A Windows software injection prevention method and system
By analyzing the blacklist list of DLL modules and matching the DLL and thread module information in the current process, the problems of high complexity and low security of anti-injection in the existing technology are solved, and the abnormal modules are automatically filtered and handled, improving the security of the software.
Patent Information
- Application Number
- CN202111580839.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-22
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2041-12-22
AI Technical Summary
When preventing the injection attack of Windows software, the existing technology is highly complex, strict in demand for developers, and is easily attacked by attackers using unknown APIs, resulting in low security.
By obtaining the data packet containing the DLL file of the dynamic link library, parse and obtain the DLL module blacklist list, iterate through each DLL module and thread module information in the current process, match the blacklist list, stop and close the exception module, and release the injected DLL module.
The automatic filtering and handling exception module is realized, which is convenient for users to use, and can prevent injection attacks to a certain extent, improving the security of the software.
Smart Images

Figure CN114428953B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of system security technology, and more specifically, to a Windows software anti-injection method and system. Background Art
[0002] Some of the recognized anti-injection methods for Windows software are generally difficult to implement technically and have too high requirements for software developers. For example, for message hooks, the injection of message hooks is currently intercepted at the driver layer, such as handle matching. This is a global interception method, which increases the complexity of message hook anti-injection. For example, for APIs, the traditional method is to avoid calling APIs with injection behavior. However, when avoiding calls, it is necessary to clearly know which types of APIs have injection behavior inside, and the chance of error is greater; some core function APIs are more complex to implement, and there are no alternative APIs. If these APIs are called, they will be injected and easily attacked by attackers through injected DLLs, with low security. If these APIs are not called, they need to implement their corresponding functions themselves, which is very costly.
[0003] The file with application number CN201610936075.X provides a message hook anti-injection method, device and client, focusing on protecting against message hook injection. The main protection mechanism is to use the system kernel callback index returned by the callback function to intercept untrusted message hook injection into the dynamic link library; the file with application number CN201510382748.7 provides an anti-injection method and device, which uses a Hook function to read the registry and loads the dynamic link library in a preset manner instead of loading it through the API, to prevent injection through the API and registry. Summary of the invention
[0004] The present invention provides a Windows software injection prevention method and system to solve the problem of how to implement Windows software injection prevention.
[0005] In order to solve the above problem, according to one aspect of the present invention, a method for preventing Windows software from being injected is provided, the method comprising:
[0006] Obtain a data packet containing a dynamic link library DLL file, and parse the data packet to obtain a DLL module blacklist list;
[0007] Traversing each DLL module in the current process, and determining an injection DLL module list according to each DLL module in the current process and the DLL file blacklist list;
[0008] Traversing the thread module information corresponding to each thread in the current process, and matching the thread module information with the injection DLL module in the injection DLL module list, and when the match is consistent, stopping the thread corresponding to the thread module information;
[0009] Traverse each window in the current process, match the window with the stopped thread, and close the window when the match is consistent;
[0010] Traverse and release each injection DLL module in the injection DLL module list.
[0011] Preferably, the step of determining the injection DLL module list according to each DLL module in the current process and the DLL file blacklist list comprises:
[0012] Obtaining first characteristic information of each DLL module in the current process and second characteristic information of each DLL module in the DLL file blacklist;
[0013] The first characteristic information and the second characteristic information are matched, and when the match is successful, the DLL module corresponding to the first characteristic information is determined as a target DLL module, and the target DLL module is stored in the injection DLL module list.
[0014] Preferably, the characteristic value includes: the module name, base address and process environment information PEB structure of the DLL module.
[0015] Preferably, the method releases each injection DLL module in the injection DLL module list through a remote thread.
[0016] Preferably, the method further comprises:
[0017] When the data packet containing the dynamic link library DLL file is an encrypted file, the data packet is decrypted according to a decryption algorithm corresponding to a preset encryption algorithm to obtain a plaintext file;
[0018] Among them, the preset encryption algorithm is: SM2 national secret encryption algorithm, MD5 algorithm, SHA1 algorithm, DES algorithm, AES algorithm or RSA algorithm.
[0019] According to another aspect of the present invention, there is provided a Windows software injection prevention system, the system comprising:
[0020] A blacklist acquisition unit is used to acquire a data packet containing a dynamic link library DLL file, and parse the data packet to acquire a DLL module blacklist;
[0021] The injection DLL module list determination unit is used to traverse each DLL module in the current process and determine the injection DLL module list according to each DLL module in the current process and the DLL file blacklist list;
[0022] A thread matching unit, used for traversing thread module information corresponding to each thread in the current process, and matching the thread module information with the injection DLL module in the injection DLL module list, and when the match is consistent, stopping the thread corresponding to the thread module information;
[0023] A window matching unit, used for traversing each window in the current process, matching the window with the stopped thread, and closing the window when the match is consistent;
[0024] The release unit is used to traverse and release each injection DLL module in the injection DLL module list.
