Detection Method, Device, Storage Medium and Processor for Malicious Data

By obtaining and analyzing the structural information of the top-stack pointer in the sandbox system, judging and counting the target attack pointer, the problem of low malicious data detection efficiency is solved, and efficient malicious data identification and labeling is achieved.

CN114297630BActive Publication Date: 2025-07-18BEIJING HILLSTONE NETWORKS INFORMATION TECHCO
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111502059.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-09
Publication Date
2025-07-18
Estimated Expiration
2041-12-09

AI Technical Summary

Technical Problem

In the prior art, malicious data detection efficiency is low and it is difficult to effectively use in large-scale sandbox systems.

Method used

By obtaining the structural information of the target data in the sandbox system, including the top pointer to the target data, we can judge whether there is a target attack pointer, and determine the data as malicious data based on the number of attack pointers.

Benefits of technology

The efficiency of malicious data detection is improved, and by determining the number of target attack pointers in the sandbox system, efficient identification and labeling of malicious data is achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114297630B_ABST
    Figure CN114297630B_ABST
Patent Text Reader

Abstract

The present application discloses a method, apparatus, storage medium, and processor for detecting malicious data. The method includes: obtaining structure information of target data in a sandbox system, where the structure information at least includes a stack top pointer pointing to the target data; determining whether there is a target attack pointer in the structure information, where the target attack pointer is a pointer pointing to malicious data; if there is a target attack pointer in the structure information, obtaining quantity information of the target attack pointer; and determining that the target data is malicious data according to the quantity information. Through the present application, the problem of low efficiency in detecting malicious data in the related art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular, to a method, device, storage medium, and processor for detecting malicious data. Background Technique

[0002] A software vulnerability refers to a defect in the logical design of an application software or an operating system software or an error generated during writing. In real offensive and defensive confrontations, hackers will use software vulnerabilities to run malicious code that hackers want to run on the victim's machine, thereby controlling the victim's machine. There are many vulnerability exploitation techniques, such as the ROP attack technique.

[0003] In the related art, the instruction stream is obtained by means of instrumentation, and then the ROP attack characteristics of the statistical instructions are calculated by a mathematical method. However, this solution needs to obtain and save a large number of assembly instructions, which will consume a large amount of computing resources and is difficult to apply in an actual large-scale sandbox system.

[0004] In view of the problem of low efficiency in detecting malicious data in the related art, no effective solution has been proposed yet. Summary of the Invention

[0005] The main purpose of the present application is to provide a method, device, storage medium, and processor for detecting malicious data, so as to solve the problem of low efficiency in detecting malicious data in the related art.

[0006] To achieve the above object, according to one aspect of the present application, a method for detecting malicious data is provided. The method includes: in a sandbox system, obtaining structure information of target data, where the structure information at least includes a stack top pointer pointing to the target data; determining whether there is a target attack pointer in the structure information, where the target attack pointer is a pointer pointing to malicious data; if there is a target attack pointer in the structure information, obtaining quantity information of the target attack pointer; and determining that the target data is malicious data according to the quantity information.

[0007] Further, before obtaining the structure information of the target data, the method further includes: receiving data to be detected; determining a stack top pointer of the data to be detected; obtaining data of a first preset byte from the position of the stack top pointer according to a target interface, where the data of the first preset byte is obtained by intercepting the data to be detected; and using the data of the first preset byte as the target data.

[0008] Further, before determining whether there is a target attack pointer in the structure information, the method further includes: grouping the data of the first preset byte to obtain a plurality of data of a second preset byte, where the first preset byte is greater than the second preset byte; and traversing the structure information of each data of the second preset byte to obtain a traversal result.

[0009] Further, determining whether there is a target attack pointer in the structure information includes: if the traversal result indicates that there is a target system pointer in the structure information, storing the target system pointer; determining whether the target system pointer is a pointer pointing to a preset assembly instruction, where the preset assembly instruction is the execution code of malicious data; if the target system pointer is a pointer pointing to a preset assembly instruction, determining that the target system pointer is a secondary pointer pointing to malicious data; and when the target system pointer is a secondary pointer pointing to malicious data, determining that there is a target attack pointer in the structure information.

