Method, apparatus, and computer-readable storage medium for detecting a sample
By reading the data of interface address from the target stack to identify the anomalies of the samples to be detected, the problem of large computing resource overhead in the prior art is solved, and the detection efficiency and sandbox processing capability are improved.
Patent Information
- Application Number
- CN202111592992.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-23
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-12-23
AI Technical Summary
The prior art has high computational resource overhead when detecting samples to be detected through sandboxes, making it difficult to process large-scale samples simultaneously.
By determining the objective function of the sample to be detected, the interface address is read from the target stack of the objective function, and the first target data and the second target data of the preset number of bytes are obtained, and based on these data, whether the sample is an exception sample is determined.
It realizes the identification of abnormal samples under low computing resource overhead, improves the detection capability of sandboxes, and can process large-scale samples at the same time.
Smart Images

Figure CN114329440B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and in particular, to a method, an apparatus, and a computer-readable storage medium for detecting a sample. Background Art
[0002] In the field of information security, a sandbox refers to a tool for testing untrusted files or application programs waiting for detection samples in an isolated environment. The sandbox is actually a virtual system program. Through this virtual system program, an operator can run a browser or other programs in the sandbox environment, and moreover, the changes generated during the operation of the sandbox can be deleted after the test. Therefore, the sandbox creates an independent operating environment, and the programs running inside it will not have a permanent impact on the hard disk.
[0003] However, in the prior art, when identifying whether there is data that can generate malicious attack behavior in a sample to be detected through a sandbox, a computer needs to use the method of instrumentation to obtain all the instructions used by the sample to be detected during the detection process, and statistically analyze all the above instructions by a mathematical method. Since this method requires the computer to obtain and store a large number of instructions, it consumes a large amount of computing resources of the computer, thus making it difficult for the sandbox to detect a large number of samples to be detected simultaneously.
[0004] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of the present invention provide a method, an apparatus, and a computer-readable storage medium for detecting a sample, so as to at least solve the technical problem of large computing resource overhead in the prior art when detecting a sample to be detected.
[0006] According to one aspect of the embodiments of the present invention, a method for detecting a sample is provided, including: determining a target function corresponding to the sample to be detected, where the target function represents a piece of code executed by an operating system when processing the sample to be detected; reading an interface address corresponding to the target function from a target stack corresponding to the target function; obtaining a first target data of a preset number of bytes and a second target data of a preset number of bytes according to the interface address, where the first target data is located before the data corresponding to the interface address, and the second target data is located after the data corresponding to the interface address; determining whether the sample to be detected is an abnormal sample according to the first target data and the second target data.
[0007] Further, the method for detecting a sample further includes: obtaining the sample to be detected; starting an interception program of a function; and determining a target function corresponding to the selection instruction from a plurality of functions corresponding to the sample to be detected through the interception program when a selection instruction is received.
[0008] Further, the method for detecting a sample further includes: reading a stack pointer pointing to the bottom of a target stack; reading an interface address from the stack space pointed to by the stack pointer.
[0009] Further, the method for detecting a sample further includes: after reading the interface address corresponding to the target function from the target stack corresponding to the target function, determining whether the interface address is an address in a preset format; in the case where the interface address is an address in the preset format, obtaining first target data and second target data according to the interface address; in the case where the interface address is an address in other formats, determining that the sample to be detected is a normal sample.
[0010] Further, the method for detecting a sample further includes: detecting whether a machine instruction code of a first instruction exists in the first target data, where the first instruction is used to control the computer to switch from executing the current program to executing a called function; in the case where the machine instruction code of the first instruction does not exist in the first target data, determining whether the sample to be detected is an abnormal sample according to the second target data; in the case where the machine instruction code of the first instruction exists in the first target data, determining that the sample to be detected is a normal sample.
[0011] Further, the method for detecting a sample further includes: detecting whether a machine instruction code of a second instruction exists in the second target data, where the second instruction is used to call data in the target stack through a control register to guide a running program instance to execute malicious code; in the case where the machine instruction code of the second instruction exists in the second target data, determining that the sample to be detected is an abnormal sample; in the case where the machine instruction code of the second instruction does not exist in the second target data, determining that the sample to be detected is a normal sample.
[0012] Further, the method for detecting a sample further includes: after determining whether the sample to be detected is an abnormal sample according to the first target data and the second target data, in the case where the sample to be detected is an abnormal sample, generating a prompt message, where the prompt message at least includes one of the following: parameter information of the target function; interface address; first instruction; second instruction.
