A memory forensics method, device and electronic device
By directly accessing the memory address space during the execution of IOT sample interrupt instruction, the inefficient memory evidence for the existing technology is solved, and fast and efficient memory data acquisition is achieved.
Patent Information
- Application Number
- CN202111423944.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-26
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-11-26
AI Technical Summary
The existing memory forensics method simulates the execution of operating system instructions through the virtual processor qemu-system, resulting in inefficiency and cannot meet the memory forensics requirements of a large number of IOT samples.
When it is detected that the IOT sample interrupt instruction execution process complies with preset rules, the memory address space of the IOT sample is directly accessed through the operating system kernel state, and the memory data is read to avoid impersonating the execution of operating system instructions.
It improves the efficiency and accuracy of memory forensics, and can quickly obtain memory data of IOT samples without waiting for the sample run to end.
Smart Images

Figure CN114153759B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer network security technology, and in particular, to a memory forensics method, device, and electronic device. Background Art
[0002] With the rapid development of the Internet of Things (IoT) technology, the number of IoT malware in the ELF format based on the Linux operating system is increasing day by day. A large number of IoT samples with non-x86 architectures need to be automatically analyzed and investigated dynamically. Moreover, today's malware is becoming increasingly complex, and the complexity and concealment of the Advanced Persistent Threat (APT) attack and defense are getting stronger and stronger. Therefore, there is an urgent need for a memory forensics method to perform instruction-level analysis on IoT samples composed of any CPU architecture, and then to detect and investigate the malicious behaviors of malware in real time. Among them, malicious behaviors can control the system server, steal important information, and damage the system stability.
[0003] The current memory forensics methods mainly perform dynamic analysis on IoT samples with any CPU architecture through the virtual processor qemu. Among them, qemu has two operating modes. One is the user-mode emulation mode qemu-user, and the other operating mode is the full-system emulation mode qemu-system. Generally, qemu-user cannot directly detect the CPU kernel layer and cannot meet the CPU instruction-level analysis requirements. While qemu-system can simulate both the user state and the kernel state of the operating system. Therefore, currently, qemu-system is mainly used to perform dynamic analysis on IoT samples with any CPU architecture.
[0004] Although the above-mentioned method based on qemu-system can achieve dynamic analysis of IoT samples with any CPU architecture, since qemu-system needs to simulate and execute all the operation instructions of the entire operating system and all the instructions of the IoT samples running on the operating system, the efficiency of memory forensics for IoT samples is not high, and it cannot meet the memory forensics requirements of a large number of IoT samples. Summary of the Invention
[0005] This application provides a memory forensics method, device, and electronic device. When it is detected that the execution process of the interrupt instruction in the IoT sample conforms to the preset rules, the memory address space corresponding to the IoT sample is further accessed, and then the memory data for memory forensics is read. This memory forensics method does not require simulating and executing the operation instructions of the operating system, and does not require the IoT sample to end its operation to quickly obtain the memory data corresponding to the IoT sample, thereby improving the efficiency and accuracy of memory forensics.
[0006] In a first aspect, the present application provides a memory forensics method, the method comprising:
[0007] When an Internet of Things (IoT) sample is obtained, execute an interrupt instruction in the IoT sample through the operating system kernel mode;
[0008] When it is detected that the execution process of the interrupt instruction conforms to a first preset rule, access the memory address space corresponding to the IoT sample in a preset manner, wherein the first preset rule is an operating rule of a malicious sample;
[0009] Read the memory data corresponding to the memory address space, and perform memory forensics on the IoT sample based on the memory data.
[0010] Through the above method, when it is detected that the execution process of the interrupt instruction in the IoT sample conforms to a preset rule, further access the memory address space corresponding to the IoT sample, and then read the memory data for memory forensics. This memory forensics method does not require simulating the execution of operating system operation instructions, and does not require the IoT sample to run to completion to quickly obtain the memory data corresponding to the IoT sample, thereby improving the efficiency and accuracy of memory forensics.
[0011] Furthermore, executing the interrupt instruction in the IoT sample through the operating system kernel mode includes:
[0012] Start the operating system based on a virtualization program for hardware virtualization;
[0013] Run the IoT sample through the user mode of the operating system, and detect whether the interrupt instruction in the IoT sample is triggered;
[0014] If so, adjust the user mode of the operating system to the kernel mode, and execute the interrupt instruction through the kernel mode of the operating system;
[0015] If not, continue to run the IoT sample in the user mode of the operating system.
[0016] Through the above method, when the interrupt instruction is triggered during the execution of the IoT sample, execute the interrupt instruction in the user mode of the operating system, which can support subsequent further obtaining the memory data corresponding to the running process of the IoT sample.
