A Powershell Script Monitoring Method, Device, Electronic Device, Medium and Product

By setting hook function monitoring in the Powershell process and obtaining the target function data, the problem of incomplete detection in the existing technology is solved, and real-time dynamic detection and comprehensive security detection of Powershell scripts are realized.

CN114444071BActive Publication Date: 2025-07-25QI AN XIN TECHNOLOGY GROUP INC +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111452649.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-01
Publication Date
2025-07-25
Estimated Expiration
2041-12-01

AI Technical Summary

Technical Problem

In the prior art, the security detection method of the Powershell process mainly conducts detection from the perspective of static features and command line parameter analysis, resulting in insufficient detection and easy for attackers to bypass detection.

Method used

When the Powershell process loads a pre-specified target module, set hook functions for the loaded target module, monitor and obtain the data of the target function, and perform security detection based on the data, including noise filtering of the target function and threat behavior recognition.

Benefits of technology

Real-time dynamic detection of Powershell scripts is realized, which improves the accuracy and comprehensiveness of detection and improves security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114444071B_ABST
    Figure CN114444071B_ABST
Patent Text Reader

Abstract

The present invention provides a Powershell script monitoring method, apparatus, electronic device, medium and product. The method includes: monitoring the started Powershell process, setting a hook function for the loaded target module when the Powershell process loads a pre-specified target module, triggering the hook function when the Powershell process executes a Powershell script, so that the hook function monitors the call of a pre-specified target function, obtaining the data of the target function when the target function is called, and finally performing a security detection on the target function according to the data of the target function. The present invention can monitor in real time the information of the target function dynamically called by the Powershell script, ensure the accuracy and comprehensiveness of the detection, and improve the efficiency of Powershell script monitoring and processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security detection, and in particular to a method, device, electronic device, medium and product for monitoring Powershell scripts. Background Art

[0002] Powershell is a tool component built into the Windows system. It is a command-line script environment developed by Microsoft and running on the Windows operating system to realize the automation of system and application management. Command-line users and script writers can make full use of the powerful functions of the.NET Framework.

[0003] In most network attack cases in recent years, attackers can be seen frequently using PowerShell. Attackers can launch attacks through PowerShell without the need to rely on other third-party executable files, and can resist traditional antivirus software file detection. With good adaptability and flexibility, it can basically meet various attack scenarios, and it is extremely easy to code and obfuscate, and can bypass the detection of traditional antivirus software with only low-cost modification.

[0004] In the prior art, most antivirus software monitors the commands or scripts of the Powershell process running, and performs security detection from the perspectives of static features and command-line parameter parsing. There are still many defects and deficiencies, the detection is not comprehensive enough, and it is easy to be bypassed by attackers for detection and recognition. Summary of the Invention

[0005] The present invention provides a method, device, electronic device, medium and product for monitoring Powershell scripts, so as to solve the technical problem that in the prior art, monitoring the commands or scripts of the Powershell process running and performing security detection technology from the perspectives of static features and command-line parameter parsing results in insufficient comprehensive detection and easy bypass by attackers, so as to achieve the purpose of comprehensive detection, real-time dynamic detection, and improved detection efficiency.

[0006] In a first aspect, the present invention provides a method for monitoring Powershell scripts, including:

[0007] Monitoring the started Powershell process, and setting a hook function for the loaded target module when the Powershell process loads a pre-specified target module;

[0008] Triggering the hook function when the Powershell process executes a Powershell script, so that the hook function monitors the call of a pre-specified target function, and obtains the data of the target function when the target function is called.

[0009] Perform a security check on the objective function according to the data of the objective function.

[0010] Furthermore, according to the Powershell script monitoring method provided by the present invention, when the Powershell process loads a pre-specified target module, setting a hook function for the loaded target module includes:

[0011] Detect the type of the loaded module;

[0012] Determine whether the loaded module is any one of the following pre-specified modules: the clrjit module, the mscorjit module, and the System.Management.Automation module;

[0013] When the loaded module is any one of the pre-specified modules, determine the loaded module as the target module, determine a monitoring point in the target module, and set a hook function according to the monitoring point.

[0014] Furthermore, according to the Powershell script monitoring method provided by the present invention, determining a monitoring point in the target module and setting a hook function according to the monitoring point includes:

[0015] When the target module is the clrjit module or the mscorjit module, monitor the just-in-time compilation engine, obtain a first specified function that is just-in-time compiled at runtime, and set a hook function for the first specified function;

[0016] When the target module is the System.Management.Automation module, obtain a second specified function that has been pre-compiled, and set a hook function for the second specified function.

