Process processing method, device, computer equipment and readable storage medium

By querying the real parent process of the child process in process processing and deciding whether to intercept the creation of the child process based on its security information, the problem that malicious processes cannot be intercepted when creating child processes through trusted processes is solved, and the security defense capabilities of process processing are improved.

CN114647842BActive Publication Date: 2025-06-06QI AN XIN SECURITY TECH ZHUHAI CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011520264.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-21
Publication Date
2025-06-06
Estimated Expiration
2040-12-21

AI Technical Summary

Technical Problem

In the prior art, when a malicious process creates a child process through a trusted process, since the parent process of the child process in the process link list is a trusted process, the illegal operations of the child process cannot be intercepted in time, thereby reducing the security defense capabilities during the process processing.

Method used

By querying the real parent process of the child process in the pre-stored process record, when the system process is detected to create a child process, query the same target process as the child process, determine that its corresponding source process is the real parent process of the child process, and decide whether to intercept the creation of the child process based on the security information of the real parent process.

Benefits of technology

By identifying and intercepting child processes created by malicious processes, the security defense capabilities during process processing are significantly improved, ensuring timely identification and interception of illegal process behaviors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114647842B_ABST
    Figure CN114647842B_ABST
Patent Text Reader

Abstract

The present invention provides a process processing method, device, computer equipment and readable storage medium. The method includes: when it is detected that a first system process creates a child process, querying the real parent process of the child process in a pre-stored process record, wherein the process record includes the corresponding relationship between the source process and the target process, the source process is a non-system process that sends a process creation message to a second system process, and the target process is the process created by the process creation message. When the child process is the same as the target process, the source process corresponding to the target process is the real parent process of the child process, and the first system process and the second system process can be the same or different; and determining whether to intercept the creation of the child process according to the real parent process. Through the present invention, the flexibility and security defense capabilities of the process processing process can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a process processing method, device, computer equipment and readable storage medium. Background Art

[0002] With the increasing popularity of network terminal devices such as mobile phones, personal computers, and wearable smart terminals in life and work, how to ensure information security has become the primary security issue to be solved. At present, mainstream security software will maintain a process list to identify the relationship between parent and child processes. When it is necessary to judge the suspicious behavior of the child process, the parent process information is usually found for verification. As long as the parent process is trustworthy, the behavior of the child process is considered trustworthy.

[0003] However, the inventors have discovered that when a malicious process creates a child process through a trusted process and performs illegal operations in real time, since the parent process of the child process in the process list is a trusted process, the illegal operations of the child process in real time cannot be intercepted. Therefore, how to improve the security defense capabilities in the process processing has become a technical problem that urgently needs to be solved in this field. Summary of the invention

[0004] The purpose of the present invention is to provide a process processing method, device, computer equipment and readable storage medium to solve the technical problems in the prior art.

[0005] On the one hand, to achieve the above objectives, the present invention provides a process processing method.

[0006] The process processing method includes: when it is detected that a first system process creates a child process, querying the real parent process of the child process in a pre-stored process record, wherein the process record includes a correspondence between a source process and a target process, the source process is a non-system process that sends a process creation message to a second system process, and the target process is a process created by the process creation message; when the child process is the same as the target process, the source process corresponding to the target process is the real parent process of the child process, and the first system process and the second system process may be the same or different; and determining whether to intercept the creation of the child process based on the real parent process.

[0007] Furthermore, the process processing method also includes: obtaining a target message passed by a message passing function; determining whether the target message is a process creation message; if the target message is a process creation message, taking the process that sends the target message as the source process, and taking the process indicated to be created by the target message as the target process, and writing them into the process record together.

[0008] Furthermore, the step of obtaining the target message passed by the message passing function includes: hooking the message passing function to obtain the parameters of the target message sent by the source process; the step of determining whether the target message is a message for creating the process includes executing the following steps through the hook function: parsing the parameters to determine whether the interface accessed by the source process is a preset interface; if the interface is the preset interface, determining whether the method accessed by the source process is an execution method; if the method is the execution method, determining whether the content executed by the method is to create a process, wherein if the content executed by the method is to create a process, determining that the target message is a message for creating the process.