[0017] Furthermore, when it is detected that the execution process of the interrupt instruction conforms to the first preset rule, accessing the memory address space corresponding to the IoT sample in a preset manner includes:
[0018] Hook the preset function to enhance the page table;
[0019] Detect whether the execution process of the interrupt instruction calls the preset function through the hook program;
[0020] If so, continue to execute the preset function and access the memory address space corresponding to the IOT sample by triggering a preset instruction;
[0021] If not, continue to execute the interrupt instruction.
[0022] Through the above method, set a trap for the preset function. When the trap is triggered, it indicates that the IOT sample may be a malicious sample. Then, further access the memory address space corresponding to the IOT sample by executing a preset instruction, which is convenient for further memory forensics analysis of the IOT sample.
[0023] Furthermore, read the memory data corresponding to the memory address space and perform memory forensics on the IOT sample based on the memory data, including:
[0024] Obtain the memory address space read / write rules corresponding to the operating system where the IOT sample is located;
[0025] According to the memory address space read / write rules, read the memory data of the memory address space corresponding to the IOT sample;
[0026] Analyze the running process of the IOT sample based on the memory data and perform memory forensics on the IOT sample.
[0027] Through the above method, read the memory data corresponding to the IOT sample memory address space and use the memory data for memory forensics analysis.
[0028] In a possible design, execute the interrupt instruction in the IOT sample through the operating system kernel mode, including:
[0029] Determine whether the IOT sample is a malicious sample;
[0030] If not, execute the interrupt instruction in the IOT sample through the operating system kernel mode;
[0031] If so, start the malicious sample according to the user-mode preset simulator plugin, where the user-mode preset simulator plugin can obtain the virtual CPU register values corresponding to the current process;
[0032] Trace the instruction execution process corresponding to the malicious sample and detect whether the execution process of the current instruction conforms to the second preset rule, where the second preset rule is the running rule of the malicious sample;
[0033] When the execution process of the current instruction conforms to the second preset rule, memory forensics is performed on the malicious sample according to the memory data corresponding to the running process of the malicious sample.
[0034] Through the above method, when the IOT sample is a malicious sample, it is not necessary to wait for the execution process of the IOT sample to enter the operating system kernel mode, and the execution process of all instructions of the IOT sample can be analyzed based on the user-mode preset plugin, which can improve the efficiency of memory forensics.
[0035] Further, tracking the instruction execution process corresponding to the malicious sample and detecting whether the execution process of the current instruction conforms to the second preset rule includes:
[0036] Using the user-mode preset simulator plugin to obtain a preset pointer;
[0037] Through the preset pointer, reading the register value of the virtual CPU corresponding to the current instruction execution process in the malicious sample;
[0038] Based on the register value, analyzing to obtain the memory data corresponding to the execution process of the current pointer;
[0039] Based on the register value and the memory data, determining whether the execution process of the current instruction conforms to the second preset rule.
[0040] Through the above method, tracking the instruction execution process of the malicious sample and obtaining the register value and memory data corresponding to the execution process of each instruction in the malicious sample, so as to realize instruction-level analysis of the IOT sample.
[0041] Further, based on the register value and the memory data, determining whether the execution process of the current instruction conforms to the second preset rule includes:
[0042] Determining whether the register value is within a first preset numerical range and determining whether the memory data is within a second preset numerical range;
[0043] If the register value is within the first preset numerical range and the memory data is within the second preset numerical range, it is determined that the execution process of the current instruction conforms to the second preset rule;
[0044] If the register value is not within the first preset numerical range and / or the memory data is not within the second preset numerical range, it is determined that the execution process of the current instruction does not conform to the second preset rule.
[0045] By the above method, determine whether the execution process of the current instruction conforms to the second preset rule, so that when the execution process of the current instruction conforms to the running rule of the malicious program, obtain the memory data corresponding to the execution process of the current instruction for memory forensics analysis.
[0046] Furthermore, perform memory forensics on the malicious sample according to the memory data corresponding to the running process of the malicious sample, including:
[0047] Monitor the running process of the malicious sample;
[0048] Read the memory data corresponding to the running process of the malicious sample according to the memory address space reading and writing rules;
[0049] Analyze the running process of the malicious sample according to the memory data, and perform memory forensics on the malicious sample.
[0050] By the above method, read the memory data corresponding to the memory address space of the malicious sample, and use the memory data for memory forensics analysis.