[0017] Furthermore, according to the Powershell script monitoring method provided by the present invention, the first specified function is the DynamicInstruction function or the MethodBase.Invoke function.

[0018] Furthermore, according to the Powershell script monitoring method provided by the present invention, the second specified function is any one of the following functions:

[0019] DynamicInstructionRun, DoComplete, and MethodInvokeDotNet.

[0020] Further, according to the Powershell script monitoring method provided by the present invention, triggering the hook function to monitor the call of a pre-specified target function by the hook function, and obtaining data of the target function when the target function is called, includes:

[0021] Trigger the hook function to monitor the call of any one of the following pre-specified target functions by the hook function: Powershell script function,.Net function, Cmdlet command, and Win32Api; and when the target function is called, obtain the function name and parameter data of the target function by parsing the.NET type data structure.

[0022] Further, according to the Powershell script monitoring method provided by the present invention, performing security detection on the target function according to the data of the target function includes:

[0023] Filter out noise points from the data of the target function.

[0024] Further, according to the Powershell script monitoring method provided by the present invention, performing security detection on the target function according to the data of the target function further includes:

[0025] Transmit the data of the target function after noise point filtering to the threat behavior recognition engine to obtain a security detection result.

[0026] Further, according to the Powershell script monitoring method provided by the present invention, performing security detection on the target function according to the data of the target function further includes:

[0027] Perform protection and interception on the target function according to the security detection result of the target function.

[0028] In a second aspect, the present invention also provides a Powershell script monitoring device, including:

[0029] A monitoring and setting module, configured to monitor a started Powershell process, and set a hook function for the loaded target module when the Powershell process loads a pre-specified target module;

[0030] A trigger module, configured to trigger the hook function when the Powershell process executes a Powershell script, so that the hook function monitors the call of a pre-specified target function, and obtains data of the target function when the target function is called;

[0031] A detection module for performing security detection on the objective function according to the data of the objective function.

[0032] In a third aspect, the present invention further provides an electronic device, including:

[0033] A processor, a memory, and a bus, wherein,

[0034] The processor and the memory complete communication with each other through the bus;

[0035] The memory stores program instructions executable by the processor, and the processor can execute the steps of the Powershell script monitoring method described in any one of the above by invoking the program instructions.

[0036] In a fourth aspect, the present invention further provides a non-transitory computer-readable storage medium, and the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions cause the computer to execute the steps of the Powershell script monitoring method described above.

[0037] In a fifth aspect, the present invention further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the Powershell script monitoring method described in any one of the above are implemented.

[0038] The present invention provides a Powershell script monitoring method, device, electronic device, medium, and product. The method includes: monitoring a started Powershell process, setting a hook function for a pre-specified target module when the Powershell process loads the target module, triggering the hook function when the Powershell process executes a Powershell script, so that the hook function monitors the call of a pre-specified objective function, and obtaining the data of the objective function when the objective function is called, and finally performing security detection on the objective function according to the data of the objective function. The Powershell script monitoring method provided by the present invention can monitor the information of the objective function dynamically called by the Powershell script in real time, ensure the accuracy and comprehensiveness of detection, and improve the efficiency of Powershell script monitoring and processing. Description of the Drawings

[0039] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0040] Figure 1 It is a schematic flowchart of a Powershell script monitoring method provided by the present invention;

[0041] Figure 2 It is a schematic overall flowchart of a Powershell script monitoring method provided by the present invention;

[0042] Figure 3 It is a schematic structural diagram of a Powershell script monitoring method device provided by the present invention;

[0043] Figure 4 It is a schematic structural diagram of an electronic device provided by the present invention. Specific embodiments

[0044] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without making creative efforts shall fall within the protection scope of the present invention.

[0045] Figure 1 It is a schematic flowchart of a Powershell script monitoring method provided by the present invention. As Figure 1 shown, the Powershell script monitoring method provided by the present invention includes the following steps:

[0046] Step 101: Monitor the started Powershell process. When the Powershell process loads a pre-specified target module, set a hook function for the loaded target module.

[0047] In this embodiment, when it is monitored that the Powershell process starts, a Powershell script dynamic monitoring engine module is installed into the process for monitoring the Powershell process. And the Powershell script dynamic monitoring engine module will monitor the loading of each target module in the Powershell process, such as the clrjit module, the mscorjit module, and the System.Management.Automation module, and set hook functions for each completed-loading target module.

[0048] It should be noted that the hook function is called the Hook function. Before the system calls the target function, the hook function can capture the target function call preferentially, obtain the control right of the target function, and perform additional processing on the target function.