[0025] Preferably, the injection DLL module list determining unit determines the injection DLL module list according to each DLL module in the current process and the DLL file blacklist list, including:
[0026] Obtaining first characteristic information of each DLL module in the current process and second characteristic information of each DLL module in the DLL file blacklist;
[0027] The first characteristic information and the second characteristic information are matched, and when the match is successful, the DLL module corresponding to the first characteristic information is determined as a target DLL module, and the target DLL module is stored in the injection DLL module list.
[0028] Preferably, the characteristic value includes: the module name, base address and process environment information PEB structure of the DLL module.
[0029] Preferably, the releasing unit releases each injection DLL module in the injection DLL module list through a remote thread.
[0030] Preferably, the blacklist acquisition unit further includes:
[0031] When the data packet containing the dynamic link library DLL file is an encrypted file, the data packet is decrypted according to a decryption algorithm corresponding to a preset encryption algorithm to obtain a plaintext file;
[0032] Among them, the preset encryption algorithm is: SM2 national secret encryption algorithm, MD5 algorithm, SHA1 algorithm, DES algorithm, AES algorithm or RSA algorithm.
[0033] The present invention provides an anti-injection method and system for Windows software, comprising: obtaining a DLL module blacklist list; traversing each DLL module in the current process, and determining an injection DLL module list according to each DLL module in the current process and the DLL file blacklist list; traversing thread module information corresponding to each thread in the current process, and matching the thread module information with the injection DLL module in the injection DLL module list, and when the match is consistent, stopping the thread corresponding to the thread module information; traversing each window in the current process, and matching the window with the stopped thread, and when the match is consistent, closing the window; traversing and releasing each injection DLL module in the injection DLL module list. The present invention automatically filters and processes abnormal modules through a blacklist file that is preset or transmitted over a network, is convenient for users to use, and can prevent injection to a certain extent. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] A more complete understanding of exemplary embodiments of the present invention may be obtained by referring to the following drawings:
[0035] Figure 1 is a flow chart of a Windows software injection prevention method 100 according to an embodiment of the present invention;
[0036] Figure 2 Schematic diagram of the structure of the Windows software injection prevention system 200 according to an embodiment of the present invention. DETAILED DESCRIPTION
[0037] Now, exemplary embodiments of the present invention are described with reference to the accompanying drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. These embodiments are provided to disclose the present invention in detail and completely and to fully convey the scope of the present invention to those skilled in the art. The terms used in the exemplary embodiments shown in the accompanying drawings are not intended to limit the present invention. In the accompanying drawings, the same units / elements are marked with the same reference numerals.
[0038] Unless otherwise specified, the terms (including technical terms) used herein have the commonly understood meanings to those skilled in the art. In addition, it is understood that the terms defined in commonly used dictionaries should be understood to have the same meanings as those in the context of the relevant fields, and should not be understood as idealized or overly formal meanings.
[0039] Figure 1 FIG. 1 is a flow chart of a Windows software injection prevention method 100 according to an embodiment of the present invention. Figure 1As shown, the Windows software injection prevention method provided by the embodiment of the present invention automatically filters and processes abnormal modules through a blacklist file that is preset or transmitted over the network, which is convenient for users to use and can prevent injection to a certain extent. The Windows software injection prevention method 100 provided by the embodiment of the present invention starts from step 101. In step 101, a data packet containing a dynamic link library DLL file is obtained, and the data packet is parsed to obtain a DLL module blacklist list.
[0040] Preferably, the method further comprises:
[0041] When the data packet containing the dynamic link library DLL file is an encrypted file, the data packet is decrypted according to a decryption algorithm corresponding to a preset encryption algorithm to obtain a plaintext file;
[0042] Among them, the preset encryption algorithm is: SM2 national secret encryption algorithm, MD5 algorithm, SHA1 algorithm, DES algorithm, AES algorithm or RSA algorithm.
[0043] The present invention provides a windows software injection method, which mainly identifies each injection module information through characteristic values and releases and closes the corresponding injected DLL, thread and window.
[0044] In the present invention, an encrypted / unencrypted data packet containing a dynamic link library DLL file is obtained as a file through network transmission, and the data packet is parsed to obtain a DLL module blacklist, including: a DLL name and a characteristic value, etc.
[0045] Wherein, when the data packet containing the dynamic link library DLL file is an encrypted file, the data packet is decrypted according to a decryption algorithm corresponding to a preset encryption algorithm to obtain a plaintext file. The preset encryption algorithm is: SM2 national secret encryption algorithm, MD5 algorithm, SHA1 algorithm, DES algorithm, AES algorithm or RSA algorithm, etc. The present invention does not specifically limit this.