[0051] In a second aspect, the present application provides a memory forensics device, and the device includes:
[0052] An execution module, configured to execute the interrupt instruction in the IOT sample through the operating system kernel mode when the IOT sample of the Internet of Things is obtained;
[0053] An access module, configured to access the memory address space corresponding to the IOT sample in a preset manner when it is detected that the execution process of the interrupt instruction conforms to the first preset rule, where the first preset rule is the running rule of the malicious sample;
[0054] A forensics module, configured to read the memory data corresponding to the memory address space, and perform memory forensics on the IOT sample based on the memory data.
[0055] Furthermore, the execution module is specifically configured to:
[0056] Start the operating system based on a virtualization program of hardware virtualization;
[0057] Run the IOT sample through the user mode of the operating system, and detect whether the interrupt instruction in the IOT sample is triggered;
[0058] If so, adjust the user mode of the operating system to the kernel mode, and execute the interrupt instruction through the kernel mode of the operating system;
[0059] If not, continue to run the IOT sample in the user mode of the operating system.
[0060] Further, the access module is specifically configured to:
[0061] Hook the preset function enhanced page table;
[0062] Through the hook program, detect whether the execution process of the interrupt instruction calls the preset function;
[0063] If so, continue to execute the preset function, and access the memory address space corresponding to the IOT sample by triggering a preset instruction;
[0064] If not, continue to execute the interrupt instruction.
[0065] Further, the reading module is specifically configured to:
[0066] Obtain the memory address space reading and writing rules corresponding to the operating system where the IOT sample is located;
[0067] According to the memory address space reading and writing rules, read the memory data of the memory address space corresponding to the IOT sample;
[0068] Based on the memory data, analyze the running process of the IOT sample and perform memory forensics on the IOT sample.
[0069] In a possible design, the execution module includes:
[0070] A determination unit, configured to determine whether the IOT sample is a malicious sample;
[0071] An execution unit, configured to, if the IOT sample is a non-malicious sample, execute the interrupt instruction in the IOT sample through the operating system kernel mode;
[0072] A startup unit, configured to, if the IOT sample is a malicious sample, start the malicious sample according to a user-mode preset simulator plugin, where the user-mode preset simulator plugin can obtain the virtual CPU register value corresponding to the current process;
[0073] A detection unit, configured to trace the instruction execution process corresponding to the malicious sample and detect whether the execution process of the current instruction conforms to a second preset rule, where the second preset rule is the running rule of the malicious sample;
[0074] A forensics unit, configured to, when the execution process of the current instruction conforms to the second preset rule, perform memory forensics on the malicious sample according to the memory data corresponding to the running process of the malicious sample.
[0075] Further, the detection unit is specifically configured to:
[0076] Use the user-mode preset simulator plugin to obtain a preset pointer;
[0077] Read the register values of the virtual CPU corresponding to the current instruction execution process in the malicious sample through the preset pointer;
[0078] Analyze and obtain the memory data corresponding to the current pointer execution process according to the register values;
[0079] Determine whether the execution process of the current instruction conforms to the second preset rule according to the register values and the memory data.
[0080] Furthermore, the detection unit is further configured to:
[0081] Determine whether the register values are within a first preset numerical range, and determine whether the memory data is within a second preset numerical range;
[0082] If the register values are within the first preset numerical range and the memory data is within the second preset numerical range, it is determined that the execution process of the current instruction conforms to the second preset rule;
[0083] If the register values are not within the first preset numerical range and / or the memory data is not within the second preset numerical range, it is determined that the execution process of the current instruction does not conform to the second preset rule.
[0084] Furthermore, the forensics unit is specifically configured to:
[0085] Monitor the running process of the malicious sample;
[0086] Read the memory data corresponding to the running process of the malicious sample according to the memory address space reading and writing rules;
[0087] Analyze the running process of the malicious sample according to the memory data, and perform memory forensics on the malicious sample.
[0088] In a third aspect, the present application provides an electronic device, including:
[0089] A memory for storing a computer program;
[0090] A processor, when executing the computer program stored on the memory, implements the steps of the above-mentioned memory forensics method.
[0091] In a fourth aspect, the present application provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned memory forensics method are implemented.
[0092] Based on the above memory forensics method, when it is detected that the execution process of the interrupt instruction in the IOT sample conforms to the preset rules, the memory address space corresponding to the IOT sample is further accessed, and then the memory data for memory forensics is read. This memory forensics method does not require simulating the execution of the operating system's operation instructions, and does not require the IOT sample to end its operation to quickly obtain the memory data corresponding to the IOT sample, thereby improving the efficiency and accuracy of memory forensics.