[0049] Step 102: When the Powershell process executes the Powershell script, trigger the hook function so that the hook function monitors the call of a pre-specified target function, and when the target function is called, obtain the data of the target function.

[0050] In this embodiment, when the Powershell process executes the Powershell script, the hook function is triggered, enabling the hook function to monitor the call of a pre-specified target function. Moreover, when the target function is called, the relevant data of the target function is obtained for subsequent detection and processing.

[0051] It should be noted that in this embodiment, the target functions are divided into two categories. One is the target function that needs to be dynamically compiled into native code by monitoring the JIT type of engine module, and the other is the target function that has been compiled into native code by NGEN. The specific types are shown in the following embodiments and are not specifically limited here.

[0052] Step 103: Perform a security check on the target function according to the data of the target function.

[0053] In this embodiment, a security behavior check is performed on the target function according to the data of the target function obtained in step 102. It should be noted that cloud detection is used as one of the implementation methods for security behavior detection. The data of the obtained target function is sent to the cloud, where corresponding detection rules are set. Detection and matching are performed according to the set detection rules and the data of the target function obtained, and the security evaluation result is returned. Corresponding processing is performed according to the returned security evaluation result, such as protection interception or release.

[0054] For example, connect to a cloud security engine, send the data of the target function to the cloud, set certain whitelist detection rules in the cloud with corresponding parameter settings, match the data of the target function with the parameters in the whitelist detection rules. If the match is successful, it indicates that the behavior of calling the target function is a secure behavior, and the returned security evaluation result is security release; if the match fails, it indicates that the behavior of calling the target function is insecure, and the returned security evaluation result is insecure and enters security protection.

[0055] It should be noted that the data of the target function includes the name and parameter data of the target function. The specific details can be seen in the following embodiments and are not specifically limited here.

[0056] The present invention provides a Powershell script monitoring method. By monitoring the started Powershell process, when the Powershell process loads a pre-specified target module, a hook function is set for the loaded target module. When the Powershell process executes a Powershell script, the hook function is triggered, so that the hook function monitors the call of a pre-specified target function, and when the target function is called, the data of the target function is obtained. Finally, based on the data of the target function, a security detection is performed on the target function. The Powershell script monitoring method provided by the present invention can monitor in real time the information of the target function dynamically called by the Powershell script, improve the security protection and monitoring ability for malicious Powershell scripts, ensure the accuracy and comprehensiveness of detection, and improve the efficiency of Powershell script monitoring and processing.

[0057] In another embodiment of the present invention, the step of setting a hook function for the loaded target module when the Powershell process loads a pre-specified target module includes:

[0058] Detect the type of the loaded module;

[0059] Determine whether the loaded module is any one of the following pre-specified modules: the clrjit module, the mscorjit module, and the System.Management.Automation module;

[0060] When the loaded module is any one of the pre-specified modules, determine the loaded module as the target module, determine a monitoring point in the target module, and set a hook function according to the monitoring point.

[0061] In this embodiment, when the Powershell process loads a pre-specified target module, a hook function needs to be set for the loaded target module. Among them, first, the type of the loaded module is detected. When the loaded module belongs to any one of the three target modules of the pre-set clrjit module, mscorjit module, and System.Management.Automation module, a hook monitoring point is set for it, and a hook function is set.

[0062] It should be noted that both the clrjit module and the mscorjit module belong to the JIT engine module, while the System.Management.Automation module belongs to the engine module that obtains the target function compiled into native code by NGEN through the C# reflection method GetMethod. The Powershell script dynamic monitoring engine module will monitor the loading of the above three target modules of the Powershell process and preset Hook monitoring points.

[0063] According to the Powershell script monitoring method provided by the present invention, by detecting the type of the loaded module, when it is determined that the loaded module is any one of the three preset modules, namely the clrjit module, the mscorjit module, and the System.Management.Automation module, it is determined as the target module, and a monitoring point is set for it. A hook function is set at the monitoring point for real-time monitoring of the loading of the target module and the dynamic call situation of the Powershell script, providing support for the subsequent security behavior identification of the Powershell script based on the monitored target data.

[0064] In another embodiment of the present invention, determining a monitoring point in the target module and setting a hook function according to the monitoring point includes:

[0065] When the target module is the clrjit module or the mscorjit module, monitor the just-in-time compilation engine, obtain the first specified function that is just-in-time compiled at runtime, and set a hook function for the first specified function;

[0066] When the target module is the System.Management.Automation module, obtain the second specified function that has been pre-compiled and set a hook function for the second specified function.