[0009] Furthermore, the step of taking the process sending the target message as the source process and the process created by the target message as the target process, and writing them into the process record together includes: obtaining the name of the created process from the message content of the target message; obtaining the PID of the source process; and writing the name and the PID into the process record.

[0010] Furthermore, the step of obtaining the target message passed by the message passing function includes: obtaining the target message passed by the NtAlpcSendWaitReceivePort function; the step of determining whether the interface accessed by the source process is a preset interface includes: determining whether the interface accessed by the source process is an IWbemService interface, whose interface GUID unique identifier is {9556dc99-828c-11cf-a37e-00aa003240c7}; the step of determining whether the method accessed by the source process is an execution method includes: whether the location of the method accessed by the source process is 0x18 (the method name is ExecMethod) or 0x19 (the method name is ExecMethodAsync); the source process is used to send the target message to the svchost process through the NtAlpcSendWaitReceivePort function, and the svchost process is used to forward the target message to the WmiPrvse process; the first system process is the WmiPrvse process, and the second system process is the svchost process.

[0011] Furthermore, the process processing method further includes: registering a process creation callback notification in a driver program to detect a process creation event; when a process creation event is detected, the callback processing function determines whether the process that creates the child process is the first system process.

[0012] Furthermore, the step of determining whether to intercept the creation of the child process based on the real parent process includes: obtaining security information of the real parent process; when the security information shows that the real parent process belongs to a trusted process, allowing the first system process to create the child process; when the security information shows that the real parent process belongs to an untrusted process, intercepting the first system process from creating the child process.

[0013] On the other hand, to achieve the above objective, the present invention provides a process processing device.

[0014] The process processing device includes: a query module, which is used to query the real parent process of the child process in a pre-stored process record when it is detected that the first system process creates a child process, wherein the process record includes the correspondence between a source process and a target process, the source process is a non-system process that sends a process creation message to the second system process, and the target process is the process created by the process creation message. When the child process is the same as the target process, the source process corresponding to the target process is the real parent process of the child process, and the first system process and the second system process may be the same or different; and a processing module, which is used to determine whether to intercept the child process according to the real parent process.

[0015] On the other hand, to achieve the above purpose, the present invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the above method when executing the computer program.

[0016] On the other hand, to achieve the above-mentioned purpose, the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned method are implemented.

[0017] The process processing method, device, computer equipment and readable storage medium provided by the present invention, when it is detected that a system process creates a child process, the real parent process of the child process is queried in the pre-stored process record. Specifically, the process record includes the corresponding relationship between the source process and the target process. The source process is a non-system process that sends a process creation message, and the target process is a process created by the process creation message. In the process record, the target process that is the same as the child process is first queried, and then it is determined that the source process corresponding to the queried target process is the real parent process of the child process, so that it can be determined whether to intercept the creation of the child process based on the real parent process, and the control of the process creation process is more flexible, and malicious processes can be intercepted from creating child processes to perform illegal acts. Through the present invention, non-system processes can be flexibly controlled to create child processes through system processes, and any malicious process can be intercepted and identified to create child processes through system processes, thereby improving the flexibility and security defense capabilities in the process processing process. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0019] Figure 1 A flowchart of a process processing method provided in Embodiment 1 of the present invention;

[0020] Figure 2 A flowchart of a recording process chain provided by an embodiment of the present invention;

[0021] Figure 3 A schematic diagram of an interception process provided by an embodiment of the present invention;

[0022] Figure 4 A block diagram of a process processing device provided in Embodiment 2 of the present invention;

[0023] Figure 5 This is a hardware structure diagram of a computer device provided in Embodiment 3 of the present invention. DETAILED DESCRIPTION

