A Linux-based process dynamic injection method, device and storage medium
By installing the kernel driver module in the Linux system to hijack process information and modifying the entry address to interrupt command, the problem of lag in the development of dynamic injection technology in Linux system and high injection failure rate is solved, and the accuracy and stability of injection is achieved.
Patent Information
- Application Number
- CN202111670897.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-31
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2041-12-31
AI Technical Summary
The development of dynamic injection technology of Linux systems is lagging, the injection failure rate is high, and the injection timing is inaccurate, making it difficult to effectively defend against malicious programs.
By installing the kernel driver module, hijacking the process information of the target process, running the application layer manager to receive the process information, starting the injector and modifying the entry address of the target process as an interrupt instruction, ensuring that the injection is carried out after the target process is initialized.
The injection operation is completed accurately as soon as the target process is started, avoiding malicious programs using blank period escape detection and analysis, and improving the success rate and stability of injection.
Smart Images

Figure CN114297655B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and more particularly, to a method, device, and storage medium for dynamically injecting processes based on the Linux system. Background Art
[0002] With the rapid development of computer science, on the one hand, people enjoy the great convenience brought by computers, and on the other hand, they suffer from the attacks and threats of malicious programs. There are already a large number of security software under the Windows system to protect our computers and reduce the harm caused by malicious programs, while there is no such rich ecological environment under the Linux system. With the continuous development of the Linux system and its use in the server field, the security of the Linux system needs to be further improved. Among the methods for dynamically detecting malicious programs, dynamic injection is one of the important methods.
[0003] At present, the dynamic injection technology of the Linux system has not developed rapidly. Most of them stay at using the API functions provided by the Linux kernel (such as through the ptrace function) for conventional injection, which is easily circumvented by malicious programs and results in injection failure. In addition, dynamic injection can cause the environment of the target process to be inconsistent before and after injection, and the injection timing is inaccurate, etc., which will all lead to injection failure, and the injection success rate cannot be guaranteed. Summary of the Invention
[0004] The present invention aims to provide a method, device, and storage medium for dynamically injecting processes based on the Linux system to solve the problems existing in the current dynamic injection technology of the Linux system.
[0005] A method for dynamically injecting processes based on the Linux system provided by the present invention includes the following steps:
[0006] (1) Install the kernel driver module and hijack the process information of the target process;
[0007] (2) Run the application layer manager and receive the process information hijacked by the kernel driver module;
[0008] (3) Start the injector and pass the process information to the injector;
[0009] (4) The injector performs injection, modifies the entry address of the target process to an interrupt instruction, so that the target process generates an interrupt after completing the initialization operation, and then performs subsequent injection operations when entering the entry address again after generating the interrupt;
[0010] (5) Execute the injection operation.
[0011] Further, the method for hijacking the process information of the target process in step (1) is: obtaining the process information of the target process by hijacking the creation function of the target process.
[0012] Further, the method for the injector to perform injection in step (4) is: the injector performs injection according to the information classification of the application layer manager.
[0013] Further, when the injector performs injection in step (4), it is necessary to determine whether the target process is a newly started program or a child process fork:
[0014] If the target process is a newly started program, modify the entry address of the target process to an interrupt instruction, so that the target process generates an interrupt after completing the initialization operation, and then perform subsequent injection operations when the interrupt is generated and the entry address is entered again;
[0015] If the target process is a child process fork, there is no entry address, and directly perform subsequent injection operations.
[0016] Further, the method for performing the injection operation in step (5) is:
[0017] (51) Obtain a free memory space of the target process;
[0018] (52) Write shellcode code into this free memory space;
[0019] (53) Set the corresponding hardware register to the function addresses of malloc and dlopen;
[0020] (54) Execute the shellcode code to allocate space;
[0021] (55) Copy the dynamic library address to the allocated space;
[0022] (56) Execute dlopen to load the dynamic library;
[0023] (57) Set the hardware register to execute the dynamic library entry function to initialize the dynamic library;
[0024] (58) After the dynamic library completes the initialization operation, the injector restores the memory space of the target process.
[0025] The present invention also provides a storage medium, on which a computer program is stored, and when the computer program runs, it executes the above-mentioned process dynamic injection method based on the Linux system.
[0026] The present invention also provides a process dynamic injection device based on the Linux system, including:
[0027] A storage medium for storing a computer program;
[0028] A processor for running the computer program; when the computer program runs, it executes the above-mentioned process dynamic injection method based on the Linux system.