[0093] For the various aspects in the second to fourth aspects above and the possible technical effects that each aspect may achieve, reference may be made to the technical effects that can be achieved in the above-mentioned first aspect or various possible solutions in the first aspect, and details will not be repeated here. Description of the Drawings
[0094] Figure 1 It is a flowchart of a memory forensics method provided by this application;
[0095] Figure 2 It is a schematic structural diagram of a memory forensics device provided by this application;
[0096] Figure 3 It is a schematic structural diagram of an electronic device provided by this application. Detailed Embodiments
[0097] In order to make the objectives, technical solutions, and advantages of this application clearer, the following will further describe this application in detail with reference to the accompanying drawings. The specific operation methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of this application, "a plurality" is understood as "at least two". "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The connection between A and B may represent: A is directly connected to B and A is connected to B through C. In addition, in the description of this application, terms such as "first" and "second" are only used for the purpose of distinguishing descriptions, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying an order.
[0098] The following will describe the embodiments of this application in detail with reference to the accompanying drawings.
[0099] At present, the main method for memory forensics of malware is to perform dynamic analysis on malicious samples of any CPU architecture through the virtual processor qemu. Among them, qemu has two operating modes. One is the user-mode simulation mode qemu-user, and the other operating mode is the full-system simulation mode qemu-system. Generally, qemu-user cannot directly detect the CPU kernel layer and cannot meet the requirements of CPU instruction-level analysis. However, qemu-system can simulate the operation of the operating system in user mode and also simulate the operation of the operating system in kernel mode. Therefore, currently, qemu-system is mainly used to perform dynamic analysis on IOT samples of any CPU architecture.
[0100] Although the above-mentioned method based on qemu-system can achieve dynamic analysis of IOT samples of any CPU architecture, since qemu-system needs to simulate and execute all the operation instructions of the entire operating system and all the instructions of the IOT samples running on the operating system, the efficiency of memory forensics of IOT samples is not high, and it cannot meet the memory forensics requirements of a large number of IOT samples.
[0101] To solve the above problems, the present application provides a memory forensics method. When it is detected that the execution process of the interrupt instruction in the IOT sample conforms to a preset rule, the memory address space corresponding to the IOT sample is directly accessed through a preset method, and the memory data for memory forensics is read. This memory forensics method does not need to simulate and execute the operation instructions of the operating system, and does not need to wait for the IOT sample to end to quickly locate the memory space address corresponding to the IOT sample and read the memory data for memory forensics, thereby improving the efficiency and accuracy of memory forensics. Among them, the methods and devices in the embodiments of the present application are based on the same technical concept. Since the principles of the problems solved by the methods and devices are similar, the embodiments of the device and the method can be referred to each other, and the repeated parts will not be described again.
[0102] As Figure 1 shown, it is a flowchart of a memory forensics method provided by the present application, which specifically includes the following steps:
[0103] S11, when obtaining an Internet of Things (IOT) sample, execute the interrupt instruction in the IOT sample through the kernel mode of the operating system;
[0104] In the embodiment of the present application, when obtaining the IOT sample, first start the operating system based on the virtualization program of hardware virtualization. Among them, the virtualization program of hardware virtualization can be the open-source virtual machine (Kernel-based Virtual Machine, KVM), or the open-source virtual machine Xen;
[0105] Then run the IOT sample in the user mode of the operating system. During the running of the IOT sample, if the current instruction in the IOT sample is an interrupt instruction, the operating mode of the operating system is adjusted from the user mode to the kernel mode, and then the interrupt instruction is executed through the kernel mode of the operating system. If the current instruction is not an interrupt instruction, the current instruction is continuously executed through the user mode of the operating system.
[0106] For example, if the current instruction is to open a system file A during the running of the IOT sample, in this case, the operation of opening file A cannot be directly completed through the user mode of the operating system. Then the running process of the IOT sample enters an interrupt, and it is necessary to adjust the operating mode of the operating system from the user mode to the kernel mode before the specific operation process of opening file A can be realized.
[0107] If the execution process of the current instruction does not require interaction between operating systems and only executes simple calculation instructions, in this case, the current instruction is directly continued to be executed based on the user mode of the operating system without entering an interrupt.
[0108] Through the above method, when an interrupt instruction is triggered during the execution of the IOT sample, the interrupt instruction is executed in the user mode of the operating system. This method can support subsequent further acquisition of the memory data corresponding to the running process of the IOT sample.
