Method, apparatus, electronic device and medium for detecting web trojans
By performing lexical analysis of web page files and reverse tracking and searching of related variables, the problem that web page Trojan detection is easily bypassed is solved, and efficient and accurate web page Trojan detection is achieved, reducing the probability of detection failure and the risk of sandbox escape.
Patent Information
- Application Number
- CN202011468408.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-14
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2040-12-14
AI Technical Summary
In the prior art, web page Trojan detection is easily bypassed by attackers through deformation, feature detection affects the efficiency of the network server, and behavior detection is easily bypassed by sandboxes, resulting in security risks and detection failures.
By performing lexical analysis of the target web page file, dividing it into a sequence of morpheme units, and performing reverse tracking and searching of the associated variables for specific morpheme units containing dangerous function calls, determining whether there are specific associated variables containing external input data in the associated variables, and determining whether the web page file is a web Trojan.
It realizes accurate detection of various deformation forms of web Trojans without intruding into the user process, reducing the probability of detection failure, avoiding the risk of sandbox escape, and improving detection efficiency.
Smart Images

Figure CN114626061B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network security technology, and more particularly, to a method, apparatus, electronic device, and medium for detecting web trojans. Background Art
[0002] A web shell is a backdoor left by an attacker in a web server using a scripting language. Essentially, a web shell is a web file that is ostensibly disguised as an ordinary web file or has malicious code directly inserted into a normal web file. When a user accesses the web file, it will automatically download the configured server side of the trojan to the visitor's computer and execute it automatically by taking advantage of vulnerabilities in the other party's system or browser.
[0003] In the process of implementing the concept of the present disclosure, the inventors found that there are at least the following problems in the prior art: Currently, the detection of web trojans can be divided into two categories: signature detection and behavior detection. The defect of signature detection is that it is easy for attackers to bypass by deforming the content of the trojan. Behavior detection generally requires installing plugins in the protected host web server to intercept attacks or executing in a virtual machine. Installing plugins in the protected host web server to intercept attacks will affect the running efficiency and stability of the web server, and the method of executing in a virtual machine is easily bypassed by attackers' sandbox, resulting in greater harm. Summary of the Invention
[0004] In view of this, the present disclosure provides a method, apparatus, electronic device, and medium for detecting web trojans.
[0005] The first aspect of the present disclosure provides a method for detecting web trojans. The method includes: performing lexical analysis on the target web file to be detected to split the target web file into a sequence of morpheme units. The method further includes: performing reverse tracing and searching for associated variables of specific morpheme units containing dangerous function calls in the sequence of morpheme units to determine whether there is a specific associated variable containing external input data in the associated variables, where the dangerous function is a special function that can execute system commands or interpret and execute code. The method further includes: if there is a specific associated variable containing external input data, determining that the target web file is a web trojan.
[0006] According to an embodiment of the present disclosure, performing lexical analysis on the target web file to be detected to split the target web file into a sequence of morpheme units includes: determining the programming language type of the target web file to be detected; and performing lexical analysis on the target web file according to the programming language type of the target web file to split the source code of the scripting language of the target web file into a sequence of morpheme units.
[0007] According to an embodiment of the present disclosure, perform reverse tracing search of associated variables for a specific morpheme unit containing a dangerous function call in a morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables, including: determining a specific morpheme unit in the morpheme unit sequence, where the specific morpheme unit is a morpheme unit containing a dangerous function call; determining a target variable participating in the dangerous function call in the specific morpheme unit; searching for the associated variable of the target variable in the previous unit of the specific morpheme unit; recursively searching for all associated variables; and determining whether there is a specific associated variable containing external input data in all associated variables.
[0008] According to an embodiment of the present disclosure, perform lexical analysis on the detected target web page file, including: if there is annotation content in the target web page file, store the annotation content, and perform lexical analysis on the target web page file after removing the annotation content. Perform reverse tracing search of associated variables for a specific morpheme unit containing a dangerous function call in the morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables, including: if there is a variable for reflecting and obtaining annotations in the associated variables, reload the stored annotation content; and perform lexical analysis and processing on the reloaded annotation content to determine whether the annotation content contains external input data.
[0009] According to an embodiment of the present disclosure, perform reverse tracing search of associated variables for a specific morpheme unit containing a dangerous function call in the morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables, including: if there are string-related operation functions in the morpheme unit sequence, simulate the execution of the operation functions and string concatenation operations to generate a concatenated string; determine whether the concatenated string contains a dangerous function, where the dangerous function is at least one of the following functions: eval function, assert function, passthru function, exec function, proc_open function, shellexec function, and system function; if the concatenated string contains a dangerous function, determine the morpheme unit containing the dangerous function as the specific morpheme unit; and perform reverse tracing search of associated variables for the specific morpheme unit to determine whether there is a specific associated variable containing external input data in the associated variables.
[0010] According to an embodiment of the present disclosure, perform reverse tracing search of associated variables for a specific morpheme unit containing a dangerous function call in a morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables, including: if there is a user-defined function in the morpheme unit sequence, reassign values to the internal variables of the user-defined function based on the passed parameters each time the user-defined function is called, and reverse trace the associated variables of the user-defined function to determine whether there is a specific associated variable containing external input data in the associated variables.
