Information detection method and device, electronic device and computer readable storage medium

By connecting with C&C and analyzing the call stack, the problems of false alarms and inaccurate detection of security threats in situational awareness technology are solved, and efficient and accurate identification and processing of security threats are achieved.

CN114491514BActive Publication Date: 2025-05-16BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210071830.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-21
Publication Date
2025-05-16
Estimated Expiration
2042-01-21

AI Technical Summary

Technical Problem

Existing situational awareness technologies may cause false positives when identifying and reporting security threats, and the detection based on beacon sets is not accurate enough, resulting in high cost and low efficiency in manual verification.

Method used

By responding to the terminal's network security alarm information, determine whether the terminal is in communication with known C&C, obtain relevant calling process and call stack information, poll whether there is a malicious call stack, and determine the handling operation based on the results.

Benefits of technology

It improves the accuracy of security threat detection, reduces manual detection costs, improves the reliability and maintenance efficiency of network security alarm information, and ensures the timely location and processing of effective detection results that are not false alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114491514B_ABST
    Figure CN114491514B_ABST
Patent Text Reader

Abstract

The present application proposes an information detection method and device, an electronic device and a computer-readable storage medium, the method comprising: in response to the network security alarm information of the terminal, determining whether the terminal is in communication with a known C&C; if the terminal is in communication with a known C&C, obtaining a call stack set related to multiple call processes initiating the communication and the startup relationship of multiple call processes in the terminal; polling the call stacks in the call stack set to see if there are malicious call stacks; and determining a handling operation for the network security alarm information according to whether there are malicious call stacks in the call stack set. The technical solution of the present application can effectively identify whether the network security alarm information is a false alarm, thereby improving network security.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present application relates to the field of network security technology, and in particular to an information detection method and device, an electronic device, and a computer-readable storage medium. [Background technology]

[0002] At present, situational awareness technology is often used to monitor network security to identify possible security threats. However, due to its own limitations, situational awareness technology may cause false positives when identifying and reporting security threats.

[0003] In this regard, in the relevant technology, the security threat is generally compared with the preset beacon set through manual verification. If the security threat exists in the preset beacon set, it means that the security threat is real and not a false alarm. However, the current network situation is complex and changeable, and the beacon set with limited content cannot completely cover all possible security threats. This makes the detection of whether the security threat is a false alarm based on the beacon set not accurate enough. At the same time, the manual detection of false alarms will consume a lot of manpower costs and affect the efficiency of network security maintenance.

[0004] Therefore, how to accurately and efficiently detect whether the current security threat is a false alarm has become a technical problem that needs to be solved urgently. [Summary of the invention]

[0005] The embodiments of the present application provide an information detection method and device, an electronic device, and a computer-readable storage medium, which aim to solve the technical problem in the related art that it is impossible to effectively identify whether the security threat detected based on situational awareness technology is a false alarm.

[0006] In a first aspect, an embodiment of the present application provides an information detection method, including: in response to network security alarm information of a terminal, determining whether the terminal is in communication with a known C&C; if the terminal is in communication with the known C&C, obtaining a call stack set related to multiple call processes initiating the communication in the terminal and a startup relationship of the multiple call processes; polling the call stacks in the call stack set to see whether there are malicious call stacks according to the order of call stacks reflected by the startup relationship of the multiple call processes; and determining a handling operation for the network security alarm information based on whether there are malicious call stacks in the call stack set.

[0007] In the above embodiment of the present application, optionally, determining whether the terminal is in communication with a known C&C includes: detecting whether a current pointer in a control inversion container of the terminal matches an invaded pointer in a virus database; if the current pointer matches the invaded pointer, determining that the terminal is in communication with the known C&C corresponding to the invaded pointer.

[0008] In the above embodiment of the present application, optionally, the polling of the call stacks in the call stack set to determine whether there is a malicious call stack includes: for any call stack in the call stack set, if the file name of the running file in the call stack matches the preset file name in the script execution capability file name library, determining that the call stack is a malicious call stack.

[0009] In the above embodiment of the present application, optionally, the polling of the call stacks in the call stack set to determine whether there are malicious call stacks also includes: if the file name of the running file in the call stack does not match the preset file name in the script execution capability file name library, determining whether the call stack has a digital certificate signature; if the call stack has a digital certificate signature, detecting whether the digital certificate signature matches the revocation signature in the certificate revocation database, wherein if the digital certificate signature matches the revocation signature, determining that the call stack is a malicious call stack; if the call stack does not have a digital certificate signature, determining that the call stack is not a malicious call stack.