[0109] S12, when it is detected that the execution process of the interrupt instruction conforms to the first preset rule, access the memory address space corresponding to the IOT sample in a preset manner;
[0110] In the embodiment of the present application, after the running process of the IOT sample enters an interrupt, the current interrupt instruction is executed in the user mode of the operating system. During the execution of the interrupt instruction, it is necessary to detect whether the execution process of the interrupt instruction conforms to the first preset rule. Among them, the first preset rule is the running rule of malicious programs. If the execution process of the interrupt instruction conforms to the first preset rule, it indicates that the IOT sample file may be a malicious sample file. Specifically, the above process includes:
[0111] Set a trap for a preset function, where the preset function is a function that may be called during the running of a malicious sample, such as the load_elf_binary function. The set trap can be an Enhanced Page Table (EPT) hook program EPT Hook, and setting the trap can be completed by a virtual machine monitor;
[0112] Next, by detecting whether the execution process of the interrupt instruction triggers a trap, it is determined whether the execution process of the interrupt instruction calls a preset function. When the execution process of the interrupt instruction triggers the set trap, it indicates that the execution process calls the preset function. At this time, it can be preliminarily determined that the IOT sample corresponding to the current interrupt instruction may be a malicious sample. Therefore, it is necessary to further access the memory address space corresponding to the IOT sample;
[0113] In this application, the method of accessing the memory address space corresponding to the IOT sample can be completed by executing a preset instruction. Specifically, the fast_singlestep instruction of the virtual program xen4.14+ can be used to quickly single-step to the associated inline hook program hook of the malicious program rootkit based on the Trap Monitor (MTF), so as to access the memory address space corresponding to the malicious program in the IOT sample; after accessing the memory address space corresponding to the malicious program in the IOT sample, the virtualization program supporting the operating system can be exited, and then memory forensics can be performed on the IOT sample.
[0114] Of course, when the execution process of the interrupt instruction does not trigger the set trap, it indicates that the execution process of the interrupt instruction does not call the preset function. At this time, the interrupt instruction is continued to be executed.
[0115] In the above manner, a trap is set for the preset function. When the trap is triggered, it indicates that the IOT sample may be a malicious sample, and then the memory address space corresponding to the IOT sample is further accessed by executing a preset instruction, which is convenient for further memory forensics analysis of the IOT sample.
[0116] S13, read the memory data corresponding to the memory address space, and perform memory forensics on the IOT sample based on the memory data.
[0117] In the embodiment of this application, after accessing the memory address space corresponding to the IOT sample, the memory address space read-write rule corresponding to the operating system where the IOT sample is located is further obtained, and then the volatility memory forensics plugin reads the memory data of the memory address space corresponding to the IOT sample according to the memory address space read-write rule, and analyzes the running process of the IOT sample based on the memory data, so as to realize the memory forensics of the IOT sample.
[0118] Based on the above memory forensics method, when it is detected that the execution process of the interrupt instruction in the IOT sample conforms to the preset rules, the memory address space corresponding to the IOT sample is further accessed, and then the memory data for memory forensics is read. This memory forensics method does not require simulating the execution of the operating system's operation instructions, and does not require the IOT sample to run to completion to quickly obtain the memory data corresponding to the IOT sample, thereby improving the efficiency and accuracy of memory forensics.
[0119] In a possible design, when the IOT sample is obtained, first determine whether the IOT sample is a malicious sample; if not, then perform memory forensics on the IOT sample through the method as Figure 1 shown; if so, perform memory forensics on the malicious sample based on the user-mode preset simulator plugin. The specific memory forensics method includes:
[0120] First, start the malicious sample according to the user-mode preset simulator plugin. Among them, the preset simulator plugin can be the preset plugin in qemu-6 after modifying the source code patch. In the embodiment of the present application, the user-mode working mode of qemu-6 after patching can support the operation of IOT samples of any CPU architecture, and the preset plugin in qemu-6 after patching can obtain the virtual CPU register values corresponding to the execution processes of all instructions in the IOT sample;
[0121] Next, use the user-mode preset simulator plugin to trace the execution process of all instructions corresponding to the malicious sample, and detect whether the execution process of the current instruction conforms to the second preset rule. Among them, the second preset rule is the running rule of the malicious sample. For example, if the current instruction is to force an advertisement or force the loading of malicious software, it indicates that the execution process of the current instruction conforms to the second preset rule, so it can be determined that the current instruction is a malicious program;
[0122] In the above process, the specific method for detecting whether the execution process of the current instruction conforms to the second preset rule can be: using the user-mode preset simulator plugin to obtain a preset pointer. Among them, the preset pointer can be the vcpu env_ptr pointer; then through the preset pointer, read the register value of the virtual CPU corresponding to the execution process of the current instruction in the malicious sample, and according to the register value, analyze the memory data corresponding to the execution process of the current pointer. Finally, according to the register value and the memory data, determine whether the execution process of the current instruction conforms to the second preset rule. The specific determination method includes:
[0123] Determine whether the register value is within the first preset numerical range, and determine whether the memory data is within the second preset numerical range; if the register value is within the first preset numerical range and the memory data is within the second preset numerical range, it is determined that the execution process of the current instruction conforms to the second preset rule;
[0124] If the register value is not within the first preset numerical range and / or the memory data is not within the second preset numerical range, it is determined that the execution process of the current instruction does not conform to the second preset rule.