[0067] In this embodiment, when the target module is the clrjit module or the mscorjit module, monitor the just-in-time compilation engine, obtain the first specified function that is just-in-time compiled at runtime, and set a hook function for the first specified function. Here, just-in-time compilation (JIT) is used to compile the converted language into a binary language for the CPU to execute. It should be noted that the first specified function refers to the target function that needs to be dynamically compiled discovered by monitoring the JIT engine, such as DynamicInstruction or MethodBase.Invoke, and then preset a hook function for the target function at runtime.

[0068] In this embodiment, when the target module is the System.Management.Automation module, obtain the pre-compiled second specified function and set a hook function for the second specified function. Here, pre-compiled means pre-compiled through NGEN (ngentest.exe). It should be noted that the second specified function refers to the target function that has been compiled into native code through NGEN obtained directly by using the C# reflection method GetMethod, such as DynamicInstructionRun, DoComplete, and MethodInvokeDotNet. Then, set a hook function for the obtained second specified function. The second specified function may also include functions other than the above three target functions, which can be specifically set according to the actual needs of the user and are not specifically limited here.

[0069] It should be noted that the Powershell process itself is built based on the Net Common Language Runtime (CLR - Common Language Runtime) and the.Net Framework. The Powershell process itself belongs to the.NET program module. There are two forms of target functions in the.NET program module. One is the target function compiled into native code through NGEN, and the other is the target function that needs to be JIT-compiled into native code during dynamic runtime. Moreover, for the two existing forms of target functions, two special preset hook function processing methods are required. As described above, it will not be elaborated here.

[0070] According to the Powershell script monitoring method provided by the present invention, different hook function setting methods need to be adopted for different target functions corresponding to two different target modules, which can ensure real-time monitoring of the call status of the target function and provide support for subsequent identification of the security behavior of the Powershell script based on the monitored target data.

[0071] In another embodiment of the present invention, the first specified function is the DynamicInstruction function or the MethodBase.Invoke function.

[0072] In this embodiment, the first specified function is the DynamicInstruction function or the MethodBase.Invoke function. Both functions belong to the target functions obtained through just-in-time compilation. By setting hook functions for the two target functions in the above embodiment, during the execution of the Powershell script, they will be triggered to enter the preset hook functions in the Powershell script dynamic monitoring engine module, and the preset hook functions will monitor the relevant information data of the first specified function in real time.

[0073] According to the Powershell script monitoring method provided by the present invention, when the first specified function is the DynamicInstruction function or the MethodBase.Invoke function, the call status of the target function can be monitored in real time, providing support for the subsequent identification of the security behavior of the Powershell script based on the monitored target data.

[0074] In another embodiment of the present invention, the second specified function is any one of the following functions:

[0075] DynamicInstructionRun, DoComplete, and MethodInvokeDotNet.

[0076] In this embodiment, the second specified function is any one of the preset DynamicInstructionRun, DoComplete, and MethodInvokeDotNet. When any one of the above three target functions is detected to be called, it is triggered to enter the preset hook function, and the specific situation of the target function being called is monitored in real time using the hook function.

[0077] According to the Powershell script monitoring method provided by the present invention, when the second specified function is any one of DynamicInstructionRun, DoComplete, and MethodInvokeDotNet, it is triggered to enter the preset hook function, ensuring that the call status of the target function can be monitored in real time, providing support for the subsequent identification of the security behavior of the Powershell script based on the monitored target data.

[0078] In another embodiment of the present invention, triggering the hook function to monitor the call of a pre-specified target function and, when the target function is called, obtaining the data of the target function includes:

[0079] Triggering the hook function to monitor the call of any one of the following pre-specified target functions: Powershell script function,.Net function, Cmdlet command, and Win32Api; and when the target function is called, obtaining the function name and parameter data of the target function by parsing the.NET type data structure.

[0080] In this embodiment, when the Powershell process runs a Powershell script, the process is triggered to enter a hook function preset in the Powershell script dynamic monitoring engine module. Through the preset hook function, the call situation of target functions in the Powershell script can be monitored, such as the call situation of Powershell script functions, .Net functions, Cmdlet commands, or Win32 APIs. Then, by parsing the .NET type data structure, the function name and parameter data of the function that calls the target function can be obtained.

[0081] For example, suppose a hook function is preset for the target function DynamicInstructionRun. DynamicInstructionRun is an execution template function in the Powershell process. For example, there are two functions in the Powershell script, namely "function name aaa(parameter 1, parameter 2)" and "function name bbb(parameter 1, parameter 2, parameter 3)". When the script executes to "function name aaa" or "function name bbb", it will enter the hook function preset for DynamicInstructionRun. Under normal circumstances, DynamicInstructionRun itself knows what function it is going to execute, how many parameters there are, and what the parameter data is, but the user doesn't know. The relevant information of the target function needs to be obtained through the preset hook function. For example, the specific function and function name executed by DynamicInstructionRun, the specific parameters and the corresponding parameter data. These information data of the target function are stored in the parameter data in the context at the moment when DynamicInstructionRun is called during the dynamic execution of the Powershell script and can be directly obtained from the preset hook function.