[0024] In order to make the purpose, technical scheme and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0025] In order to improve the security defense capability in the process of process processing, the inventor studied the process processing in the prior art and found that in some cases, the parent process of the child process in the process list is the system process. For example, after a malicious process creates a child process through WMI, the parent process of the child process in the process list is the system process WmiPrvSE.exe, and the system processes are trusted by default, which leads to the interruption of the maintained real parent-child process relationship chain. At this time, when the child process performs suspicious behavior, because the located parent process is the system process instead of the real original parent process, the behavior cannot be intercepted in time, that is, the identification and interception of illegal behavior cannot be achieved by verifying its parent process.

[0026] Based on this, the present application proposes a process processing method, apparatus, computer equipment and readable storage medium. In the process processing method, when it is detected that a first system process creates a child process, the real parent process of the child process is queried in the pre-stored process record. Specifically, the process record includes the correspondence between the source process and the target process. The source process is a non-system process that sends a process creation message, and the target process is the process created by the process creation message. In the process record, the target process that is the same as the child process is first queried. When the target process is found, it can be determined that the source process corresponding to the queried target process is the real parent process of the child process. Therefore, it can be determined whether to intercept the creation of the child process based on the real parent process, making the process control more flexible. When the real parent process is a malicious process, the malicious process can be intercepted from creating a child process to perform illegal activities, thereby improving the security defense capability.

[0027] Specific embodiments of the process processing method, apparatus, computer device, and readable storage medium provided in the present application will be described in detail below.

[0028] Embodiment 1

[0029] The embodiment of the present invention provides a process processing method, through which the security defense capability in the process of process processing can be improved. Specifically, Figure 1 A flowchart of a process processing method provided in Embodiment 1 of the present invention is shown in FIG. Figure 1 As shown, the process processing method provided by this embodiment includes the following steps S101 and S102.

[0030] Step S101: when it is detected that the first system process creates a child process, the real parent process of the child process is queried in the pre-stored process records.

[0031] Among them, the process record includes the correspondence between the source process and the target process. The source process is a non-system process that sends a process creation message to the second system process. The target process is the process created by the process creation message. When the child process is the same as the target process, the source process corresponding to the target process is the real parent process of the child process.

[0032] It should be noted that the first system process and the second system process may be the same or different. The first and the second here are only used to distinguish between two logical scenarios, that is, only used to distinguish between the system process that creates a subprocess and the system process that receives a process creation message.

[0033] Optionally, detect an event of creating a process, and when the event of creating a process is detected, determine whether it is a system process that creates the process, and if so, execute step S101; or, optionally, detect an event of a system process creating a process, and when the event of a system process creating a process is detected, execute step S101.

[0034] Optionally, when a non-system process sends a process creation message to a system process, the non-system process is used as the source process, and the process to be created by the non-system process is used as the target process. A correspondence between the source process and the target process is formed in the process record and stored in the process record. For the target process, the source process is actually its real parent process.

[0035] In step S101, when it is detected that the first system process creates a child process, the child process is used to match the target process in the pre-stored process record. When the target process is matched, it indicates that the first system process is not actually the real parent process of the child process, and the source process corresponding to the target process that matches the child process in the process record is the real parent process of the child process.

[0036] Step S102: Determine whether to intercept the creation of the child process according to the real parent process.

[0037] When the real parent process of the child process to be created by the first system process is determined in step S101, it can be determined in this step whether to intercept the creation of the child process according to the information of the real parent process. For example, the control logic of the child process created by the system process can be set according to the real parent process to achieve flexible control of the child process created by the system process.

[0038] Furthermore, information reflecting the security of the real parent process can be obtained to determine whether to intercept the creation of the child process based on the real parent process. When the security risks of the real parent process are relatively large, for example, the real parent process belongs to the blacklist process, the first system process is intercepted from creating the child process; when the real parent process is a trusted process, the first system process is allowed to create the child process.

