A method, device, electronic device and medium for protecting the lsass process

By obtaining and judging the target process and removing its read and write permissions to the lsass process, the problem of not being able to effectively protect the lsass process in the existing technology is solved, and the full protection of the lsass process is achieved to ensure its security.

CN114254272BActive Publication Date: 2025-06-24HANGZHOU DBAPPSECURITY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111565696.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-20
Publication Date
2025-06-24
Estimated Expiration
2041-12-20

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively protect the lsass process, especially when a program opens the handle of the lsass process through the OpenProces function, the protection of the lsass process cannot be achieved by monitoring the API with dump process function.

Method used

By obtaining the target process, determine whether it is a System, Csrss, wininit or lsass process. If not, the function is called to remove the permissions owned by the handle of the open lsass process in the target process to achieve protection of the lsass process.

Benefits of technology

From the root cause, illegal programs read and write lsass processes are prevented, ensuring the security of lsass processes, and avoiding the problem of insufficient protection of traditional methods in specific situations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114254272B_ABST
    Figure CN114254272B_ABST
Patent Text Reader

Abstract

The present application discloses a method, device, electronic device and medium for protecting the lsass process, mainly related to the computer field. The method first obtains a target process, and then determines whether the target process is a System, csrss, wininit or lsass process; if not, it calls a function to calculate the removal of read and write permissions from GrantedAccessBits, where GrantedAccessBits are the permissions held by the handle that opens the lsass process in the target process. Compared with the traditional method of protecting the lsass process by monitoring APIs with the function of dumping processes, this method protects the lsass process by removing the read and write permissions of the target process to the lsass process, preventing illegal programs from reading and writing the lsass process from the source and effectively ensuring the security of the lsass process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computers, and particularly to a method, device, electronic device, and medium for protecting the lsass process. Background Art

[0002] With the rapid development of the Internet industry, computers have become increasingly common in life. In personal operating systems, the Windows system has a high proportion. Since Windows authentication is based on the lsass process, whether it is the authentication of a computer network authorization protocol (Kerberos) in a domain environment or the query / response authentication protocol (ntlm) authentication in a workgroup environment, the credentials after the final authentication will be stored in the memory of the lsass process. Therefore, protecting the lsass process is crucial.

[0003] Currently, the protection of the lsass process is achieved by monitoring the application programming interface (API) with the function of dumping processes. However, when a program opens the handle of the lsass process through the OpenProces function and directly reads the lsass process, the protection of the lsass process cannot be achieved by monitoring the API with the function of dumping processes.

[0004] It can be seen that how to protect the lsass process is an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0005] The purpose of this application is to provide a method, device, electronic device, and medium for protecting the lsass process to prevent illegal programs from reading and writing the lsass process.

[0006] To solve the above technical problems, this application provides a method for protecting the lsass process, including:

[0007] Obtain a target process;

[0008] Determine whether the target process is the System, csrss, wininit, or lsass process;

[0009] If not, call a function to calculate the removal of read and write permissions for GrantedAccessBits, where GrantedAccessBits are the permissions owned by the handle that opens the lsass process in the target process.

[0010] Preferably, if the target process is a newly created process, before obtaining the target process, it further includes:

[0011] Create a notification event for monitoring the creation of the target process.

[0012] Preferably, before determining whether the target process is a System, csrss, wininit, or lsass process, it further includes:

[0013] Determine whether the target process applies for read and write permissions to the lsass process;

[0014] If not, determine that the target process is successfully created;

[0015] If so, enter the step of determining whether the target process is a System, csrss, wininit, or lsass process.

[0016] Preferably, if the target process is a process with read and write permissions to the lsass process screened by the user-mode program, obtaining the target process includes:

[0017] Receive the ID of the target process and the handle value for opening the lsass process sent by the user-mode program;

[0018] Correspondingly, determining whether the target process is a System, csrss, wininit, or lsass process includes:

[0019] Determine whether the target process is a System, csrss, wininit, or lsass process according to the ID of the target process.

[0020] Preferably, before calling the function to calculate the removal of read and write permissions for GrantedAccessBits, it further includes:

[0021] Obtain the ObjectTable address through the EPROCESS structure of the target process;

[0022] Obtain the TableCode pointer according to the HANDLE_TABLE structure corresponding to the ObjectTable address;

[0023] Read the TableCode address pointed to by the TableCode pointer and calculate the level of the private handle table of the target process according to the TableCode address.