[0010] In the above embodiment of the present application, optionally, the polling of the call stacks in the call stack set to determine whether there is a malicious call stack also includes: if the digital certificate signature does not match the revocation signature, detecting whether the issuer of the digital certificate signature is a trusted object; when the issuer of the digital certificate signature is a trusted object, determining that the call stack is not a malicious call stack; when the issuer of the digital certificate signature is not a trusted object, if the running file matches the trusted file in the trusted file hash library, determining that the call stack is not a malicious call stack, otherwise, determining that the call stack is a malicious call stack.

[0011] In the above embodiment of the present application, optionally, it also includes: when it is determined that the network security alarm information is valid, generating first report information for the network security alarm information, the first report information includes a call stack set related to multiple calling processes that initiated the communication and the first malicious call stack polled.

[0012] In the above embodiment of the present application, optionally, it also includes: when it is determined that the network security alarm information is valid, generating second report information for the network security alarm information, the second report information including: the startup relationship and command line of the calling process to which the first malicious call stack belongs; and / or memory dump information for the calling process to which the first malicious call stack belongs.

[0013] In the second aspect, an embodiment of the present application provides an information detection device, including: a C&C communication judgment unit, used to determine whether the terminal is in communication with a known C&C in response to the network security alarm information of the terminal; a call stack information acquisition unit, used to obtain a call stack set related to multiple call processes that initiated the communication in the terminal and the startup relationship of the multiple call processes if the terminal is in communication with the known C&C; a call stack polling unit, used to poll the call stacks in the call stack set to see whether there are malicious call stacks according to the call stack sequence reflected by the startup relationship of the multiple call processes; a polling detection unit, used to determine the handling operation for the network security alarm information based on whether there are malicious call stacks in the call stack set.

[0014] In the above embodiment of the present application, optionally, the C&C communication judgment unit is used to: detect whether the current pointer in the control inversion container of the terminal matches the invaded pointer in the virus database; if the current pointer matches the invaded pointer, determine the known C&C communication between the terminal and the invaded pointer.

[0015] In the above embodiment of the present application, optionally, the call stack polling unit is used to: for any call stack in the call stack set, if the file name of the running file in the call stack matches the preset file name in the script execution capability file name library, determine that the call stack is a malicious call stack.

[0016] In the above embodiment of the present application, optionally, the call stack polling unit is also used to: if the file name of the running file in the call stack does not match the preset file name in the script execution capability file name library, determine whether the call stack has a digital certificate signature; if the call stack has a digital certificate signature, detect whether the digital certificate signature matches the revocation signature in the certificate revocation database, wherein if the digital certificate signature matches the revocation signature, determine that the call stack is a malicious call stack; if the call stack does not have a digital certificate signature, determine that the call stack is not a malicious call stack.

[0017] In the above embodiment of the present application, optionally, the call stack polling unit is also used to: if the digital certificate signature does not match the revocation signature, detect whether the issuer of the digital certificate signature is a trusted object; when the issuer of the digital certificate signature is a trusted object, determine that the call stack is not a malicious call stack; when the issuer of the digital certificate signature is not a trusted object, if the running file matches the trusted file in the trusted file hash library, determine that the call stack is not a malicious call stack, otherwise, determine that the call stack is a malicious call stack.

[0018] In the above embodiment of the present application, optionally, it also includes: a first report information generating unit, which is used to generate first report information for the network security alarm information when it is determined that the network security alarm information is valid, and the first report information includes a call stack set related to multiple calling processes that initiated the communication and the first malicious call stack polled.

[0019] In the above embodiment of the present application, optionally, it also includes: a second report information generating unit, which is used to generate second report information for the network security alarm information when it is determined that the network security alarm information is valid, and the second report information includes: the startup relationship and command line of the calling process to which the first malicious call stack belongs; and / or memory dump information for the calling process to which the first malicious call stack belongs.

[0020] In a third aspect, an embodiment of the present application provides an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are configured to execute any of the methods described in the first aspect above.

[0021] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute the method flow described in any one of the first aspects above.

