and further improve the recognition accuracy, wherein the expert system is a malicious program identification system trained by machine learning.
[0090] By applying the technical solution of this embodiment, the execution operation behaviors of the target application and the associated programs are monitored, and the target behavior chain of the target application and the associated behavior chain of the associated programs are determined, so as to identify the target behavior chain and the associated behavior chain, and intercept the target application and the associated programs when at least one of them is identified as a malicious behavior chain. Compared with the prior art method of independently identifying the characteristic values of each program file, the embodiment of the present application can track and identify multiple associated programs during the program running process, which not only improves the recognition efficiency of malicious programs, but also in the case of multiple programs working together to do evil, as long as one malicious program is identified, other related malicious programs can be discovered immediately, thereby improving the recognition accuracy of related programs.
[0091] In an embodiment of the present application, optionally, the associated program includes an upstream associated program and / or a downstream associated program, the target application is created and / or downloaded by executing the process of the upstream associated program, and the downstream associated program is created and / or downloaded by executing the process of the target application.
[0092] In the above embodiment, for the target application, the associated program may include an upstream associated program and / or a downstream associated program. The upstream associated program can specifically create and download the target application by calling a process. Conversely, the downstream associated program is specifically a program that the target application creates and downloads by calling a process. It can also be said that the target application is a program that is created and downloaded by executing the upstream associated program through a certain process, and the downstream associated program is a program that is created and downloaded by executing the target application through a certain process. Therefore, the present application solution can not only track whether the target application is malicious by tracking the upstream and downstream processes across processes, but also track the associated programs in the upstream and downstream processes with the target application, ensuring that the identification of malicious programs is more thorough and accurate.
[0093] like Figure 2 As shown, malicious program A downloads malicious program B from the cloud to the local computer. Malware program A is the upstream associated program of malicious program B. Conversely, malicious program B is the downstream associated program of malicious program A. Similarly, malicious program A loads malicious program B into the startup item by modifying the registry. The operating system considers malicious program B in the startup item as created by malicious program A. At this time, malicious program A is the upstream associated program of malicious program B. Conversely, malicious program B is the downstream associated program of malicious program A.
[0094] Furthermore, when identifying malicious programs, not only the target application itself can be identified, but also the corresponding associated programs can be identified, so as to reduce the phenomenon that the malicious program feature library is not comprehensive enough, resulting in the omission of malicious programs. As long as a program is identified as a malicious program, other programs on the same link can be intercepted, thereby improving the efficiency and accuracy of malicious program identification, thereby improving system security. For example, for the identification of program A, not only the behavior chain of program A itself can be identified, but also the behavior chains of the upstream and downstream associated programs B and C of program A can be identified. Assuming that program B is considered a malicious program, then the related programs A and C can be temporarily considered as malicious programs and intercepted. Figure 2 As shown, if only a single program is identified, malicious program A only downloads / registers malicious program B. Based on the existing malicious program identification mechanism, it may be difficult to identify the program as a malicious program. However, if the associated program, that is, malicious program B, is tracked and identified, based on the malicious program B's startup, browser checking, address book checking, mailbox checking, data sending and other behaviors, when the associated program B is determined to be a malicious program, the malicious program A can be identified more accurately and quickly.
[0095] Further, as a refinement and extension of the specific implementation of the above embodiment, in order to fully illustrate the specific implementation process of this embodiment, another program processing method based on associated program tracking is provided, such as Figure 3 As shown, the method includes:
[0096] Step 201, obtaining the preset malicious behavior chain, and saving the preset malicious behavior chain in a local preset storage location, wherein the preset malicious behavior chain is determined by parsing a plurality of ordered behaviors obtained by analyzing sensitive program operation behavior records.
[0097] Generally speaking, the operational behaviors of malicious programs include two aspects. One is malicious operational behaviors, such as denial of network services, network viruses, etc. These behaviors are aimed at consuming server resources, affecting the normal operation of the server, and even paralyzing the network where the server is located; the other is malicious intrusion behavior, which will lead to the leakage of sensitive server information. The intruder can do whatever he wants and wantonly destroy the server.
