Malicious Code Naming Method and Device, Electronic Device, and Storage Medium
Through the multi-dimensional automatic naming method, the problem of large number of malicious code files and difficult to name is solved, and the rapid and accurate identification and analysis of malicious code files is achieved, which improves the efficiency of network security.
Patent Information
- Application Number
- CN202111614170.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-27
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2041-12-27
AI Technical Summary
In the prior art, there are too many malicious code files and it is difficult to name quickly and efficiently, resulting in difficulty in user identification and analysis.
By obtaining file information in multiple dimensions of malicious code files, we can judge whether the predetermined naming conditions are met in order of priority, and automatically naming them using dimensions such as known name mapping relationships, digital signatures, interface functions and static information.
It realizes fast, efficient and accurate naming of malicious code files, improves the convenience and effectiveness of naming, helps users quickly understand the nature and content of code files, and improves network security maintenance efficiency.
Smart Images

Figure CN114281771B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a method and device for naming malicious code, an electronic device, and a storage medium.
Background Art
[0002] The most intuitive generalization of a malicious code file is often its name, which can reveal information such as the type to which the malicious code file belongs, the platform on which it runs, and its core behavior, which can reflect the nature and content of the malicious code file.
[0003] However, currently, the amount of information in the network explodes, and correspondingly, the number of malicious code files has also increased exponentially. For the attacker itself, in order to prevent the malicious code file from being detected by users, it often sets a meaningless name for the malicious code file, such as Agent, Malicious, Gen, Suspicious, etc., or even sets the name of the malicious code file as a string of meaningless numbers. This results in users being unable to identify it as malicious in a timely manner when they come into contact with the malicious code file.
[0004] At the same time, when statistically analyzing known malicious code files, it is also necessary to name them reasonably to reduce the difficulty of identifying malicious code files and improve users' understanding of malicious code files. However, in related technologies, it is often necessary to analyze and name known malicious code files manually, which is time-consuming and laborious.
[0005] Therefore, how to name a large number of malicious code files quickly and efficiently has become an urgent technical problem to be solved at present.
Summary of the Invention
[0006] Embodiments of the present invention provide a method and device for naming malicious code, an electronic device, and a storage medium, aiming to solve the technical problems in related technologies that malicious code files are inconvenient to identify due to their large quantity and have a high naming difficulty.
[0007] In a first aspect, an embodiment of the present invention provides a method for naming malicious code, including: obtaining file information of a malicious code file in multiple dimensions; determining whether the file information of the malicious code file in a target dimension meets a predetermined naming condition corresponding to the target dimension; when the determination result is yes, determining a malicious code name corresponding to the malicious code file based on a naming method corresponding to the target dimension; when the determination result is no, setting the dimension next in order to the target dimension as the target dimension in a preset dimension order, and continuing to determine whether the file information of the malicious code file in the target dimension set this time meets the predetermined naming condition corresponding to the target dimension.
[0008] In the above embodiments of the present invention, optionally, the preset dimension order, in order of priority, is: known name mapping relationship dimension, digital signature dimension, interface function dimension, and static information dimension.
[0009] In the above embodiments of the present invention, optionally, determining whether the file information of the malicious code file in the target dimension meets the predetermined naming condition corresponding to the target dimension includes: when the target dimension is the known name mapping relationship dimension, based on the C2 information of the malicious code file and a preset mapping library, determining whether the malicious code file matches a known malicious code family name. Wherein, when the malicious code file matches the known malicious code family name, determining the malicious code name corresponding to the malicious code file based on the naming method corresponding to the target dimension includes: determining the known malicious code family name as the malicious code name corresponding to the malicious code file; when the malicious code file does not match the known malicious code family name, the step of setting the next dimension in the target dimension as the target dimension includes: setting the digital signature dimension as the target dimension.
[0010] In the above embodiments of the present invention, optionally, determining whether the file information of the malicious code file in the target dimension meets the predetermined naming condition corresponding to the target dimension includes: when the target dimension is the digital signature dimension, determining whether the malicious code file has a digital signature and whether the digital signature is a valid signature; when the malicious code file has the valid signature, determining the malicious code name corresponding to the malicious code file based on the naming method corresponding to the target dimension includes: determining the name of all parties of the valid signature as the malicious code name corresponding to the malicious code file; when the malicious code file does not have the valid signature, the step of setting the next dimension in the target dimension as the target dimension includes: setting the interface function dimension as the target dimension.