[0125] Based on the method, it is detected whether the execution process of the current instruction conforms to the second preset rule. By tracing the instruction execution process of the malicious sample and obtaining the register values and memory data corresponding to the execution process of each instruction in the malicious sample, instruction-level analysis of the IOT sample can be achieved.
[0126] Furthermore, when it is detected that the execution process of the current instruction conforms to the second preset rule, the virtualization program for running the user-mode preset simulator plugin is controlled to exit the operation. Then, memory forensics is performed on the malicious sample according to the memory data corresponding to the running process of the malicious sample, where the memory data corresponding to the running process of the malicious sample is obtained through the above-mentioned preset simulator plugin. Specifically, the method of performing memory forensics on the malicious sample according to the memory data corresponding to the running process of the malicious sample can be:
[0127] Use the hypervisor to monitor the running process of the malicious sample, and notify the volatility memory forensics plugin to read the memory data corresponding to the running process of the malicious sample according to the memory address space read / write rules. Finally, analyze the running process of the malicious sample according to the memory data to achieve memory forensics on the malicious sample.
[0128] Of course, it is also possible to scan the memory data corresponding to the running process of the malicious sample by invoking the yara rule and analyze the memory data through the preset rule, so as to achieve memory forensics on the malicious sample, where the preset rule can be the Command-and-Control (C2) rule.
[0129] Through the above method, when it is determined that the IOT sample is a malicious sample, during the running process of the IOT sample, without waiting for the execution process of the IOT sample to enter the operating system kernel mode, it is possible to analyze the execution process of all instructions of the IOT sample based on the user-mode preset plugin, and this method can improve the efficiency of memory forensics.
[0130] Based on the same inventive concept, an embodiment of the present application also provides a memory forensics device, as Figure 2 shown, which is a structural schematic diagram of a memory forensics device in the present application. The device includes:
[0131] An execution module 21, configured to execute the interrupt instruction in the IOT sample through the operating system kernel mode when the Internet of Things (IOT) sample is obtained;
[0132] An access module 22, configured to access the memory address space corresponding to the IOT sample in a preset manner when it is detected that the execution process of the interrupt instruction conforms to a first preset rule, where the first preset rule is the running rule of a malicious sample;
[0133] An evidence collection module 23, configured to read the memory data corresponding to the memory address space and perform memory forensics on the IOT sample based on the memory data.
[0134] Further, the execution module 21 is specifically configured to:
[0135] Start the operating system based on a virtualization program with hardware virtualization;
[0136] Run the IOT sample in the user mode of the operating system and detect whether the interrupt instruction in the IOT sample is triggered;
[0137] If so, adjust the user mode of the operating system to the kernel mode and execute the interrupt instruction through the kernel mode of the operating system;
[0138] If not, continue to run the IOT sample in the user mode of the operating system.
[0139] Further, the access module 22 is specifically configured to:
[0140] Hook a preset function in the enhanced page table;
[0141] Detect whether the execution process of the interrupt instruction calls the preset function through the hook program;
[0142] If so, continue to execute the preset function and access the memory address space corresponding to the IOT sample by triggering a preset instruction;
[0143] If not, continue to execute the interrupt instruction.
[0144] Further, the evidence collection module 23 is specifically configured to:
[0145] Obtain the memory address space read / write rule corresponding to the operating system where the IOT sample is located;
[0146] Read the memory data of the memory address space corresponding to the IOT sample according to the memory address space read / write rule;
[0147] Analyze the running process of the IOT sample based on the memory data and perform memory forensics on the IOT sample.
[0148] In a possible design, the execution module 21 includes:
[0149] A determination unit for determining whether the IOT sample is a malicious sample;
[0150] An execution unit for executing the interrupt instruction in the IOT sample through the operating system kernel mode if the IOT sample is a non-malicious sample;
[0151] A startup unit for starting the malicious sample according to a preset emulator plugin in user mode if the IOT sample is a malicious sample, where the preset emulator plugin in user mode can obtain the virtual CPU register values corresponding to the current process;
[0152] A detection unit for tracking the instruction execution process corresponding to the malicious sample and detecting whether the execution process of the current instruction conforms to a second preset rule, where the second preset rule is the running rule of the malicious sample;
[0153] An evidence collection unit for performing memory forensics on the malicious sample according to the memory data corresponding to the running process of the malicious sample when the execution process of the current instruction conforms to the second preset rule.