[0011] According to an embodiment of the present disclosure, perform reverse tracing search of associated variables for a specific morpheme unit containing a dangerous function call in a morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables, including: if there is a deserialization function in the morpheme unit sequence, perform reverse tracing and splicing on the variables passed to the deserialization function to determine whether there is a user-defined class; if there is a user-defined class in the morpheme unit sequence, trace and search for magic functions for processing the user-defined class at the time of creation and deletion to determine whether the magic functions contain external input data.
[0012] According to an embodiment of the present disclosure, perform reverse tracing search of associated variables for a specific morpheme unit containing a dangerous function call in a morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables, including: if there is a callback function in the morpheme unit sequence, perform reverse tracing processing on the callback function respectively according to the passed form of the callback function to determine whether there is a specific associated variable containing external input data in the associated variables of the callback function.
[0013] According to an embodiment of the present disclosure, perform reverse tracing search of associated variables for a specific morpheme unit containing a dangerous function call in a morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables, including: if there is a dynamic variable function in the morpheme unit sequence, extract the variables of the dynamic variable function and perform reverse tracing on the variables of the dynamic variable function to determine whether the source of the variables of the dynamic variable function is external input data.
[0014] According to an embodiment of the present disclosure, perform reverse tracing search of associated variables for a specific morpheme unit containing a dangerous function call in a morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables, including: if there is a file inclusion class function in the morpheme unit sequence, perform reverse tracing search according to the associated files included in the file inclusion class function to determine whether the associated files contain external input data.
[0015] The second aspect of the present disclosure provides a device for detecting web page trojans. The above-mentioned device includes: a lexical analysis module, a reverse tracing module, and a web page file determination module. The lexical analysis module is used to perform lexical analysis on the target web page file to be detected, so as to split the target web page file into a sequence of morpheme units. The reverse tracing module is used to perform reverse tracing and search for associated variables of specific morpheme units containing dangerous function calls in the sequence of morpheme units, so as to determine whether there is a specific associated variable containing external input data in the associated variables. The dangerous function is a special function that can execute system commands or interpret and execute code. The web page file determination module is used to determine that the target web page file is a web page trojan when there is a specific associated variable containing external input data.
[0016] The third aspect of the present disclosure provides an electronic device. The above-mentioned electronic device includes: one or more processors; and a storage device for storing one or more programs. Wherein, when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement any of the methods described above.
[0017] The fourth aspect of the present disclosure provides a computer-readable storage medium. An executable instruction is stored on the above-mentioned computer-readable storage medium, and when the instruction is executed by a processor, the processor is caused to implement any of the methods described above.
[0018] The fifth aspect of the present disclosure provides a computer program product. The above-mentioned computer program product includes computer-executable instructions, which are used to implement any of the methods described above after being executed.
[0019] According to the embodiments of the present disclosure, by performing lexical analysis on the target web page file to split the target web page file into a sequence of morpheme units, each morpheme unit and its execution sequence can be accurately obtained. Reverse tracing is performed on specific morpheme units containing dangerous function calls in the sequence of morpheme units, and all associated variables are recursively searched. By determining whether the associated variables contain external input data, it is determined whether the target web page file is a web page trojan. No matter what form of deformation the attacker makes to the file content of the web page trojan, the execution logic of the trojan cannot be changed. In this way, various deformed forms of web page trojans can be found. Without invading the user process, a good web page trojan detection effect can be achieved, and the probability of detection failure caused by the attacker's deformation of the file content of the web page trojan can be greatly reduced. At the same time, the security risk of sandbox escape caused by actually executing the script file in the sandbox is avoided, and the detection efficiency is higher. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, the above and other objects, features, and advantages of the present disclosure will become clearer. In the drawings:
[0021] Figure 1 Schematically shows the system architecture of the method for detecting web trojans according to an embodiment of the present disclosure;
[0022] Figure 2 Schematically shows the flowchart of the method for detecting web trojans according to an embodiment of the present disclosure;
[0023] Figure 3 Schematically shows the detailed implementation flowchart of operation S11 according to an embodiment of the present disclosure;
[0024] Figure 4 Schematically shows the detailed implementation flowchart of operation S12 according to an embodiment of the present disclosure;
[0025] Figure 5 Schematically shows the structural block diagram of the device for detecting web trojans according to an embodiment of the present disclosure;
[0026] Figure 6 Schematically shows the structural block diagram of the reverse tracing module according to an embodiment of the present disclosure; and
[0027] Figure 7 Schematically shows the structural block diagram of the electronic device according to an embodiment of the present disclosure. Detailed implementation manners
[0028] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure. However, obviously, one or more embodiments can be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily obscuring the concepts of the present disclosure.
[0029] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0030] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0031] In the case of using expressions such as "at least one of A, B, and C, etc.", generally, it should be interpreted according to the meaning that those skilled in the art usually understand this expression (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.). In the case of using expressions such as "at least one of A, B, or C, etc.", generally, it should be interpreted according to the meaning that those skilled in the art usually understand this expression (for example, "a system having at least one of A, B, or C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).
[0032] Embodiments of the present disclosure provide a method, device, electronic device, and medium for detecting web trojans. In the above method for detecting web trojans, lexical analysis is performed on the target web page file to be detected to segment the target web page file into a sequence of morpheme units. Then, reverse tracing and searching for associated variables are performed on specific morpheme units containing dangerous function calls in the sequence of morpheme units to determine whether there are specific associated variables containing external input data among the associated variables. The above dangerous function is a special function that can execute system commands or interpret and execute code. If there are specific associated variables containing external input data, it is determined that the target web page file is a web trojan.