[0011] In the above embodiments of the present invention, optionally, determining whether the file information of the malicious code file in the target dimension meets the predetermined naming condition corresponding to the target dimension includes: when the target dimension is the interface function dimension, for the target function with the most call times among the multiple interface functions used by the malicious code file, determining whether the call times of the target function are greater than or equal to a specified threshold; when the call times of the target function are greater than the specified threshold, determining the malicious code name corresponding to the malicious code file based on the naming method corresponding to the target dimension includes: using the name of the target function or the predetermined name information corresponding to the target function as the malicious code name corresponding to the malicious code file; when the call times of the target function are less than the specified threshold, the step of setting the next dimension in the target dimension as the target dimension includes: setting the static information dimension as the target dimension.
[0012] In the above embodiments of the present invention, optionally, determining whether the file information of the malicious code file in the target dimension meets the predetermined naming condition corresponding to the target dimension includes: when the target dimension is the static information dimension, determining that the static information of the malicious code file meets the corresponding predetermined naming condition; determining the malicious code name corresponding to the malicious code file based on the naming method corresponding to the target dimension includes: based on the predetermined static information priority, selecting the target static information with the highest priority from the multiple static information of the malicious code file; using the target static information or the predetermined name information corresponding to the target static information as the malicious code name corresponding to the malicious code file.
[0013] In the above embodiments of the present invention, optionally, determining whether the file information of the malicious code file in the target dimension meets the predetermined naming condition corresponding to the target dimension includes: when the target dimension is the static information dimension, determining that the static information of the malicious code file meets the corresponding predetermined naming condition; determining the malicious code name corresponding to the malicious code file based on the naming method corresponding to the target dimension includes: connecting the multiple static information of the malicious code file in order from high to low according to the static information priority to obtain comprehensive static information, and using it as the malicious code name corresponding to the malicious code file.
[0014] Second aspect, an embodiment of the present invention provides a malicious code naming device, including: a file information acquisition unit, configured to acquire file information of a malicious code file in multiple dimensions; a naming condition verification unit, configured to determine whether the file information of the malicious code file in a target dimension meets a predetermined naming condition corresponding to the target dimension; a first execution unit, configured to, when the judgment result of the naming condition verification unit is yes, determine a malicious code name corresponding to the malicious code file based on a naming method corresponding to the target dimension; a second execution unit, configured to, when the judgment result of the naming condition verification unit is no, set the dimension next in order of the target dimension as the target dimension in a preset dimension order, and continue to determine whether the file information of the malicious code file in the target dimension set this time meets the predetermined naming condition corresponding to the target dimension.
[0015] In the above embodiment of the present invention, optionally, the preset dimension order, in order of priority, is respectively: a known name mapping relationship dimension, a digital signature dimension, an interface function dimension, and a static information dimension.
[0016] In the above embodiment of the present invention, optionally, the naming condition verification unit is configured to: when the target dimension is the known name mapping relationship dimension, based on the C2 information of the malicious code file and a preset mapping library, determine whether the malicious code file matches a known malicious code family name, where, when the malicious code file matches the known malicious code family name, the first execution unit is configured to: determine the known malicious code family name as the malicious code name corresponding to the malicious code file; when the malicious code file does not match the known malicious code family name, the second execution unit is configured to: set the digital signature dimension as the target dimension.
[0017] In the above embodiment of the present invention, optionally, the naming condition verification unit is configured to: when the target dimension is the digital signature dimension, determine whether the malicious code file has a digital signature and whether the digital signature is a valid signature; when the malicious code file has the valid signature, the first execution unit is configured to: determine all party names of the valid signature as the malicious code name corresponding to the malicious code file; when the malicious code file does not have the valid signature, the second execution unit is configured to: set the interface function dimension as the target dimension.
[0018] In the above embodiments of the present invention, optionally, the naming condition verification unit is configured to: when the target dimension is the interface function dimension, for the target function with the most call times among the multiple interface functions used by the malicious code file, determine whether the call times of the target function are greater than or equal to a specified threshold; when the call times of the target function are greater than the specified threshold, the first execution unit is configured to: use the name of the target function or the corresponding predetermined name information of the target function as the malicious code name corresponding to the malicious code file; when the call times of the target function are less than the specified threshold, the second execution unit is configured to: set the static information dimension as the target dimension.