[0013] According to another aspect of the embodiments of the present invention, there is also provided a device for detecting a sample, including: a first determination module, configured to determine a target function corresponding to the sample to be detected, where the target function represents a piece of code executed by an operating system when processing the sample to be detected; a reading module, configured to read an interface address corresponding to the target function from a target stack corresponding to the target function; an obtaining module, configured to obtain first target data with a preset number of bytes and second target data with a preset number of bytes according to the interface address, where the first target data is before the data corresponding to the interface address, and the second target data is after the data corresponding to the interface address; a second determination module, configured to determine whether the sample to be detected is an abnormal sample according to the first target data and the second target data.
[0014] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the above method for detecting a sample when running.
[0015] According to another aspect of the embodiments of the present invention, there is also provided an electronic device including one or more processors; a storage device for storing one or more programs, and when the one or more programs are executed by the one or more processors, enabling the one or more processors to implement running a program, wherein the program is configured to execute the above method for detecting a sample when running.
[0016] In the embodiments of the present invention, a method is adopted to detect a sample to be detected based on a small amount of data. By determining an objective function corresponding to the sample to be detected and reading an interface address corresponding to the objective function from an objective stack corresponding to the objective function, first objective data of a preset number of bytes and second objective data of a preset number of bytes are obtained according to the interface address, and it is determined whether the sample to be detected is an abnormal sample based on the first objective data and the second objective data. Wherein, the objective function represents a piece of code executed by the operating system when processing the sample to be detected, the first objective data is located before the data corresponding to the interface address, and the second objective data is located after the data corresponding to the interface address.
[0017] As can be seen from the above, in the present application, by obtaining data for determining whether a sample to be detected is an abnormal sample from the objective stack, the purpose of detecting whether the sample to be detected contains data that can generate malicious attack behaviors is achieved, and further the effect of improving information security is realized. In addition, compared with the prior art, the present application does not need to obtain all instructions used in the detection process when detecting a sample to be detected, but only needs to determine whether the sample to be detected is an abnormal sample through a small amount of data. Therefore, the effect of reducing the computing resource overhead of the computer is achieved, which is beneficial to improving the detection ability of the sandbox and can detect a large number of samples to be detected simultaneously.
[0018] Thus, through the technical solution of the present application, the purpose of identifying whether a sample to be detected is an abnormal sample by using a small amount of computing resources is achieved, thereby realizing the technical effect of improving the detection efficiency, and further solving the technical problem of large computing resource overhead in the prior art when detecting a sample to be detected. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The drawings described herein are used to provide a further understanding of the present invention, form a part of this application, and the illustrative embodiments and descriptions of the present invention are used to explain the present invention, and do not constitute an improper limitation of the present invention. In the drawings:
[0020] Figure 1 is a flowchart of a method for detecting a sample according to an embodiment of the present invention;
[0021] Figure 2 is a schematic diagram of a process for calling a target function according to an embodiment of the present invention;
[0022] Figure 3 is a flowchart of a method for detecting a sample according to an embodiment of the present invention;
[0023] Figure 4 is a flowchart of a method for detecting a sample according to an embodiment of the present invention;
[0024] Figure 5 is a schematic diagram of a ROP malicious attack behavior according to an embodiment of the present invention;
[0025] Figure 6 is a schematic diagram of a sandbox according to an embodiment of the present invention;
[0026] Figure 7 is a schematic diagram of a device for detecting a sample according to an embodiment of the present invention. Detailed implementation manners
[0027] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0028] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0029] It should also be noted that in the technical solution of the present application, the acquisition, storage, application, etc. of the user's personal information are all information authorized by the user or fully authorized by all parties.
[0030] Embodiment 1
[0031] According to an embodiment of the present invention, an embodiment of a method for detecting a sample is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0032] In addition, it should also be noted that the electronic device can be the execution subject of the method for detecting the sample in this application. Among them, the electronic device at least includes devices such as desktop computers, laptop computers, smartphones, smart tablets, and smart watches. In addition, the electronic device as the execution subject also includes the software system running on the electronic device and the software program in operation.
[0033] Figure 1 is a flowchart of the method for detecting a sample according to an embodiment of the present invention, as Figure 1 shown, the method includes the following steps:
[0034] Step S102, determine the objective function corresponding to the sample to be detected.
[0035] In step S102, the objective function represents a piece of code executed by the operating system when processing the sample to be detected. Among them, the sample to be detected can be a file or an application program. For example, the sample to be detected can be a browser parsing script or an application software. In addition, the sample to be detected can correspond to multiple functions, among which at least the objective function is included. The objective function can be a function for ensuring the security of the operating system, application program, and file, or a function for reading key information. In addition, in this application, the function can be represented by an API.
[0036] Step S104, read the interface address corresponding to the objective function from the objective stack corresponding to the objective function.