[0010] Further, determining that the target data is malicious data according to the quantity information includes: judging whether the quantity information of the target attack pointer is greater than a target threshold; if the quantity information of the target attack pointer is greater than the target threshold, determining that the target data is malicious data.

[0011] Further, after determining that the target data is malicious data according to the quantity information, the method further includes: marking the target data to obtain the marked data; and outputting the marked data.

[0012] To achieve the above object, according to another aspect of the present application, there is provided a detection device for malicious data. The device includes: a first acquisition unit, configured to acquire the structure information of target data in a sandbox system, where the structure information at least includes a stack top pointer pointing to the target data; a judgment unit, configured to judge whether there is a target attack pointer in the structure information, where the target attack pointer is a pointer pointing to malicious data; a second acquisition unit, configured to acquire the quantity information of the target attack pointer if there is a target attack pointer in the structure information; and a first determination unit, configured to determine that the target data is malicious data according to the quantity information.

[0013] Further, the device further includes: a receiving unit, configured to receive the data to be detected before acquiring the structure information of the target data; a second determination unit, configured to determine the stack top pointer of the data to be detected; a third acquisition unit, configured to acquire the data of a first preset byte from the position of the stack top pointer according to a target interface, where the data of the first preset byte is obtained by intercepting the data to be detected; and a third determination unit, configured to use the data of the first preset byte as the target data.

[0014] Further, the device further includes: a grouping unit, configured to group the data of the first preset byte to obtain a plurality of data of a second preset byte before judging whether there is a target attack pointer in the structure information, where the first preset byte is greater than the second preset byte; and a traversal unit, configured to traverse the structure information of each data of the second preset byte to obtain a traversal result.

[0015] Further, the determination unit includes: a storage module, configured to store the target system pointer if the traversal result indicates that there is a target system pointer in the structure information; a first determination module, configured to determine whether the target system pointer is a pointer pointing to a preset assembly instruction, where the preset assembly instruction is an execution code of malicious data; a first determination module, configured to determine that the target system pointer is a secondary pointer pointing to malicious data if the target system pointer is a pointer pointing to a preset assembly instruction; a second determination module, configured to determine that there is a target attack pointer in the structure information when the target system pointer is a secondary pointer pointing to malicious data.

[0016] Further, the first determination unit includes: a second determination module, configured to determine whether the quantity information of the target attack pointer is greater than a target threshold; a third determination module, configured to determine that the target data is malicious data if the quantity information of the target attack pointer is greater than the target threshold.

[0017] Further, the apparatus further includes: a marking unit, configured to mark the target data after determining that the target data is malicious data according to the quantity information, to obtain marked data; an output unit, configured to output the marked data.

[0018] According to another aspect of the embodiments of the present application, there is also provided a processor, where the processor is configured to run a program, and when the program runs, it executes the method of any one of the above.

[0019] According to another aspect of the embodiments of the present application, there is also provided a computer-readable storage medium, on which a computer program / instruction is stored, and when the computer program / instruction is executed by a processor, it executes the method of any one of the above.

[0020] Through the present application, the following steps are adopted: in a sandbox system, obtain the structure information of target data, where the structure information at least includes a stack top pointer pointing to the target data; determine whether there is a target attack pointer in the structure information, where the target attack pointer is a pointer pointing to malicious data; if there is a target attack pointer in the structure information, obtain the quantity information of the target attack pointer; determine that the target data is malicious data according to the quantity information. This solves the problem of low detection efficiency of malicious data in the related art. By determining the quantity of target attack pointers in the sandbox system and determining that the target data is malicious data according to the quantity information, the effect of improving the detection efficiency of malicious data is achieved. Description of the Drawings

[0021] The drawings constituting a part of this application are used to provide a further understanding of this application. The schematic embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation to this application. In the drawings:

[0022] Figure 1It is a flowchart of a method for detecting malicious data provided according to an embodiment of the present application;

[0023] Figure 2 It is a flowchart of reading stack data of a method for detecting malicious data provided according to an embodiment of the present application;

[0024] Figure 3 It is a flowchart of finding a target system pointer of a method for detecting malicious data provided according to an embodiment of the present application;

[0025] Figure 4 It is a flowchart of determining malicious data of a method for detecting malicious data provided according to an embodiment of the present application;

[0026] Figure 5 It is a schematic diagram of the structure of a sandbox system of a method for detecting malicious data provided according to an embodiment of the present application;

[0027] Figure 6 It is a schematic diagram of a device for detecting malicious data provided according to an embodiment of the present application. Detailed implementation manners

[0028] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the drawings and in combination with the embodiments.