[0022] The above technical solution addresses the technical problem that related technologies cannot effectively identify whether the security threats detected based on situational awareness technology are false alarms. It can avoid the problem of inaccurate network security detection results caused by the limitations of the network security detection method itself, save manual detection costs, improve the reliability of network security alarm information and network security maintenance efficiency, facilitate timely positioning and processing of threat content for effective detection results that are not false alarms, and improve network security.

Brief Description of the Drawings

[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0024] Figure 1 A flow chart of an information detection method according to an embodiment of the present application is shown;

[0025] Figure 2 A block diagram of an information detection device according to an embodiment of the present application is shown;

[0026] Figure 3 A block diagram of an electronic device according to an embodiment of the present application is shown. [Specific implementation method]

[0027] In order to better understand the technical solution of the present application, the embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0028] It should be clear that the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without creative work are within the scope of protection of the present application.

[0029] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. The singular forms "a", "said" and "the" used in the embodiments of the present application and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.

[0030] Figure 1 A flow chart of an information detection method according to an embodiment of the present application is shown.

[0031] like Figure 1 As shown, the process of the information detection method according to an embodiment of the present application includes:

[0032] Step 102: In response to the network security alarm information of the terminal, determine whether the terminal is in communication with a known C&C.

[0033] The network security alarm information of the terminal includes, but is not limited to, the security threats faced by the terminal predicted by situational awareness technology, and may also be the security threats faced by the terminal detected by any means other than situational awareness technology.

[0034] C&C (Command & Control Server), also known as CNC, refers to the main control server that commands and controls the botnet. The C&C server mentioned in the context is the same concept as C&C and will not be described in detail later. Generally, after malware infects a terminal, the C&C server can send instructions to it by communicating with the instance of the malware to drive it to work. Specifically, if a terminal is infected with malware, the instance of the malware can communicate with an external C&C server, and the C&C server directs the malware's attack behavior and attack activities. During this communication process, the C&C server directs the malware's attack behavior and attack activities, including but not limited to uploading information stolen from the terminal to the C&C server and periodically encrypting and extorting files sent to the terminal. In this regard, when the terminal's network security alarm information is detected through network security detection methods including but not limited to situational awareness technology, it can be determined whether the network security alarm information is caused by the above-mentioned C&C communication method.

[0035] Specifically, it can be detected whether the current pointer in the control inversion container of the terminal matches the invaded pointer in the virus database; if the current pointer matches the invaded pointer, it is determined that the terminal is in communication with the known C&C corresponding to the invaded pointer.

[0036] The terminal's Inversion of Control (IoC) container is used to couple objects in the software that controls the terminal as a third party. It uses pointers to store variables such as memory addresses and file types involved. When malware infects a terminal, it often invades the pointer in the terminal's IoC container and replaces it with the invaded pointer used for C&C communication.

[0037] On this basis, a virus database can be set up to store various known malware and known C&C communication-related invaded pointers in the virus database. Further, if it is detected that the current pointer in the control reversal container of the terminal matches the invaded pointer in the virus database, it means that the current pointer has been invaded by malware and converted by the malware into an invaded pointer for C&C communication. Thus, the known C&C communication between the terminal and the invaded pointer can be determined.

[0038] Next, we will check whether the terminal's network security alarm information is a false alarm based on the situation where the terminal is communicating with a known C&C.

[0039] Step 104: If the terminal is in communication with the known C&C, a call stack set related to multiple call processes initiating the communication and a start relationship of the multiple call processes in the terminal are obtained.

[0040] The communication between the terminal and the known C&C usually needs to call multiple calling processes, and these calling processes have a sequential start relationship in the logical order. At the same time, the calling process can store the return address and subroutine variables through the corresponding call stack, and pass parameter information and environment information through the corresponding call stack. Therefore, the call stack corresponding to the calling process can reflect the specific work information such as the calling function involved in the calling process. In other words, the security of the call stack can reflect the security of the calling process to a certain extent. If the call stack is a malicious call stack, the corresponding calling process is a malicious process. On the contrary, if the call stack is a safe call stack, the corresponding calling process is a safe process.

[0041] Step 106: poll the call stacks in the call stack set to see whether there are any malicious call stacks according to the call stack sequence reflected by the startup relationship of the multiple calling processes.

[0042] Step 108: Determine a handling operation for the network security warning information according to whether there is a malicious call stack in the call stack set.