[0024] Preferably, if the private handle table is a first-level handle table, obtaining GrantedAccessBits includes:

[0025] Calculate the private handle table address according to the TableCode address;

[0026] Calculate the handle attribute address according to the handle value and the private handle table address;

[0027] Obtain GrantedAccessBits from the HANDLE_TABLE_ENTRY structure corresponding to the handle attribute address.

[0028] Preferably, if the private handle table is a secondary handle table, obtaining GrantedAccessBits includes:

[0029] Calculate the storage address based on the TableCode address, and the storage address includes multiple private handle table addresses;

[0030] Determine the private handle table storing the handle according to the handle value, and obtain the private handle table address corresponding to the private handle table from the storage address;

[0031] Calculate the handle attribute address based on the handle value and the private handle table address;

[0032] Obtain GrantedAccessBits from the HANDLE_TABLE_ENTRY structure corresponding to the handle attribute address.

[0033] To solve the above technical problems, the present application also provides a device for protecting the lsass process, including:

[0034] An acquisition module, configured to acquire a target process;

[0035] A judgment module, configured to judge whether the target process is a System, csrss, wininit, or lsass process;

[0036] A call module, configured to call a function to calculate the removal of read and write permissions for GrantedAccessBits, where GrantedAccessBits are the permissions owned by the handle that opens the lsass process in the target process.

[0037] To solve the above technical problems, the present application also provides an electronic device, including:

[0038] A memory, configured to store a computer program;

[0039] A processor, configured to implement the steps of the above method for protecting the lsass process when executing the computer program.

[0040] To solve the above technical problems, the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method for protecting the lsass process are implemented.

[0041] The present application proposes a method for protecting the lsass process. The method first obtains the target process; then determines whether the target process is the System, csrss, wininit, or lsass process; if not, it calls a function to calculate the removal of read and write permissions for GrantedAccessBits, where GrantedAccessBits are the permissions owned by the handle that opens the lsass process in the target process. Compared with the traditional method of protecting the lsass process by monitoring APIs with dump process functions, this method protects the lsass process by removing the read and write permissions of the target process to the lsass process, preventing illegal programs from reading and writing the lsass process at the source and effectively ensuring the security of the lsass process.

[0042] In addition, the device, electronic device, and medium for protecting the lsass process provided by the present application correspond to the method for protecting the lsass process, and the effects are as described above. Brief Description of the Drawings

[0043] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0044] Figure 1 It is a flowchart of a method for protecting the lsass process provided by the present application;

[0045] Figure 2 It is a structural diagram of a device for protecting the lsass process provided by the present application;

[0046] Figure 3 It is a structural diagram of an electronic device provided by the present application. Detailed Embodiments

[0047] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present application.

[0048] The core of the present application is to provide a method for protecting the lsass process to prevent illegal programs from reading and writing the lsass process.

[0049] To enable those skilled in the art to better understand the solution of the present application, the following will further describe the present application in detail with reference to the drawings and specific embodiments.

[0050] Figure 1 This is a flowchart of a method for protecting the lsass process provided by this application. As Figure 1 shown, the method includes:

[0051] S1: Obtain the target process.

[0052] In this embodiment, the target process can be a newly created process or a process with read and write permissions to the lsass process screened by a user-mode program. Among them, the user-mode program can traverse the handle table through the NtQuerySystemInformation function to screen the target process, or can also select other methods to traverse the handle table to screen the target process according to the actual situation. This embodiment does not limit this. If the target process is a newly created process, the behavior of creating the target process will be captured using the created notification event, and the creation of the target process will be monitored, and then the target process will be obtained; if the target process is a process with read and write permissions to the lsass process screened by a user-mode program, after the user-mode program finds the target process, it will send the ID of the target process and the handle value of the opened lsass process to the driver layer of Windows through an input / output request packet (IRP). At this time, the driver layer will receive the ID of the target process and the handle value of the opened lsass process sent by the user-mode program to obtain the target process. It should be noted that in this embodiment, the user-mode program encapsulates the ID of the target process and the handle value of the opened lsass process into a fixed data structure through the IRP and sends it to the driver layer. After receiving this data structure, the driver layer needs to parse this data structure to obtain the ID of the target process and the handle value of the opened lsass process.

[0053] S2: Determine whether the target process is the System, csrss, wininit, or lsass process. If not, go to step S3.