[0033] Figure 1 Schematically shows the system architecture of the method for detecting web trojans according to an embodiment of the present disclosure. It should be noted that, Figure 1 The shown is only an example of the system architecture to which the embodiments of the present disclosure can be applied to help those skilled in the art understand the technical content of the present disclosure, but it does not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments, or scenarios.
[0034] Referring to Figure 1 As shown, the system architecture 1 according to this embodiment may include a terminal device 10, a network 11, and a server 12. The network 11 is used to provide a medium for a communication link between the terminal device 10 and the server 12. The network 11 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0035] A user can use the terminal device 10 to interact with the server 12 through the network 11 to receive or send web page content or information, etc. Various communication client applications may be installed on the terminal device 10, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).
[0036] The terminal device 10 can be various electronic devices with a display screen and supporting web browsing. For example, the terminal device is Figure 1 the exemplified smart phone 101, tablet computer 102 or notebook computer 103 shown, or other types of electronic devices such as a desktop computer, smart watch, etc.
[0037] The server 12 can be a server providing various services. For example, it can be a background management server (only for example) that supports the websites browsed by the user using the terminal device 10. The background management server can analyze and process data such as user requests received, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal device.
[0038] It should be noted that the method for detecting web page Trojans provided by the embodiments of the present disclosure can generally be executed by the terminal device 10. Correspondingly, the device for detecting web page Trojans provided by the embodiments of the present disclosure can generally be set in the terminal device 10. It should be understood that Figure 1 the numbers of the terminal devices, networks, and servers in
[0039] The first exemplary embodiment of the present disclosure provides a method for detecting web page Trojans. This method can detect a target web page file among multiple web page files.
[0040] Figure 2 Schematically shows a flowchart of the method for detecting web page Trojans according to the embodiments of the present disclosure.
[0041] Referring to Figure 2 shown, the method for detecting web page Trojans in this embodiment includes the following operations: S11, S12, and S13a.
[0042] In operation S11, perform lexical analysis on the detected target web page file to split the target web page file into a sequence of morpheme units.
[0043] In operation S12, perform reverse tracing search for associated variables of specific morpheme units containing dangerous function calls in the morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables. The above-mentioned dangerous functions are special functional functions that can execute system commands or interpret and execute code.
[0044] In operation S13a, if there is a specific associated variable containing external input data, determine that the target web page file is a web page Trojan.
[0045] Referring to Figure 2As shown, the above method further includes operation S13b. If there is no specific associated variable containing external input data in the associated variables, it is determined that the target web page file is a normal file.
[0046] In the above embodiment, by performing lexical analysis on the target web page file and splitting the target web page file into a sequence of morpheme units, each morpheme unit and its execution sequence can be accurately obtained. Reverse tracing is performed on the specific morpheme units containing dangerous function calls in the morpheme unit sequence, and all associated variables are recursively searched. By determining whether the associated variables contain external input data, it is determined whether the target web page file is a web trojan. No matter what form of deformation the attacker makes to the file content of the web trojan, the execution logic of the trojan cannot be changed. In this way, various deformed forms of web trojans can be detected. Without invading the user process, a good web trojan detection effect can be achieved, and the probability of detection failure caused by the attacker's deformation of the file content of the web trojan can be greatly reduced. At the same time, the security risk of sandbox escape caused by actually executing the script file in the sandbox is avoided, and the detection efficiency is higher.
[0047] Figure 3 Schematically shows a detailed implementation flowchart of operation S11 according to an embodiment of the present disclosure.
[0048] According to an embodiment of the present disclosure, the operation of performing lexical analysis on the detected target web page file to split the target web page file into a sequence of morpheme units includes the following sub-operations: S111 and S112.
[0049] In sub-operation S111, determine the programming language type of the detected target web page file.
[0050] In sub-operation S112, perform lexical analysis on the target web page file according to the programming language type of the target web page file to split the source code of the script language of the target web page file into a sequence of morpheme units.
[0051] The programming language type of the target web page file includes, but is not limited to, one of the following languages: Hypertext Preprocessor (PHP), Java, JSP, ASP, JavaScript, VBScript, Python, etc.
[0052] The lexical analysis of the target web page file is performed in different ways according to the language type of the target web page file, so that the source code of the script language of the target web page file can be segmented into a sequence of morpheme units. In the present disclosure, the existing lexical analysis methods can be used for the lexical analysis of the target web page files of different language types. For example, the above sub-operation S112 can be implemented by a lexical analyzer, and the lexical analyzer can be constructed by re2c. re2c represents a processor / processing method for converting a regular expression into the form of C language or C++ code.
[0053] For example, after performing lexical analysis on the target web page file of PHP type, the source code of the script language is segmented into multiple string units arranged in a specific order. In the present disclosure, the units obtained after segmenting the source code of the script language of various language types are collectively referred to as morpheme (token) units.
[0054] In the related art, in the PHP language, individual independent morpheme units cannot fully express semantics. It is necessary to go through the syntax analysis / parsing stage to convert the token units into an abstract syntax tree (AST), and then the abstract syntax tree is converted into machine instructions for execution. In the web trojan detection method of the present disclosure, only the lexical analysis of the target web page file is required, and the source code of the script language of the target web page file is segmented into morpheme units, without further syntax parsing to obtain an abstract syntax tree. Therefore, the performance consumption of the execution system can be reduced. The execution system is, for example, a terminal device that needs to load the target web page file. Before the terminal device loads the target web page file, the target web page file is pre-detected based on the above web trojan detection method, and the target web page file is loaded only when it is determined that the target web page file is a normal file.