[0098] In this embodiment, before the terminal executes the program, it can first obtain a preset malicious behavior chain and store it in a preset storage location, so that the preset malicious behavior chain can be read at the location later to identify the malicious program. The preset malicious behavior chain can be determined by the preset terminal by parsing the preset sensitive program operation behavior record. The sensitive program can include a predetermined malicious program, and can also include related programs of the malicious program, such as programs controlled by the malicious program. For malicious programs, multiple ordered behaviors can be obtained by obtaining the operation behavior log of the malicious program and parsing the log, and the ordered behaviors are arranged in sequence to form a behavior chain. For the related programs of the malicious program, the corresponding behavior chain can be obtained by the method set by the technician, or by parsing the malicious operation records of the related programs.
[0099] Specifically, for malicious programs and related programs manipulated by malicious programs (hereinafter referred to as malicious programs), the operation behavior of malicious programs can be extracted through feature code detection and killing technology. Here, the feature code detection and killing technology can be to extract feature codes in the malicious program code, extract feature codes through special character strings, extract universal killing feature codes, etc., and the operation behavior of malicious programs can also be extracted through heuristic detection and killing technology, for example, by analyzing the order of malicious program execution instructions or specific behavior combination characteristics, and the operation behavior of malicious programs can also be extracted through virtual machine detection and killing technology. For example, when scanning malicious programs, by loading malicious programs into a virtual machine environment to run, the malicious programs are automatically unpacked and restored to the existing state. Among them, the sandbox mechanism is equivalent to a virtual machine environment. Through redirection technology, each operation behavior in the malicious program can be tested, so as to extract each behavior operation in the process of the malicious program executing the operation behavior, and form a behavior chain of the malicious program executing the operation behavior. After extracting the operation behavior of the malicious program, since the sandbox mechanism is in a closed environment and has high security, the operation behavior of the malicious program is parsed through the sandbox mechanism to obtain at least one malicious behavior chain corresponding to each malicious program.
[0100] Step 202: monitor the execution operation behaviors corresponding to the target application and the associated programs of the target application.
[0101] Step 203: Based on the execution operation behavior, determine the target behavior chain of the target application program and the associated behavior chain of the associated program.
[0102] The embodiment of the present application can monitor each application running in the system. The monitoring is not limited to the execution operation behavior of the target application of the present application, but can also include the execution operation behavior of the associated programs of the target application, that is, downloading and creating the upstream associated programs of the target application, and the downstream associated programs downloaded and created by the target application. Then, based on the monitoring information, the target behavior chain of the target application and the associated behavior chain of the associated programs are generated.
[0103] Step 204: According to the preset malicious behavior chain, the target similarity between the target behavior chain and the preset malicious behavior chain and the association similarity between the association behavior chain and the preset malicious behavior chain are determined respectively.
[0104] In the embodiment of the present application, the target similarity between the target behavior chain and the preset malicious behavior chain can be used to identify whether the target application belongs to a known malicious program type, and the associated similarity between the associated behavior chain and the preset malicious behavior chain can be used to identify whether the associated application belongs to a known malicious program type. Optionally, the preset malicious behavior chain includes at least one malicious behavior chain sample corresponding to at least one application sample; step 204 can specifically include:
[0105] Step 204-1, if the application sample includes the target application, determine the target malicious behavior chain sample corresponding to the target program in the preset malicious behavior chain, and the associated malicious behavior chain sample corresponding to the associated program; calculate the similarity between the target behavior chain and the target malicious behavior chain sample to obtain the target similarity; calculate the similarity between the associated behavior chain and the associated malicious behavior chain sample to obtain the associated similarity.
[0106] Step 204-2, if the application sample does not include the target application, the similarity between the target behavior chain and the malicious behavior chain sample is calculated to obtain the target similarity, and the similarity between the associated behavior chain and the malicious behavior chain sample is calculated to obtain the associated similarity.
