Attack code detection method, device, electronic device, program, and storage medium

By obtaining the call function return address within the process stack range in the system, it directly detects whether there is an attack code in the system, solving the problem of low recognition efficiency caused by the complex establishment of feature databases in the existing technology, and achieving efficient attack code detection.

CN114662098BActive Publication Date: 2025-07-25QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202011540159.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-23
Publication Date
2025-07-25
Estimated Expiration
2040-12-23

AI Technical Summary

Technical Problem

In the prior art, attack code recognition methods require the establishment of a feature library based on a large amount of data, the recognition process is complex and the recognition efficiency is low.

Method used

By obtaining the return address of the calling function within the process stack range in the system, if the return address does not belong to the system configuration address, it is determined that there is an attack code in the system, and the detection of the attack code is directly realized without establishing a feature library.

Benefits of technology

It simplifies the attack code identification process, improves the recognition efficiency, has a wide range of applications, and can efficiently detect attack codes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114662098B_ABST
    Figure CN114662098B_ABST
Patent Text Reader

Abstract

The present invention provides a method, device, electronic device, program and storage medium for detecting attack code. The return addresses of the calling functions within the process stack range in the system are obtained. If there is a return address that does not belong to the system configuration address for storing system executable files, it is determined that there is attack code in the system. By directly obtaining the return addresses of the calling functions, the detection of attack code is realized, without the need to establish a feature library, and the recognition process is simple, which is beneficial to improving the recognition efficiency of attack code.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security protection, and in particular, to a method, device, electronic device, program, and storage medium for detecting attack code. Background Art

[0002] Network devices inevitably have vulnerabilities, and attackers will use these vulnerabilities to construct a piece of attack code to attack the network devices. For example, attackers can use the attack code to perform operations such as privilege escalation, program execution, and connection to remote machines in the network devices, so as to achieve the purpose of arbitrarily controlling the network devices. For example, the attack code shellcode of a Linux server used for attack.

[0003] In the prior art, it is necessary to learn the call chain sequence of system calls in advance and establish a normal behavior feature library, and then match the sequence of system calls of the system with the normal sequence feature library to identify vulnerability exploitation behaviors. However, this method has the following disadvantages: it is necessary to learn and establish a feature library in advance, and it is necessary to ensure that there are no vulnerability exploitation behaviors during the learning process; the matching logic is relatively complex and will inevitably consume too much system resources. It can be seen that the existing method for identifying attack code needs to establish a feature library based on a large amount of data, the identification process is relatively complex, and the identification efficiency is relatively low. Summary of the Invention

[0004] The present invention provides a method, device, electronic device, program, and storage medium for detecting attack code, so as to solve the defect that the existing method for identifying attack code needs to establish a feature library based on a large amount of data, the identification process is relatively complex, and the identification efficiency is relatively low, and to achieve identifying attack code in a simple way and improving the identification efficiency.

[0005] The present invention provides a method for detecting attack code, including:

[0006] Obtaining the return address of the calling function; wherein, the calling function is a function called by the target process of the system;

[0007] If the return address does not belong to the system configuration address, there is attack code in the system; the system configuration address is the code segment address of the executable file loaded by the target process.

[0008] According to the method for detecting attack code provided by the present invention, on the basis of the above, before obtaining the return address of the calling function, the method further includes:

[0009] Obtaining monitoring information on whether the monitoring function is called; wherein, the monitoring function is determined according to the historical call information of the function by the attack code.

[0010] If the monitoring information indicates that the monitoring function is called, the process that calls the monitoring function is used as the target process.

[0011] According to the present invention, an attack code detection method is provided. On this basis, the obtaining of the return address of the calling function includes:

[0012] Obtaining the function stack frame of the calling function from the kernel and / or obtaining the function stack frame of the calling function from the application layer;

[0013] Obtaining the return address according to the function stack frame of the calling function.