[0019] In the above embodiments of the present invention, optionally, the naming condition verification unit is configured to: when the target dimension is the static information dimension, determine that the static information of the malicious code file meets the corresponding predetermined naming condition; the first execution unit is configured to: based on the predetermined static information priority, select the target static information with the highest priority among the multiple static information of the malicious code file; use the target static information or the corresponding predetermined name information of the target static information as the malicious code name corresponding to the malicious code file.
[0020] In the above embodiments of the present invention, optionally, the naming condition verification unit is configured to: when the target dimension is the static information dimension, determine that the static information of the malicious code file meets the corresponding predetermined naming condition; the first execution unit is configured to: connect the multiple static information of the malicious code file in order from high to low according to the static information priority to obtain comprehensive static information, and use it as the malicious code name corresponding to the malicious code file.
[0021] In a third aspect, an embodiment of the present invention provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are set to execute the method according to any one of the above first aspects.
[0022] In a fourth aspect, an embodiment of the present invention provides a storage medium storing computer-executable instructions for executing the method flow according to any one of the above first aspects.
[0023] For the technical problems in the related art that malicious code files are inconvenient to identify due to their large quantity and have a high naming difficulty, the above technical solutions can quickly, efficiently, and accurately name malicious code files, improve the convenience and effectiveness of malicious code naming, facilitate users to conveniently and quickly understand the content and nature of the malicious code files through the obtained names, and contribute to the improvement of the efficiency of network security maintenance.
Description of the Drawings
[0024] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0025] Figure 1 Shows a flowchart of a malicious code naming method according to an embodiment of the present invention;
[0026] Figure 2 Shows a block diagram of a malicious code naming device according to an embodiment of the present invention;
[0027] Figure 3 Shows a block diagram of an electronic device according to an embodiment of the present invention.
Detailed Embodiments
[0028] To better understand the technical solutions of the present invention, the embodiments of the present invention will be described in detail below with reference to the drawings.
[0029] It should be clear that the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0030] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms of "a", "the" and "said" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0031] In an actual scenario, if it is necessary to name a known malicious code file, the following technical solutions of this application can be adopted.
[0032] In another actual scenario, it can be an external traffic detection device or an internal traffic detection module for an electronic device. When external traffic passes through the traffic detection device or the internal traffic detection module, the malicious code file in the traffic is identified by the traffic detection device or the internal traffic detection module, and the following technical solutions of this application are used to name the malicious code file, so that users can understand the attack content carried by the traffic.
[0033] Figure 1 Shows a flowchart of a malicious code naming method according to an embodiment of the present invention.
[0034] Such asFigure 1 As shown in Figure 1 , the process of the malicious code naming method according to an embodiment of the present invention includes:
[0035] Step 102, obtaining file information of the malicious code file in multiple dimensions.
[0036] The preset dimension order, in the order of priority from high to low, is: known name mapping relationship dimension, digital signature dimension, interface function dimension, and static information dimension. The higher the priority of a dimension, the more substantial content of the malicious code file can be reflected when naming based on this dimension, which is more conducive to users understanding the malicious code file itself.
[0037] Among them, the file information of the known name mapping relationship dimension is PE structure information, time stamp, version, number of bits, etc. Based on these contents, the C2 information of the malicious code file can be determined for subsequent judgment steps; the file information of the digital signature dimension is the digital signature and the validity of the digital signature; the file information of the interface function dimension is the name and call times of the interface function; the static information dimension includes, but is not limited to, mutex, pdb, guid, special strings, etc. used by the sample, which can show the structure or content of the malicious code file.
[0038] Step 104, judging whether the file information of the malicious code file under the target dimension meets the predetermined naming condition corresponding to the target dimension. When the judgment result is yes, go to step 106; when the judgment result is no, go to step 108.
[0039] Step 106, determining the malicious code name corresponding to the malicious code file based on the naming method corresponding to the target dimension.
[0040] If the file information of the malicious code file under the target dimension meets the predetermined naming condition corresponding to the target dimension, the naming method corresponding to the target dimension can be called to name the malicious code file. When making the first judgment, the target dimension is the known name mapping relationship dimension with the highest priority among the multiple dimensions.