[0054] Since the System, csrss, wininit, and lsass processes are system processes, other processes cannot use the above four system processes to read and write the lsass process through normal operations. Therefore, to prevent some legitimate programs from being unable to read and write the lsass process, this embodiment only removes the read and write permissions of the handles of other processes except the System, csrss, wininit, and lsass processes. If the target process is a newly created process, the ID of the target process can be directly obtained through the notification event, and it is determined whether the target process is the System, csrss, wininit, or lsass process according to the ID of the target process; if the target process is a process with read and write permissions to the lsass process screened by the user-mode program, the user-mode program will send the ID of the target process to the driver layer, and the driver layer will then determine whether the target process is the System, csrss, wininit, or lsass process according to the received ID of the target process.

[0055] S3: Call a function to calculate the removal of read and write permissions for GrantedAccessBits. GrantedAccessBits is the permission owned by the handle that opens the lsass process in the target process.

[0056] In this embodiment, if it is determined that the target process is another process other than the System, csrss, wininit, and lsass processes, the read and write permissions of the target process need to be removed, where the read and write permissions are the permissions to read and write the lsass process. This embodiment realizes the removal of the read and write permissions of the target process by modifying the value of GrantedAccessBits. For example, if the value of GrantedAccessBits is 0x10 and its binary representation is 00010000, where the flag bit representing the read right is 1, the read right can be removed by changing this flag bit to 0. Correspondingly, the write right can be removed by changing the flag bit representing the write right to 0. It should be noted that there can be multiple handles in the target process, but each handle has only one GrantedAccessBits. In this embodiment, GrantedAccessBits is the permission owned by the handle that opens the lsass process in the target process, including not only the read and write permissions of the lsass process but also other permissions such as query permissions.

[0057] If the target process is a newly created process, the GrantedAccessBits can be directly obtained through the notification event, and then the read and write permissions of the target process can be removed by modifying the value of the GrantedAccessBits. If the target process is a process with read and write permissions to the lsass process obtained by filtering user-level programs, it is necessary to first calculate the level of the target process's private handle table, and then calculate the handle attribute address based on the handle value of the opened lsass process sent by the user-level program and the calculated private handle table address, and then obtain the GrantedAccessBits in the HANDLE_TABLE_ENTRY structure corresponding to the handle attribute address. Among them, the methods for obtaining the private handle table address are different for private handle tables of different levels. In addition, after removing the read and write permissions of the target process, the processed handle will be returned, so that other processes cannot perform read and write operations on the lsass process after obtaining this handle.

[0058] This embodiment proposes a method for protecting the lsass process. This method first obtains the target process; then determines whether the target process is the System, csrss, wininit, or lsass process; if not, it calls a function to calculate the removal of read and write permissions for the GrantedAccessBits, where the GrantedAccessBits are the permissions owned by the handle of the opened lsass process in the target process. This method protects the lsass process by removing the read and write permissions of the target process to the lsass process, so that other processes cannot perform read and write operations on the lsass process through the target process, preventing illegal programs from reading and writing the lsass process from the root cause and effectively guaranteeing the security of the lsass process.

[0059] If the target process in the above embodiment is a newly created process, before obtaining the target process, it is also necessary to capture the creation behavior of the target process and monitor the creation of the target process. This embodiment creates a notification event, where the notification event is used to monitor the creation of the target process, and the creation behavior of the target process is captured and the creation of the target process is monitored through the notification event. It should be noted that in this embodiment, the notification event is created by calling a pre-registered function, and the registration of this function can be achieved through the API provided by windows.

[0060] This embodiment creates a notification event to monitor the creation of the target process through the notification event in order to obtain the target process.

[0061] If the target process in the above embodiments is a newly created process, since removing read and write permissions is based on the target process having the permissions to read and write the lsass process, before determining whether the target process is the System, csrss, wininit, or lsass process, it should first be determined whether the target process has applied for the read and write permissions of the lsass process. This step includes:

[0062] Determine whether the target process has applied for the read and write permissions of the lsass process;

[0063] If not, it is determined that the target process has been successfully created;

[0064] If so, proceed to the step of determining whether the target process is the System, csrss, wininit, or lsass process.