[0029] In summary, due to the adoption of the above technical solutions, the beneficial effects of the present invention are:
[0030] Compared with the existing dynamic injection technology of the Linux system, the present invention can accurately complete the injection operation at the first time when the target process starts, without generating a blank period due to injecting after running the target program first, avoiding malicious programs from using this period to escape detection and analysis. The present invention makes the injection of malicious programs more accurate and stable. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0032] Figure 1 It is a flowchart of the process dynamic injection method based on the Linux system in Embodiment 1 of the present invention.
[0033] Figure 2 It is an example display diagram of the kernel driver module hijacking the target process creation function in Embodiment 1 of the present invention.
[0034] Figure 3 It is a flowchart of performing the injection operation in Embodiment 1 of the present invention.
[0035] Figure 4 It is an example display diagram of the memory space state of the target process before injection in Embodiment 1 of the present invention.
[0036] Figure 5 It is an example display diagram of the memory space state of the target process after injection in Embodiment 1 of the present invention.
[0037] Figure 6 It is a flowchart of the process dynamic injection method based on the Linux system in Embodiment 2 of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0038] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and illustrated herein can be arranged and designed in various different configurations.
[0039] Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0040] Embodiment 1
[0041] As Figure 1 shown, this embodiment proposes a method for dynamic process injection based on the Linux system, including the following steps:
[0042] (1) Install the kernel driver module and hijack the process information of the target process; in this embodiment, the method for hijacking the process information of the target process is: obtain the process information of the target process by hijacking the creation function of the target process; an example display diagram of the kernel driver module hijacking the target process creation function is as Figure 2 shown;
[0043] (2) Run the application layer manager and receive the process information hijacked by the kernel driver module;
[0044] (3) Start the injector and pass the process information to the injector;
[0045] (4) The injector performs injection, modifies the entry address of the target process to an interrupt instruction, so that the target process generates an interrupt after completing the initialization operation, and then performs subsequent injection operations when entering the entry address again after the interrupt occurs; in this embodiment, the method for the injector to perform injection is: the injector performs injection according to the information classification of the application layer manager;
[0046] (5) Execute the injection operation. In this embodiment, as Figure 3 shown, the method for executing the injection operation is:
[0047] (51) Obtain a free memory space of the target process. An example display diagram of the memory space state of the target process before injection is as Figure 4 shown;
[0048] (52) Write the shellcode code into this free memory space;
[0049] (53) Set the corresponding hardware register to the addresses of the malloc and dlopen functions;
[0050] (54) Execute the shellcode code to allocate space;
[0051] (55) Copy the dynamic library address into the allocated space;
[0052] (56) Execute dlopen to load the dynamic library;
[0053] (57) Set the hardware register to execute the entry function of the dynamic library to initialize the dynamic library;
[0054] (58) After the dynamic library completes the initialization operation, the injector restores the memory space of the target process. An example display diagram of the memory space state of the target process after injection is shown in Figure 5 as shown.
[0055] The key of the present invention lies in how to know the precise timing when the target process just completes initialization. The present invention hijacks the process information by loading the kernel driver module. The injector completes the first injection, modifies the entry address of the target process to an interrupt instruction, allows it to complete the initialization operation, and after the initialization is completed, an interrupt will be generated and it will enter the entry address again. The injector then continues with the subsequent injection operations to ensure the success of the injection. Thus, compared with the existing dynamic injection technology of the Linux system, the present invention can accurately complete the injection operation at the first moment when the target process starts, without generating a blank period due to injecting after running the target program first, and avoids malicious programs using this period to escape detection and analysis. The present invention makes the injection of malicious programs more accurate and stable.
[0056] This application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of this application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate for implementing in the process Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks the device with the specified functions.
[0057] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements in the processFigure 1 one or more processes and / or boxes Figure 1 the functions specified in one or more boxes.
[0058] As described above, this embodiment also provides a storage medium, on which a computer program is stored, and when the computer program runs, it executes the above-mentioned process dynamic injection method based on the Linux system.
[0059] As described above, this embodiment also provides a process dynamic injection device based on the Linux system, including:
[0060] a storage medium for storing a computer program;
[0061] a processor for running the computer program; when the computer program runs, it executes the above-mentioned process dynamic injection method based on the Linux system.