[0041] Step 108, taking the order of priority of the multiple dimensions as the sequence, setting the next dimension in the target dimension as the target dimension, and returning to step 104 to continue judging whether the file information of the malicious code file under the currently set target dimension meets the predetermined naming condition corresponding to the target dimension.
[0042] If the file information of the malicious code file in the target dimension does not meet the predetermined naming condition corresponding to the target dimension, then, in the order of the priorities of the multiple dimensions, it is determined whether the predetermined naming condition is met in the next dimension with a priority lower than the target dimension until the predetermined naming condition corresponding to a certain dimension is met.
[0043] Through the above technical solution, the malicious code file can be automatically named according to the dimension with the highest possible priority among the multiple dimensions of the malicious code file. In this way, it is possible to preferentially select the dimension that is more important for the malicious code file to name the malicious code file. On the basis of improving the automation and convenience of the naming of the malicious code file, the reliability of the naming of the malicious code file is effectively improved, so that its naming can show the substantial content of the malicious code file as much as possible, facilitating users to understand and learn.
[0044] Specifically, when the target dimension is the known name mapping relationship dimension, step 104 includes: based on the C2 information of the malicious code file and the mapping relationship between the C2 information in the preset mapping library and the known malicious code family name, determining whether the malicious code file matches the known malicious code family name. When the malicious code file matches the known malicious code family name, step 106 includes: determining the known malicious code family name as the malicious code name corresponding to the malicious code file; when the malicious code file does not match the known malicious code family name, step 108 includes: setting the digital signature dimension as the target dimension.
[0045] Previously, it was necessary to obtain the family name and C2 information of the known malicious code and store the association relationship between the two in the preset mapping library. Specifically, the methods for obtaining the family name and C2 information of the known malicious code include the web crawler crawling method and the manual input method. Among them, in the web crawler crawling method, content such as the description information, analysis report, family name, and C2 information of the known malicious code can be obtained. In the manual input method, the yara rules, family name, and C2 information of the known malicious code can be determined. Among them, the C2 information refers to the information used to identify the malicious code, including but not limited to sample hash, URL, domain name, IP, etc.
[0046] After obtaining the information through the web crawler crawling method and the manual input method, various C2 information is associated with the family name based on this information and stored in the preset mapping library.
[0047] Then, if there is a known malicious code family name in the preset mapping library that matches the C2 information of the malicious code file, the known malicious code family name can be directly set as the malicious code name corresponding to the malicious code file. This can directly show the family to which the malicious code file belongs in the name, enabling users to quickly understand the origin of the malicious code and its corresponding features based on its name.
[0048] Conversely, if there is no known malicious code family name in the preset mapping library that matches the C2 information of the malicious code file, the second-step judgment is entered in the digital signature dimension.
[0049] Specifically, in the second-step judgment, step 104 includes: when the target dimension is the digital signature dimension, determining whether the malicious code file has a digital signature and whether the digital signature is a valid signature; when the malicious code file has the valid signature, step 106 includes: determining the name of all parties of the valid signature as the malicious code name corresponding to the malicious code file; when the malicious code file does not have the valid signature, step 108 includes: setting the interface function dimension as the target dimension.
[0050] If the malicious code file has a digital signature and the digital signature is valid, it indicates that the malicious code file is made or handled by all parties who perform the digital signature, and these all parties are at least one of the sources of the malicious code file. Therefore, the name of all parties of the valid signature can be directly determined as the malicious code name corresponding to the malicious code file, enabling users to quickly understand the source of the malicious code file through the name and facilitating users to make corresponding handling based on the source.
[0051] Conversely, if the malicious code file does not have a valid digital signature, it indicates that its source is unclear, and the third-step judgment is entered in the interface function dimension.
[0052] Specifically, in the third-step judgment, step 104 includes: when the target dimension is the interface function dimension, for the target function with the most call times among the multiple interface functions used by the malicious code file, determining whether the call times of the target function are greater than or equal to a specified threshold; when the call times of the target function are greater than the specified threshold, step 106 includes: using the name of the target function or the corresponding predetermined name information of the target function as the malicious code name corresponding to the malicious code file; when the call times of the target function are less than the specified threshold, step 108 includes: setting the static information dimension as the target dimension.
[0053] The interface functions used by malicious code files include, but are not limited to, process call functions, network call functions, file call functions, registry call functions, and service call functions. When the family name and source of the malicious code file are unknown, a name can be set for it based on the interface functions it mainly uses, so as to show through the name that the main behavior of the malicious code file is to use these interface functions.