[0029] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data used can be interchanged under appropriate circumstances so as to implement the embodiments of the present application described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0031] For the convenience of description, some nouns or terms related to the embodiments of the present application are described below:

[0032] ROP: Return-oriented Programming, is a new type of attack based on code reuse technology.

[0033] Gadget: In ROP attacks, it refers to a piece of assembly code in an existing library (.dll) or executable file in computer memory. A string of logic composed of multiple consecutive gadgets is called a ROP chain.

[0034] According to an embodiment of the present application, a method for detecting malicious data is provided.

[0035] Figure 1 It is a flowchart of the method for detecting malicious data according to an embodiment of the present application. As Figure 1 shown, the method includes the following steps:

[0036] Step S101, in the sandbox system, obtain the structure information of the target data, where the structure information at least includes the stack top pointer pointing to the target data.

[0037] Specifically, use the stack to temporarily store the data and address to be detected, obtain the stack top pointer of the stack, and insert or delete the data to be detected in advance.

[0038] Optionally, in the method for detecting malicious data provided in the embodiment of the present application, before obtaining the structure information of the target data, the method further includes: receiving the data to be detected; determining the stack top pointer of the data to be detected; obtaining the data of the first preset byte from the position of the stack top pointer according to the target interface, where the data of the first preset byte is obtained by intercepting the data to be detected; and using the data of the first preset byte as the target data.

[0039] Specifically, Figure 2 It is a flowchart of reading stack data of the method for detecting malicious data provided in the embodiment of the present application. As Figure 2 shown, when starting the monitor in the sandbox system, the target process calls the target API to read the data of M bytes before and after the stack top pointer at this time (corresponding to the first preset byte in the present application), and uses the M-byte data as the target data. By starting the monitor in the sandbox system, the detection efficiency of malicious data is improved, and the detection overhead of the system is saved.

[0040] Step S102, determine whether there is a target attack pointer in the structure information, where the target attack pointer is a pointer pointing to malicious data.

[0041] For example, before determining whether there is a target attack pointer in the structure information, it is necessary to group the data of M bytes before and after the read stack top pointer and traverse the grouped data.

[0042] Optionally, in the malicious data detection method provided in the embodiments of the present application, before determining whether there is a target attack pointer in the structure information, the method further includes: grouping the data of the first preset byte to obtain multiple data of the second preset byte, where the first preset byte is greater than the second preset byte; traversing the structure information of each data of the second preset byte to obtain a traversal result.

[0043] Specifically, as Figure 3 shown, the M-byte data is grouped into groups of every 4 bytes (corresponding to the second preset data in the present application) to obtain multiple groups of data, and each group of data is traversed to obtain a traversal result. By dividing the target data into multiple groups for traversal, the detection efficiency of malicious data is improved.

[0044] Optionally, in the malicious data detection method provided in the embodiments of the present application, determining whether there is a target attack pointer in the structure information includes: if the traversal result indicates that there is a target system pointer in the structure information, storing the target system pointer; determining whether the target system pointer is a pointer pointing to a preset assembly instruction, where the preset assembly instruction is the execution code of malicious data; if the target system pointer is a pointer pointing to a preset assembly instruction, then determining that the target system pointer is a secondary pointer pointing to malicious data; in the case where the target system pointer is a secondary pointer pointing to malicious data, determining that there is a target attack pointer in the structure information.