[0107] In the above embodiment, the pre-acquired preset malicious behavior chain may include at least one malicious behavior chain sample corresponding to different application samples (i.e., sensitive programs). In order to improve recognition efficiency and accuracy, malicious behavior chain samples corresponding to application samples that are the same or of the same type as the target application can be obtained in the preset malicious behavior chain as target malicious behavior chain samples. Furthermore, if the target malicious behavior chain samples include multiple, the similarity between each target malicious behavior chain sample and the target behavior chain can be calculated separately, and the maximum similarity can be obtained as the target similarity. If there is only one target malicious behavior chain sample, the similarity between the one target malicious behavior chain sample and the target behavior chain is directly used as the target similarity. The calculation method of the associated similarity is similar to the calculation method of the target similarity in step 204-1, which will not be repeated here.
[0108] In addition, if the application sample corresponding to the preset malicious behavior chain does not include the target application, nor does it include a program sample of the same type as the target application, then based on the characteristic that the operation behaviors of malicious programs are similar, the application corresponding to the behavior chain can be ignored, and the similarity between the target behavior chain and each preset malicious behavior chain can be calculated respectively, and the maximum similarity is obtained as the target similarity. The calculation method of the associated similarity is similar to the calculation method of the target similarity in step 204-2, and will not be repeated here.
[0109] In a specific application scenario, optionally, the method for calculating the target similarity in step 204-1 may specifically include: determining each target execution operation behavior in the target behavior chain and its corresponding occurrence order; respectively, in the first sample execution operation behavior corresponding to each of the target malicious behavior chain samples, extracting the behavior that at least partially matches the target execution operation behavior and has the same occurrence order as the first target similar behavior corresponding to each of the target malicious behavior chain samples; respectively calculating the first ratio of each of the first target similar behaviors to the first sample execution operation behavior corresponding to each of the first target similar behaviors, and obtaining the similarity between each of the target behavior chains and the target malicious behavior chain samples; determining the similarity corresponding to the first ratio with the largest value as the target similarity;
[0110] The method for calculating the association similarity in step 204-1 may specifically include: determining each associated execution operation behavior in the associated behavior chain and its corresponding occurrence order; respectively, in the second sample execution operation behavior corresponding to each of the associated malicious behavior chain samples, extracting the behavior that at least partially matches the associated execution operation behavior and has the same occurrence order as the first associated similar behavior corresponding to each of the associated malicious behavior chain samples; respectively calculating the second proportion of each of the first associated similar behaviors to the corresponding second sample execution operation behavior, to obtain the similarity between each of the associated behavior chains and the associated malicious behavior chain samples; and determining the similarity corresponding to the second proportion with the largest value as the association similarity.
[0111] In this embodiment, the target execution operation behaviors and the order in which each behavior occurs in the target behavior chain are obtained. For any target malicious behavior chain sample, the behaviors that match or partially match the target execution operation behaviors and have the same occurrence order are extracted from the first sample execution operation behaviors contained in the target malicious behavior chain sample and are used as the first target similar behaviors.
[0112] For example, the target behavior chain A includes behavior 1, behavior 2, behavior 3, behavior 4, and behavior 5 in sequence, and a target malicious behavior chain sample B includes behavior 1, behavior 6, behavior 3, and behavior 4 in order. Then, based on the first behavior in behavior chain A, namely behavior 1, we can first identify whether behavior chain sample B contains behavior 1. If so, we will extract behavior 1, and identify whether the second behavior in behavior chain A, namely behavior 2, is included in the remaining behaviors of behavior chain sample B (namely behavior 6, behavior 3, and behavior 4). If not, we will continue to identify whether the remaining behaviors (since no new behaviors are acquired, the remaining behavior chains remain unchanged) contain the third behavior in behavior chain A, namely behavior 3. If so, we will extract behavior 3, and continue to identify whether the remaining behaviors after behavior 3 in behavior chain sample B contain the fourth behavior in behavior chain A, namely behavior 4. If so, we will extract behavior 4, and complete the identification of all behaviors in behavior chain A. Finally, the first target similar behaviors extracted include behavior 1, behavior 3, and behavior 4. Based on a target malicious behavior chain sample, after obtaining the first target similar behavior, the ratio of the number of the first target similar behavior to the total number of behaviors of the target malicious behavior chain sample can be calculated. After calculating all target malicious behavior chain samples, the maximum ratio calculated is used as the target similarity. In addition, the calculation method of the association similarity is similar to the above-mentioned method of calculating the target similarity, which will not be repeated here.