[0154] Furthermore, the detection unit is specifically used for:
[0155] Obtaining a preset pointer by using the preset emulator plugin in user mode;
[0156] Reading the register values of the virtual CPU corresponding to the current instruction execution process in the malicious sample through the preset pointer;
[0157] Analyzing to obtain the memory data corresponding to the execution process of the current pointer according to the register values;
[0158] Determining whether the execution process of the current instruction conforms to the second preset rule according to the register values and the memory data.
[0159] Furthermore, the detection unit is also used for:
[0160] Determining whether the register values are within a first preset numerical range and determining whether the memory data is within a second preset numerical range;
[0161] If the register values are within the first preset numerical range and the memory data is within the second preset numerical range, it is determined that the execution process of the current instruction conforms to the second preset rule;
[0162] If the register values are not within the first preset numerical range and / or the memory data is not within the second preset numerical range, it is determined that the execution process of the current instruction does not conform to the second preset rule.
[0163] Further, the evidence collection unit is specifically configured to:
[0164] Monitor the running process of the malicious sample;
[0165] Read the memory data corresponding to the running process of the malicious sample according to the memory address space reading and writing rules;
[0166] Analyze the running process of the malicious sample according to the memory data, and perform memory forensics on the malicious sample.
[0167] Based on the above memory forensics device, when it is detected that the execution process of the interrupt instruction in the IOT sample conforms to a preset rule, the memory address space corresponding to the IOT sample is further accessed, and then the memory data for memory forensics is read. This memory forensics method does not require simulating the execution of operating system operation instructions, and does not require the IOT sample to end its operation to quickly obtain the memory data corresponding to the IOT sample, thereby improving the efficiency and accuracy of memory forensics.
[0168] Based on the same inventive concept, an electronic device is further provided in an embodiment of the present application. The electronic device can implement the functions of the foregoing memory forensics device. Refer to Figure 3 , the electronic device includes:
[0169] At least one processor 31, and a memory 32 connected to at least one processor 31. In the embodiment of the present application, the specific connection medium between the processor 31 and the memory 32 is not limited. Figure 3 In, it is taken as an example that the processor 31 and the memory 32 are connected through a bus 30. The bus 30 is represented by a thick line in Figure 3 . The connection manners between other components are only for illustrative purposes and are not limited thereto. The bus 30 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 3 In, it is only represented by a thick line, but it does not mean that there is only one bus or one type of bus. Alternatively, the processor 31 can also be referred to as a controller, and the name is not limited.
[0170] In the embodiment of the present application, the memory 32 stores instructions executable by at least one processor 31. By executing the instructions stored in the memory 32, at least one processor 31 can execute the memory forensics method described above. The processor 31 can implement Figure 2 the functions of each module in the device shown.
[0171] Among them, the processor 31 is the control center of the device, which can connect various parts of the entire control device through various interfaces and circuits. By running or executing the instructions stored in the memory 32 and calling the data stored in the memory 32, various functions of the device and process data, so as to monitor the device as a whole.
[0172] In a possible design, the processor 31 may include one or more processing units. The processor 31 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor may not be integrated into the processor 31 either. In some embodiments, the processor 31 and the memory 32 may be implemented on the same chip, and in some embodiments, they may also be separately implemented on independent chips.
[0173] The processor 31 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the memory forensics method disclosed in combination with the embodiments of the present application may be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0174] The memory 32 serves as a non-volatile computer-readable storage medium and can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 32 may include at least one type of storage medium. For example, it may include flash memory, hard disks, multimedia cards, card-type memories, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memories, magnetic disks, optical discs, etc. The memory 32 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 32 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.
[0175] By programming the design of the processor 31, the code corresponding to the memory forensics method introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute Figure 1 the steps of the memory forensics method of the illustrated embodiment. How to program the design of the processor 31 is a well-known technology to those skilled in the art and will not be elaborated here.
[0176] Based on the same inventive concept, the embodiments of the present application also provide a storage medium storing computer instructions, which, when run on a computer, cause the computer to execute the memory forensics method discussed above.
[0177] In some possible implementation manners, various aspects of the memory forensics method provided in the present application may also be implemented in the form of a program product, which includes program code. When the program product runs on a device, the program code is used to cause the control device to execute the steps of the memory forensics method according to various exemplary embodiments of the present application described above in this specification.
[0178] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0179] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.
[0180] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.
[0181] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.
[0182] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.