[0054] Generally, a malicious code file uses multiple interface functions. Then, a specified threshold is set, and this specified threshold is the minimum number of calls when an interface function is sufficient to represent the main behavior of the malicious code file. If the target function with the most calls among multiple interface functions has a call count greater than the specified threshold, it indicates that this target function with the most calls is sufficient to represent the main behavior of the malicious code file. At this time, a name can be set for the malicious code file based on this target function with the most calls.
[0055] Among them, the name of the target function can be directly used as the name of the malicious code file, so that users can directly understand based on this name that the main behavior of the malicious code file is to use this interface function. Or, corresponding predefined name information can be set for the target function, and the predefined name information is common information related to the target function. In this way, users can also directly understand based on this predefined name information that the main behavior of the malicious code file is to use this interface function.
[0056] When the call count of the target function is less than the specified threshold, it indicates that the target function with this call count is not sufficient to represent the main behavior of the malicious code file, and other methods need to be further used for naming. At this time, the fourth-step judgment can be entered in the static information dimension.
[0057] In another possible design, if the target function with the highest call count is multiple functions with the same call count, the names of the multiple functions can be concatenated in the order of their priorities as the name of the malicious code file, or the predefined name information corresponding to the multiple functions can be concatenated in the order of their priorities as the name of the malicious code file.
[0058] In yet another possible design, all functions with call counts greater than the specified threshold among the multiple call functions used by the malicious code file can be extracted, and the names of the functions can be concatenated in the order of the number of calls from most to least as the name of the malicious code file, or the predefined name information corresponding to each function can be concatenated in the order of the number of calls from most to least among all functions as the name of the malicious code file.
[0059] In another possible design, all functions with a call count greater than a specified threshold among the multiple call functions used by the malicious code file can be extracted, and corresponding weights can be set for each function based on the call count and priority of each function in all functions. Then, in the order of the weights of each function from high to low, the names of each function are concatenated as the name of the malicious code file, or, in the order of the weights of each function from high to low, the corresponding predetermined name information of each function is concatenated as the name of the malicious code file.
[0060] In addition, for any interface function used by the malicious code file, determine the number of occurrences of the keyword corresponding to the interface function in the file information of the malicious code file, and determine the number of occurrences as the call count of the interface function.
[0061] For example, an interface function keyword list can be set, which stores: 5 keywords related to process call functions, 4 keywords related to network call functions, 3 keywords related to file call functions, 2 keywords related to registry call functions, and 1 keyword related to service call functions.
[0062] Among the functions called by the malicious code file, only process call functions and service call functions appear. Among them, keyword a of the process call function appears 3 times, keyword b appears 3 times, and the remaining keywords appear 0 times. And keyword x of the service call function appears 7 times. If the preset threshold is 6 times, it can be determined that the call count of the service call function is 7 times, which is greater than the preset threshold of 6 times, and the service call function is determined as the target function.
[0063] It should be noted that the above example is only one implementation method included in this application, and the actual application of this application is not limited to the numerical limitations given in this example.
[0064] In the fourth-step judgment, step 104 includes: when the target dimension is the static information dimension, determining that the static information of the malicious code file meets the corresponding predetermined naming condition; step 106 includes: based on the predetermined static information priority, selecting the target static information with the highest priority among the multiple static information of the malicious code file; using the target static information or the corresponding predetermined name information of the target static information as the malicious code name corresponding to the malicious code file.
[0065] Since the static information dimension is the last dimension and the malicious code file needs to be named directly with the static information, after entering the fourth-step judgment, it is directly determined that the static information of the malicious code file meets the corresponding predetermined naming condition, and the malicious code file is directly named with its static information.
[0066] The specific naming method is as follows: select the target static information with the highest priority from the static information of the malicious code file, and use the target static information as the malicious code name corresponding to the malicious code file. Since the target static information with the highest priority can best reflect the nature or influence of the malicious code file in the dimension of static information, naming it with this target static information enables users to quickly and effectively understand the static information of the malicious code file based on the name. Alternatively, a predetermined information name reflecting its core can be set for the target static information, and use this predetermined name information as the malicious code name corresponding to the malicious code file. Similarly, users can quickly and effectively understand the most influential static information of the malicious code file based on the name.