[0043] Among them, if there is a malicious call stack in the call stack set, it can be determined that the network security alarm information is not a false alarm, and if there is no malicious call stack in the call stack set, it can be determined that the network security alarm information is a false alarm.

[0044] Specifically, the processing operations for the network security alarm information specifically include: when any call stack polled is found to be a malicious call stack, or when all call stacks in the call stack set are not malicious call stacks, terminating the polling, wherein, if any call stack polled is found to be a malicious call stack, determining that the network security alarm information is valid; if all call stacks in the call stack set are not malicious call stacks, determining that the network security alarm information is invalid.

[0045] Since the terminal often needs to call multiple call processes to communicate with the known C&C, multiple call stacks are involved. In this regard, the call stack sequence reflected by the startup relationship of the multiple call processes can be used to detect whether each call stack is a malicious call stack.

[0046] During the detection process, once any call stack is polled as a malicious call stack, it means that there is a malicious call process in the process of communication between the terminal and the known C&C, and the terminal's network security alarm information is valid and not a false alarm. At this time, the polling can be terminated directly and the detection result that it is not a false alarm can be output.

[0047] If all the call stacks polled are not malicious call stacks, it means that all the call processes in the process of communication between the terminal and the known C&C are not malicious, and the network security alarm information of the terminal is inaccurate and is a false alarm.

[0048] The above technical solution can automatically detect the accuracy of the terminal's network security alarm information and identify whether it is a false alarm when the terminal communicates with a known C&C. In this way, it can avoid the problem of inaccurate network security detection results caused by the inherent limitations of the network security detection method, save manual detection costs, improve the reliability of network security alarm information and network security maintenance efficiency, facilitate timely positioning and processing of threat content for effective detection results that are not false alarms, and improve network security.

[0049] On the basis of the above technical solution, according to an information detection method of another embodiment of the present application, for any call stack in the call stack set, the process of detecting whether it is a malicious call stack includes:

[0050] Step 202, for any call stack in the call stack set, determine whether the file name of the running file in the call stack matches the preset file name in the script execution capability file name library, and when the judgment result is yes, proceed to step 212, otherwise, proceed to step 204.

[0051] The script execution capability file name library records the file names of files with script execution capability, such as CMD, EXE and other executable external scripts. If the file name of the running file in the call stack matches the preset file name in the script execution capability file name library, it means that the running file in the call stack can be executed by the external script and there is a risk of being controlled by the external script. Therefore, the call stack can be judged as a malicious call stack.

[0052] If the file name of the running file in the call stack does not match the preset file name in the script execution capability file name library, the security of the call stack is further judged by whether it has a digital certificate signature.

[0053] Step 204 , determining whether the call stack has a digital certificate signature, if the call stack has a digital certificate signature, proceeding to step 206 , if the call stack does not have a digital certificate signature, proceeding to step 214 .

[0054] The digital certificate signature is a unique string identifier set by an external publisher for the call stack. If the call stack does not have a digital certificate signature, it means that it is not in communication with the external publisher and does not have the risk of being infected by malware. Therefore, it can be determined that the call stack is not a malicious call stack.

[0055] On the contrary, if the call stack has a digital certificate signature, it means that it is in communication with an external publisher and may be at risk of being infected by malware. Therefore, the security of the call stack can be determined by further judging the security of its digital certificate signature.

[0056] Step 206, detect whether the digital certificate signature matches the revocation signature in the certificate revocation database. If the digital certificate signature matches the revocation signature, proceed to step 212; if the digital certificate signature does not match the revocation signature, proceed to step 208.

[0057] The certificate revocation database is used to record certificates that have been revoked by issuers, that is, to record certificates with security risks. If the digital certificate signature of the call stack matches the revocation signature in the certificate revocation database, it means that the digital certificate signature of the call stack has security risks and is at risk of being infected by malware. At this time, the call stack can be determined to be a malicious call stack.

[0058] On the contrary, if the digital certificate signature of the call stack does not match the revocation signature in the certificate revocation database, it means that the digital certificate signature of the call stack is reliable, but the security of the call stack cannot be guaranteed. At this time, the security of the call stack can be further determined by verifying the security of the issuer of the digital certificate signature.

[0059] Step 208, detect whether the issuer of the digital certificate signature is a trusted object. When the issuer of the digital certificate signature is a trusted object, proceed to step 214; when the issuer of the digital certificate signature is not a trusted object, proceed to step 210.