[0037] In step S104, the interface address is the return address of the objective function after the electronic device calls the objective function. For example, the sample to be detected is the following program:
[0038]
[0039] Optionally, as Figure 2As shown, when the above program-controlled electronic device calls the target function "printf" to output "helloworld", the electronic device will first push the pointer of the parameter "hello world" corresponding to the target function "printf" onto the target stack, and then the electronic device will execute the assembly instruction "call printf". Among them, "call printf" is a call instruction. In addition, through the call instruction, the electronic device can also push the pointer of the next instruction of the call instruction, that is, Figure 2 the pointer of "addesp,4" in it, onto the target stack, and then the electronic device modifies the instruction register and executes the target function "printf". After the execution of the target function "printf" ends, the electronic device will return to the original target function according to the pointer saved in the target stack and continue to execute the next function.
[0040] It should be noted that in the above process, the instruction immediately preceding the instruction pointed to by the return address of the target function "printf" is a call instruction. That is, according to the function call convention, the instruction immediately preceding the instruction pointed to by the return address of the target function should be a call instruction.
[0041] In addition, the target stack is divided into multiple layers. As Figure 2 shown, the target stack includes multiple local variables of the target function "printf" and the stack bottom pointer of the previous function. Among them, Figure 2 shows 3 local variables of the target function "printf", namely local variable 1, local variable 2, and local variable 3. In addition, Figure 2 also shows the stack top pointer, the current stack bottom pointer, and the stack space of the previous function. Among them, the stack top pointer is saved in the register.
[0042] Step S106: Obtain first target data of a preset number of bytes and second target data of a preset number of bytes according to the interface address.
[0043] In step S106, the first target data is located before the data corresponding to the interface address, and the second target data is located after the data corresponding to the interface address. In addition, the preset number of bytes can be a custom number of bytes. For example, 2 bytes, 3 bytes, or 4 bytes. It should be noted that the above number of bytes is only an example. In actual applications, the operator can set the preset number of bytes according to actual needs, and the present application does not make special limitations on this.
[0044] Optionally, the electronic device may select, according to the interface address, data with a preset number of bytes before the data corresponding to the interface address as the first target data. Similarly, the electronic device may also select data with a preset number of bytes after the data corresponding to the interface address as the second target data.
[0045] It should be noted that, in the above process, the electronic device only needs a small amount of computing resources to process the first target data with the preset number of bytes and the second target data with the preset number of bytes. Therefore, the technical problem of large computing resource overhead existing in the prior art when detecting a sample to be detected is avoided, and the effect of reducing the detection cost is achieved.
[0046] Step S108: Determine whether the sample to be detected is an abnormal sample according to the first target data and the second target data.
[0047] In step S108, the abnormal sample is an application program or file with a malicious attack behavior. Among them, the malicious attack behavior may be a ROP malicious attack behavior, and the ROP malicious attack behavior is a new type of attack behavior based on code reuse technology. Specifically, the attacker extracts instruction fragments (gadgets) from the existing system-provided function libraries (.dll) or executable files, constructs malicious code composed of multiple gadgets, and generates an abnormal sample based on the malicious code. Thus, the abnormal sample calls some functions in the ROP manner to bypass the protection mechanisms of the operating system and software.
[0048] In addition, the gadget instruction in the ROP attack behavior refers to a section of assembly code in a function library (.dll) or an executable file that already exists in the computer memory, generally less than 6 instructions, and is required to end with a "ret" instruction. For example: "mov esp,ebx; pop ebx; ret". Specifically, the attacker usually uses system vulnerabilities or software vulnerabilities to write the pointer pointing to the gadget instruction into the stack space, or uses system vulnerabilities or software vulnerabilities to hijack the stack space to the space where the pointer of the gadget instruction is written, so that the computer process executes a gadget instruction or several consecutive gadget instructions through the "ret" instruction, and then guides the computer process to execute the above-mentioned real malicious code. In addition, a string of logic composed of multiple consecutive gadget instructions is called a ROP chain. The main function of the gadget instruction is to control the registers, adjust the data in the stack space, and thus guide the computer process to call some functions that can bypass the protection mechanisms of the operating system and software.
[0049] Optionally, after the electronic device obtains the first target data and the second target data, the electronic device may match the machine instruction code of the call instruction in the first target data. If the machine instruction code of the call instruction exists in the first target data, the electronic device determines that the target application interface called this time is normal, and the sample to be detected is a normal sample. If the machine instruction code of the call instruction does not exist in the first target data, the electronic device determines that the target application interface called this time is abnormal, and it is necessary to continue to detect whether the machine instruction code of the gadget instruction exists in the second target data. If the machine instruction code of the gadget instruction exists in the second target data, it is determined that the sample to be detected is an abnormal sample, and the sample to be detected has a ROP malicious attack behavior. If the machine instruction code of the gadget instruction does not exist in the second target data, it is determined that the sample to be detected is a normal sample, and the sample to be detected does not have a malicious ROP attack behavior.