[0039] Optionally, in step S102, security information of the real parent process is obtained; when the security information shows that the real parent process is a trusted process, the first system process is allowed to create a child process; when the security information shows that the real parent process is an untrusted process, the first system process is intercepted from creating a child process.

[0040] Alternatively, it is also possible to determine whether to intercept the creation of a child process by combining the security of the real parent process and the action performed by the child process to be created. For example, when the action performed by the child process to be created belongs to the preset high-risk action type, the security requirements for the real parent process are higher. In short, after determining the real parent process of the child process, it can be determined whether to allow the creation of the child process based on the real parent process.

[0041] In the process processing method provided by this embodiment, when it is detected that a system process creates a child process, the real parent process of the child process is queried in the pre-stored process record. Specifically, the process record includes the corresponding relationship between the source process and the target process. The source process is a non-system process that sends a process creation message, and the target process is a process created by the process creation message. In the process record, the target process that is the same as the child process is first queried, and then it is determined that the source process corresponding to the queried target process is the real parent process of the child process, so that it can be determined whether to intercept the creation of the child process based on the real parent process. When the real parent process is a malicious process, the creation of the child process is intercepted, that is, the malicious process is intercepted from creating the child process to perform illegal acts. The process processing method provided by this embodiment can flexibly control the non-system process to create a child process through the system process, and can intercept and identify any malicious process that creates a child process through the system process, thereby improving the flexibility and security defense capabilities in the process processing process.

[0042] Optionally, in one embodiment, the process processing method also includes: obtaining a target message passed by a message passing function; determining whether the target message is a process creation message; if the target message is a process creation message, taking the process that sends the target message as the source process, and taking the process indicated to be created by the target message as the target process, and writing them into the process record together.

[0043] Specifically, when a malicious process creates a child process through a system process, it will directly send the process creation message to the system process that creates the child process through a message passing function, or it can also send the process creation message to other system processes through a message passing function, and then the other system processes will forward the message to the system process that creates the child process. In short, the malicious process will pass the process creation message through a message passing function. Based on this, in this embodiment, the target message passed by the message passing function is obtained, and it is determined whether the target message belongs to the process creation information. If it does, the process that sends the target message is recorded as the source process, and the process created by the target message is recorded as the target process. The identification information of the source process and the identification information of the target process are written into the process record together, so that the malicious process that creates the child process and the child process can be recorded. Then, in the above step S101, if the child process created by the system process is the target process in the record, then its real parent process can be identified as a malicious process, and the creation of the child process can be intercepted.

[0044] By adopting the process processing method provided in this embodiment, the process of creating a child process by means of the system process can be recorded, so that the real parent process can be traced when the child process is created, and the creation of the child process can be controlled according to the real parent process. When the real parent process is a malicious process, the malicious process can be effectively blocked from creating a child process by means of the system process.

[0045] Optionally, in one embodiment, the step of obtaining the target message passed by the message passing function includes: hooking the message passing function to obtain the parameters of the target message sent by the source process; the step of determining whether the target message is a process creation message includes executing the following steps through the hook function: parsing the parameters to determine whether the interface accessed by the source process is a preset interface; if the interface is a preset interface, determining whether the method accessed by the source process is an execution method; if the method is an execution method, determining whether the content of the method execution is to create a process, wherein if the content of the method execution is to create a process, determining that the target message is a process creation message.