[0055] Figure 4 A detailed flowchart of operation S12 according to an embodiment of the present disclosure is schematically shown.
[0056] According to an embodiment of the present disclosure, referring to Figure 4 As shown, the operation S12 of backward tracing and searching for associated variables of specific morpheme units containing dangerous function calls in the morpheme unit sequence and determining whether there are specific associated variables containing external input data in the associated variables includes the following sub-operations: S121, S122, S123, S124, and S125.
[0057] In sub-operation S121, a specific morpheme unit is determined in the morpheme unit sequence, and the specific morpheme unit is a morpheme unit containing a dangerous function call.
[0058] The dangerous functions are special functional functions that can execute system commands or interpret and execute code. For example, including but not limited to the following functions: eval function, system function, passthru function, exec function, proc_open function, shellexec function, or assert function, etc.
[0059] In sub-operation S122, determine the target variable involved in the dangerous function call in the specific morpheme unit.
[0060] In sub-operation S123, search for the associated variable of the target variable in the previous unit of the specific morpheme unit.
[0061] In sub-operation S124, recursively search for all associated variables.
[0062] In sub-operation S125, determine whether there is a specific associated variable containing external input data among all the associated variables.
[0063] Exemplarily, in an instance, for example, the script language source code of the target web page file is in the following form:
[0064]
[0065] After performing lexical analysis on the above target web page file and splitting the script language source code of the target web page file into a sequence of morpheme units, a sequence of morpheme units in the following form is obtained:
[0066]
[0067]
[0068] Among them, each line represents a morpheme unit or a morpheme statement. In each morpheme unit / each morpheme statement, the morpheme (token) is in the front and the parameter is in the back.
[0069] In the sequence of morpheme units, there are morphemes with various functions, such as: morphemes for function calls, morphemes for assignments, etc. A specific morpheme unit is obtained by searching for the morpheme that calls the dangerous function in the morpheme for function calls.
[0070] In the present disclosure, an associated variable is a variable associated with a target variable, and this association is reflected in the variables that participate in the process of executing a dangerous function call in the above-mentioned target web page file. That is, the associated variable is the variable that participates in the operation of executing the dangerous function call for the target variable. For example, in the above-mentioned sequence of morpheme units obtained by lexical analysis of the target web page file, the specific morpheme unit containing a dangerous function call is determined to be: INCLUDE_OR_EVAL!1. After EVAL, the target variable participating in the call of the dangerous function EVAL is obtained as:!1. And the associated variables involved in the process of the target variable!1 executing the dangerous function call are recursively searched as follows: the associated variable of the target variable!1 is: $5, the associated variable of $5 is: $3, the associated variable of $3 is: $2, and the associated variable of $2 is: _GET. Thus, all associated variables can be recursively found.
[0071] Specifically, to implement the above sub-operation S121, search for the specific morpheme unit containing a dangerous function call in the above-mentioned sequence of morpheme units, and INCLUDE_OR_EVAL!1, EVAL can be found. Then, sub-operation S122 can be implemented to obtain the target variable participating in the dangerous function call in the specific morpheme units INCLUDE_OR_EVAL!1, EVAL as:!1.
[0072] Then, implement sub-operation S123 to search for the associated variable of the target variable in the previous units of this morpheme unit INCLUDE_OR_EVAL!1, EVAL. That is, search for the morpheme units containing the target variable!1 and the variables related to the target variable!1 in all the morpheme units before INCLUDE_OR_EVAL!1, EVAL. For example, in this example, the target variable!1 can be found in the statement ASSIGN!1, $5. And the statements before this morpheme unit ASSIGN!1, $5 are DO_ICALL$5, SEND_VAR!0, and INIT_FCALL 'base64_decode'. Further before is the parameter assignment statement ASSIGN!0, $3 of base64_decode. SEND_VAR!0 is to pass the variable!0 with the value of $3 to the base64_decode function. Thus, the associated variable $3 of the target variable is found in the previous units. Then, by analogy, implement sub-operation S124 to recursively search for all associated variables, and then find the associated variable $2 of $3. Finally, it is found that $2 comes from _GET. Implement sub-operation S125 to determine whether there is a specific associated variable containing external input data among all the associated variables. After determination, _GET is external input data, or is called a user input variable. Thus, it can be determined that this target web page file is a web trojan.
[0073] The above example is the simplest example of finding associated variables. The target web page file to be searched is sequential and branchless. In fact, the method for detecting web page trojans based on the present disclosure is applicable to detecting target web page files with complex structural forms such as some conditional branches, function calls, class calls, etc. When searching, it is necessary to search for all possible executed morpheme units in front of the specific morpheme unit containing a dangerous function call.
[0074] External input data includes: query string data (QUERYSTRING), POST data, or user client authentication information data (COOKIE data), etc.
[0075] After creating an http request, methods such as GET, POST, UPDATE, DELETE, etc., and the URL address of the request will be specified. For POST, the data is placed in the message body, but there is no regulation on what encoding must be used, and the user can decide the format of the message body by themselves. When submitting data via POST, it generally involves two parts: the content type (Content-Type) and the message body encoding method.
[0076] In the above operation S12, the sequence of morpheme units can include structural forms with different contents, such as at least one of the following: strings, functions, classes, etc. The definition of a class includes the form of data and the operations on the data. The class can be a user-defined class.