[0014] According to the present invention, an attack code detection method is provided. On this basis, the obtaining of the function stack frame of the calling function from the kernel includes:

[0015] Obtaining the user-mode context structure saved in the kernel stack when the target process enters the kernel from the kernel stack;

[0016] Determining the base address of the first function stack frame within the range of the target process stack according to the user-mode context structure as the first base address;

[0017] Obtaining each function stack frame within the range of the target process stack starting from the first base address to obtain the function stack frame of the calling function.

[0018] According to the present invention, an attack code detection method is provided. On this basis, the obtaining of the function stack frame of the calling function from the application layer includes:

[0019] Obtaining the base address of the first function stack frame within the range of the target process stack from the user stack in the application layer as the second base address;

[0020] Obtaining each function stack frame within the range of the target process stack starting from the second base address to obtain the function stack frame of the calling function.

[0021] According to the present invention, an attack code detection method is provided. On this basis, before the return address does not belong to the system configuration address, it further includes:

[0022] Determining the virtual memory block structure corresponding to the return address through the virtual memory management structure in the memory, and determining whether the return address belongs to the system configuration address according to the address pointed to by the member describing the mapped file in the virtual memory block structure;

[0023] And / or obtaining a memory layout file representing the memory layout from the application layer, obtaining the line content where the return address is located from the memory layout file, and determining whether the return address belongs to the system configuration address according to the file path in the line content.

[0024] The present invention also provides an attack code detection device, comprising:

[0025] An acquisition module, configured to acquire the return address of a called function; wherein, the called function is a function called by a target process of the system;

[0026] A determination module, configured to determine that there is attack code in the system if the return address does not belong to the system configuration address; the system configuration address is the code segment address of the executable file loaded by the target process.

[0027] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the steps of any one of the above-mentioned attack code detection methods are implemented.

[0028] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of any one of the above-mentioned attack code detection methods are implemented.

[0029] The present invention also provides a computer program, and when the computer program is executed by a processor, the steps of any one of the above-mentioned attack code detection methods are implemented.

[0030] An attack code detection method, device, electronic device, program, and storage medium provided by the present invention acquire the return address of a called function within the process stack range of the system, and if there is a return address that does not belong to the system configuration address for storing the system executable file, it is determined that there is attack code in the system. By directly acquiring the return address of the called function, the detection of attack code is realized, without the need to establish a feature library, and the recognition process is simple, which is beneficial to improving the recognition efficiency of attack code. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings according to these drawings without creative efforts.

[0032] Figure 1 is one of the flowcharts of the attack code detection method provided by the present invention;

[0033] Figure 2 is the structural diagram of the stack frame in the stack provided by the present invention;

[0034] Figure 3It is a schematic diagram of the process of obtaining the function call chain through the kernel provided by the present invention;

[0035] Figure 4 It is a schematic diagram of the process of detecting attack code through the kernel provided by the present invention;

[0036] Figure 5 It is one of the structural block diagrams of the attack code detection device provided by the present invention;

[0037] Figure 6 It is a schematic diagram of the physical structure of the electronic device provided by the present invention; Specific embodiments

[0038] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without making creative efforts shall fall within the protection scope of the present invention.

[0039] Figure 1 It is a schematic diagram of the process of the attack code detection method provided in this embodiment. The attack code detection method can be executed by a device (server or terminal) to be detected for attack code. For example, the attack code detection method can be executed by a Linux server, specifically by a protection driver module implanted in the Linux server. Refer to Figure 1 This attack code detection method includes:

[0040] Step 101: Obtain the return address of the calling function; wherein, the calling function is a function called by the target process of the system.

[0041] The processes of the system usually complete the tasks corresponding to the processes by calling functions in the system. The calling functions called by the processes can obtain function stack frames from the stacks created for the processes. There is information about the calling functions in the function stack frames, including local variables of the calling functions, the address of the previous stack frame, the return address, and so on. Among them, the return address indicates the address of the code to be executed after the function execution is completed.