[0113] It should be noted that in order to improve recognition accuracy and efficiency, when determining the preset malicious behavior chain, the most critical core behaviors can be retained as much as possible in each behavior chain, so that when the program generates the core execution operation behavior, the malicious program can be accurately identified.
[0114] In an embodiment of the present application, optionally, step 204-2 may specifically include: determining each target execution operation behavior in the target behavior chain and its corresponding occurrence order; respectively, in the third sample execution operation behavior corresponding to each of the malicious behavior chain samples, extracting the behavior that at least partially matches the target execution operation behavior and has the same occurrence order as the second target similar behavior corresponding to each of the malicious behavior chain samples; respectively calculating the third proportion of each of the second target similar behavior to the corresponding third sample execution operation behavior, to obtain the similarity between each of the target behavior chains and the malicious behavior chain samples; determining the similarity corresponding to the third proportion with the largest value as the target similarity; and,
[0115] Determine each associated execution operation behavior in the associated behavior chain and its corresponding occurrence order; respectively, in the fourth sample execution operation behavior corresponding to each of the malicious behavior chain samples, extract the behavior that at least partially matches the associated execution operation behavior and has the same occurrence order as the second associated similar behavior corresponding to each of the malicious behavior chain samples; respectively calculate the fourth ratio of each of the second associated similar behaviors to the corresponding fourth sample execution operation behavior, and obtain the similarity between each of the associated behavior chains and the malicious behavior chain samples; determine the similarity corresponding to the fourth ratio with the largest value as the associated similarity ratio.
[0116] In the above embodiment, after determining the target execution operation behavior and the order of occurrence corresponding to the target behavior chain, for any malicious behavior chain sample, the second target similar behavior is extracted, and the number of second target similar behaviors is calculated as the ratio of all behaviors in the malicious behavior chain sample, so that the maximum ratio corresponding to each malicious behavior chain sample is used as the target similarity. The specific calculation method is similar to the method of determining the first target similar behavior and calculating the target similarity corresponding to the first target similar behavior above, and will not be repeated here. Similarly, the correlation similarity can be obtained based on a similar method.
[0117] Step 205: Identify whether the target behavior chain and the associated behavior chain belong to the malicious behavior chain based on the target similarity, the associated similarity and a preset similarity condition.
[0118] Step 206: When the target behavior chain and / or the associated behavior chain belongs to the malicious behavior chain, intercept the target application and the associated program.
[0119] In the embodiment of the present application, the preset similarity condition may specifically include a target similarity threshold and an associated similarity threshold, wherein the target similarity threshold and the associated similarity threshold may be the same or different. When it is determined that at least one of the target similarity and the associated similarity satisfies the preset similarity condition, the target application and its corresponding associated program may be temporarily identified as malicious programs and intercepted. This enables rapid identification of the program itself and associated programs during program operation.
[0120] By applying the technical solution of the embodiments of the present application, during the operation of a malicious program, the similarity between the behavior chain corresponding to the executed behavior and the corresponding preset malicious behavior chain can be calculated in real time based on the monitoring mechanism, so that when the preset similarity conditions are met, the target application and associated programs can be intercepted. As long as the malicious program executes a certain number of behaviors in the preset malicious behavior chain, the malicious program and its corresponding associated programs can be quickly identified based on the mechanism, thereby improving the efficiency and accuracy of malicious program identification.
[0121] Further, as Figure 1 The specific implementation of the method, the embodiment of the present application provides a program processing device based on associated program tracking, such as Figure 4 As shown, the device comprises:
[0122] A monitoring module, used to monitor the execution operation behaviors corresponding to the target application and the associated programs of the target application;
[0123] A behavior chain determination module, used to determine the target behavior chain of the target application program and the associated behavior chain of the associated program based on the execution operation behavior;
[0124] A behavior chain identification module, used to identify whether the target behavior chain and the associated behavior chain are malicious behavior chains;
[0125] A program processing module is used to intercept the target application and the associated program when the target behavior chain and / or the associated behavior chain belong to the malicious behavior chain.