[0045] It should be noted that when implementing the ROP attack, a "stable" system DLL is generally selected. Stable means that the loading position of this system DLL is fixed each time and it is loaded into the memory space managed by the system. For example: "msvcr71.dll" in versions of office before 2010. Select a "stable" gadget in this "stable" system DLL. As Figure 4 shown, if there is a system DLL pointer (corresponding to the target system pointer in the present application) in the stack, determine whether the target system pointer is a pointer pointing to a preset assembly instruction. If the DLL pointer points to a preset assembly instruction, then determine that there is a gadget pointer (corresponding to the target attack pointer in the present application) in the structure information. By using the target system pointer to search for the target attack pointer, the detection efficiency of malicious data is further improved.

[0046] Step S103, if there is a target attack pointer in the structure information, obtain the quantity information of the target attack pointer.

[0047] Specifically, as Figure 4 shown, the present application can also determine whether the DLL pointer is a pointer pointing to a preset assembly instruction according to the commonly used gadgets in the ROP attack, and further identify that there is a target attack pointer in the structure information.

[0048] Step S104, determine that the target data is malicious data according to the quantity information.

[0049] Specifically, traverse the system DLL pointers. If a gadget pointer is obtained, acquire the quantity information of the gadget pointer.

[0050] Optionally, in the malicious data detection method provided in the embodiments of the present application, determining that the target data is malicious data according to the quantity information includes: determining whether the quantity information of the target attack pointer is greater than the target threshold; if the quantity information of the target attack pointer is greater than the target threshold, determine that the target data is malicious data.

[0051] Specifically, as Figure 4 shown, if the quantity of gadget pointers exceeds the target threshold, determine that the target data is malicious data and there is an attack behavior. If the quantity of gadget pointers does not exceed the target threshold, determine that there is no attack behavior in the target data. By judging the quantity of gadget pointers, the efficiency of malicious data detection is further improved.

[0052] Optionally, in the malicious data detection method provided in the embodiments of the present application, after determining that the target data is malicious data according to the quantity information, the method further includes: marking the target data to obtain the marked data; outputting the marked data.

[0053] Specifically, when the quantity of gadget pointers exceeds a certain threshold, mark that the target data has a ROP attack behavior and output the ROP attack information. By marking the malicious data, the tracking of malicious data is realized.

[0054] Figure 5 is a schematic structural diagram of a sandbox system according to the malicious data detection method provided in the embodiments of the present application. As Figure 5 shown, in the sandbox system, receive the sample (data) to be detected, monitor the target process using multiple monitors, and generate a detection report on the target data after processing the detection results.

[0055] In summary, in the malicious data detection method provided in the embodiments of the present application, in the sandbox system, obtain the structural information of the target data, where the structural information at least includes the stack top pointer pointing to the target data; determine whether there is a target attack pointer in the structural information, where the target attack pointer is a pointer pointing to malicious data; if there is a target attack pointer in the structural information, obtain the quantity information of the target attack pointer; determine that the target data is malicious data according to the quantity information. This solves the problem of low efficiency in malicious data detection in the related art. By determining the quantity of target attack pointers in the sandbox system and determining that the target data is malicious data according to the quantity information, the effect of improving the efficiency of malicious data detection is achieved.

[0056] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0057] The embodiment of the present application also provides a malicious data detection device. It should be noted that the malicious data detection device of the embodiment of the present application can be used to execute the malicious data detection method provided by the embodiment of the present application. The malicious data detection device provided by the embodiment of the present application will be introduced below.

[0058] Figure 6 is a schematic diagram of the malicious data detection device according to the embodiment of the present application. As Figure 6 shown, the device includes: a first acquisition unit 601, a judgment unit 602, a second acquisition unit 603, and a first determination unit 604.

[0059] Specifically, the first acquisition unit 601 is used to acquire the structure information of the target data in the sandbox system, where the structure information at least includes a stack top pointer pointing to the target data;

[0060] The judgment unit 602 is used to judge whether there is a target attack pointer in the structure information, where the target attack pointer is a pointer pointing to malicious data;

[0061] The second acquisition unit 603 is used to acquire the quantity information of the target attack pointer if there is a target attack pointer in the structure information;

[0062] The first determination unit 604 is used to determine that the target data is malicious data according to the quantity information.