[0065] As mentioned in the above embodiments, the creation of the target process is monitored through the notification event. Therefore, in this embodiment, it is determined whether the target process monitored by the notification event has applied for the read and write permissions of the lsass process. If the target process has not applied for the read and write permissions of the lsass process, it means that there is no need to perform the operation of removing the read and write permissions on it, and it can be directly determined that the target process has been successfully created; if the target process has applied for the read and write permissions of the lsass process, at this time, it is necessary to determine whether the target process is the System, csrss, wininit, or lsass process, and decide whether to remove the read and write permissions of the target process to the lsass process according to the result of whether the target process is the System, csrss, wininit, or lsass process.

[0066] When the target process is a newly created process, this embodiment determines whether the target process has applied for the read and write permissions of the lsass process, and decides whether it is necessary to determine whether the target process is the System, csrss, wininit, or lsass process according to the judgment result. When the target process has not applied for the read and write permissions of the lsass process, there is no need to further determine whether the target process is the System, csrss, wininit, or lsass process, but directly determine that it has been successfully created, effectively simplifying the operation steps.

[0067] If the target process in the above embodiments is a process with the read and write permissions of the lsass process screened by the user-level program, then the target process needs to be obtained from the user-level program. This step includes:

[0068] Receive the ID of the target process and the handle value for opening the lsass process sent by the user-level program;

[0069] Correspondingly, determining whether the target process is the System, csrss, wininit, or lsass process includes:

[0070] Determine whether the target process is a System, csrss, wininit, or lsass process based on the ID of the target process.

[0071] In this embodiment, the user-mode program calls the NtQuerySystemInformation function to traverse the handle table, and determines whether the process has read / write permissions for the lsass process. If the process does not have read / write permissions for the lsass process, it does not need to be sent to the driver layer, so as to implement the filtering of the target process by the user-mode program. The target process in this embodiment is the process obtained by the user-mode program traversing the handle table and having read / write permissions for the lsass process. After the user-mode program finds the target process, it sends the ID of the target process and the handle value for opening the lsass process to the driver layer through an IRP. The driver layer will determine whether the target process is a System, csrss, wininit, or lsass process based on the ID of the target process sent by the user layer, and subsequently calculate the handle attribute address according to the handle value for opening the lsass process to obtain the GrantedAccessBits.

[0072] When the target process is a process obtained by filtering by the user-mode program and having read / write permissions for the lsass process, this embodiment receives the ID of the target process and the handle value for opening the lsass process sent by the user-mode program, so as to determine whether the target process is a System, csrss, wininit, or lsass process based on the ID of the target process and subsequently calculate the handle attribute address according to the handle value for opening the lsass process to obtain the GrantedAccessBits.

[0073] Before calculating the removal of read / write permissions for the GrantedAccessBits by calling a function in the above embodiment, it is necessary to first obtain the GrantedAccessBits. Since the GrantedAccessBits are stored in the HANDLE_TABLE_ENTRY structure corresponding to the handle attribute address, and the handle attribute address is calculated from the private handle table address and the handle value for opening the lsass process sent by the user-mode program, and different levels of private handle tables obtain the private handle table address in different ways, it is necessary to first calculate the level of the private handle table. This step includes:

[0074] Obtain the ObjectTable address through the EPROCESS structure of the target process;

[0075] Obtain the TableCode pointer according to the HANDLE_TABLE structure corresponding to the ObjectTable address;

[0076] Read the TableCode address pointed to by the TableCode pointer, and calculate the level of the private handle table of the target process based on the TableCode address.

[0077] In this embodiment, the target process is a process with read and write permissions to the lsass process screened by the user-level program. A process has only one EPROCESS structure, and there is only one ObjectTable address in an EPROCESS structure. Since the offset of each structure is fixed, the ObjectTable address in the EPROCESS structure can be obtained through the offset. Since the ObjectTable address stores the HANDLE_TABLE structure, the TableCode pointer is stored in this structure, and the offset of each structure is fixed, so the TableCode pointer can be obtained from the HANDLE_TABLE structure through the offset. After reading the TableCode address pointed to by the TableCode pointer, perform a bitwise AND operation (&) on the TableCode address and 3. According to the calculation result, the level of the private handle table of the target process can be obtained. It should be noted that there is a corresponding relationship between the calculation result of the bitwise AND operation (&) on the TableCode address and 3 and the level of the private handle table. If the calculation result is 0, the private handle table is a first-level handle table; if the calculation result is 1, the private handle table is a second-level handle table; if the calculation result is 2, the private handle table is a third-level handle table. For example, if the value of TableCode is 0xFFFF80013A2BF0C1, then perform a bitwise AND operation on 0xFFFF80013A2BF0C1 and 3, and the calculation result is 1. According to the corresponding relationship between this calculation result and the private handle table, the level of the private handle table is obtained as the second level.