[0060] In this regard, a whitelist can be established for trusted certificates. If the issuer of the digital certificate signature is in the whitelist, it is a trusted object, and the digital certificate signature provided by the trusted object can be directly identified as safe. At this time, it can be determined that the call stack is not a malicious call stack. On the contrary, if the issuer of the digital certificate signature is not in the whitelist, it is an untrusted object. At this time, other conditions need to be used to further determine the security of the call stack.

[0061] Step 210, determining whether the running file matches the trusted file in the trusted file hash library. If the running file matches the trusted file in the trusted file hash library, proceed to step 214; otherwise, proceed to step 212.

[0062] The trusted file hash library records the hash values ​​of trusted executable files without digital signatures. If the hash value of the running file of the call stack matches the hash value of the trusted file in the trusted file hash library, it means that the running file of the call stack is a trusted file, and the call stack is not a malicious call stack. On the contrary, if the hash value of the running file of the call stack does not match the hash value of the trusted file in the trusted file hash library, it means that the running file of the call stack is not a trusted file, and the call stack has the risk of malware infection and is a malicious call stack.

[0063] Step 212: determine that the call stack is a malicious call stack.

[0064] Step 214: Determine whether the call stack is a malicious call stack.

[0065] The above technical solution can determine the reliability of any call stack by verifying whether the running file in the call stack can be executed by an external script, whether it has a digital certificate signature, whether the digital certificate signature is reliable, whether the issuer of the digital certificate signature is trustworthy, whether the running file is a trustworthy file, etc. When the call stack is determined to be a malicious call stack or a non-malicious call stack in any dimension, the result is directly output without making any judgments in other dimensions.

[0066] Therefore, the security of the call stack can be accurately judged in multiple dimensions and efficiently based on the basic information of the running files in the call stack, which improves the efficiency and accuracy of false alarm identification.

[0067] Finally, when it is determined that the network security alarm information is valid, a first report information is generated for the network security alarm information, wherein the first report information includes a call stack set related to multiple call processes that initiate the communication and the first malicious call stack polled.

[0068] That is, the call stack set corresponding to multiple call processes involved in the terminal's communication with the known C&C and the first malicious call stack polled can be reported, so as to determine the call process used by the malware to infect the terminal, which is convenient for locating and processing the infection location and infection situation.

[0069] Optionally, when it is determined that the network security alarm information is valid, a second report information is generated for the network security alarm information, and the second report information includes: the startup relationship and command line of the calling process to which the first malicious call stack belongs; and / or memory dump information for the calling process to which the first malicious call stack belongs. The startup relationship of the calling process reflects the association between the calling process and other processes, and the command line is an identifier that prompts for command input, reflecting the controlled status of the calling process. Therefore, reporting the startup relationship and command line of the calling process to which the first malicious call stack is polled facilitates unified security verification and threat location of the calling process involved in the malware-infected terminal and its other associated processes, which helps to improve network security.

[0070] The memory dump information of the calling process to which the first malicious call stack belongs reflects the specific running information of the calling process. By reporting the memory dump information, it is convenient to take effective network security maintenance measures according to the specific running information of the calling process.

[0071] In summary, the problem of inaccurate network security detection results caused by the inherent limitations of network security detection methods can be avoided, manual detection costs can be saved, the reliability of network security alarm information and network security maintenance efficiency can be improved, and it is convenient to timely locate and process threat content for effective detection results that are not false positives, thereby improving network security.

[0072] Figure 2 A block diagram of an information detection device according to an embodiment of the present application is shown.

[0073] like Figure 2 As shown, according to an embodiment of the present application, an information detection device 200 includes: a C&C communication judgment unit 202, which is used to determine whether the terminal is in communication with a known C&C in response to the network security alarm information of the terminal; a call stack information acquisition unit 204, which is used to obtain a call stack set related to multiple call processes that initiate the communication in the terminal and the startup relationship of the multiple call processes if the terminal is in communication with the known C&C; a call stack polling unit 206, which is used to poll the call stacks in the call stack set to see whether there are malicious call stacks according to the call stack sequence reflected by the startup relationship of the multiple call processes; and a polling detection unit 208, which is used to determine the handling operation for the network security alarm information according to whether there are malicious call stacks in the call stack set.