[0063] In summary, for the malicious data detection device provided by the embodiment of the present application, the first acquisition unit 601 acquires the structure information of the target data in the sandbox system, where the structure information at least includes a stack top pointer pointing to the target data; the judgment unit 602 judges whether there is a target attack pointer in the structure information, where the target attack pointer is a pointer pointing to malicious data; the second acquisition unit 603 acquires the quantity information of the target attack pointer if there is a target attack pointer in the structure information; the first determination unit 604 determines that the target data is malicious data according to the quantity information, solving the problem of low malicious data detection efficiency in the related art. By determining the quantity of the target attack pointer in the sandbox system and determining that the target data is malicious data according to the quantity information, the effect of improving the malicious data detection efficiency is achieved.

[0064] Optionally, in the malicious data detection device provided in the embodiments of the present application, the device further includes: a receiving unit, configured to receive the data to be detected before obtaining the structure information of the target data; a second determining unit, configured to determine the stack top pointer of the data to be detected; a third obtaining unit, configured to obtain the data of the first preset number of bytes from the position of the stack top pointer according to the target interface, where the data of the first preset number of bytes is obtained by intercepting the data to be detected; a third determining unit, configured to use the data of the first preset number of bytes as the target data.

[0065] Optionally, in the malicious data detection device provided in the embodiments of the present application, the device further includes: a grouping unit, configured to group the data of the first preset number of bytes to obtain a plurality of data of the second preset number of bytes before determining whether there is a target attack pointer in the structure information, where the first preset number of bytes is greater than the second preset number of bytes; a traversing unit, configured to traverse the structure information of each data of the second preset number of bytes to obtain a traversal result.

[0066] Optionally, in the malicious data detection device provided in the embodiments of the present application, the determination unit 602 includes: a storage module, configured to store the target system pointer if the traversal result indicates that there is a target system pointer in the structure information; a first judgment module, configured to judge whether the target system pointer is a pointer pointing to a preset assembly instruction, where the preset assembly instruction is the execution code of the malicious data; a first determination module, configured to determine that the target system pointer is a secondary pointer pointing to the malicious data if the target system pointer is a pointer pointing to the preset assembly instruction; a second determination module, configured to determine that there is a target attack pointer in the structure information when the target system pointer is a secondary pointer pointing to the malicious data.

[0067] Optionally, in the malicious data detection device provided in the embodiments of the present application, the first determination unit 604 includes: a second judgment module, configured to judge whether the quantity information of the target attack pointer is greater than a target threshold; a third determination module, configured to determine that the target data is malicious data if the quantity information of the target attack pointer is greater than the target threshold.

[0068] Optionally, in the malicious data detection device provided in the embodiments of the present application, the device further includes: a marking unit, configured to mark the target data after determining that the target data is malicious data according to the quantity information to obtain the marked data; an output unit, configured to output the marked data.

[0069] The malicious data detection device includes a processor and a memory. The above-mentioned first obtaining unit 601, determination unit 602, second obtaining unit 603, first determination unit 604, etc. are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to implement corresponding functions.

[0070] The processor contains cores, which retrieve corresponding program units from the memory. One or more cores can be set, and malicious data detection is performed by adjusting core parameters.

[0071] The memory may include non-permanent memory in a computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0072] An embodiment of the present invention provides a storage medium, on which a program is stored, and when the program is executed by a processor, a malicious data detection method is implemented.

[0073] An embodiment of the present invention provides a processor for running a program, and when the program runs, a malicious data detection method is executed.

[0074] An embodiment of the present invention provides a device, which includes a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, the following steps are implemented: In a sandbox system, obtain the structure information of target data, where the structure information at least includes a stack top pointer pointing to the target data; determine whether there is a target attack pointer in the structure information, where the target attack pointer is a pointer pointing to malicious data; if there is a target attack pointer in the structure information, obtain the quantity information of the target attack pointer; determine that the target data is malicious data according to the quantity information.