[0126] In an embodiment of the present application, optionally, the associated program includes an upstream associated program and / or a downstream associated program, the target application is created and / or downloaded by executing the process of the upstream associated program, and the downstream associated program is created and / or downloaded by executing the process of the target application.
[0127] In an embodiment of the present application, optionally, the behavior chain identification module is specifically used to: determine, according to a preset malicious behavior chain, the target similarity between the target behavior chain and the preset malicious behavior chain and the association similarity between the associated behavior chain and the preset malicious behavior chain; and identify, based on the target similarity, the association similarity and the preset similarity condition, whether the target behavior chain and the associated behavior chain belong to the malicious behavior chain.
[0128] In the embodiment of the present application, optionally, the preset malicious behavior chain includes at least one malicious behavior chain sample corresponding to at least one application sample; the behavior chain identification module is specifically used to:
[0129] Determine a target malicious behavior chain sample corresponding to the target program in the preset malicious behavior chain, and an associated malicious behavior chain sample corresponding to the associated program;
[0130] Calculating the similarity between the target behavior chain and the target malicious behavior chain sample to obtain the target similarity;
[0131] The similarity between the associated behavior chain and the associated malicious behavior chain sample is calculated to obtain the associated similarity.
[0132] In the embodiment of the present application, optionally, the behavior chain identification module is specifically used to:
[0133] Determine each target execution operation behavior in the target behavior chain and its corresponding occurrence order; respectively, in the first sample execution operation behavior corresponding to each target malicious behavior chain sample, extract the behavior that at least partially matches the target execution operation behavior and has the same occurrence order as the first target similar behavior corresponding to each target malicious behavior chain sample; respectively calculate the first ratio of each first target similar behavior to the first sample execution operation behavior corresponding to each of the first target similar behaviors, and obtain the similarity between each target behavior chain and the target malicious behavior chain sample; determine the similarity corresponding to the first ratio with the largest value as the target similarity; and,
[0134] Determine each associated execution operation behavior in the associated behavior chain and its corresponding occurrence order; respectively, in the second sample execution operation behavior corresponding to each of the associated malicious behavior chain samples, extract the behavior that at least partially matches the associated execution operation behavior and has the same occurrence order as the first associated similar behavior corresponding to each of the associated malicious behavior chain samples; respectively calculate the second proportion of each of the first associated similar behaviors to the respective corresponding second sample execution operation behavior, and obtain the similarity between each of the associated behavior chains and the associated malicious behavior chain samples; determine the similarity corresponding to the second proportion with the largest value as the associated similarity.
[0135] In the embodiment of the present application, optionally, the behavior chain identification module is specifically used to:
[0136] If the application sample includes the target application, determining the target malicious behavior chain sample corresponding to the target program in the preset malicious behavior chain, and the associated malicious behavior chain sample corresponding to the associated program;
[0137] If the application sample does not include the target application, the similarity between the target behavior chain and the malicious behavior chain sample is calculated to obtain the target similarity, and the similarity between the associated behavior chain and the malicious behavior chain sample is calculated to obtain the associated similarity.
[0138] In the embodiment of the present application, optionally, the behavior chain identification module is specifically used to:
[0139] Determine each target execution operation behavior in the target behavior chain and its corresponding occurrence order; respectively, in the third sample execution operation behavior corresponding to each of the malicious behavior chain samples, extract the behavior that at least partially matches the target execution operation behavior and has the same occurrence order as the second target similar behavior corresponding to each of the malicious behavior chain samples; respectively calculate the third ratio of each of the second target similar behavior to the corresponding third sample execution operation behavior, and obtain the similarity between each of the target behavior chains and the malicious behavior chain samples; determine the similarity corresponding to the third ratio with the largest value as the target similarity; and,
[0140] Determine each associated execution operation behavior in the associated behavior chain and its corresponding occurrence order; respectively, in the fourth sample execution operation behavior corresponding to each of the malicious behavior chain samples, extract the behavior that at least partially matches the associated execution operation behavior and has the same occurrence order as the second associated similar behavior corresponding to each of the malicious behavior chain samples; respectively calculate the fourth ratio of each of the second associated similar behaviors to the corresponding fourth sample execution operation behavior, and obtain the similarity between each of the associated behavior chains and the malicious behavior chain samples; determine the similarity corresponding to the fourth ratio with the largest value as the associated similarity ratio.