[0050] It should be noted that by using the first target data with a preset number of bytes and the second target data with a preset number of bytes to determine whether the sample to be detected is an abnormal sample, the purpose of identifying whether there is data that can generate a ROP malicious attack behavior in the sample to be detected is achieved, and the effect of reducing the computing resource overhead of the computer is realized.
[0051] Based on the content of the above steps S102 to S108, it can be seen that in the embodiment of the present invention, a method of detecting the sample to be detected based on a small amount of data is adopted. By determining the target function corresponding to the sample to be detected and reading the interface address corresponding to the target function from the target stack corresponding to the target function, the first target data with a preset number of bytes and the second target data with a preset number of bytes are obtained according to the interface address, and it is determined whether the sample to be detected is an abnormal sample according to the first target data and the second target data. Among them, the target function represents a piece of code executed by the operating system when processing the sample to be detected, the first target data is before the data corresponding to the interface address, and the second target data is after the data corresponding to the interface address.
[0052] From the above content, it can be seen that in this application, by obtaining the data for determining whether the sample to be detected is an abnormal sample from the target stack, the purpose of detecting whether the sample to be detected contains data that can generate a malicious attack behavior is achieved, and the effect of improving information security is further realized. In addition, compared with the prior art, this application does not need to obtain all the instructions used in the detection process when detecting the sample to be detected, but only needs to determine whether the sample to be detected is an abnormal sample through a small amount of data. Therefore, the effect of reducing the computing resource overhead of the computer is realized, which is beneficial to improving the detection ability of the sandbox and can detect a large number of samples to be detected at the same time.
[0053] It can be seen that through the technical solution of the present application, the purpose of identifying whether the sample to be detected is an abnormal sample by using a small amount of computing resources is achieved, thereby realizing the technical effect of improving the detection efficiency, and further solving the technical problem of large computing resource overhead in the prior art when detecting the sample to be detected.
[0054] In an alternative embodiment, when the electronic device detects the sample to be detected, it first obtains the sample to be detected, then starts the function interception program, and when receiving a selection instruction, determines the target function corresponding to the selection instruction from multiple functions corresponding to the sample to be detected through the interception program.
[0055] Optionally, the above interception program is used to intercept and pause the current call process when the electronic device calls a function. For example, when an operator detects the sample to be detected, it may not be necessary to detect the call process of all functions, and only the call process of some target functions needs to be detected. Therefore, after the interception program is started, the operator can input a selection instruction on the electronic device, and thus after the electronic device receives the selection instruction, it will intercept and pause the call process of the target function corresponding to the selection instruction. Then the operator can analyze and make logical judgments on the data generated during the call of the target function, such as reading the data in the target stack. Finally, after the operator finishes the analysis, the electronic device can resume the execution of the call process of the intercepted target function.
[0056] In addition, when the target function is intercepted, the interface address corresponding to the target function will be automatically saved to the target stack, so that the interface address can be directly read by the electronic device.
[0057] It should be noted that by designing the interception program to determine the target function, the target function can be flexibly selected from multiple functions for detection, which is beneficial to improving the detection efficiency when the high sandbox detects the sample to be detected.
[0058] In an alternative embodiment, after the electronic device determines the target function through the interception program, it reads the interface address corresponding to the target function from the target stack corresponding to the target function. Specifically, the electronic device reads the stack pointer pointing to the bottom of the target stack and reads the interface address from the stack space pointed to by the stack pointer.
[0059] Optionally, Figure 3 is a flowchart of the method for detecting a sample according to an embodiment of the present invention. As Figure 3As shown, after the electronic device obtains the sample to be detected, it starts the monitor and the interception program through the sandbox, and then executes the target process in the sandbox for the detection process. When the electronic device calls the target function, the electronic device will read the stack bottom pointer in the target stack (the stack pointer corresponding to the bottom of the target stack), and according to the stack bottom pointer, read the interface address corresponding to the target function from the target stack. It should be noted that the stack is a basic data structure with the principle of last-in-first-out. Moreover, in the function call convention, the parameters of the function, the stack bottom pointer of the previous function, the return address, and the local variables will be stored in a memory space according to the storage logic of the stack. Among them, the previous function is the caller that calls the current function. For example, if the printf function is executed during the execution of the main function, then the main function is the caller of the printf function. In addition, as Figure 3 shown, after reading the interface address, the electronic device can detect whether there is an abnormality in the call process of the target function according to the interface address.