[0074] In the above embodiment of the present application, optionally, the C&C communication judgment unit 202 is used to: detect whether the current pointer in the control inversion container of the terminal matches the invaded pointer in the virus database; if the current pointer matches the invaded pointer, determine the known C&C communication between the terminal and the invaded pointer.

[0075] In the above embodiment of the present application, optionally, the call stack polling unit 206 is used to: for any call stack in the call stack set, if the file name of the running file in the call stack matches the preset file name in the script execution capability file name library, determine that the call stack is a malicious call stack.

[0076] In the above embodiment of the present application, optionally, the call stack polling unit 206 is also used to: if the file name of the running file in the call stack does not match the preset file name in the script execution capability file name library, determine whether the call stack has a digital certificate signature; if the call stack has a digital certificate signature, detect whether the digital certificate signature matches the revocation signature in the certificate revocation database, wherein if the digital certificate signature matches the revocation signature, determine that the call stack is a malicious call stack; if the call stack does not have a digital certificate signature, determine that the call stack is not a malicious call stack.

[0077] In the above embodiment of the present application, optionally, the call stack polling unit 206 is also used to: if the digital certificate signature does not match the revocation signature, detect whether the issuer of the digital certificate signature is a trusted object; when the issuer of the digital certificate signature is a trusted object, determine that the call stack is not a malicious call stack; when the issuer of the digital certificate signature is not a trusted object, if the running file matches the trusted file in the trusted file hash library, determine that the call stack is not a malicious call stack, otherwise, determine that the call stack is a malicious call stack.

[0078] In the above embodiment of the present application, optionally, it also includes: a first report information generating unit, which is used to generate first report information for the network security alarm information when it is determined that the network security alarm information is valid, and the first report information includes a call stack set related to multiple calling processes that initiated the communication and the first malicious call stack polled.

[0079] In the above embodiment of the present application, optionally, it also includes: a second report information generating unit, which is used to generate second report information for the network security alarm information when it is determined that the network security alarm information is valid, and the second report information includes: the startup relationship and command line of the calling process to which the first malicious call stack belongs; and / or memory dump information for the calling process to which the first malicious call stack belongs.

[0080] The information detection device 200 uses any of the solutions described in the above embodiments, and therefore has all the above technical effects, which will not be described in detail here.

[0081] Figure 3 A block diagram of an electronic device according to an embodiment of the present application is shown.

[0082] like Figure 3 As shown, an electronic device 300 of an embodiment of the present application includes at least one memory 302; and a processor 304 in communication with the at least one memory 302; wherein the memory stores instructions executable by the at least one processor 304, and the instructions are configured to execute the solution described in any of the above embodiments. Therefore, the electronic device 300 has the same technical effects as any of the above embodiments, which will not be described in detail here.

[0083] The electronic devices of the embodiments of the present application exist in various forms, including but not limited to:

[0084] (1) Mobile communication devices: These devices are characterized by their mobile communication functions and their main purpose is to provide voice and data communications. These terminals include: smart phones (such as iPhone), multimedia phones, functional phones, and low-end phones.

[0085] (2) Ultra-mobile personal computer devices: These devices fall into the category of personal computers, have computing and processing capabilities, and generally also have mobile Internet access features. These terminals include: PDA, MID and UMPC devices, such as iPad.

[0086] (3) Portable entertainment devices: These devices can display and play multimedia content. They include audio and video players (such as iPods), handheld game consoles, e-books, as well as smart toys and portable car navigation devices.

[0087] (4) Server: A device that provides computing services. The server consists of a processor, hard disk, memory, system bus, etc. The server is similar to a general computer architecture, but because it needs to provide highly reliable services, it has higher requirements in terms of processing power, stability, reliability, security, scalability, and manageability.

[0088] (5) Other electronic devices with data interaction functions.

[0089] In addition, an embodiment of the present application provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute the method flow described in any of the above embodiments.

[0090] The above, in combination with the accompanying drawings, describes in detail the technical solution of the present application. Through the technical solution of the present application, the problem of inaccurate network security detection results caused by the inherent limitations of the network security detection method can be avoided, the cost of manual detection can be saved, the reliability of network security alarm information and the efficiency of network security maintenance can be improved, and it is convenient to timely locate and process threat content for effective detection results that are not false alarms, thereby improving network security.

[0091] It should be understood that the term "and / or" used in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.

[0092] The word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)", depending on the context.

[0093] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0094] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of hardware plus software functional units.