[0141] In the embodiments of the present application, Figure 5 As shown, optionally, the device further includes:
[0142] A malicious behavior chain acquisition module is used to obtain the preset malicious behavior chain before determining the target similarity between the target behavior chain and the preset malicious behavior chain and the association similarity between the association behavior chain and the preset malicious behavior chain according to the preset malicious behavior chain, and save the preset malicious behavior chain in a local preset storage location, wherein the preset malicious behavior chain is determined by multiple ordered behaviors obtained by parsing sensitive program operation behavior records.
[0143] It should be noted that for other corresponding descriptions of the functional units involved in the program processing device based on associated program tracking provided in the embodiment of the present application, reference can be made to Figures 1 to 3 The corresponding description in the method will not be repeated here.
[0144] Based on the above Figures 1 to 3 The method shown in the embodiment of the present application is accordingly provided with a storage medium on which a computer program is stored, and when the computer program is executed by a processor, the above-mentioned Figures 1 to 3 The program processing method based on associated program tracking is shown.
[0145] Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.), and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each implementation scenario of the present application.
[0146] Based on the above Figures 1 to 3 The method shown, and Figures 4 to 5 In order to achieve the above-mentioned purpose, the embodiment of the present application further provides a computer device, which can be a personal computer, a server, a network device, etc. The computer device includes a storage medium and a processor; the storage medium is used to store a computer program; the processor is used to execute the computer program to achieve the above-mentioned Figures 1 to 3 The program processing method based on associated program tracking is shown.
[0147] Optionally, the computer device may further include a user interface, a network interface, a camera, a radio frequency (RF) circuit, a sensor, an audio circuit, a WI-FI module, etc. The user interface may include a display, an input unit such as a keyboard, etc., and the optional user interface may also include a USB interface, a card reader interface, etc. The network interface may optionally include a standard wired interface, a wireless interface (such as a Bluetooth interface, a WI-FI interface), etc.
[0148] Those skilled in the art will appreciate that the computer device structure provided in this embodiment does not limit the computer device, and may include more or fewer components, or a combination of certain components, or different component arrangements.
[0149] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages and saves the hardware and software resources of the computer device, and supports the operation of information processing programs and other software and / or programs. The network communication module is used to realize communication between the components inside the storage medium, and communication with other hardware and software in the physical device.
[0150] Through the description of the above implementation methods, those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform, or by means of hardware to monitor the execution behavior of the target application and the associated program, determine the target behavior chain of the target application and the associated behavior chain of the associated program, thereby identifying the target behavior chain and the associated behavior chain, and intercepting the target application and the associated program when at least one of them is identified as a malicious behavior chain. Compared with the prior art method of independently identifying the characteristic values of each program file, the embodiment of the present application can track and identify multiple associated programs during program execution, which not only improves the efficiency of identifying malicious programs, but also, in the case of multiple programs working together to do evil, as long as one malicious program is identified, other related malicious programs can be discovered immediately, thereby improving the accuracy of identifying related programs.
[0151] Those skilled in the art will appreciate that the accompanying drawings are only schematic diagrams of a preferred implementation scenario, and the modules or processes in the accompanying drawings are not necessarily necessary for implementing the present application. Those skilled in the art will appreciate that the modules in the devices in the implementation scenario can be distributed in the devices of the implementation scenario according to the description of the implementation scenario, or can be changed accordingly and located in one or more devices different from the present implementation scenario. The modules of the above-mentioned implementation scenario can be combined into one module, or can be further split into multiple submodules.