[0060] In an optional embodiment, after the electronic device reads the interface address corresponding to the target function from the target stack corresponding to the target function, it will also determine whether the interface address is an address in a preset format. Among them, when the interface address is an address in a preset format, the first target data and the second target data are obtained according to the interface address; when the interface address is an address in other formats, it is determined that the sample to be detected is a normal sample.
[0061] Optionally, the above-mentioned preset format address is an address in the format of a system DLL (Dynamic Link Library). Among them, the system is a computer operating system. After the electronic device reads the interface address from the target stack, it first determines whether the interface address is an address in the system DLL format. If the interface address is an address in the system DLL format, it continues to determine whether the sample to be detected is an abnormal sample according to the first target data and the second target data. If the interface address is not an address in the system DLL format, it is determined that the sample to be detected is a normal sample.
[0062] It should be noted that since the interface address corresponding to the abnormal sample is usually in the DLL format, therefore, during the detection process, by judging the interface address corresponding to the sample to be detected, it can be initially determined whether the sample to be detected is a normal sample, thereby reducing the number of samples to be detected that need to be continuously detected subsequently, and thus achieving the effect of improving the detection efficiency and reducing the computational resource overhead.
[0063] In an alternative embodiment, the electronic device may determine whether the sample to be detected is an abnormal sample based on the first target data and the second target data. Specifically, the electronic device detects whether there is a machine instruction code of the first instruction in the first target data. If there is no machine instruction code of the first instruction in the first target data, it determines whether the sample to be detected is an abnormal sample according to the second target data; if there is a machine instruction code of the first instruction in the first target data, it determines that the sample to be detected is a normal sample. Wherein, the first instruction is used to control the computer to switch from executing the current program to executing the called function.
[0064] Optionally, Figure 4 is a flowchart of a method for detecting a sample according to an embodiment of the present invention. As Figure 4 shown, the first instruction is the call instruction. After the electronic device obtains the interface address corresponding to the target function, the electronic device reads the first target data according to the interface address. Further, based on the first target data, the electronic device detects whether there is a machine instruction code of the call instruction in the first target data. If there is a machine instruction code of the call instruction in the first target data, it determines that the call process of the target function is normal, thereby determining that there is no data in the sample to be detected that can generate a ROP malicious attack behavior, and further determining that the sample to be detected is a normal sample. If there is no machine instruction code of the call instruction in the first target data, it determines that the call process of the target function may be abnormal and needs to be further determined by detecting the second target data.
[0065] In an alternative embodiment, the electronic device may determine whether the sample to be detected is an abnormal sample based on the second target data. Specifically, the electronic device detects whether there is a machine instruction code of the second instruction in the second target data. If there is a machine instruction code of the second instruction in the second target data, it determines that the sample to be detected is an abnormal sample; if there is no machine instruction code of the second instruction in the second target data, it determines that the sample to be detected is a normal sample. Wherein, the second instruction is used to call the data in the target stack through the control register to guide the running program instance to execute malicious code.
[0066] Optionally, the second instruction is the gadget instruction. As Figure 4As shown, after the electronic device detects that the machine instruction code of the call instruction does not exist in the first target data, it will read the second target data corresponding to the target function and detect whether the machine instruction code of the gadget instruction exists in the second target data. If the machine instruction code of the gadget instruction does not exist in the second target data, it is determined that the call process of the target application is normal, so it is determined that there is no data in the sample to be detected that can generate a ROP malicious attack behavior, and thus the sample to be detected is a normal sample. If the machine instruction code of the gadget instruction exists in the second target data, it is determined that the call process of the target application is abnormal, so it is determined that there is data in the sample to be detected that can generate a ROP malicious attack behavior, and thus it is determined that the sample to be detected is a normal sample.
[0067] It should be noted that Figure 5 is a schematic diagram of the ROP malicious attack behavior according to an embodiment of the present invention. As Figure 5 shown, in order to bypass the protection measures of some operating systems or software, an attacker will use the ROP attack method on a vulnerable software to control the electronic device to call some functions. Before calling a function, the attacker needs to carefully adjust the data in the stack corresponding to the function using the gadget instruction, so as to control the parameters of the function and the logic after the function execution ends. Among them, as Figure 5 shown, in order to enable the electronic device to continue executing malicious code after the target function call ends, the attacker will adjust the return address of the target function to a pointer pointing to the gadget. When the target function execution ends, the electronic device will execute this gadget instruction, that is, the attacker controls the electronic device to continue executing the subsequent malicious code through the gadget instruction. Combining Figure 2 it can be seen that Figure 5 in, the "return address of printf" is tampered with as the "gadget pointer". Therefore, the instruction pointed to by the "gadget pointer" is no longer "add esp, 4", but the "gadget" instruction. On this basis, the previous instruction of the "gadget" instruction may also no longer be the call instruction of "call printf", but other instructions.