[0046] Step 102, traverse each DLL module in the current process, and determine the injection DLL module list according to each DLL module in the current process and the DLL file blacklist list.
[0047] Preferably, the step of determining the injection DLL module list according to each DLL module in the current process and the DLL file blacklist list comprises:
[0048] Obtaining first characteristic information of each DLL module in the current process and second characteristic information of each DLL module in the DLL file blacklist;
[0049] The first characteristic information and the second characteristic information are matched, and when the match is successful, the DLL module corresponding to the first characteristic information is determined as a target DLL module, and the target DLL module is stored in the injection DLL module list.
[0050] Preferably, the characteristic value includes: the module name, base address and process environment information PEB structure of the DLL module.
[0051] In the present invention, after obtaining the DLL file blacklist, the characteristic value information (including: module name, base address, PEB structure, etc.) of each DLL module of the process is traversed and matched. If the DLL module characteristic value matches that in the blacklist, the injection DLL module list is obtained based on the successful match.
[0052] Specifically, first characteristic information of each DLL module in the current process and second characteristic information of each DLL module in the DLL file blacklist are obtained; then, the first characteristic information and the second characteristic information are matched, and when the match is successful, the DLL module corresponding to the first characteristic information is determined to be the target DLL module, and the target DLL module is stored in the injection DLL module list, thereby obtaining the injection DLL module list.
[0053] In step 103, thread module information corresponding to each thread in the current process is traversed, and the thread module information is matched with the injection DLL module in the injection DLL module list, and when the match is consistent, the thread corresponding to the thread module information is stopped.
[0054] In step 104, each window in the current process is traversed, and the window is matched with the stopped thread, and when the match is consistent, the window is closed.
[0055] In step 105, each injection DLL module in the injection DLL module list is traversed and released.
[0056] Preferably, the method releases each injection DLL module in the injection DLL module list through a remote thread.
[0057] In an embodiment of the present invention, after determining the injection DLL module list, traverse the thread information in the process, and if the DLL module corresponding to a thread matches the DLL module in the injection DLL module list, stop the thread. Traverse the window modules of the process, and if the window module matches the injection thread, close and unregister the window. It is also necessary to traverse the injection DLL modules and enable the remote thread to release the injection DLL module.
[0058] The key technical point of the present invention is to obtain the windows software process module information, thread information and window information, and process the corresponding injected DLL, thread and window according to the characteristic value of the injection module. The method of the present invention automatically screens and processes abnormal modules through a blacklist file preset or transmitted over the network, which is convenient for users to use and prevents the occurrence of injection to a certain extent.
[0059] Figure 2 FIG. 2 is a schematic diagram of the structure of an anti-injection system 200 for Windows software according to an embodiment of the present invention. Figure 2 As shown, the Windows software injection prevention system 200 provided by the embodiment of the present invention includes: a blacklist acquisition unit 201, an injection DLL module list determination unit 202, a thread matching unit 203, a window matching unit 204 and a release unit 205.
[0060] Preferably, the blacklist acquisition unit 201 is used to acquire a data packet containing a dynamic link library DLL file, and parse the data packet to acquire a DLL module blacklist.
[0061] Preferably, the blacklist acquisition unit 201 further includes:
[0062] When the data packet containing the dynamic link library DLL file is an encrypted file, the data packet is decrypted according to a decryption algorithm corresponding to a preset encryption algorithm to obtain a plaintext file;
[0063] Among them, the preset encryption algorithm is: SM2 national secret encryption algorithm, MD5 algorithm, SHA1 algorithm, DES algorithm, AES algorithm or RSA algorithm.
[0064] Preferably, the injection DLL module list determining unit 202 is used to traverse each DLL module in the current process, and determine the injection DLL module list according to each DLL module in the current process and the DLL file blacklist.
[0065] Preferably, the injection DLL module list determining unit 202 determines the injection DLL module list according to each DLL module in the current process and the DLL file blacklist list, including:
[0066] Obtaining first characteristic information of each DLL module in the current process and second characteristic information of each DLL module in the DLL file blacklist;
[0067] The first characteristic information and the second characteristic information are matched, and when the match is successful, the DLL module corresponding to the first characteristic information is determined as a target DLL module, and the target DLL module is stored in the injection DLL module list.
[0068] Preferably, the characteristic value includes: the module name, base address and process environment information PEB structure of the DLL module.
[0069] Preferably, the thread matching unit 203 is used to traverse the thread module information corresponding to each thread in the current process, and match the thread module information with the injection DLL module in the injection DLL module list, and when the match is consistent, stop the thread corresponding to the thread module information.