[0082] According to the Powershell script monitoring method provided by the present invention, by triggering the preset hook function, the hook function monitors the call of any one of the following pre-specified target functions: Powershell script functions, .Net functions, Cmdlet commands, and Win32 APIs; and in the case where the target function is called, the function name and parameter data of the target function are obtained by parsing the .NET type data structure, providing data support for subsequent security behavior identification based on the obtained data.

[0083] In another embodiment of the present invention, the security detection of the target function according to the data of the target function includes:

[0084] Filter the noise points from the data of the target function.

[0085] In this embodiment, it is necessary to input the obtained data of the target function into the noise filtering module for noise filtering. In this implementation, there are two processing methods for noise filtering. One is to match the obtained data of the target function with a preset whitelist. The functions in the whitelist are low-risk functions. If the match is successful, it passes safely and is directly filtered through. If the match is unsuccessful, the filtering fails and it cannot proceed to the next analysis and judgment. The other is to call the target function frequently. When the target function belongs to a frequently called target function, it is considered safe and the filtering passes. If it does not belong to a frequently called target function, the filtering does not pass, resulting in a failure of noise filtering. Among them, the frequently called target functions can be functions such as Write-Host, Split, Test-Path, etc., which can be specifically set according to actual needs and are not specifically limited here.

[0086] For example, assume that the threshold set for the frequently called target function is 20 times. The number of times target function 1 is called is obtained as 22 times, and the number of times target function 2 is called is 15 times. When the relevant data information of the two target functions is input into the noise filtering model, it is determined that the number of times target function 1 is called is greater than the preset threshold, and target function 1 is determined as a frequently called target function, and it is directly filtered through and enters the next analysis and processing; it is determined that the number of times target function 2 is called is less than the preset threshold, that is, target function 2 cannot be determined as a frequently called target function, and the filtering fails for it.

[0087] According to the Powershell script monitoring method provided by the present invention, by performing noise filtering processing on the data of the target function, it provides data support for subsequent security behavior identification based on the processed data, and ensures the accuracy of the security behavior identification result.

[0088] In another embodiment of the present invention, the security detection of the target function based on the data of the target function further includes:

[0089] Transmit the data of the target function after noise filtering to the threat behavior recognition engine to obtain a security detection result.

[0090] In this embodiment, it is also necessary to transmit the data of the target function after noise filtering to the threat behavior recognition engine for security behavior identification, and return the obtained security detection result. The threat behavior recognition engine in this embodiment belongs to a cloud security engine, and the obtained data of the target function will be sent to the cloud security engine. The cloud security engine will detect the obtained target function according to the set security detection rules, and the cloud security engine will also return the security behavior identification result.

[0091] According to the Powershell script monitoring method provided by the present invention, by transmitting the data of the target function after noise filtering to the threat behavior recognition engine, a security detection result is obtained, which ensures the accuracy of the security behavior identification result for subsequent determination of corresponding security protection measures based on the returned security detection result.

[0092] In another embodiment of the present invention, the security detection of the target function based on the data of the target function further includes:

[0093] Performing protection interception on the target function according to the security detection result of the target function.

[0094] In this embodiment, protection interception is performed on the target function according to the returned security detection result of the target function. There are two processing methods for protection interception in this embodiment. One is to directly terminate the Powershell process, and the other is to end the call process of the current target function. When it is detected that the target function is an insecure target function, either directly terminating the Powershell process or ending the call process of the current target function can be selected. The specific processing method can be set according to the actual needs of the user and is not specifically limited herein.

[0095] According to the Powershell script monitoring method provided by the present invention, by performing corresponding processing based on the security identification result of the target function, the security protection and monitoring ability for malicious Powershell scripts is improved, ensuring the accuracy and comprehensiveness of detection, and improving the efficiency of Powershell script monitoring and processing.

[0096] In another embodiment of the present invention, as Figure 2 shown, when it is monitored that the Powershell process starts, a Powershell script dynamic monitoring engine module is installed into the process. The Powershell script dynamic monitoring engine module will monitor the loading of the target module of the Powershell process in real time. The target module can be the clrjit module, or the mscorjit module, or the System.Management.Automation module, and preset hook functions for the target module that has been loaded.