[0042] Among them, the return addresses of each calling function are sequentially obtained within the stack range of the target process, and these return addresses are sequentially stored in a linked list, which constitutes the function call chain of the target process. Therefore, the function call chain actually represents the call path between functions in the process. During the program execution process, each stack frame corresponds to an unfinished calling function, and the stack frame stores the return address, stack base address, local variables, and so on of the calling function. Figure 2This is a schematic structural diagram of the stack frames in the stack provided in this embodiment. Each stack frame corresponds to a calling function, and the return address of the calling function can be directly obtained from the stack frame. The return address of the calling function indicates the address where the code to be executed next is located after the called function has completed processing.

[0043] It should be noted that since each process is allocated space in the application layer and the kernel when it runs, the function stack frames of each calling function can be obtained through both the application layer and the kernel, and thus the return address of the calling function can be obtained.

[0044] Step 102: If the return address does not belong to the system configuration address, there is attack code in the system; the system configuration address is the code segment address of the executable file loaded by the target process.

[0045] Since during the process of not being attacked by attack code, the return address of each function executed by the system process should belong to the system configuration address allocated for the system's executable file, in this embodiment, if it is detected that any return address does not belong to the system configuration address, it is determined that there is attack code in the system. Among them, the system's executable file depends on the system. For example, in a Linux server, the executable file is an ELF file (ELF files are actually executable files and dynamic link libraries on the Linux system). For example, it is determined by the protection driver module implanted in the Linux server whether each file pointed to by the return address of each calling function of the target process belongs to an ELF file (that is, whether the return address belongs to the system configuration address). If so, there is no attack code in this Linux server; otherwise, there is attack code in this Linux server. There is attack code in the system, more specifically, the application program to which the target process belongs has been attacked by attack code.

[0046] An attack code detection method in this embodiment obtains the return address of the calling function within the process stack range of the system. If there is a return address that does not belong to the system configuration address used to store the system's executable file, it is determined that there is attack code in the system. By directly obtaining the return address of the calling function, the detection of attack code is realized without establishing a feature library, and the recognition process is simple, which is beneficial to improving the recognition efficiency of attack code.

[0047] It can be seen that compared with the prior art, the attack code detection method provided in this embodiment has the following advantages: it realizes the monitoring of processes on Linux, does not require a learning process, is ready to use out of the box, does not require a feature library, detects all return addresses on the call chain, alarms if the detection is non-compliant, has a wider scope of application, and monitors the call chain of all processes through the kernel driver, which is very efficient.

[0048] Further, on the basis of the above embodiments, before obtaining the return address of the called function, the method further includes:

[0049] Obtaining monitoring information on whether a monitoring function is called; wherein, the monitoring function is determined according to the historical call information of the function by the attack code;

[0050] If the monitoring information indicates that the monitoring function is called, the process that calls the monitoring function is used as the target process.

[0051] It should be noted that the monitoring function is determined according to the historical call information of the function by the attack code and is a function with a relatively high possibility of being called by the attack code. Since space is allocated to each process in both the kernel and application layers when the process runs, the monitoring of the call of the monitoring function can be achieved through both the kernel and application layers, thereby triggering the detection of the attack code.

[0052] Further, the obtaining of the monitoring information on whether the monitoring function is called includes:

[0053] Obtaining the monitoring information on whether the monitoring function monitored through the kernel is called, wherein the monitoring functions monitored through the kernel include at least one of the following: execve, socketcall, bind, connect;

[0054] And / or, obtaining the monitoring information on whether the monitoring function monitored through the application layer is called, wherein the monitoring functions monitored through the application layer include at least one of the following: execve, execl, execlp, execle, execv, execvp, execvpe, bind, connect, system.

[0055] Among them, the obtaining of the monitoring information on whether the monitoring function monitored through the kernel is called specifically includes: (protection driver module) setting the monitoring function monitored through the kernel as a hook point and detecting whether the monitoring function at the hook point is called through hook detection.

[0056] Among them, the obtaining of the monitoring information on whether the monitoring function monitored through the application layer is called specifically includes: (protection driver module) pre-generating call check code for checking whether the monitoring function is called and injecting the call check code into the process (such as a web server process) through LD_PRELOAD or / etc / ld.so.preload to replace the monitoring function that is easily called by the attack code.