[0046] Specifically, by setting a hook function, the message transfer function is hooked, the parameters of the target message sent by the source process are obtained, and the target message transferred by the message transfer function is judged by the hook function whether it is a process creation message. When the hook function makes a judgment, it judges whether the source process wants to access the preset interface according to the parsed parameters, wherein the preset interface includes an execution method that can create a process. Different interfaces have different identifiers, and the interface identifier is unique to the interface. Therefore, the interface identifier can be parsed by parsing the parameters, and then the parsed interface identifier is compared with the interface identifier of the preset interface to determine whether the source process wants to access the preset interface. If the source process wants to access the preset interface, it is further determined which method under the interface the source process accesses. Among them, the preset interface includes several methods, and different methods have different and fixed ids under a fixed interface. Therefore, the id of the method under the preset interface to be accessed can be parsed by parsing the parameters, and then it can be determined whether the specific accessed method is an execution method. If the access method is the execution method, further determine the specific execution content of the execution method, that is, the content of the message, where the content of the message can be to create a process or to operate a registry or file, etc. Therefore, by parsing the parameters, it can be determined whether the content of the message is to create a process, and then it can be determined whether the target message is a message to create a process.

[0047] The process processing method provided in this embodiment is adopted to determine whether the target message transmitted by the message transmission function is a process creation message by presetting a hook function, wherein the hook function performs judgment layer by layer, which can not only accurately identify the process creation message, but also has high execution efficiency.

[0048] Optionally, in one embodiment, the process sending the target message is taken as the source process, and the process created by the target message is taken as the target process, and the steps of writing them into the process record include: obtaining the name of the created process from the message content of the target message; obtaining the PID of the source process; and writing the name and PID into the process record.

[0049] Specifically, when creating a process, it is necessary to provide the name of the created process. The name of the created process will be included in the message content of the target message. Therefore, the name of the created process in the target message is extracted as the identifier of the target process. When the process is created, that is, in the above step S101, the name of the created child process can be directly compared with the name of the target process in the process record to determine whether the created child process belongs to the target process in the process record table. Different processes have different PIDs. The PID of the source process can also be obtained through the hook message passing function. The PID of the process can be easily obtained to identify the source process, so that in the above step S102, after determining the real parent process, its PID is used to obtain its related feature information, including security information, so as to use the feature information to control the creation of the child process.

[0050] Optionally, in one embodiment, the step of obtaining the target message passed by the message passing function includes: obtaining the target message passed by the NtAlpcSendWaitReceivePort function; the step of determining whether the interface accessed by the source process is a preset interface includes: determining whether the interface accessed by the source process is an IWbemService interface; the step of determining whether the method accessed by the source process is an execution method includes: determining whether the location of the method accessed by the source process is 0x18 or 0x19; the source process is used to send the target message to the svchost process through the NtAlpcSendWaitReceivePort function, and the svchost process is used to forward the target message to the WmiPrvse process; the first system process is the WmiPrvse process.

[0051] Specifically, the Windows operating system supports the WMI method to create a process. The parent process of the process created by the WMI method is WmiPrvSE.exe by default, which causes the parent-child process relationship chain to be interrupted. When the created process commits an illegal act, the real original parent process cannot be located. Through this embodiment, the WMI creation process is traced to the source, and the real parent process can be located.

[0052] WMI is an interface for managing system resources provided by Microsoft. It has been built into Windows since Windows 2000 and supports common operations such as files, processes, services, and registry. This embodiment can locate the PID of the real parent process when WmiPrvSE.exe creates a process by reversing the internal structure.

[0053] When a process A (the source process) wants to create foo.exe (the target process) via WMI, the internal implementation process is:

[0054] 1. A.exe passes the target message to svchost.exe (winmgment) through NtAlpcSendWaitReceivePort function;

[0055] 2.svchost.exe (winmgment) forwards the target message to WmiPrvse.exe;

[0056] 3. WmiPrvse.exe receives the target message and starts to create the process foo.exe.