[0097] It should be noted that the Powershell process itself is built on the Net Common Language Runtime (CLR) and the.Net Framework. The Powershell process itself belongs to the.NET program module. There are two forms of functions in the.NET program module. One is the target function compiled into native code by NGEN, and the other is the target function that needs to be JIT-compiled into native code at runtime. Moreover, there are two special processing logics for the preset hook functions of the Powershell target function. One is to monitor the JIT engine module in real time. When it is found that the target function that needs to be dynamically compiled is DynamicInstruction or MethodBase.Invoke, a preset monitoring point is set for its target function, and a hook function is preset at the monitoring point. The other is to directly use the C# reflection method GetMethod to obtain the target function compiled into native code by NGEN, such as the DynamicInstructionRun function, the DoComplete function, and the MethodInvokeDotNet function, etc., preset monitoring points, and set hook functions at the monitoring points.

[0098] In this embodiment, when the Powershell process executes the Powershell script, the process is triggered to enter the hook function preset by the Powershell script dynamic monitoring engine module. Through the preset hook function, the call conditions of the Powershell script functions, the.Net functions, the Cmdlet commands, or the Win32API called in the Powershell script can be monitored. Then, by parsing the.NET type data structure, the called function name and parameter data can be obtained, and the obtained target function name and parameter data are transmitted to the noise filtering model. The target function data is filtered by the noise filtering model. Among them, the noise filtering strategy can be in the form of a whitelist, or in the form of setting high-frequency call target functions, such as functions like Write-Host, Split, Test-Path, etc.

[0099] In this embodiment, it is also necessary to pass the data filtered by the noise filtering module to the threat behavior recognition engine for security identification and detection, and return the security detection result. Then, according to the security detection result, security protection and interception processing are performed. Among them, there are two forms of security protection and interception processing. One is to terminate the Powershell process, and the other is to intercept and terminate the current function call process.

[0100] Figure 3 A Powershell script monitoring device provided for an embodiment of the present invention, as Figure 3As shown in the figure, the Powershell script monitoring device provided by the embodiment of the present invention includes:

[0101] A monitoring and setting module 301, configured to monitor the started Powershell process, and set a hook function for the loaded target module when the Powershell process loads a pre-specified target module;

[0102] A trigger module 302, configured to trigger the hook function when the Powershell process executes a Powershell script, so that the hook function monitors the call of a pre-specified target function, and obtains the data of the target function when the target function is called;

[0103] A detection module 303, configured to perform a security detection on the target function according to the data of the target function.

[0104] The present invention provides a Powershell script monitoring device. By monitoring the started Powershell process, setting a hook function for the loaded target module when the Powershell process loads a pre-specified target module, triggering the hook function when the Powershell process executes a Powershell script, so that the hook function monitors the call of a pre-specified target function, and obtaining the data of the target function when the target function is called, and finally performing a security detection on the target function according to the data of the target function, it can monitor the information of the target function dynamically called by the Powershell script in real time, improve the security protection monitoring ability for malicious Powershell scripts, ensure the accuracy and comprehensiveness of the detection, and improve the efficiency of Powershell script monitoring and processing.

[0105] Furthermore, the monitoring and setting module 301 is further configured to:

[0106] Detect the type of the loaded module;

[0107] Determine whether the loaded module is any one of the following pre-specified modules: the clrjit module, the mscorjit module, and the System.Management.Automation module;

[0108] When the loaded module is any one of the pre-specified modules, determine the loaded module as the target module, determine a monitoring point in the target module, and set a hook function according to the monitoring point.

[0109] According to the Powershell script monitoring device provided by the present invention, by detecting the types of loaded modules, when it is determined that the loaded module is any one of the three preset modules, namely the clrjit module, the mscorjit module, and the System.Management.Automation module, it is determined as the target module, and monitoring points are set for it. Hook functions are set at the monitoring points to monitor the loading of the target module and the dynamic invocation of Powershell scripts in real time, providing support for the subsequent identification of the security behavior of Powershell scripts based on the monitored target data.

[0110] Furthermore, the monitoring and setting module 301 is further configured to:

[0111] When the target module is the clrjit module or the mscorjit module, monitor the just-in-time compilation engine, obtain the first specified function that is just-in-time compiled at runtime, and set a hook function for the first specified function;

[0112] When the target module is the System.Management.Automation module, obtain the second specified function that has been pre-compiled, and set a hook function for the second specified function.

[0113] According to the Powershell script monitoring device provided by the present invention, different hook function setting methods need to be adopted for different target functions corresponding to two different target modules, which can ensure the real-time monitoring of the call status of the target function and provide support for the subsequent identification of the security behavior of Powershell scripts based on the monitored target data.