[0077] Functions can be functions of various forms and types. For example, they can be user-defined functions, or magic functions for processing classes, including constructor functions, destructor functions, and _invoke functions, etc. The function / function of the _invoke function is: when attempting to call an object in the way of calling a function, the _invoke function method will be automatically called. It can also be a callback function. The callback function is, for example, one of the following functions: array_map function, usort function, array_filter function, register_shutdown_function function, etc. It can also be a dynamic variable function, such as $a($b).
[0078] The reverse tracing method adopted in the present disclosure is different from the traditional taint tracing method. It analyzes the sources of all associated variables one by one from the back to the front in the order of program execution logic by using the sequence of morpheme units generated after lexical analysis. And it is not necessary to make taint marks on the input parameter variables themselves, thus avoiding the risk of marking failure in some special cases. If external input data can be found in the associated variables after reverse tracing, it proves that the target web page file is a web page trojan. If all associated variables do not come from HTTP input, the target web page file is a normal file.
[0079] An exemplary description is given below in the way of backward tracing for a sequence of morpheme units with different structural forms of content.
[0080] According to an embodiment of the present disclosure, the lexical analysis of the detected target web page file includes: if there is annotation content in the target web page file, the annotation content is stored, and lexical analysis is performed on the target web page file after removing the annotation content.
[0081] Correspondingly, the operation S12 of backward tracing to find associated variables for specific morpheme units containing dangerous function calls in the sequence of morpheme units to determine whether there is a specific associated variable containing external input data in the associated variables includes: if there is a variable for reflecting and obtaining annotations in the associated variables, the stored annotation content is reloaded; and lexical analysis and processing are performed on the reloaded annotation content to determine whether the annotation content contains external input data.
[0082] In the PHP language, variables for reflecting and obtaining annotations are, for example, in the following variable form: ReflectionClass::getDocComment.
[0083] In the PHP language, ReflectionClass::getDocComment can be used to obtain the annotation content in the source file of the scripting language and pass it into a dangerous function, resulting in dangerous behavior. Therefore, when there is a variable for reflecting and obtaining annotations in the associated variables, the annotation content removed during the process of lexical analysis and segmentation to obtain the sequence of morpheme units in operation S11 is reloaded; and lexical analysis and processing are performed on the reloaded annotation content to determine whether the annotation content contains external input data. This way avoids the risk caused by the bypass detection of the document annotation content.
[0084] According to an embodiment of the present disclosure, the operation S12 of backward tracing and searching for associated variables of specific morpheme units containing dangerous function calls in the morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is an operation function related to strings in the morpheme unit sequence, simulate the execution of the operation function and the string concatenation operation to generate the concatenated string. Then, determine whether the concatenated string contains a dangerous function. The dangerous function is at least one of the following functions: eval function, assert function, passthru function, exec function, proc_open function, shellexec function, and system function. If the concatenated string contains a dangerous function, determine the morpheme unit containing the dangerous function as a specific morpheme unit. Then, perform backward tracing and searching for associated variables of the specific morpheme unit to determine whether there is a specific associated variable containing external input data in the associated variables.
[0085] The evel function executes the string as PHP code. Since the evel function allows the execution of arbitrary PHP code, strings generated from externally input data provided by users without complete verification may pose potential risks.
[0086] The assert function is an assertion function that checks the specified assertion and takes appropriate actions when the result is FALSE. This function should only be used for debugging.
[0087] Functions such as system, passthru, exec, proc_open, and shellexec execute external programs and display the output. If the external command execution is successful, it returns the last line of the command output; if the execution fails, it returns FALSE.
[0088] In this embodiment, the operation functions related to strings include at least one of the following functions: str_replace, strtr, str_rot13, base64_decode, and chr.
[0089] The str_replace function means replacing some other characters in a string with a string. The form of the str_replace function is: str_replace(find, replace, string) or str_replace(find, replace, string, count), where find represents the value to be searched for, replace represents the value to replace the find value, string represents the string to be searched, and count is an optional parameter in the above str_replace function, and count represents a variable for counting the number of replacements.
[0090] The strtr function represents converting specific characters in a string. The forms of the strtr function are: strtr(string, from, to) or strtr(string, array). If the lengths of the from and to parameters are different, they are formatted to the shortest length. string represents the string to be converted. from represents the characters to be changed. to represents the characters to be changed into. array represents an array where the key names are the original characters and the key values are the target characters.
[0091] The str_rot13 function represents performing ROT13 encoding on a string. ROT13 encoding is obtained by moving each letter 13 letters forward in the alphabet, and numbers and non-alphabetic characters remain unchanged.
[0092] The base64_decode function represents decoding data encoded using MIME base64. The base64_encode function represents encoding a string using MIME base64.
[0093] The chr function represents returning a character from a specified ASCII value. The ASCII value can be specified as a decimal value, an octal value, or a hexadecimal value. Octal values are defined with a leading 0, and hexadecimal values are defined with a leading 0x.
[0094] The function of string concatenation can be achieved by string concatenation operators. Exemplarily, in PHP, the string concatenation operator "." or the assignment operator ".=" can be used for string concatenation.
[0095] Simulate the execution of the above string-related operation functions and operations such as string concatenation to generate the concatenated string.
[0096] The eval function, assert function, passthru function, exec function, proc_open function, shellexec function, and system function are examples of dangerous functions. Any special function that can execute system commands or interpret and execute code is within the scope of protection of dangerous functions.