[0095] The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer-readable storage medium. The above-mentioned software functional unit is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor (Processor) to perform some steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), disk or optical disk and other media that can store program codes.

[0096] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. An information detection method, characterized in that: include: In response to the network security warning information of the terminal, determining whether the terminal is in communication with a known C&C; If the terminal is in communication with the known C&C, obtaining a call stack set related to multiple call processes initiating the communication in the terminal and a start relationship of the multiple call processes; According to the call stack sequence reflected by the startup relationship of the multiple calling processes, polling the call stacks in the call stack set to see whether there are malicious call stacks; Polling the call stacks in the call stack set to see whether there are malicious call stacks includes: For any call stack in the call stack set, if the file name of the running file in the call stack matches the preset file name in the script execution capability file name library, determine that the call stack is a malicious call stack; if the file name of the running file in the call stack does not match the preset file name in the script execution capability file name library, determine whether the call stack has a digital certificate signature; If the call stack has a digital certificate signature, detecting whether the digital certificate signature matches a revocation signature in a certificate revocation database, wherein if the digital certificate signature matches the revocation signature, determining that the call stack is a malicious call stack; if the call stack does not have a digital certificate signature, determining that the call stack is not a malicious call stack; According to whether there is a malicious call stack in the call stack set, a handling operation for the network security warning information is determined.

2. The information detection method according to claim 1, characterized in that: The determining whether the terminal is in communication with a known C&C includes: Detecting whether a current pointer in a control reversal container of the terminal matches an invaded pointer in a virus database; If the current pointer matches the invaded pointer, it is determined that the terminal is in communication with the known C&C corresponding to the invaded pointer.

3. The information detection method according to claim 1, characterized in that: The polling of the call stacks in the call stack set to determine whether there are malicious call stacks further includes: If the digital certificate signature does not match the revocation signature, detecting whether the issuer of the digital certificate signature is a trusted object; When the issuer of the digital certificate signature is a trusted object, determining that the call stack is not a malicious call stack; When the issuer of the digital certificate signature is not a trusted object, if the running file matches the trusted file in the trusted file hash library, it is determined that the call stack is not a malicious call stack, otherwise, it is determined that the call stack is a malicious call stack.

4. The information detection method according to claim 1, characterized in that: Also includes: When it is determined that the network security alarm information is valid, first report information is generated for the network security alarm information, wherein the first report information includes a call stack set related to multiple call processes that initiate the communication and a first malicious call stack polled.

5. The information detection method according to claim 4, characterized in that: Also includes: When it is determined that the network security alarm information is valid, generating second report information for the network security alarm information, the second report information including: a startup relationship and a command line of a calling process to which the first malicious call stack belongs; And / or memory dump information of the calling process to which the first malicious call stack belongs.

6. An information detection device, characterized in that: include: A C&C communication determination unit, configured to determine whether the terminal is in communication with a known C&C in response to network security warning information of the terminal; A call stack information acquisition unit, configured to acquire, if the terminal is in communication with the known C&C, a call stack set related to multiple call processes initiating the communication in the terminal and a startup relationship of the multiple call processes; A call stack polling unit, configured to poll the call stacks in the call stack set to determine whether there are malicious call stacks according to the call stack sequence reflected by the startup relationship of the multiple calling processes; Polling the call stacks in the call stack set to see whether there are malicious call stacks includes: For any call stack in the call stack set, if the file name of the running file in the call stack matches the preset file name in the script execution capability file name library, determine that the call stack is a malicious call stack; if the file name of the running file in the call stack does not match the preset file name in the script execution capability file name library, determine whether the call stack has a digital certificate signature; If the call stack has a digital certificate signature, detecting whether the digital certificate signature matches a revocation signature in a certificate revocation database, wherein if the digital certificate signature matches the revocation signature, determining that the call stack is a malicious call stack; if the call stack does not have a digital certificate signature, determining that the call stack is not a malicious call stack; The polling detection unit is used to determine a handling operation for the network security warning information according to whether there is a malicious call stack in the call stack set.

7. An electronic device, characterized in that: include: at least one processor; and, a memory communicatively coupled to the at least one processor; The memory stores instructions executable by the at least one processor, and the instructions are configured to execute the method according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that: Computer executable instructions are stored, and the computer executable instructions are used to execute the method process according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Network security detection method, terminal and network security equipment

    CN111786964A