[0114] Furthermore, in this embodiment, the first specified function is the DynamicInstruction function or the MethodBase.Invoke function.

[0115] According to the Powershell script monitoring device provided by the present invention, when the first specified function is the DynamicInstruction function or the MethodBase.Invoke function, it can ensure the real-time monitoring of the call status of the target function and provide support for the subsequent identification of the security behavior of Powershell scripts based on the monitored target data.

[0116] Furthermore, in this embodiment, the second specified function is any one of the following functions:

[0117] DynamicInstructionRun, DoComplete, and MethodInvokeDotNet.

[0118] According to the Powershell script monitoring device provided by the present invention, when the second specified function is any one of DynamicInstructionRun, DoComplete, and MethodInvokeDotNet, it triggers to enter a preset hook function, ensuring real-time monitoring of the call status of the target function, and providing support for subsequent identification of the security behavior of the Powershell script based on the monitored target data.

[0119] Furthermore, in this embodiment, the trigger module 302 is further configured to:

[0120] Trigger the hook function to monitor the call of any one of the following pre-specified target functions: Powershell script function,.Net function, Cmdlet command, and Win32Api; and when the target function is called, obtain the function name and parameter data of the target function by parsing the.NET type data structure.

[0121] According to the Powershell script monitoring device provided by the present invention, by triggering a preset hook function, the hook function is enabled to monitor the call of any one of the following pre-specified target functions: Powershell script function,.Net function, Cmdlet command, and Win32API; and when the target function is called, obtain the function name and parameter data of the target function by parsing the.NET type data structure, providing data support for subsequent identification of security behavior based on the obtained data.

[0122] Furthermore, the detection module 303 is further configured to:

[0123] Filter out noise from the data of the target function.

[0124] According to the Powershell script monitoring device provided by the present invention, by filtering out noise from the data of the target function, it provides data support for subsequent identification of security behavior based on the processed data, ensuring the accuracy of the security behavior identification result.

[0125] Furthermore, the detection module 303 is further configured to:

[0126] Transmit the data of the target function after noise filtering to the threat behavior recognition engine to obtain a security detection result.

[0127] According to the Powershell script monitoring device provided by the present invention, by transmitting the data of the target function after noise filtering to the threat behavior recognition engine, a security detection result is obtained, which ensures the accuracy of the security behavior identification result for subsequent determination of corresponding security protection measures based on the returned security detection result.

[0128] Furthermore, the detection module 303 is further configured to:

[0129] Perform protection interception on the target function according to the security detection result of the target function.

[0130] According to the Powershell script monitoring device provided by the present invention, by performing corresponding processing according to the security identification result of the target function, the security protection monitoring ability for malicious Powershell scripts is improved, ensuring the accuracy and comprehensiveness of detection, and improving the efficiency of Powershell script monitoring and processing.

[0131] Since the principle of the device in the embodiment of the present invention is the same as that of the method in the above embodiment, no more detailed explanation will be given here.

[0132] Figure 4 It is a schematic diagram of the entity structure of the electronic device provided in the embodiment of the present invention. As Figure 4 shown, the present invention provides an electronic device, including: a processor 401, a memory 402, and a bus 403;

[0133] Among them, the processor 401 and the memory 402 communicate with each other through the bus 403;

[0134] The processor 401 is configured to call program instructions in the memory 402 to execute the methods provided in the above method embodiments, for example, including: monitoring the started Powershell process, and setting a hook function for the loaded target module when the Powershell process loads a pre-specified target module; triggering the hook function when the Powershell process executes a Powershell script, so that the hook function monitors the call of a pre-specified target function, and obtains the data of the target function when the target function is called; performing security detection on the target function according to the data of the target function.

[0135] In an embodiment of the present invention, a non-transitory computer-readable storage medium is provided. The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions cause the computer to execute the methods provided in the above method embodiments. For example, it includes: monitoring the started Powershell process, and when the Powershell process loads a pre-specified target module, setting a hook function for the loaded target module; when the Powershell process executes a Powershell script, triggering the hook function so that the hook function monitors the call of a pre-specified target function, and when the target function is called, obtaining the data of the target function; performing a security detection on the target function according to the data of the target function.

[0136] The present invention also provides a computer program product. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the methods provided in the above embodiments. The method includes: monitoring the started Powershell process, and when the Powershell process loads a pre-specified target module, setting a hook function for the loaded target module; when the Powershell process executes a Powershell script, triggering the hook function so that the hook function monitors the call of a pre-specified target function, and when the target function is called, obtaining the data of the target function; performing a security detection on the target function according to the data of the target function.