[0097] According to an embodiment of the present disclosure, the operation S12 of performing reverse tracing search of associated variables on a specific morpheme unit containing a dangerous function call in a morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is a user-defined function in the morpheme unit sequence, when each user-defined function is called, the internal variables of the user-defined function are reassigned based on the passed parameters, and the associated variables of the user-defined function are traced backward to determine whether there is a specific associated variable containing external input data in the associated variables. In addition, the above operation S12 further includes an extraction processing operation on anonymous functions to determine whether there is external input data in the anonymous functions.
[0098] According to an embodiment of the present disclosure, the operation S12 of performing reverse tracing search of associated variables on a specific morpheme unit containing a dangerous function call in a morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is a deserialization function in the morpheme unit sequence, the variables passed to the deserialization function are traced backward and concatenated to determine whether there is a user-defined class; If there is a user-defined class in the morpheme unit sequence, the magic functions for processing the user-defined class are traced and searched at the time of creation (new) and deletion to determine whether the magic functions contain external input data.
[0099] The serialize function encodes variables and their values into a text form, that is, it produces a representable value for storage. The unserialize function operates on a single serialized variable and converts it back to a PHP value. By tracing backward and concatenating the variables passed to the unserialize function, the class name of the user-defined class can be determined.
[0100] If there is a user-defined class in the morpheme unit sequence, based on lexical analysis, each user-defined class can be decomposed into a morpheme unit sequence, and the member variables are extracted and saved separately. Since magic functions for processing classes, such as constructor functions, destructor functions, and _invoke functions, etc., do not have explicit calls, the present disclosure traces and searches for magic functions at the time of creation (new) and deletion to avoid risks caused by implicit calls to magic functions. In this way, when a magic function is called while processing a user-defined class, the magic function can be traced to determine whether the magic function contains external input data, thereby improving the accuracy of Trojan detection.
[0101] According to an embodiment of the present disclosure, the operation of performing reverse tracing search of associated variables on a specific morpheme unit containing a dangerous function call in a morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is a callback function in the morpheme unit sequence, perform reverse tracing processing on the callback function respectively according to the passing form of the callback function to determine whether there is a specific associated variable containing external input data in the associated variables of the callback function.
[0102] The callback function is, for example, one of the following functions: array_map function, usort function, array_filter function, register_shutdown_function function, etc. The passing methods of the callback functions are different. Some callback functions are passed in the form of function variables, and the function names of some callback functions are passed in the form of strings. It is necessary to perform targeted reverse tracing processing according to the different passing forms of the callback functions to prevent the problem of detection failure caused by the splicing of function variables and strings.
[0103] According to an embodiment of the present disclosure, the operation of performing reverse tracing search of associated variables on a specific morpheme unit containing a dangerous function call in a morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is a dynamic variable function in the morpheme unit sequence, extract the variables of the dynamic variable function and perform reverse tracing on the variables of the dynamic variable function to determine whether the source of the variables of the dynamic variable function is external input data.
[0104] By tracing the source of the variables of the dynamic variable function, various forms of potential Trojan risks can be identified.
[0105] According to an embodiment of the present disclosure, the operation of performing reverse tracing search of associated variables on a specific morpheme unit containing a dangerous function call in a morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is a file inclusion function in the morpheme unit sequence, perform reverse tracing search according to the associated file included in the file inclusion function to determine whether the associated file contains external input data.
[0106] The file inclusion function is, for example: include function or require function. By performing reverse tracing search on the associated file included in the file inclusion function, for example, the associated file can be found on the disk, and then it can be determined whether the associated file contains external input data.
[0107] Based on the above exemplary introduction of operation S12, it can be seen that no matter what form of transformation the attacker performs on the file content of the web trojan, the execution logic of the trojan cannot be changed. In this way, web trojans in various transformed forms can all be found through reverse tracing. Without invading the user process, a good detection effect for web trojans can be achieved, and the probability of detection failure caused by the attacker's transformation of the file content of the web trojan can be greatly reduced. At the same time, the security risk of sandbox escape caused by actually executing the script file in the sandbox is avoided, and the detection efficiency is higher.
[0108] The second exemplary embodiment of the present disclosure provides a device for detecting web trojans.
[0109] Figure 5 A schematic block diagram of a device for detecting web trojans according to an embodiment of the present disclosure is shown.
[0110] Referring to Figure 5 As shown, the device 2 for detecting web trojans in this embodiment includes: a lexical analysis module 21, a reverse tracing module 22, and a web page file determination module 23.
[0111] The lexical analysis module 21 is used to perform lexical analysis on the target web page file to segment the target web page file into a sequence of morpheme units.
[0112] The reverse tracing module 22 is used to perform reverse tracing and search for associated variables of specific morpheme units containing dangerous function calls in the sequence of morpheme units to determine whether there is a specific associated variable containing external input data in the associated variables. The dangerous function is a special function that can execute system commands or interpret and execute code.
[0113] The web page file determination module 23 is used to determine that the target web page file is a web trojan when there is a specific associated variable containing external input data.
[0114] Figure 6 A schematic block diagram of the reverse tracing module according to an embodiment of the present disclosure is shown.
[0115] Referring to Figure 6 As shown, the above reverse tracing module 22 includes the following sub-modules: a specific morpheme unit determination sub-module 221, a target variable determination sub-module 222, and an associated variable search sub-module 223.
[0116] The specific morpheme unit determination sub-module 221 is used to determine specific morpheme units in the sequence of morpheme units. The specific morpheme units are morpheme units containing dangerous function calls.
[0117] The target variable determination sub-module 222 is used to determine target variables participating in dangerous function calls in specific morpheme units.