[0070] Preferably, the window matching unit 204 is used to traverse each window in the current process, match the window with the stopped thread, and close the window when the match is consistent.
[0071] Preferably, the releasing unit 205 is used to traverse and release each injection DLL module in the injection DLL module list.
[0072] Preferably, the releasing unit 205 releases each injection DLL module in the injection DLL module list through a remote thread.
[0073] The Windows software injection prevention system 200 of the embodiment of the present invention corresponds to the Windows software injection prevention method 100 of another embodiment of the present invention, which will not be described in detail here.
[0074] The invention has been described above with reference to a few embodiments. However, it is readily apparent to a person skilled in the art that other embodiments than the ones disclosed above are equally within the scope of the invention, as defined by the appended patent claims.
[0075] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / said / the [means, components, etc.]" are to be openly interpreted as at least one instance of the means, components, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not necessarily have to be performed in the exact order disclosed, unless explicitly stated otherwise.
[0076] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0077] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0078] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0079] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0080] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A method for preventing Windows software from being injected. It is characterized in that The method comprises: Obtain a data packet containing a dynamic link library DLL file, and parse the data packet to obtain a DLL module blacklist list; Traversing each DLL module in the current process, and determining an injection DLL module list according to each DLL module in the current process and the DLL module blacklist; Traversing the thread module information corresponding to each thread in the current process, and matching the thread module information with the injection DLL module in the injection DLL module list, and when the match is consistent, stopping the thread corresponding to the thread module information; Traverse each window in the current process, match the window with the stopped thread, and close the window when the match is consistent; Traverse and release each injection DLL module in the injection DLL module list; Wherein, the step of determining the injection DLL module list according to each DLL module in the current process and the DLL module blacklist list comprises: Obtaining first characteristic information of each DLL module in the current process and second characteristic information of each DLL module in the DLL file blacklist; Matching the first characteristic information with the second characteristic information, and when the match succeeds, determining the DLL module corresponding to the first characteristic information as a target DLL module, and storing the target DLL module in the injection DLL module list; The characteristic information includes: the module name, base address and process environment information PEB structure of the DLL module.
2. The method according to claim 1, It is characterized in that The method releases each injection DLL module in the injection DLL module list through a remote thread.
3. The method according to claim 1, It is characterized in that The method further comprises: When the data packet containing the dynamic link library DLL file is an encrypted file, the data packet is decrypted according to a decryption algorithm corresponding to a preset encryption algorithm to obtain a plaintext file; Among them, the preset encryption algorithm is: SM2 national secret encryption algorithm, MD5 algorithm, SHA1 algorithm, DES algorithm, AES algorithm or RSA algorithm. 4.An anti-injection system for Windows software, It is characterized in that The system comprises: A blacklist acquisition unit is used to acquire a data packet containing a dynamic link library DLL file, and parse the data packet to acquire a DLL module blacklist; The injection DLL module list determination unit is used to traverse each DLL module in the current process and determine the injection DLL module list according to each DLL module in the current process and the DLL module blacklist list; A thread matching unit, used for traversing thread module information corresponding to each thread in the current process, and matching the thread module information with the injection DLL module in the injection DLL module list, and when the match is consistent, stopping the thread corresponding to the thread module information; A window matching unit, used for traversing each window in the current process, matching the window with the stopped thread, and closing the window when the match is consistent; A release unit, used for traversing and releasing each injection DLL module in the injection DLL module list; The injection DLL module list determination unit determines the injection DLL module list according to each DLL module in the current process and the DLL module blacklist, including: Obtaining first characteristic information of each DLL module in the current process and second characteristic information of each DLL module in the DLL file blacklist; Matching the first characteristic information with the second characteristic information, and when the match succeeds, determining the DLL module corresponding to the first characteristic information as a target DLL module, and storing the target DLL module in the injection DLL module list; The characteristic information includes: the module name, base address and process environment information PEB structure of the DLL module.
5. The system according to claim 4, It is characterized in that The releasing unit releases each injection DLL module in the injection DLL module list through a remote thread.
6. The system according to claim 4, It is characterized in that The blacklist acquisition unit further includes: When the data packet containing the dynamic link library DLL file is an encrypted file, the data packet is decrypted according to a decryption algorithm corresponding to a preset encryption algorithm to obtain a plaintext file; Among them, the preset encryption algorithm is: SM2 national secret encryption algorithm, MD5 algorithm, SHA1 algorithm, DES algorithm, AES algorithm or RSA algorithm.
Citation Information
Patent Citations
Anti-injection method and device of message hook, and client side
CN106709331A
Anti-injection method and apparatus
CN106326735A
Protection method and device of application
CN106778234A