[0137] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the foregoing storage medium includes various media such as ROM, RAM, magnetic disk, or optical disc that can store program codes.

[0138] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A Powershell script monitoring method, characterized in that, Including: Monitor the started Powershell process. When the Powershell process loads a pre-specified target module, set a hook function for the loaded target module; When the Powershell process executes a Powershell script, trigger the hook function so that the hook function monitors the call of a pre-specified target function, and when the target function is called, obtain the data of the target function; Perform a security check on the target function according to the data of the target function; The step of setting a hook function for the loaded target module when the Powershell process loads a pre-specified target module includes: Detect the type of the loaded module; Judge whether the loaded module is any one of the following pre-specified modules: clrjit module, mscorjit module, and System.Management.Automation module; When the loaded module is any one of the pre-specified modules, determine the loaded module as the target module, determine a monitoring point in the target module, and set a hook function according to the monitoring point; the step of determining a monitoring point in the target module and setting a hook function according to the monitoring point includes: When the target module is the clrjit module or the mscorjit module, monitor the just-in-time compilation engine, obtain the first specified function that is just-in-time compiled at runtime, and set a hook function for the first specified function; When the target module is the System.Management.Automation module, obtain the second specified function that has been pre-compiled, and set a hook function for the second specified function; The step of triggering the hook function so that the hook function monitors the call of a pre-specified target function and obtains the data of the target function when the target function is called includes: Trigger the hook function so that the hook function monitors the call of any one of the following pre-specified target functions: Powershell script function, .Net function, Cmdlet command, and Win32Api; and when the target function is called, obtain the function name and parameter data of the target function by parsing the .NET type data structure.

2. The Powershell script monitoring method according to claim 1, wherein The first specified function is the DynamicInstruction function or the MethodBase.Invoke function.

3. The Powershell script monitoring method according to claim 1, wherein The second specified function is any one of the following functions: DynamicInstructionRun, DoComplete, and MethodInvokeDotNet.

4. The Powershell script monitoring method according to claim 1, wherein The step of performing a security check on the target function according to the data of the target function includes: Filter out noise from the data of the target function.

5. The Powershell script monitoring method according to claim 4, characterized in that, Performing security detection on the objective function based on the data of the objective function further includes: Transmitting the data of the objective function after noise filtering to a threat behavior recognition engine to obtain a security detection result.

6. The Powershell script monitoring method according to claim 5, characterized in that, Performing security detection on the objective function based on the data of the objective function further includes: Performing protection interception on the objective function according to the security detection result of the objective function.

7. A Powershell script monitoring device, characterized in that, It includes: A monitoring and setting module for monitoring the started Powershell process and setting a hook function for the loaded target module when the Powershell process loads a pre-specified target module; A trigger module for triggering the hook function when the Powershell process executes a Powershell script, so that the hook function monitors the call of a pre-specified objective function and obtains the data of the objective function when the objective function is called; A detection module for performing security detection on the objective function according to the data of the objective function; The monitoring and setting module is further used for: Detecting the type of the loaded module; Judging whether the loaded module is any one of the following pre-specified modules: the clrjit module, the mscorjit module, and the System.Management.Automation module; When the loaded module is any one of the pre-specified modules, determining the loaded module as the target module, determining a monitoring point in the target module, and setting a hook function according to the monitoring point; The monitoring and setting module is further used for: When the target module is the clrjit module or the mscorjit module, monitoring the just-in-time compilation engine, obtaining a first specified function that is just-in-time compiled at runtime, and setting a hook function for the first specified function; When the target module is the System.Management.Automation module, obtaining a second specified function that has been pre-compiled and setting a hook function for the second specified function; The trigger module is further used for: Triggering the hook function so that the hook function monitors the call of any one of the following pre-specified objective functions: Powershell script functions,.Net functions, Cmdlet commands, and Win32Api; and when the objective function is called, obtaining the function name and parameter data of the objective function by parsing the.NET type data structure.

8. An electronic device, characterized in that, It includes: A processor, a memory, and a bus, where The processor and the memory communicate with each other through the bus; The memory stores program instructions executable by the processor, and the processor can execute the steps of the Powershell script monitoring method according to any one of claims 1 to 6 by calling the program instructions.

9. A computer program product, the computer program product comprising computer-executable instructions, characterized in that, The instructions, when executed, are used to implement the steps of the Powershell script monitoring method according to any one of claims 1 to 6.

10. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions that cause a computer to perform the steps of the Powershell script monitoring method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Detecting script-based malware

    US20190188384A1