[0152] The above serial numbers of this application are only for description and do not represent the advantages and disadvantages of the implementation scenarios. The above disclosure is only a few specific implementation scenarios of this application, but this application is not limited to them, and any changes that can be thought of by technicians in this field should fall within the scope of protection of this application.
Claims
1. A program processing method based on associated program tracking, It is characterized in that include: Monitoring the execution operation behaviors of the target application and the associated programs of the target application; Based on the execution operation behavior, determining a target behavior chain of the target application program and an associated behavior chain of the associated program; Identifying whether the target behavior chain and the associated behavior chain belong to a malicious behavior chain, comprising: determining, according to a preset malicious behavior chain, a target similarity between the target behavior chain and the preset malicious behavior chain and an associated similarity between the associated behavior chain and the preset malicious behavior chain; identifying whether the target behavior chain and the associated behavior chain belong to the malicious behavior chain according to the target similarity, the associated similarity and a preset similarity condition; When the target behavior chain and / or the associated behavior chain belongs to the malicious behavior chain, intercepting the target application and the associated program; The preset malicious behavior chain includes at least one malicious behavior chain sample corresponding to at least one application sample; and determining, according to the preset malicious behavior chain, the target similarity between the target behavior chain and the preset malicious behavior chain and the association similarity between the association behavior chain and the preset malicious behavior chain, respectively, including: Determine a target malicious behavior chain sample corresponding to the target application program in the preset malicious behavior chain, and an associated malicious behavior chain sample corresponding to the associated program; Determine each target execution operation behavior in the target behavior chain and its corresponding occurrence order; respectively, in the first sample execution operation behavior corresponding to each target malicious behavior chain sample, extract the behavior that at least partially matches the target execution operation behavior and has the same occurrence order as the first target similar behavior corresponding to each target malicious behavior chain sample; respectively calculate the first ratio of each first target similar behavior to the first sample execution operation behavior corresponding to each, and obtain the similarity between each target behavior chain and the target malicious behavior chain sample; determine the similarity corresponding to the first ratio with the largest value as the target similarity; Determine each associated execution operation behavior in the associated behavior chain and its corresponding occurrence order; respectively, in the second sample execution operation behavior corresponding to each of the associated malicious behavior chain samples, extract the behavior that at least partially matches the associated execution operation behavior and has the same occurrence order as the first associated similar behavior corresponding to each of the associated malicious behavior chain samples; respectively calculate the second proportion of each of the first associated similar behaviors to the respective corresponding second sample execution operation behavior, and obtain the similarity between each of the associated behavior chains and the associated malicious behavior chain samples; determine the similarity corresponding to the second proportion with the largest value as the associated similarity.
2. The method according to claim 1, It is characterized in that The associated program includes an upstream associated program and / or a downstream associated program, the target application is created and / or downloaded by executing a process of the upstream associated program, and the downstream associated program is created and / or downloaded by executing a process of the target application.
3. The method according to claim 1, It is characterized in that The determining, according to the preset malicious behavior chain, respectively the target similarity between the target behavior chain and the preset malicious behavior chain and the association similarity between the association behavior chain and the preset malicious behavior chain specifically includes: If the application sample includes the target application, determining the target malicious behavior chain sample corresponding to the target application in the preset malicious behavior chain, and the associated malicious behavior chain sample corresponding to the associated program; If the application sample does not include the target application, the similarity between the target behavior chain and the malicious behavior chain sample is calculated to obtain the target similarity, and the similarity between the associated behavior chain and the malicious behavior chain sample is calculated to obtain the associated similarity.