[0057] When A.exe passes the target message to svchost.exe through the NtAlpcSendWaitReceivePort function, the NtAlpcSendWaitReceivePort function is hooked through the hook function, such as Figure 2 The specific processing is as follows:

[0058] 1. The hook function obtains the parameters of the message sent by process A;

[0059] 2. Parse the parameters, including the interface, method and message that process A wants to access;

[0060] 3. Determine whether the interface to be accessed is the IWbemService interface (that is, the WMI interface is unique, and its interface GUID unique identifier is {9556dc99-828c-11cf-a37e-00aa003240c7}); or 0x19;

[0061] 4. If the interface to be accessed is the IWbemService interface, determine whether the method to be accessed is the method at position 0x18 (method name ExecMethod) and position 0x19 (method name ExecMethodAsync) (that is, synchronous execution method and asynchronous execution method);

[0062] 5. If the method to be accessed is the method at position 0x18 and 0x19, determine whether the message is a message for creating a process;

[0063] 6. If the message is a message to create a process, obtain the name of the created process from the message content, obtain the PID of process A, and save it in the linked list, that is, save it in the process record.

[0064] If the interface to be accessed is not the IWbemService interface, or if the method to be accessed is not the method at positions 0x18 and 0x19, or the message is not a message for creating a process, or after saving the process record, the original process is executed, that is, the three steps of "Process A (that is, the source process) wants to create foo.exe through WMI" mentioned above.

[0065] By using the process processing method provided in this embodiment, when the source process sends a message to svchost for the first time, the PID of the source process and the name of the process to be created are recorded in a data linked list, and when WmiPrvse.exe creates the process, the PID of the source process can be queried through the data linked list.

[0066] Optionally, in one embodiment, the process processing method further includes: registering a process creation callback notification in a driver program to detect a process creation event; when a process creation event is detected, the callback processing function determines whether the process that creates the child process is the first system process.

[0067] Specifically, a process creation notification callback can be registered in the driver of the security software, so that when a process creates a child process, the callback processing function is used to determine whether it is the system process that creates the child process. Optionally, Figure 3 As shown, when a process creates a child process, the callback processing function determines whether the process is WmiPrvse.exe. If so, it determines whether the child process is in the WMI record, that is, it queries the data linked list of the record to find the name of the created process foo.exe. After the query is successful, the information of process A in the record is taken out. This process A is the real parent process of foo.exe. Then it can be determined whether the real parent process A is a trusted process. If it is an untrusted process, the creation of foo.exe process is intercepted. If process A is trusted, the creation of foo.exe process is allowed. If the process is not WmiPrvse.exe, or the process name foo.exe is not found in the data linked list, the creation of foo.exe process is allowed.

[0068] The process processing method provided by this embodiment is adopted to record when any process accesses the IWbemServices interface of WMI to create a process, and the parent process and the target process to be created are recorded and saved. When WmiPrvSE receives the message to start creating a process, it matches the name of the created process saved in the recorded data table. If the match is successful, it determines whether the parent process is a trusted process based on the real parent process information saved in the record table. If it is trusted, the child process is allowed to be created. Otherwise, WmiPrvSE is prevented from creating a child process. It can intercept and identify any process to create a process through WMI, and obtain the real parent process information when creating the process, thereby improving security defense capabilities.

[0069] Embodiment 2

[0070] Corresponding to the above-mentioned embodiment 1, embodiment 2 of the present invention provides a process processing device. The corresponding technical feature details and corresponding technical effects can be referred to the above-mentioned embodiment 1, and will not be repeated in this embodiment. Figure 4 A block diagram of a process processing device provided in Embodiment 2 of the present invention, such as Figure 4 As shown, the device includes: a query module 201 and a processing module 202.

[0071] Among them, the query module 201 is used to query the real parent process of the child process in the pre-stored process record when it is detected that the first system process creates a child process, wherein the process record includes the correspondence between the source process and the target process, the source process is a non-system process that sends a process creation message to the second system process, and the target process is the process created by the process creation message. When the child process is the same as the target process, the source process corresponding to the target process is the real parent process of the child process, and the first system process and the second system process may be the same or different; and the processing module 202 is used to determine whether to intercept the child process based on the real parent process.

[0072] Optionally, in one embodiment, the process processing device also includes: an acquisition module, used to acquire a target message passed by a message passing function; a judgment module, used to judge whether the target message is a process creation message; and a recording module, used to take the process sending the target message as the source process and the process indicated to be created by the target message as the target process, and write them into the process record together if the target message is a process creation message.