[0067] In another possible design, step 104 includes: when the target dimension is the static information dimension, determining that the static information of the malicious code file meets the corresponding predetermined naming conditions; step 106 includes: connecting the multiple static information of the malicious code file in order from the highest to the lowest static information priority to obtain comprehensive static information, which is used as the malicious code name corresponding to the malicious code file.
[0068] In this way, all static information can be reflected in the name of the malicious code file, so that users can comprehensively understand the specific situation of its static information through its name, which helps to understand and process the malicious code file.
[0069] Through the above technical solutions, the malicious code file can be named quickly, efficiently, and accurately, improving the convenience and effectiveness of malicious code naming, facilitating users to conveniently and quickly understand the content and nature of the malicious code file through the obtained name, and helping to improve the efficiency of network security maintenance.
[0070] Figure 2 The block diagram of a malicious code naming device according to an embodiment of the present invention is shown;
[0071] As Figure 2As shown in the figure, an embodiment of the present invention provides a malicious code naming device 200, including: a file information acquisition unit 202, configured to acquire file information of a malicious code file in multiple dimensions; a naming condition verification unit 204, configured to determine whether the file information of the malicious code file in the target dimension meets the predetermined naming condition corresponding to the target dimension; a first execution unit 206, configured to, when the judgment result of the naming condition verification unit is yes, determine the malicious code name corresponding to the malicious code file based on the naming method corresponding to the target dimension; a second execution unit 208, configured to, when the judgment result of the naming condition verification unit is no, set the dimension next in order of the target dimension as the target dimension in the preset dimension order, and continue to determine whether the file information of the malicious code file in the target dimension set this time meets the predetermined naming condition corresponding to the target dimension.
[0072] In the above embodiment of the present invention, optionally, the preset dimension order, in order of priority, is respectively: known name mapping relationship dimension, digital signature dimension, interface function dimension, and static information dimension.
[0073] In the above embodiment of the present invention, optionally, the naming condition verification unit 202 is configured to: when the target dimension is the known name mapping relationship dimension, based on the C2 information of the malicious code file and a preset mapping library, determine whether the malicious code file matches a known malicious code family name, where, when the malicious code file matches the known malicious code family name, the first execution unit 204 is configured to: determine the known malicious code family name as the malicious code name corresponding to the malicious code file; when the malicious code file does not match the known malicious code family name, the second execution unit 208 is configured to: set the digital signature dimension as the target dimension.
[0074] In the above embodiment of the present invention, optionally, the naming condition verification unit 204 is configured to: when the target dimension is the digital signature dimension, determine whether the malicious code file has a digital signature, and whether the digital signature is a valid signature; when the malicious code file has the valid signature, the first execution unit 206 is configured to: determine the name of all parties of the valid signature as the malicious code name corresponding to the malicious code file; when the malicious code file does not have the valid signature, the second execution unit 208 is configured to: set the interface function dimension as the target dimension.
[0075] In the above embodiments of the present invention, optionally, the naming condition verification unit 204 is configured to: when the target dimension is the interface function dimension, for the target function with the most call times among the multiple interface functions used by the malicious code file, determine whether the call times of the target function are greater than or equal to a specified threshold; when the call times of the target function are greater than the specified threshold, the first execution unit 206 is configured to: use the name of the target function or the corresponding predetermined name information of the target function as the malicious code name corresponding to the malicious code file; when the call times of the target function are less than the specified threshold, the second execution unit 208 is configured to: set the static information dimension as the target dimension.
[0076] In the above embodiments of the present invention, optionally, it further includes: a call times determination unit, configured to determine the occurrence times of the keyword corresponding to the interface function in the file information of the malicious code file for any interface function used by the malicious code file, and determine the occurrence times as the call times of the interface function.
[0077] In the above embodiments of the present invention, optionally, the naming condition verification unit 204 is configured to: when the target dimension is the static information dimension, determine that the static information of the malicious code file meets the corresponding predetermined naming condition; the first execution unit 206 is configured to: based on the predetermined static information priority, select the target static information with the highest priority from the multiple static information of the malicious code file; use the target static information or the corresponding predetermined name information of the target static information as the malicious code name corresponding to the malicious code file.
[0078] In the above embodiments of the present invention, optionally, the naming condition verification unit 204 is configured to: when the target dimension is the static information dimension, determine that the static information of the malicious code file meets the corresponding predetermined naming condition; the first execution unit 206 is configured to: connect the multiple static information of the malicious code file in order from high to low according to the static information priority to obtain comprehensive static information, and use it as the malicious code name corresponding to the malicious code file.