4. The method according to claim 3, It is characterized in that The calculating the similarity between the target behavior chain and the malicious behavior chain sample to obtain the target similarity specifically includes: Determine each target execution operation behavior in the target behavior chain and its corresponding occurrence order; Extracting behaviors that at least partially match the target execution operation behaviors and have the same occurrence order from the third sample execution operation behaviors corresponding to each of the malicious behavior chain samples as the second target similar behaviors corresponding to each of the malicious behavior chain samples; Calculate the third ratio of each of the second target similar behaviors to the third sample execution operation behaviors respectively, and obtain the similarity between each of the target behavior chains and the malicious behavior chain samples; Determine the similarity corresponding to the third ratio with the largest value as the target similarity; The calculating the similarity between the associated behavior chain and the malicious behavior chain sample to obtain the associated similarity specifically includes: Determine each associated execution operation behavior in the associated behavior chain and its corresponding occurrence order; Respectively, from the fourth sample execution operation behaviors corresponding to each of the malicious behavior chain samples, extract behaviors that at least partially match the associated execution operation behaviors and have the same occurrence order as the second associated similar behaviors corresponding to each of the malicious behavior chain samples; Calculate respectively a fourth ratio of each of the second associated similar behaviors to the fourth sample execution operation behaviors corresponding to each of the second associated similar behaviors, and obtain a similarity between each of the associated behavior chains and the malicious behavior chain sample; The similarity corresponding to the fourth ratio with the largest value is determined as the associated similarity ratio.
5. The method according to claim 1, It is characterized in that Before respectively determining the target similarity between the target behavior chain and the preset malicious behavior chain and the association similarity between the association behavior chain and the preset malicious behavior chain according to the preset malicious behavior chain, the method further includes: The preset malicious behavior chain is obtained and saved in a local preset storage location, wherein the preset malicious behavior chain is determined by a plurality of ordered behaviors obtained by parsing sensitive program operation behavior records.
6. A program processing device based on associated program tracking, It is characterized in that include: A monitoring module, used to monitor the execution operation behaviors corresponding to the target application and the associated programs of the target application; A behavior chain determination module, used to determine the target behavior chain of the target application program and the associated behavior chain of the associated program based on the execution operation behavior; A behavior chain identification module, used to identify whether the target behavior chain and the associated behavior chain are malicious behavior chains; A program processing module, configured to intercept the target application and the associated program when the target behavior chain and / or the associated behavior chain belong to the malicious behavior chain; The behavior chain identification module is further used to: determine the target similarity between the target behavior chain and the preset malicious behavior chain and the association similarity between the associated behavior chain and the preset malicious behavior chain according to the preset malicious behavior chain; and identify whether the target behavior chain and the associated behavior chain belong to the malicious behavior chain according to the target similarity, the association similarity and the preset similarity condition; The preset malicious behavior chain includes at least one malicious behavior chain sample corresponding to at least one application sample; the behavior chain identification module is specifically used to: determine the target malicious behavior chain sample corresponding to the target application in the preset malicious behavior chain, and the associated malicious behavior chain sample corresponding to the associated program; calculate the similarity between the target behavior chain and the target malicious behavior chain sample to obtain the target similarity; calculate the similarity between the associated behavior chain and the associated malicious behavior chain sample to obtain the associated similarity; The behavior chain identification module is also used for: Determine each target execution operation behavior in the target behavior chain and its corresponding occurrence order; respectively, in the first sample execution operation behavior corresponding to each target malicious behavior chain sample, extract the behavior that at least partially matches the target execution operation behavior and has the same occurrence order as the first target similar behavior corresponding to each target malicious behavior chain sample; Calculate the first ratio of each of the first target similar behaviors to the first sample execution operation behaviors corresponding to each of the first target behaviors to obtain the similarity between each of the target behavior chains and the target malicious behavior chain samples; determine the similarity corresponding to the first ratio with the largest value as the target similarity; and Determine each associated execution operation behavior in the associated behavior chain and its corresponding occurrence order; Respectively, from the second sample execution operation behaviors corresponding to each of the associated malicious behavior chain samples, extract behaviors that at least partially match the associated execution operation behaviors and have the same occurrence order as the first associated similar behaviors corresponding to each of the associated malicious behavior chain samples; Calculate the second ratio of each of the first associated similar behaviors to the second sample execution operation behavior corresponding to each of the first associated similar behaviors, and obtain the similarity between each of the associated behavior chains and the associated malicious behavior chain samples; determine the similarity corresponding to the second ratio with the largest value as the associated similarity.
7. A storage medium having a computer program stored thereon, It is characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.
8. A computer device comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, It is characterized in that When the processor executes the computer program, the method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
A network attack detection method and an electronic device
CN109040136A