[0073] Optionally, in one embodiment, when the acquisition module acquires the target message passed by the message passing function, the specific steps executed include: hooking the message passing function to obtain the parameters of the target message sent by the source process; the step of determining whether the target message is a message for creating the process includes executing the following steps through the hook function: parsing the parameters to determine whether the interface accessed by the source process is a preset interface; if the interface is the preset interface, determining whether the method accessed by the source process is an execution method; if the method is the execution method, determining whether the content executed by the method is to create a process, wherein if the content executed by the method is to create a process, determining that the target message is a message for creating the process.

[0074] Optionally, in one embodiment, when the recording module writes the process that sends the target message as the source process and the process created by the target message as the target process into the process record, the specific steps executed include: obtaining the name of the created process from the message content of the target message; obtaining the PID of the source process; and writing the name and the PID into the process record.

[0075] Optionally, in one embodiment, the step of obtaining the target message passed by the message passing function includes: obtaining the target message passed by the NtAlpcSendWaitReceivePort function; the step of determining whether the interface accessed by the source process is a preset interface includes: determining whether the interface accessed by the source process is an IWbemService interface; the step of determining whether the method accessed by the source process is an execution method includes: whether the location of the method accessed by the source process is 0x18 or 0x19; the source process is used to send the target message to the svchost process through the NtAlpcSendWaitReceivePort function, and the svchost process is used to forward the target message to the WmiPrvse process; the first system process is the WmiPrvse process, and the second system process is the svchost process.

[0076] Optionally, in one embodiment, the process processing device also includes: a registration module, used to register a process creation callback notification in a driver program to detect a process creation event; when a process creation event is detected, the callback processing function determines whether the process that creates the child process is the first system process.

[0077] Optionally, in one embodiment, when the processing module 202 determines whether to intercept the creation of the child process based on the real parent process, the specific steps performed include: obtaining the security information of the real parent process; when the security information shows that the real parent process is a trusted process, allowing the first system process to create the child process; when the security information shows that the real parent process is an untrusted process, intercepting the first system process from creating the child process.

[0078] Embodiment 3

[0079] This third embodiment also provides a computer device, such as a smart phone, tablet computer, laptop computer, desktop computer, rack server, blade server, tower server or cabinet server (including an independent server or a server cluster composed of multiple servers) that can execute programs. Figure 5 As shown, the computer device 01 of this embodiment includes at least but is not limited to: a memory 012 and a processor 011 which can be interconnected through a system bus. Figure 5 It should be pointed out that Figure 5 Only a computer device 01 having components memory 012 and processor 011 is shown, but it should be understood that it is not required to implement all of the components shown, and more or fewer components may be implemented instead.

[0080] In this embodiment, the memory 012 (i.e., readable storage medium) includes flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 012 can be an internal storage unit of the computer device 01, such as a hard disk or memory of the computer device 01. In other embodiments, the memory 012 can also be an external storage device of the computer device 01, such as a plug-in hard disk equipped on the computer device 01, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. Of course, the memory 012 can also include both the internal storage unit of the computer device 01 and its external storage device. In this embodiment, the memory 012 is generally used to store the operating system and various application software installed on the computer device 01, such as the program code of the process processing device of the second embodiment. In addition, the memory 012 can also be used to temporarily store various types of data that have been output or are to be output.

[0081] In some embodiments, the processor 011 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips. The processor 011 is generally used to control the overall operation of the computer device 01. In this embodiment, the processor 011 is used to run the program code stored in the memory 012 or process data, such as a process processing method.

[0082] Embodiment 4

[0083] The fourth embodiment also provides a computer-readable storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory (for example, an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a disk, an optical disk, a server, an App application store, etc., on which a computer program is stored, and the program realizes the corresponding function when executed by the processor. The computer-readable storage medium of this embodiment is used to store a process processing device, and when executed by the processor, the process processing method of the first embodiment is realized.