[0079] The malicious code naming device 200 uses the solution described in any one of the above embodiments, and therefore has all the above technical effects, which will not be elaborated here.
[0080] Figure 3 The block diagram of an electronic device according to an embodiment of the present invention is shown.
[0081] As Figure 3As shown in the figure, an electronic device 300 according to an embodiment of the present invention includes at least one memory 302; and a processor 304 communicatively connected to the at least one memory 302; wherein, the memory stores instructions executable by the at least one processor 304, and the instructions are configured to execute the solutions described in any of the above embodiments. Therefore, the electronic device 300 has the same technical effects as any of the above embodiments, and will not be elaborated herein.
[0082] The electronic devices according to the embodiments of the present invention exist in various forms, including but not limited to:
[0083] (1) Mobile communication devices: Such devices are characterized by having mobile communication functions and mainly aim to provide voice and data communication. Such terminals include: smart phones (such as iPhone), multimedia phones, functional phones, and low-end phones, etc.
[0084] (2) Ultra-mobile personal computer devices: Such devices belong to the category of personal computers, have computing and processing functions, and generally also have the characteristic of mobile Internet access. Such terminals include: PDAs, MIDs, and UMPC devices, etc., such as iPad.
[0085] (3) Portable entertainment devices: Such devices can display and play multimedia content. Such devices include: audio and video players (such as iPod), handheld game consoles, e-books, and smart toys and portable in-vehicle navigation devices.
[0086] (4) Servers: Devices that provide computing services. The composition of a server includes a processor, a hard disk, a memory, a system bus, etc. Servers are similar to general computer architectures, but due to the need to provide highly reliable services, they have higher requirements in terms of processing power, stability, reliability, security, scalability, and manageability.
[0087] (5) Other electronic devices with data interaction functions.
[0088] In addition, an embodiment of the present invention provides a storage medium storing computer-executable instructions for executing the method flow described in any of the above embodiments.
[0089] The technical solutions of the present invention have been described in detail above with reference to the accompanying drawings. Through the technical solutions of the present invention, malicious code files can be named quickly, efficiently, and accurately, improving the convenience and effectiveness of malicious code naming, facilitating users to conveniently and quickly understand the content and nature of malicious code files through the obtained names, and contributing to the improvement of the efficiency of network security maintenance.
[0090] Depending on the context, as used herein, the word "if" can be interpreted as "when" or "while" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detected (stated condition or event)" can be interpreted as "when determined" or "in response to determining" or "when detected (stated condition or event)" or "in response to detecting (stated condition or event)".
[0091] In several embodiments provided by the present invention, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in electrical, mechanical, or other forms.
[0092] In addition, in each embodiment of the present invention, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a hardware plus software functional unit.
[0093] The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer-readable storage medium. The above-mentioned software functional unit stored in a storage medium includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute some steps of the methods described in each embodiment of the present invention. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.
[0094] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A malicious code naming method, characterized in that, Including: Obtaining file information of a malicious code file in dimensions of known name mapping relationship, digital signature, interface function, and static information; Judging whether the file information of the malicious code file in the target dimension meets the predetermined naming condition corresponding to the target dimension; When the judgment result is yes, determining the malicious code name corresponding to the malicious code file based on the naming method corresponding to the target dimension; When the judgment result is no, setting the dimension next in order to the target dimension as the target dimension in the preset dimension order, and continuing to judge whether the file information of the malicious code file in the currently set target dimension meets the predetermined naming condition corresponding to the target dimension; The judging whether the file information of the malicious code file in the target dimension meets the predetermined naming condition corresponding to the target dimension includes: When the target dimension is the known name mapping relationship dimension, determining whether the malicious code file matches a known malicious code family name based on the C2 information of the malicious code file and a preset mapping library, where When the malicious code file matches a known malicious code family name, the determining the malicious code name corresponding to the malicious code file based on the naming method corresponding to the target dimension includes: Determining the known malicious code family name as the malicious code name corresponding to the malicious code file; When the malicious code file does not match the known malicious code family name, the step of setting the dimension next in order to the target dimension as the target dimension includes: Setting the digital signature dimension as the target dimension.