[0075] When the processor executes the program, the following steps are also implemented: Before obtaining the structure information of the target data, receive the data to be detected; determine the stack top pointer of the data to be detected; obtain the data of the first preset byte from the position of the stack top pointer according to the target interface, where the data of the first preset byte is obtained by intercepting the data to be detected; use the data of the first preset byte as the target data.

[0076] When the processor executes the program, the following steps are also implemented: Before determining whether there is a target attack pointer in the structure information, group the data of the first preset byte to obtain a plurality of data of the second preset byte, where the first preset byte is greater than the second preset byte; traverse the structure information of each data of the second preset byte to obtain a traversal result.

[0077] When the processor executes the program, the following steps are also implemented: If the traversal result indicates that there is a target system pointer in the structure information, store the target system pointer; determine whether the target system pointer is a pointer pointing to a preset assembly instruction, where the preset assembly instruction is the execution code of malicious data; if the target system pointer is a pointer pointing to a preset assembly instruction, determine that the target system pointer is a secondary pointer pointing to malicious data; in the case where the target system pointer is a secondary pointer pointing to malicious data, determine that there is a target attack pointer in the structure information.

[0078] When the processor executes the program, the following steps are also implemented: Determine whether the quantity information of the target attack pointer is greater than the target threshold; if the quantity information of the target attack pointer is greater than the target threshold, determine that the target data is malicious data.

[0079] When the processor executes the program, the following steps are also implemented: After determining that the target data is malicious data according to the quantity information, mark the target data to obtain the marked data; output the marked data.

[0080] The device in this article can be a server, a PC, a PAD, a mobile phone, etc.

[0081] This application also provides a computer program product, which when executed on a data processing device, is suitable for executing a program initialized with the following method steps: In a sandbox system, obtain the structure information of the target data, where the structure information at least includes a stack top pointer pointing to the target data; determine whether there is a target attack pointer in the structure information, where the target attack pointer is a pointer pointing to malicious data; if there is a target attack pointer in the structure information, obtain the quantity information of the target attack pointer; determine that the target data is malicious data according to the quantity information.

[0082] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: Before obtaining the structure information of the target data, receive the data to be detected; determine the stack top pointer of the data to be detected; obtain the data of the first preset byte from the position of the stack top pointer according to the target interface, where the data of the first preset byte is obtained by intercepting the data to be detected; use the data of the first preset byte as the target data.

[0083] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: Before determining whether there is a target attack pointer in the structure information, group the data of the first preset byte to obtain multiple data of the second preset byte, where the first preset byte is greater than the second preset byte; traverse the structure information of each data of the second preset byte to obtain a traversal result.

[0084] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: if the traversal result indicates that there is a target system pointer in the structure information, store the target system pointer; determine whether the target system pointer is a pointer pointing to a preset assembly instruction, where the preset assembly instruction is the execution code of malicious data; if the target system pointer is a pointer pointing to a preset assembly instruction, determine that the target system pointer is a secondary pointer pointing to malicious data; in the case where the target system pointer is a secondary pointer pointing to malicious data, determine that there is a target attack pointer in the structure information.

[0085] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: determine whether the quantity information of the target attack pointer is greater than a target threshold; if the quantity information of the target attack pointer is greater than the target threshold, determine that the target data is malicious data.

[0086] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: after determining that the target data is malicious data according to the quantity information, mark the target data to obtain the marked data; output the marked data.

[0087] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0088] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0089] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device realizes the functions in the processFigure 1 one or more processes and / or blocks Figure 1 the functions specified in one or more blocks.

[0090] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more processes and / or blocks Figure 1 one or more blocks.

[0091] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0092] The memory may include non-permanent memory in the computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.

[0093] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.

[0094] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of another identical element in the process, method, commodity or device comprising the element.