[0062] Embodiment 2
[0063] Different from Embodiment 1, in step (4), when the injector performs injection, it is necessary to determine whether the target process is a newly started program or a forked child process:
[0064] If the target process is a newly started program, modify the entry address of the target process to an interrupt instruction, so that the target process generates an interrupt after completing the initialization operation, and then perform subsequent injection operations when the interrupt is generated and the entry address is entered again;
[0065] If the target process is a forked child process, there is no entry address, and subsequent injection operations are directly performed.
[0066] Therefore, this embodiment proposes a process dynamic injection method based on the Linux system, see Figure 6 , including the following steps:
[0067] (1) Install the kernel driver module and hijack the process information of the target process;
[0068] (2) Run the application layer manager and receive the process information hijacked by the kernel driver module;
[0069] (3) Start the injector and pass the process information to the injector;
[0070] (4) The injector performs injection and determines whether the target process is a newly started program or a forked child process:
[0071] If the target process is a newly started program, modify the entry address of the target process to an interrupt instruction, so that the target process generates an interrupt after completing the initialization operation, and then perform subsequent injection operations when the interrupt is generated and the entry address is entered again;
[0072] If the target process is a child process forked out, there is no entry address, and subsequent injection operations are directly performed;
[0073] (5) Perform injection operations. In this embodiment, the method for performing injection operations is as follows:
[0074] (51) Obtain a free memory space of the target process;
[0075] (52) Write shellcode code into this free memory space;
[0076] (53) Set the corresponding hardware registers to the addresses of the malloc and dlopen functions;
[0077] (54) Execute the shellcode code to allocate space;
[0078] (55) Copy the dynamic library address to the allocated space;
[0079] (56) Execute dlopen to load the dynamic library;
[0080] (57) Set the hardware registers to execute the entry function of the dynamic library to initialize the dynamic library;
[0081] (58) After the dynamic library completes the initialization operation, the injector restores the memory space of the target process.
[0082] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A Linux-based process dynamic injection method, characterized in that: The injection operation can be completed accurately at the first time when the target process is started, and there will be no blank period caused by running the target program first and then injecting, so as to prevent malicious programs from using this period to escape detection and analysis. The method includes the following steps: (1) Install the kernel driver module to hijack the process information of the target process; (2) Run the application layer manager to receive process information hijacked by the kernel driver module; (3) Start the injector and pass the process information to the injector; (4) The injector performs injection, modifies the entry address of the target process to an interrupt instruction, so that the target process generates an interrupt after completing the initialization operation, and performs subsequent injection operations after the interrupt is generated and the process enters the entry address again; the method for the injector to perform injection in step (4) is: the injector performs injection according to the information classification of the application layer manager; in step (4), when the injector performs injection, it is necessary to determine whether the target process is a new program startup or a forked child process: if the target process is a new program startup, the entry address of the target process is modified to an interrupt instruction, so that the target process generates an interrupt after completing the initialization operation, and performs subsequent injection operations after the interrupt is generated and the process enters the entry address again; if the target process is a forked child process, there is no entry address, and the subsequent injection operation is performed directly; (5) performing an injection operation; the method for performing the injection operation in step (5) is: (51) Obtain a section of free memory space of the target process; (52) Write the shellcode code into the free memory space; (53) Set the corresponding hardware registers to the malloc and dlopen function addresses; (54) Execute shellcode to allocate space; (55)Copy the dynamic library address to the allocated space; (56) Execute dlopen to load the dynamic library; (57) Setting the hardware register to execute the dynamic library entry function to initialize the dynamic library; (58) After the dynamic library completes the initialization operation, the injector restores the memory space of the target process.
2. The Linux-based process dynamic injection method according to claim 1, characterized in that: The method for hijacking the process information of the target process in step (1) is: obtaining the process information of the target process by hijacking the creation function of the target process.
3. A storage medium, characterized in that: The storage medium stores a computer program, which, when running, executes the Linux system-based process dynamic injection method according to any one of claims 1 to 2.
4. A process dynamic injection device based on Linux system, characterized in that: include: Storage medium for storing computer programs; A processor is used to run the computer program; when the computer program is running, the Linux system-based process dynamic injection method as described in any one of claims 1 to 2 is executed.
Citation Information
Patent Citations
Dynamic link library injection method and apparatus
CN105843640A
dll injection method and system under Windows platform
CN111475229A