2. The malicious code naming method according to claim 1, wherein The preset dimension order, in order of priority, is respectively: known name mapping relationship dimension, digital signature dimension, interface function dimension, and static information dimension.
3. The malicious code naming method according to claim 2, wherein, The judging whether the file information of the malicious code file in the target dimension meets the predetermined naming condition corresponding to the target dimension includes: When the target dimension is the digital signature dimension, determining whether the malicious code file has a digital signature and whether the digital signature is a valid signature; When the malicious code file has the valid signature, the determining the malicious code name corresponding to the malicious code file based on the naming method corresponding to the target dimension includes: Determining all party names of the valid signature as the malicious code name corresponding to the malicious code file; When the malicious code file does not have the valid signature, the step of setting the dimension next in order to the target dimension as the target dimension includes: Setting the interface function dimension as the target dimension.
4. The malicious code naming method according to claim 2, wherein, The judging whether the file information of the malicious code file in the target dimension meets the predetermined naming condition corresponding to the target dimension includes: When the target dimension is the interface function dimension, for the target function with the most call times among the multiple interface functions used by the malicious code file, determining whether the call times of the target function are greater than or equal to a specified threshold; When the number of calls to the target function is greater than the specified threshold, determining the malicious code name corresponding to the malicious code file based on the naming method corresponding to the target dimension includes: Using the name of the target function or the predetermined name information corresponding to the target function as the malicious code name corresponding to the malicious code file; When the number of calls to the target function is less than the specified threshold, the step of setting the dimension next in line to the target dimension as the target dimension includes: Setting the static information dimension as the target dimension.
5. The malicious code naming method according to claim 2, characterized in that, Judging whether the file information of the malicious code file under the target dimension meets the predetermined naming conditions corresponding to the target dimension includes: When the target dimension is the static information dimension, determining that the static information of the malicious code file meets the corresponding predetermined naming conditions; Based on the naming method corresponding to the target dimension, determining the malicious code name corresponding to the malicious code file includes: Based on the predetermined static information priority, selecting the target static information with the highest priority from among the multiple static information of the malicious code file; Using the target static information or the predetermined name information corresponding to the target static information as the malicious code name corresponding to the malicious code file.
6. The malicious code naming method according to claim 2, characterized in that Judging whether the file information of the malicious code file under the target dimension meets the predetermined naming conditions corresponding to the target dimension includes: When the target dimension is the static information dimension, determining that the static information of the malicious code file meets the corresponding predetermined naming conditions; Based on the naming method corresponding to the target dimension, determining the malicious code name corresponding to the malicious code file includes: Sequentially connecting the multiple static information of the malicious code file in the order from the highest to the lowest static information priority to obtain comprehensive static information, which is used as the malicious code name corresponding to the malicious code file.
7. A malicious code naming device, characterized in that, Includes: A file information acquisition unit, configured to acquire the file information of the known name mapping relationship dimension, digital signature dimension, interface function dimension, and static information dimension of the malicious code file; A naming condition verification unit, configured to judge whether the file information of the malicious code file under the target dimension meets the predetermined naming conditions corresponding to the target dimension; A first execution unit, configured to, when the judgment result of the naming condition verification unit is yes, determine the malicious code name corresponding to the malicious code file based on the naming method corresponding to the target dimension; A second execution unit, configured to, when the judgment result of the naming condition verification unit is no, set the dimension next in line to the target dimension as the target dimension in a preset dimension order, and continue to judge whether the file information of the malicious code file under the target dimension set this time meets the predetermined naming conditions corresponding to the target dimension; The named condition verification unit is further configured to: when the target dimension is the known name mapping relationship dimension, determine whether the malicious code file matches a known malicious code family name based on the C2 information of the malicious code file and a preset mapping library. Wherein, when the malicious code file matches the known malicious code family name, the first execution unit is configured to: determine the known malicious code family name as the malicious code name corresponding to the malicious code file; when the malicious code file does not match the known malicious code family name, the second execution unit is configured to: set the digital signature dimension as the target dimension.
8. An electronic device, characterized in that, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are configured to execute the method described in any one of claims 1 to 6 above.
9. A storage medium, characterized in that, stores computer-executable instructions for executing the method flow described in any one of claims 1 to 6.
Citation Information
Patent Citations
Classification method for serialized operations of file system
CN104216980A
Tolerance display system
JP2001312498A