[0068] In addition, through the analysis of ROP malicious attack behaviors, it can be known that the instruction immediately preceding the gadget instruction used to execute the ROP malicious attack behavior is not a call instruction. Therefore, when the return address of a target function is maliciously adjusted to a gadget pointer by an attacker using a software vulnerability or a system vulnerability, there will be a situation where the instruction immediately preceding the instruction pointed to by the return address of the target function is not a call instruction, which means that the call to the target function this time is not initiated by a call instruction, and there is an abnormal situation that violates the function call convention. After the electronic device detects this abnormal situation, in order to further determine whether this call is a malicious call, the electronic device will continue to detect whether the instruction pointed to by the return address of the target function is a gadget instruction. If the instruction pointed to by the return address is a gadget instruction, it can be determined that the sample to be detected contains data that can generate ROP malicious attack behaviors.
[0069] It can be seen that when the instruction immediately preceding the instruction pointed to by the return address of a target function is not a call instruction and the instruction pointed to by the return address of the target function is a gadget instruction, it can be determined that the sample to be detected is an abnormal sample. According to this rule, the present application uses the first target data and the second target data to achieve the purpose of detecting the sample to be detected with a small amount of computing resources, and realizes the effect of improving the detection efficiency.
[0070] In an optional embodiment, after the electronic device determines whether the sample to be detected is an abnormal sample according to the first target data and the second target data, in the case where the sample to be detected is an abnormal sample, a prompt message may be generated, where the prompt message includes at least one of the following: parameter information of the target function; interface address; first instruction; second instruction.
[0071] Optionally, the above parameter information includes the name, identifier, and program content of the target application. Further, the electronic device may send the prompt message to a display device connected to the electronic device, so as to prompt the operator which target function specifically has an abnormality when the abnormal sample is called, which is conducive to the operator's timely statistical analysis of the sample to be detected and improves the detection efficiency.
[0072] In an optional embodiment, Figure 6 is a schematic diagram of a sandbox according to an embodiment of the present invention. As Figure 6 shown, the sandbox can detect multiple samples to be detected at the same time, where each sample to be detected is detected by a detection module. As Figure 6As shown, VM1 and VM2 are two independent detection modules in the sandbox. Each detection module contains a monitor for monitoring the detection process and a target process for executing the detection process. Additionally, after each sample to be detected is detected by the detection module, the sandbox generates a final detection report based on the detection result. Among them, multiple final detection reports are independent of each other.
[0073] It should be noted that the sandbox in this application can detect a large number of samples to be detected simultaneously, thereby achieving the effect of improving the detection efficiency and facilitating the saving of detection costs.
[0074] From the above content, it can be seen that in this application, by obtaining data from the target stack to determine whether the sample to be detected is an abnormal sample, the purpose of detecting whether the sample to be detected contains data that can generate malicious attack behaviors is achieved, and thus the effect of enhancing information security is realized. Additionally, compared with the prior art, this application does not need to obtain all the instructions used in the detection process when detecting the sample to be detected, but only needs a small amount of data to determine whether the sample to be detected is an abnormal sample. Therefore, the effect of reducing the computational resource overhead of the computer is achieved, which is beneficial to improving the detection ability of the sandbox and can detect a large number of samples to be detected simultaneously.
[0075] Thus, through the technical solution of this application, the purpose of identifying whether the sample to be detected is an abnormal sample using a small amount of computational resources is achieved, thereby realizing the technical effect of improving the detection efficiency and further solving the technical problem of large computational resource overhead in the prior art when detecting the sample to be detected.
[0076] Embodiment 2
[0077] According to an embodiment of the present invention, there is also provided an embodiment of a device for detecting samples, where Figure 7 is a schematic diagram of a device for detecting samples according to an embodiment of the present invention, as Figure 7 shown, the device includes: a first determination module 701, a reading module 702, an acquisition module 703, and a second determination module 704.
[0078] Among them, the first determination module 701 is configured to determine an objective function corresponding to a sample to be detected, where the objective function represents a piece of code executed by an operating system when processing the sample to be detected; a reading module 702 is configured to read an interface address corresponding to the objective function from an objective stack corresponding to the objective function; an obtaining module 703 is configured to obtain a first objective data of a preset byte quantity and a second objective data of a preset byte quantity according to the interface address, where the first objective data is located before the data corresponding to the interface address, and the second objective data is located after the data corresponding to the interface address; a second determination module 704 is configured to determine whether the sample to be detected is an abnormal sample according to the first objective data and the second objective data.