[0095] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0096] The above are only the embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A method for detecting malicious data, characterized in that, including: In a sandbox system, obtain the structure information of target data, where the structure information at least includes a stack top pointer pointing to the target data; Determine whether there is a target attack pointer in the structure information, where the target attack pointer is a pointer pointing to malicious data; If there is a target attack pointer in the structure information, obtain the quantity information of the target attack pointer; Determine that the target data is malicious data according to the quantity information, including: judge whether the quantity information of the target attack pointer is greater than a target threshold; if the quantity information of the target attack pointer is greater than the target threshold, determine that the target data is malicious data; Determining whether there is a target attack pointer in the structure information includes: traversing the structure information, if the traversal result indicates that there is a target system pointer in the structure information, store the target system pointer; judge whether the target system pointer is a pointer pointing to a preset assembly instruction; if the target system pointer is a pointer pointing to a preset assembly instruction, determine that the target system pointer is a secondary pointer pointing to malicious data; in the case that the target system pointer is a secondary pointer pointing to malicious data, determine that there is a target attack pointer in the structure information, where the preset assembly instruction is the execution code of the malicious data.

2. The method according to claim 1, wherein Before obtaining the structure information of the target data, the method further includes: Receive the data to be detected; Determine the stack top pointer of the data to be detected; Obtain the data of the first preset byte from the position of the stack top pointer according to a target interface, where the data of the first preset byte is obtained by intercepting the data to be detected; Use the data of the first preset byte as the target data.

3. The method according to claim 2, wherein Before determining whether there is a target attack pointer in the structure information, the method further includes: Group the data of the first preset byte to obtain a plurality of data of the second preset byte, where the first preset byte is greater than the second preset byte; Traverse the structure information of each data of the second preset byte to obtain a traversal result.

4. The method according to claim 1, wherein After determining that the target data is malicious data according to the quantity information, the method further includes: Mark the target data to obtain the marked data; Output the marked data.

5. A malicious data detection device, characterized in that, including: A first obtaining unit, configured to obtain the structure information of target data in a sandbox system, where the structure information at least includes a stack top pointer pointing to the target data; A judging unit, configured to judge whether there is a target attack pointer in the structure information, where the target attack pointer is a pointer pointing to malicious data; A second obtaining unit, configured to obtain the quantity information of the target attack pointer if there is a target attack pointer in the structure information; A first determining unit, configured to determine that the target data is malicious data according to the quantity information, including: a second judging module, configured to judge whether the quantity information of the target attack pointer is greater than a target threshold; a third determining module, configured to determine that the target data is malicious data if the quantity information of the target attack pointer is greater than the target threshold The judgment unit includes: a storage module configured to traverse the structure information, and store the target system pointer if the traversal result indicates that a target system pointer exists in the structure information; a first judgment module configured to judge whether the target system pointer is a pointer pointing to a preset assembly instruction; a first determination module configured to, if the target system pointer is a pointer pointing to a preset assembly instruction, determine that the target system pointer is a secondary pointer pointing to malicious data; a second determination module configured to, when the target system pointer is a secondary pointer pointing to malicious data, determine that a target attack pointer exists in the structure information, where the preset assembly instruction is the execution code of the malicious data.

6. The device according to claim 5, characterized in that The device further includes: a receiving unit configured to receive the data to be detected before obtaining the structure information of the target data; a second determination unit configured to determine the stack top pointer of the data to be detected; a third obtaining unit configured to obtain data of a first preset byte from the position of the stack top pointer according to a target interface, where the data of the first preset byte is obtained by intercepting the data to be detected; a third determination unit configured to use the data of the first preset byte as the target data.

7. The device according to claim 6, characterized in that, The device further includes: a grouping unit configured to group the data of the first preset byte to obtain a plurality of data of a second preset byte before judging whether a target attack pointer exists in the structure information, where the first preset byte is greater than the second preset byte; a traversal unit configured to traverse the structure information of each data of the second preset byte to obtain a traversal result.

8. The device according to claim 5, characterized in that, The device further includes: a marking unit configured to mark the target data after determining that the target data is malicious data according to the quantity information to obtain marked data; an output unit configured to output the marked data.

9. A processor, characterized in that, The processor is configured to run a program, where the program, when running, executes the malicious data detection method according to any one of claims 1 to 4.

10. A computer-readable storage medium, characterized in that, The storage medium includes a stored program, where the program executes the malicious data detection method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • ROP attack detection method based on RET instructions and JMP instructions

    CN105138903A

  • Attack protection for valid GADGET control transfers

    CN106687972A