[0118] The associated variable lookup sub-module 223 is configured to look up the associated variables of the target variable in the preceding units of a specific morpheme unit, recursively look up all the associated variables, and determine whether there is a specific associated variable that includes external input data among all the associated variables.
[0119] According to embodiments of the present disclosure, any plurality of modules, sub-modules, units, and sub-units, or at least some functions of any of them may be implemented in one module. Any one or more of the modules, sub-modules, units, and sub-units according to embodiments of the present disclosure may be split into multiple modules for implementation. Any one or more of the modules, sub-modules, units, and sub-units according to embodiments of the present disclosure may be at least partially implemented as a hardware circuit, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or may be implemented by any other reasonable way of integrating or packaging circuits, or implemented by hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in a suitable combination of any several of them. Alternatively, one or more of the modules, sub-modules, units, and sub-units according to embodiments of the present disclosure may be at least partially implemented as a computer program module, and when the computer program module is run, it can execute the corresponding functions.
[0120] For example, any plurality of the lexical analysis module 21, the reverse tracing module 22, and the web page file determination module 23 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least some functions of one or more of these modules may be combined with at least some functions of other modules and implemented in one module. According to embodiments of the present disclosure, at least one of the lexical analysis module 21, the reverse tracing module 22, and the web page file determination module 23 may be at least partially implemented as a hardware circuit, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or may be implemented by any other reasonable way of integrating or packaging circuits and other hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in a suitable combination of any several of them. Alternatively, at least one of the lexical analysis module 21, the reverse tracing module 22, and the web page file determination module 23 may be at least partially implemented as a computer program module, and when the computer program module is run, it can execute the corresponding functions.
[0121] The third exemplary embodiment of the present disclosure provides an electronic device. The above-mentioned electronic device includes: one or more processors; and a storage device for storing one or more programs. Wherein, when the one or more programs are executed by the one or more processors, the one or more processors implement any of the methods described above.
[0122] Figure 7 A block diagram of an electronic device according to an embodiment of the present disclosure is schematically shown.
[0123] Referring Figure 7 As shown, the electronic device 3 according to an embodiment of the present disclosure includes a processor 301, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 302 or the program loaded from the storage section 308 into the random access memory (RAM) 303. The processor 301 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), and so on. The processor 301 may also include on-board memory for caching purposes. The processor 301 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0124] In the RAM 303, various programs and data required for the operation of the electronic device 3 are stored. The processor 301, the ROM 302, and the RAM 303 are connected to each other through a bus 304. The processor 301 executes various operations of the method flow according to an embodiment of the present disclosure by executing the programs in the ROM 302 and / or the RAM 303. It should be noted that the program may also be stored in one or more memories other than the ROM 302 and the RAM 303. The processor 301 may also execute various operations of the method flow according to an embodiment of the present disclosure by executing the programs stored in the one or more memories.
[0125] According to an embodiment of the present disclosure, the electronic device 3 may further include an input / output (I / O) interface 305, and the input / output (I / O) interface 305 is also connected to the bus 304. The electronic device 3 may further include one or more of the following components connected to the I / O interface 305: an input portion 306 including a keyboard, a mouse, etc.; an output portion 307 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 308 including a hard disk, etc.; and a communication portion 309 including a network interface card such as a local area network card, a modem, etc. The communication portion 309 performs communication processing via a network such as the Internet. The drive 310 is also connected to the I / O interface 305 as needed. A removable medium 311, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 310 as needed so that a computer program read from it is installed into the storage portion 308 as needed.
[0126] The fourth exemplary embodiment of the present disclosure provides a computer-readable storage medium. An executable instruction is stored on the above computer-readable storage medium, and when the instruction is executed by a processor, the processor implements any of the methods described above.
[0127] The computer-readable storage medium may be included in the device / device / system described in the above embodiment; or it may exist separately and not be assembled into the device / device / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method according to the embodiment of the present disclosure is implemented.
[0128] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program can be used by or combined with an instruction execution system, device, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the above-described ROM 302 and / or RAM 303 and / or one or more memories other than ROM 302 and RAM 303.
[0129] The fifth exemplary embodiment of the present disclosure provides a computer program product. The above computer program product contains computer-executable instructions, and after the instructions are executed, they are used to implement any of the methods described above.
[0130] According to an embodiment of the present disclosure, the method flow according to the embodiments of the present disclosure can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable storage medium, and the computer program includes program codes for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication part 309, and / or installed from the removable medium 311. When the computer program is executed by the processor 301, the above-mentioned functions defined in the system of the embodiments of the present disclosure are executed. According to an embodiment of the present disclosure, the above-mentioned systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0131] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above-mentioned module, program segment, or part of code includes one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for executing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0132] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.
[0133] The above embodiments of the present disclosure have been described. However, these embodiments are only for illustrative purposes and not for limiting the scope of the present disclosure. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present disclosure.
Claims
1. A method for detecting web trojans, comprising: Performing lexical analysis on the target web page file to be detected to split the target web page file into a sequence of morpheme units; Performing reverse tracing lookup of associated variables for specific morpheme units containing dangerous function calls in the sequence of morpheme units to determine whether there is a specific associated variable containing external input data in the associated variables, where the dangerous function is a special function that can execute system commands or interpret and execute code; And If there is a specific associated variable containing external input data, determining that the target web page file is a web trojan, wherein, the performing reverse tracing lookup of associated variables for specific morpheme units containing dangerous function calls in the sequence of morpheme units to determine whether there is a specific associated variable containing external input data in the associated variables includes: Determining a specific morpheme unit in the sequence of morpheme units, where the specific morpheme unit is a morpheme unit containing a dangerous function call; Determining a target variable participating in the dangerous function call in the specific morpheme unit; Looking up the associated variable of the target variable in the previous unit of the specific morpheme unit; Recursively looking up all associated variables; and Determining whether there is a specific associated variable containing external input data in all associated variables; wherein, the associated variable is a variable that all participates in the operation of the dangerous function call by the target variable.