[0079] It should be noted that the above calls to the first determination module 701, the reading module 702, the obtaining module 703, and the second determination module 704 correspond to steps S102 to S108 in the above embodiment. The examples and application scenarios implemented by the four modules and the corresponding steps are the same, but are not limited to the content disclosed in the above embodiment 1.
[0080] Optionally, the above first determination module further includes: a first obtaining module, a starting module, and a third determination module. Among them, the first obtaining module is configured to obtain a sample to be detected; the starting module is configured to start an interception program of a function; the third determination module is configured to, in the case of receiving a selection instruction, determine, through the interception program, an objective function corresponding to the selection instruction from multiple functions corresponding to the sample to be detected.
[0081] Optionally, the above reading module further includes: a first reading module and a second reading module. Among them, the first reading module is configured to read a stack pointer pointing to the bottom of the objective stack; the second reading module is configured to read an interface address from a stack address space pointed to by the stack pointer.
[0082] Optionally, the device for detecting a sample further includes: a fourth determination module, a first obtaining module, and a fifth determination module. Among them, the fourth determination module is configured to determine whether the interface address is an address in a preset format; the first obtaining module is configured to, in the case that the interface address is an address in the preset format, obtain the first objective data and the second objective data according to the interface address; the fifth determination module is configured to, in the case that the interface address is an address in other formats, determine that the sample to be detected is a normal sample.
[0083] Optionally, the above first determination module further includes: a detection module, a sixth determination module, and a seventh determination module. Among them, the detection module is configured to detect whether there is a machine instruction code of a first instruction in the first target data, where the first instruction is used to control the computer to switch from executing the current program to executing the called function; the sixth determination module is configured to determine whether the sample to be detected is an abnormal sample according to the second target data when there is no machine instruction code of the first instruction in the first target data; the seventh determination module is configured to determine that the sample to be detected is a normal sample when there is a machine instruction code of the first instruction in the first target data.
[0084] Optionally, the above sixth determination module further includes: a first detection module, an eighth determination module, and a ninth determination module. Among them, the first detection module is configured to detect whether there is a machine instruction code of a second instruction in the second target data, where the second instruction is used to call data in the target stack through a control register to guide the running program instance to execute malicious code; the eighth determination module is configured to determine that the sample to be detected is an abnormal sample when there is a machine instruction code of the second instruction in the second target data; the ninth determination module is configured to determine that the sample to be detected is a normal sample when there is no machine instruction code of the second instruction in the second target data.
[0085] Optionally, the device for detecting a sample further includes: a generation module, configured to generate a prompt message when the sample to be detected is an abnormal sample, where the prompt message includes at least one of the following: parameter information of a target function; an interface address; a first instruction; a second instruction.
[0086] Embodiment 3
[0087] On the other hand, according to an embodiment of the present invention, there is also provided a computer-readable storage medium storing a computer program, where the computer program is configured to execute the method for detecting a sample in the above Embodiment 1 when running.
[0088] Embodiment 4
[0089] On the other hand, according to an embodiment of the present invention, there is also provided an electronic device including one or more processors; a storage device configured to store one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement a program for running, where the program is configured to execute the method for detecting a sample as described above when running.
[0090] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages and disadvantages of the embodiments.
[0091] In the above embodiments of the present invention, the descriptions of the various embodiments each have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0092] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0093] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0094] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0095] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention. The foregoing storage medium includes: USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks or optical disks and other various media that can store program codes.
[0096] The above is only the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A method for detecting a sample, characterized in that, Including: Determine a target function corresponding to a sample to be detected, where the target function represents a piece of code executed by an operating system when processing the sample to be detected; Read an interface address corresponding to the target function from a target stack corresponding to the target function; Obtain first target data of a preset byte quantity and second target data of the preset byte quantity according to the interface address, where the first target data is located before data corresponding to the interface address, and the second target data is located after the data corresponding to the interface address; Determine whether the sample to be detected is an abnormal sample according to the first target data and the second target data; Among them, determining whether the sample to be detected is an abnormal sample according to the first target data and the second target data includes: detecting whether a machine instruction code of a first instruction exists in the first target data, where the first instruction is used to control a computer to switch from executing a current program to executing a called function; in a case where the machine instruction code of the first instruction does not exist in the first target data, detecting whether a machine instruction code of a second instruction exists in the second target data, where the second instruction is used to call data in the target stack through a control register to guide a running program instance to execute malicious code; in a case where the machine instruction code of the second instruction exists in the second target data, determining that the sample to be detected is the abnormal sample.
2. The method according to claim 1, wherein Determining a target function corresponding to a sample to be detected includes: Obtain the sample to be detected; Start an interception program of a function; In a case where a selection instruction is received, determine, through the interception program, the target function corresponding to the selection instruction from multiple functions corresponding to the sample to be detected.