[0078] This embodiment first obtains the ObjectTable address in the EPROCESS structure of the target process, then obtains the TableCode pointer in the HANDLE_TABLE structure corresponding to the ObjectTable address, then reads the TableCode address pointed to by the TableCode pointer, and calculates the level of the private handle table of the target process based on the TableCode address, so as to obtain the private handle table address according to the level of the private handle table, and then calculate the handle attribute address and obtain the GrantedAccessBits.

[0079] The above embodiments have described in detail the steps for calculating the level of the private handle table. Since GrantedAccessBits is stored in the HANDLE_TABLE_ENTRY structure corresponding to the handle attribute address, and the handle attribute address is calculated from the private handle table address and the handle value of the opened lsass process sent by the user-level program, and different levels of private handle tables obtain the private handle table address in different ways, therefore, the steps for different levels of private handle tables to obtain GrantedAccessBits are different. This embodiment describes the steps for obtaining GrantedAccessBits when the private handle table is a first-level handle table. The steps include:

[0080] Calculate the private handle table address based on the TableCode address;

[0081] Calculate the handle attribute address based on the handle value and the private handle table address;

[0082] Obtain GrantedAccessBits from the HANDLE_TABLE_ENTRY structure corresponding to the handle attribute address.

[0083] When the private handle table is a first-level handle table, all handle attributes are saved in a page with a size of 4096 bytes. In a 32-bit system, one handle attribute occupies 8 bytes, and in a 64-bit system, it occupies 16 bytes. The maximum number of handles that can be stored in each handle table for different-bit operating systems is 512 and 256 respectively. In this embodiment, first perform a bitwise AND operation on the TableCode address and ~3 to obtain the private handle table address. Then, divide the handle value of the opened lsass process sent by the user-level program by 4, multiply the result by 0x10, and add the private handle table address to obtain the handle attribute address. Since the handle attribute address corresponds to a HANDLE_TABLE_ENTRY structure, the structure can be found through the handle attribute address, and then GrantedAccessBits in the structure can be obtained.

[0084] This embodiment has described in detail the steps for obtaining GrantedAccessBits when the private handle table is a first-level handle table. First, calculate the private handle table address based on the TableCode address obtained in the above embodiment, then calculate the handle attribute address based on the handle value and the private handle table address, and obtain GrantedAccessBits from the HANDLE_TABLE_ENTRY structure corresponding to the handle attribute address, so as to remove the permissions of the target process to read and write the lsass process.

[0085] The above embodiments illustrate the steps of obtaining GrantedAccessBits when the private handle table is a first-level handle table. Since the steps of obtaining GrantedAccessBits for different levels of private handle tables are different, this embodiment illustrates the steps of obtaining GrantedAccessBits when the private handle table is a second-level handle table. The steps include:

[0086] Calculate the storage address based on the TableCode address. The storage address includes multiple private handle table addresses;

[0087] Determine the private handle table storing the handle according to the handle value, and obtain the private handle table address corresponding to the private handle table from the storage address;

[0088] Calculate the handle attribute address based on the handle value and the private handle table address;

[0089] Obtain GrantedAccessBits from the HANDLE_TABLE_ENTRY structure corresponding to the handle attribute address.

[0090] In this embodiment, the storage address can be obtained by performing a bitwise AND operation between the TableCode address and 3. Different from the first-level handle table, in the second-level handle table, the private handle table address cannot be directly calculated based on the TableCode address. Instead, the storage address storing the private handle table address is calculated based on the TableCode address. Since multiple private handle table addresses are stored in the storage address, it is also necessary to determine the private handle table storing the handle according to the handle value of the open lsass process sent by the user-level program, and then obtain the private handle table address corresponding to the private handle table from the storage address. After obtaining the private handle table address, divide the handle value by 4, multiply by 0x10, and add the private handle table address to obtain the handle attribute address, find the HANDLE_TABLE_ENTRY structure corresponding to the handle attribute address, and then obtain GrantedAccessBits in the structure. In addition, if the private handle table is a third-level handle table, the address stored in the address obtained by performing a bitwise AND operation between the TableCode address and 3 is the address of the second-level handle table, and the calculation method of the second-level handle table needs to be followed to obtain GrantedAccessBits.