Claims
1. A memory forensics method, characterized in that, The method includes: When an Internet of Things (IOT) sample is obtained, execute the interrupt instruction in the IOT sample through the operating system kernel mode to determine whether the IOT sample is a malicious sample; If not, when it is detected that the execution process of the interrupt instruction conforms to a first preset rule, access the memory address space corresponding to the IOT sample in a preset manner, where the first preset rule is to call functions that may be called when a malicious sample runs during the execution process of the interrupt instruction; Read the memory data corresponding to the memory address space and perform memory forensics on the IOT sample based on the memory data; If so, start the malicious sample according to a preset user-mode simulator plugin, where the preset user-mode simulator plugin can obtain the virtual CPU register values corresponding to the current process; Track the instruction execution process corresponding to the malicious sample and detect whether the execution process of the current instruction conforms to a second preset rule, where the second preset rule is that the execution process of the current instruction is the same as the running rule of the malicious sample; When the execution process of the current instruction conforms to the second preset rule, perform memory forensics on the malicious sample based on the memory data corresponding to the running process of the malicious sample.
2. The method according to claim 1, wherein Executing the interrupt instruction in the IOT sample through the operating system kernel mode includes: Start the operating system based on a virtualization program for hardware virtualization; Run the IOT sample through the operating system user mode and detect whether the interrupt instruction in the IOT sample is triggered; If so, adjust the operating system user mode to the kernel mode and execute the interrupt instruction through the operating system kernel mode; If not, continue to run the IOT sample in the operating system user mode.
3. The method according to claim 1, wherein When it is detected that the execution process of the interrupt instruction conforms to the first preset rule, accessing the memory address space corresponding to the IOT sample in a preset manner includes: Set a hook program for an enhanced page table for a preset function; Through the hook program, detect whether the preset function is called during the execution process of the interrupt instruction; If so, continue to execute the preset function and access the memory address space corresponding to the IOT sample by triggering a preset instruction; If not, continue to execute the interrupt instruction.
4. The method according to claim 1, wherein Reading the memory data corresponding to the memory address space and performing memory forensics on the IOT sample based on the memory data includes: Obtain the memory address space read / write rules corresponding to the operating system where the IOT sample is located; According to the memory address space read / write rules, read the memory data of the memory address space corresponding to the IOT sample; Analyze the running process of the IOT sample based on the memory data and perform memory forensics on the IOT sample.
5. The method according to claim 1, wherein Tracking the instruction execution process corresponding to the malicious sample and detecting whether the execution process of the current instruction conforms to the second preset rule includes: Use the preset user-mode simulator plugin to obtain a preset pointer; Through the preset pointer, read the register values of the virtual CPU corresponding to the current instruction execution process in the malicious sample; According to the register values, analyze and obtain the memory data corresponding to the current pointer execution process; Determine whether the execution process of the current instruction complies with the second preset rule according to the register value and the memory data.
6. The method according to claim 5, characterized in that, Determining whether the execution process of the current instruction complies with the second preset rule according to the register value and the memory data includes: Determine whether the register value is within a first preset numerical range, and determine whether the memory data is within a second preset numerical range; If the register value is within the first preset numerical range and the memory data is within the second preset numerical range, it is determined that the execution process of the current instruction complies with the second preset rule; If the register value is not within the first preset numerical range and / or the memory data is not within the second preset numerical range, it is determined that the execution process of the current instruction does not comply with the second preset rule.
7. A memory forensics device, characterized in that, The device includes: An execution module, configured to, when an Internet of Things (IOT) sample is obtained, execute an interrupt instruction in the IOT sample through the operating system kernel mode to determine whether the IOT sample is a malicious sample; An access module, configured to, if the IOT sample is a non-malicious sample, access the memory address space corresponding to the IOT sample in a preset manner when it is detected that the execution process of the interrupt instruction complies with a first preset rule, where the first preset rule is to call functions that may be called during the execution of a malicious sample; An evidence collection module, configured to read the memory data corresponding to the memory address space and perform memory forensics on the IOT sample based on the memory data; A startup unit, configured to, if the IOT sample is a malicious sample, start the malicious sample according to a preset user-mode simulator plugin, where the preset user-mode simulator plugin can obtain the virtual CPU register value corresponding to the current process; A detection unit, configured to trace the instruction execution process corresponding to the malicious sample and detect whether the execution process of the current instruction complies with a second preset rule, where the second preset rule is that the execution process of the current instruction is the same as the running rule of the malicious sample; An evidence collection unit, configured to, when the execution process of the current instruction complies with the second preset rule, perform memory forensics on the malicious sample according to the memory data corresponding to the running process of the malicious sample.
8. An electronic device, characterized in that, Includes: A memory for storing a computer program; A processor, configured to, when executing the computer program stored on the memory, implement the method steps described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any one of claims 1-6 are implemented.
Citation Information
Patent Citations
Malicious program recognition method and device, storage medium and electronic equipment
CN113010268A