3. The method according to claim 1, characterized in that, Reading an interface address corresponding to the target function from a target stack corresponding to the target function includes: Read a stack pointer pointing to the bottom of the target stack; Read the interface address from a stack space pointed to by the stack pointer.
4. The method according to claim 1, characterized in that, After reading the interface address corresponding to the target function from the target stack corresponding to the target function, the method further includes: Determine whether the interface address is an address in a preset format; In a case where the interface address is an address in the preset format, obtain the first target data and the second target data according to the interface address; In a case where the interface address is an address in other formats, determine that the sample to be detected is a normal sample.
5. The method according to claim 1, wherein Determining whether the sample to be detected is an abnormal sample according to the first target data and the second target data includes: In a case where the machine instruction code of the first instruction exists in the first target data, determine that the sample to be detected is a normal sample.
6. The method according to claim 5, wherein The method further includes: In a case where the machine instruction code of the second instruction does not exist in the second target data, determine that the sample to be detected is the normal sample.
7. The method according to claim 6, wherein After determining whether the sample to be detected is an abnormal sample according to the first target data and the second target data, the method further includes: When the sample to be detected is the abnormal sample, a prompt message is generated, where the prompt message includes at least one of the following: parameter information of the objective function; the interface address; the first instruction; the second instruction.
8. A device for detecting a sample, characterized in that, including: A first determination module, configured to determine an objective function corresponding to a sample to be detected, where the objective function represents a piece of code executed by an operating system when processing the sample to be detected; A reading module, configured to read an interface address corresponding to the objective function from an objective stack corresponding to the objective function; An obtaining module, configured to obtain first objective data of a preset byte quantity and second objective data of the preset byte quantity according to the interface address, where the first objective data is located before data corresponding to the interface address, and the second objective data is located after data corresponding to the interface address; A second determination module, configured to determine whether the sample to be detected is an abnormal sample according to the first objective data and the second objective data; Among them, the second determination module includes: a detection module, configured to detect whether a machine instruction code of a first instruction exists in the first objective data, where the first instruction is used to control a computer to switch from executing a current program to executing a called function; a sixth determination module, configured to determine whether the sample to be detected is an abnormal sample according to the second objective data when the machine instruction code of the first instruction does not exist in the first objective data; The sixth determination module further includes: a first detection module, configured to detect whether a machine instruction code of a second instruction exists in the second objective data, where the second instruction is used to call data in an objective stack through a control register to guide a running program instance to execute malicious code; an eighth determination module, configured to determine that the sample to be detected is an abnormal sample when the machine instruction code of the second instruction exists in the second objective data.
9. The device according to claim 8, characterized in that, The first determination module includes: A first obtaining module, configured to obtain a sample to be detected; A starting module, configured to start an interception program of a function; A third determination module, configured to determine an objective function corresponding to a selection instruction from multiple functions corresponding to the sample to be detected through the interception program when a selection instruction is received.
10. The device according to claim 8, characterized in that, The reading module includes: A first reading module, configured to read a stack pointer pointing to the bottom of an objective stack; A second reading module, configured to read an interface address from a stack address space pointed to by the stack pointer.
11. The device according to claim 8, characterized in that, The apparatus further includes: A fourth determination module, configured to determine whether the interface address is an address in a preset format; A first obtaining module, configured to obtain first objective data and second objective data according to the interface address when the interface address is an address in a preset format; A fifth determination module, configured to determine that the sample to be detected is a normal sample when the interface address is an address in other formats.
12. The device according to claim 8, characterized in that, The second determination module includes: A seventh determination module, configured to determine that the sample to be detected is a normal sample when a machine instruction code of a first instruction exists in the first objective data.
13. The device according to claim 12, characterized in that, The sixth determination module includes: A ninth determination module, configured to determine that the sample to be detected is a normal sample when the machine instruction code of the second instruction does not exist in the second target data.
14. The device according to claim 13, characterized in that, The apparatus further includes: A generation module, configured to generate a prompt message when the sample to be detected is an abnormal sample, where the prompt message includes at least one of the following: parameter information of the objective function; interface address; first instruction; second instruction.
15. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, where the computer program is configured to execute the method for detecting a sample according to any one of claims 1 to 7 when running.
16. An electronic device, characterized in that, The electronic device includes one or more processors; a storage device, configured to store one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement a program for running, where the program is configured to execute the method for detecting a sample according to any one of claims 1 to 7 when running.
Citation Information
Patent Citations
Method for vulnerability detection in Windows operating environment based on instrumentation tool
CN105184169A
Malicious code confusion detection method and system, computer device, and medium
CN108985063A