[0091] In this embodiment, when the private handle table is a secondary handle table, the steps for obtaining the GrantedAccessBits are described in detail. First, the storage address is calculated based on the TableCode address. Since the storage address includes multiple private handle table addresses, then, according to the handle value, the private handle table storing the handle is determined, and the corresponding private handle table address is obtained from the storage address. The handle attribute address is calculated based on the handle value and the private handle table address, and the HANDLE_TABLE_ENTRY structure is found, and then the GrantedAccessBits in this structure are obtained, so as to remove the read and write permissions of the target process to the lsass process.

[0092] In the above embodiment, the method for protecting the lsass process is described in detail. The present application also provides an embodiment corresponding to the device for protecting the lsass process. It should be noted that the present application describes the embodiment of the device part from two perspectives, one is from the perspective of functional modules, and the other is from the perspective of hardware.

[0093] Figure 2 It is a structural diagram of a device for protecting the lsass process provided by the present application. As Figure 2 shown, the device includes:

[0094] An obtaining module 10, configured to obtain a target process;

[0095] A judging module 11, configured to judge whether the target process is a System, csrss, wininit or lsass process;

[0096] An invoking module 12, configured to invoke a function to calculate the removal of the read and write permissions of the GrantedAccessBits, where the GrantedAccessBits are the permissions owned by the handle for opening the lsass process in the target process.

[0097] Since the embodiment of the device part corresponds to the embodiment of the method part, for the embodiment of the device part, please refer to the description of the embodiment of the method part, and details are not described here for the time being.

[0098] The device for protecting the lsass process provided in this embodiment obtains a target process through an acquisition module; determines whether the target process is a System, csrss, wininit, or lsass process through a judgment module; and calls a function through a call module to calculate the removal of read and write permissions for GrantedAccessBits, where GrantedAccessBits are the permissions owned by the handle that opens the lsass process in the target process. By removing the read and write permissions of the target process to the lsass process, this device prevents other processes from reading and writing the lsass process through the target process, thereby preventing illegal programs from reading and writing the lsass process from the root cause and protecting the lsass process.

[0099] Figure 3 It is a structural diagram of an electronic device provided in another embodiment of this application. As Figure 3 shown, the electronic device includes: a memory 20 for storing a computer program;

[0100] a processor 21 for implementing the steps of the method for protecting the lsass process mentioned in the above embodiment when executing the computer program.

[0101] The electronic device provided in this embodiment may include, but is not limited to, a smart phone, a tablet computer, a notebook computer, or a desktop computer, etc.

[0102] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 may be implemented in at least one hardware form of a Digital Signal Processor (DSP), a Field-Programmable Gate Array (FPGA), or a Programmable Logic Array (PLA). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the wake state, also known as the Central Processing Unit (CPU); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 21 may be integrated with a Graphics Processing Unit (GPU), and the GPU is responsible for rendering and drawing the content required to be displayed on the display screen. In some embodiments, the processor 21 may also include an Artificial Intelligence (AI) processor, and the AI processor is used to process computational operations related to machine learning.

[0103] The memory 20 may include one or more computer-readable storage media, which may be non-transitory. The memory 20 may further include high-speed random access memory, as well as non-volatile memory, such as one or more disk storage devices and flash storage devices. In this embodiment, the memory 20 is at least used to store the following computer program 201. After the computer program is loaded and executed by the processor 21, it can implement the relevant steps of the method for protecting the lsass process disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory 20 may further include an operating system 202 and data 203, etc., and the storage method may be transient storage or permanent storage. Among them, the operating system 202 may include Windows, Unix, Linux, etc. The data 203 may include, but is not limited to, the handle value of the target process opening the lsass process, etc.

[0104] In some embodiments, the electronic device may further include a display screen 22, an input / output interface 23, a communication interface 24, a power supply 25, and a communication bus 26.

[0105] Those skilled in the art can understand that Figure 3 the structure shown in does not constitute a limitation on the electronic device, and it may include more or fewer components than shown in the figure.

[0106] The electronic device provided by the embodiment of the present application includes a memory and a processor. When the processor executes the program stored in the memory, it can implement the method for protecting the lsass process as described above, and the effect is the same.

[0107] Finally, the present application also provides an embodiment corresponding to a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by the processor, it implements the steps of the method for protecting the lsass process as recorded in the foregoing method embodiments.