[0084] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.

[0085] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.

[0086] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method.

[0087] The above are only preferred embodiments of the present invention, and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A process processing method, It is characterized in that include: When it is detected that the first system process creates a child process, querying the real parent process of the child process in a pre-stored process record, wherein the process record includes a correspondence between a source process and a target process, the source process is a non-system process that sends a process creation message to the second system process, and the target process is a process created by the process creation message, when the child process is the same as the target process, the source process corresponding to the target process is the real parent process of the child process, and the first system process and the second system process are the same or different; and Determining whether to intercept the creation of the child process based on the real parent process includes: obtaining security information of the real parent process; when the security information shows that the real parent process belongs to a trusted process, allowing the first system process to create the child process; when the security information shows that the real parent process belongs to an untrusted process, intercepting the first system process from creating the child process.

2. The process processing method according to claim 1, It is characterized in that The process processing method further includes: Get the target message passed by the message passing function; Determine whether the target message is the process creation message; If the target message is a process creation message, the process sending the target message is taken as the source process, and the process created by the target message is taken as the target process, and both are written into the process record.

3. The process processing method according to claim 2, It is characterized in that The step of obtaining the target message transmitted by the message transmission function comprises: hooking the message transmission function to obtain the parameters of the target message sent by the source process; The step of determining whether the target message is a message created by the process includes executing the following steps through a hook function: Parsing the parameters to determine whether the interface accessed by the source process is a preset interface; If the interface is the preset interface, determining whether the method accessed by the source process is an execution method; If the method is the execution method, it is determined whether the content of the method execution is to create a process, wherein if the content of the method execution is to create a process, it is determined that the target message is the process creation message.

4. The process processing method according to claim 3, It is characterized in that The step of taking the process that sends the target message as the source process and the process that is created as indicated by the target message as the target process, and writing both into the process record comprises: Obtaining the name of the created process from the message content of the target message; Obtaining the PID of the source process; and The name and the PID are written to the process record.

5. The process processing method according to claim 4, It is characterized in that The step of obtaining the target message passed by the message passing function includes: obtaining the target message passed by the NtAlpcSendWaitReceivePort function; The step of determining whether the interface accessed by the source process is a preset interface includes: determining whether the interface accessed by the source process is an IWbemService interface; The step of determining whether the method accessed by the source process is an execution method comprises: determining whether the location of the method accessed by the source process is 0x18 or 0x19; The source process is used to send the target message to the svchost process through the NtAlpcSendWaitReceivePort function, and the svchost process is used to forward the target message to the WmiPrvse process; The first system process is the WmiPrvse process, and the second system process is the svchost process.

6. The process processing method according to any one of claims 1 to 5, It is characterized in that The process processing method further includes: Register the process creation callback notification in the driver to detect the process creation event; When a process creation event is detected, the callback processing function determines whether the process that creates the child process is the first system process.

7. A process processing device, It is characterized in that include: a query module, configured to query a real parent process of the child process in a pre-stored process record when detecting that the first system process creates a child process, wherein the process record includes a correspondence between a source process and a target process, the source process is a non-system process that sends a process creation message to the second system process, the target process is a process created by the process creation message, when the child process is the same as the target process, the source process corresponding to the target process is the real parent process of the child process, and the first system process and the second system process are the same or different; and A processing module is used to determine whether to intercept the child process based on the real parent process, and the specific execution steps include: obtaining the security information of the real parent process; when the security information shows that the real parent process is a trusted process, allowing the first system process to create the child process; when the security information shows that the real parent process is an untrusted process, intercepting the first system process from creating the child process.

8. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, It is characterized in that When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, Features: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Method and device for intercepting behaviors of program, and client equipment

    CN102932329A

  • Method for intercepting application behavior and terminal

    CN105956470A