2. The method according to claim 1, wherein, The performing lexical analysis on the target web page file to be detected to split the target web page file into a sequence of morpheme units includes: Determining the programming language type of the target web page file to be detected; and Performing lexical analysis on the target web page file according to the programming language type of the target web page file to split the source code of the scripting language of the target web page file into a sequence of morpheme units.
3. According to the method of claim 1, wherein, The performing lexical analysis on the target web page file to be detected includes: If the target web page file has annotation content, storing the annotation content and performing lexical analysis on the target web page file after removing the annotation content; The performing reverse tracing lookup of associated variables for specific morpheme units containing dangerous function calls in the sequence of morpheme units to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is a variable for reflecting and obtaining annotations in the associated variables, reloading the stored annotation content; and Performing lexical analysis and processing on the reloaded annotation content to determine whether the annotation content contains external input data.
4. The method according to claim 1, wherein, The performing reverse tracing lookup of associated variables for specific morpheme units containing dangerous function calls in the sequence of morpheme units to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is an operation function related to strings in the sequence of morpheme units, simulating the execution of the operation function and string concatenation operation to generate a concatenated string; Determine whether the concatenated string contains dangerous functions, where the dangerous functions are at least one of the following functions: eval function, assert function, passthru function, exec function, proc_open function, shellexec function, and system function; If the concatenated string contains dangerous functions, determine that the morpheme unit containing the dangerous function is a specific morpheme unit; and Perform reverse tracing and lookup of associated variables for the specific morpheme unit to determine whether there is a specific associated variable containing external input data in the associated variables.
5. The method according to claim 1, wherein The reverse tracing and lookup of associated variables for the specific morpheme unit containing a dangerous function call in the morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is a user-defined function in the morpheme unit sequence, reassign the internal variables of the user-defined function based on the passed-in parameters each time the user-defined function is called, and reverse trace the associated variables of the user-defined function to determine whether there is a specific associated variable containing external input data in the associated variables of the user-defined function.
6. The method according to claim 1, wherein The reverse tracing and lookup of associated variables for the specific morpheme unit containing a dangerous function call in the morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is a deserialization function in the morpheme unit sequence, perform reverse tracing and concatenation on the variables passed into the deserialization function to determine whether there is a user-defined class; If there is a user-defined class in the morpheme unit sequence, trace and lookup the magic functions for handling the user-defined class at the time of creation and deletion to determine whether the magic functions contain external input data.
7. The method according to claim 1, wherein, The reverse tracing and lookup of associated variables for the specific morpheme unit containing a dangerous function call in the morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is a callback function in the morpheme unit sequence, perform reverse tracing processing on the callback function respectively according to the passed-in form of the callback function to determine whether there is a specific associated variable containing external input data in the associated variables of the callback function.
8. The method according to claim 1, wherein The reverse tracing and lookup of associated variables for the specific morpheme unit containing a dangerous function call in the morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is a dynamic variable function in the morpheme unit sequence, extract the variables of the dynamic variable function and perform reverse tracing on the variables of the dynamic variable function to determine whether the source of the variables of the dynamic variable function is external input data.
9. The method according to claim 1, wherein The reverse tracing and lookup of associated variables for the specific morpheme unit containing a dangerous function call in the morpheme unit sequence to determine whether there is a specific associated variable containing external input data in the associated variables includes: If there is a file inclusion class function in the sequence of morpheme units, perform backward tracing and searching according to the associated files included in the file inclusion class function to determine whether the associated files contain external input data.
10. A device for detecting web page trojans, comprising: A lexical analysis module for performing lexical analysis on the target web page file to be detected, so as to segment the target web page file into a sequence of morpheme units; A backward tracing module for performing backward tracing and searching of associated variables for specific morpheme units containing dangerous function calls in the sequence of morpheme units, to determine whether there is a specific associated variable containing external input data in the associated variables, where the dangerous function is a special function that can execute system commands or interpret and execute code; And A web page file determination module for determining that the target web page file is a web page trojan when there is a specific associated variable containing external input data; wherein, the performing backward tracing and searching of associated variables for specific morpheme units containing dangerous function calls in the sequence of morpheme units to determine whether there is a specific associated variable containing external input data in the associated variables includes: Determining a specific morpheme unit in the sequence of morpheme units, where the specific morpheme unit is a morpheme unit containing a dangerous function call; Determining a target variable participating in the dangerous function call in the specific morpheme unit; Searching for the associated variable of the target variable in the previous unit of the specific morpheme unit; Recursively searching for all associated variables; and Determining whether there is a specific associated variable containing external input data in all the associated variables; wherein, the associated variable is a variable that all participates in the operation of the dangerous function call by the target variable.
11. An electronic device, comprising: One or more processors; A storage device for storing one or more programs, wherein, when the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1-9.
12. A computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor implements the method according to any one of claims 1-9.
13. A computer program product, comprising computer-executable instructions, and after the instructions are executed, they are used to implement the method according to any one of claims 1-9.