[0108] It can be understood that if the method in the foregoing embodiments is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and executes all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0109] The computer-readable storage medium provided by this application includes the method for protecting the lsass process mentioned above, and the effect is the same as above.

[0110] The method, apparatus, electronic device, and medium for protecting the lsass process provided by this application have been introduced in detail above. Each embodiment in the specification is described in a progressive manner. The key point of each embodiment is the difference from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description of the method part. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.

[0111] It should also be noted that in this specification, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including the said element.

Claims

1. A method for protecting the lsass process, characterized in that, Including: Obtain a target process, where the target process is a process with read and write permissions to the lsass process screened by a user-mode program; Among them, obtaining the target process includes: receiving the ID of the target process sent by the user-mode program and the handle value for opening the lsass process; Determine whether the target process is the System, csrss, wininit, or lsass process; Among them, determining whether the target process is the System, csrss, wininit, or lsass process includes: judging whether the target process is the System, the csrss, the wininit, or the lsass process according to the ID of the target process; If not, obtain the ObjectTable address through the EPROCESS structure of the target process; obtain the TableCode pointer according to the HANDLE_TABLE structure corresponding to the ObjectTable address; read the TableCode address pointed to by the TableCode pointer, and calculate the level of the private handle table of the target process according to the TableCode address; and obtain the corresponding private handle table address according to the level of the private handle table; obtain the GrantedAccessBits according to the private handle table address and the handle value, and call a function to calculate the GrantedAccessBits after removing the read and write permissions, where the GrantedAccessBits are the permissions owned by the handle for opening the lsass process in the target process.

2. The method for protecting the lsass process according to claim 1, wherein If the target process is a newly created process, before obtaining the target process, it further includes: Create a notification event, which is used to monitor the creation of the target process.

3. The method for protecting the lsass process according to claim 2, wherein Before determining whether the target process is the System, csrss, wininit, or lsass process, it further includes: Determine whether the target process applies for the read and write permissions of the lsass process; If not, determine that the target process is successfully created; If so, enter the step of determining whether the target process is the System, csrss, wininit, or lsass process.

4. The method for protecting the lsass process according to claim 1, wherein If the private handle table is a first-level handle table, obtaining the GrantedAccessBits includes: Calculate the private handle table address according to the TableCode address; Calculate the handle attribute address according to the handle value and the private handle table address; Obtain the GrantedAccessBits from the HANDLE_TABLE_ENTRY structure corresponding to the handle attribute address.

5. The method for protecting the lsass process according to claim 4, wherein If the private handle table is a second-level handle table, obtaining the GrantedAccessBits includes: Calculate the storage address according to the TableCode address, and the storage address includes multiple private handle table addresses; Determine the private handle table storing the handle according to the handle value, and obtain the private handle table address corresponding to the private handle table from the storage address; Calculate the handle attribute address according to the handle value and the private handle table address; Obtain the GrantedAccessBits from the HANDLE_TABLE_ENTRY structure corresponding to the handle attribute address.

6. A device for protecting the lsass process, characterized in that, Include: An obtaining module, configured to obtain a target process, where the target process is a process with read and write permissions for the lsass process screened by a user-mode program; Wherein, the obtaining module is specifically configured to: receive the ID of the target process sent by the user-mode program and the handle value for opening the lsass process; A judging module, configured to judge whether the target process is a System, csrss, wininit or lsass process; Wherein, the judging module is specifically configured to: judge whether the target process is the System, the csrss, the wininit or the lsass process according to the ID of the target process; A calling module, configured to obtain the ObjectTable address through the EPROCESS structure of the target process; obtain the TableCode pointer according to the HANDLE_TABLE structure corresponding to the ObjectTable address; read the TableCode address pointed to by the TableCode pointer, and calculate the level of the private handle table of the target process according to the TableCode address; and obtain the corresponding private handle table address according to the level of the private handle table; obtain the GrantedAccessBits according to the private handle table address and the handle value, and call a function to perform a calculation to remove read and write permissions on the GrantedAccessBits, where the GrantedAccessBits are the permissions of the handle for opening the lsass process in the target process.

7. An electronic device, characterized in that, Include a memory for storing a computer program; A processor, configured to implement the steps of the method for protecting the lsass process according to any one of claims 1 to 5 when executing the computer program.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method for protecting the lsass process according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • File clearing method and device, storage medium and mobile terminal

    CN108170854A