[0057] Since the monitoring function is a function that is very likely to be called by the attack code, when it is detected that a certain process calls the set monitoring function, then the process also has a relatively high probability of being attacked by the attack code. Therefore, this process can be used as the target process, and then it can be determined whether it is attacked by the attack function through the return address of each calling function of the target process.

[0058] In this embodiment, the monitoring information of the monitoring function narrows the range of functions that need to be detected for the attack code, improves the effectiveness of the attack code detection process, and avoids the ineffective occupation of system resources.

[0059] Further, on the basis of the above embodiments, the obtaining of the return address of the calling function includes:

[0060] Obtaining the function stack frame of the calling function from the kernel and / or obtaining the function stack frame of the calling function from the application layer;

[0061] Obtaining the return address according to the function stack frame of the calling function.

[0062] Since space is allocated for the process both in the kernel and the application layer when the process is running, the function stack frame of the calling function of the process can be obtained through both the kernel and the application layer. As Figure 2 shown, the return address of the calling function can be read from each stack frame.

[0063] In this embodiment, the obtaining of the function stack frame of the calling function is realized through the kernel and / or the application layer, and then the return address of each calling function is obtained through the function stack frame of the calling function, so as to realize the judgment of whether there is an attack code in the system.

[0064] Further, on the basis of the above embodiments, the obtaining of the function stack frame of the calling function from the kernel includes:

[0065] Obtaining the user-mode context structure saved in the kernel stack when the target process enters the kernel from the kernel stack;

[0066] Determining the base address of the first function stack frame within the range of the target process stack according to the user-mode context structure as the first base address;

[0067] Obtaining each function stack frame within the range of the target process stack starting from the first base address to obtain the function stack frame of the calling function.

[0068] It should be noted that the base address of the function stack frame represents the starting position of the function stack frame. Since the function stack frames within the target process stack are stored in sequence according to the calling relationship of functions in the target process, starting from the first base address and following the structural characteristics of the stack itself, each function stack frame from the stack starting address to the stack top within the target process stack can be traversed.

[0069] When the process runs in the application layer, it is in the user mode. When the process runs in the kernel mode, it is in the kernel mode. During the process of running, the process enters the kernel mode through a system call. When the process enters the kernel mode, the context information when executing in the user mode will be transferred into the kernel. Therefore, all the information of the called functions of the process can also be obtained through the kernel. The user context structure corresponding to the context information when executing in the user mode contains the addresses of each function stack frame within the process stack range. Thus, the base address of the first function stack frame can be obtained through the user context structure, and then starting from the base address of the first function stack frame, each function stack frame within the process stack range can be traversed to obtain each function stack frame within the process stack range.

[0070] For the kernel, (the protection driver module) can obtain the return functions in each function stack frame within the target process stack through the check function A in the kernel, form a function call chain, traverse each return address in the function call chain, and determine whether any return address does not belong to the system configuration address. Figure 3 The process diagram for obtaining the function call chain through the kernel provided in this embodiment is shown in Figure 3 , and the process includes:

[0071] Obtain the user context structure pt_regs from the kernel stack of the target process;

[0072] Obtain the current user mode stack frame base address bp from pt_regs;

[0073] Traverse all the stack frames upward along bp and save the return address of each stack frame into an array. This array is the data structure for storing the call chain.

[0074] Specifically, for the kernel, (the protection driver module) can obtain the function call chain through the check function A in the kernel, and then obtain the return address of each called function through the function call chain, and determine whether there is attack code in the system according to the return address of each called function. Figure 4Schematic diagram of the process for detecting attack code through the kernel provided in this embodiment. The process includes: when the (protection driver module) hooks into system calls execve, socketcall, bind, and connect, it enters the check function A. The check function A first obtains the call chain from the user-mode context of the target process hooked. The call chain contains the return addresses of all stack frames. It loops through each return address to determine whether it comes from an ELF file. If it is found that a return address does not come from an ELF file after the determination, it is very likely that the shellcode code is being executed, and an alarm log is generated. If all return addresses come from ELF files, then this check is completed.

[0075] In this embodiment, the return address of each called function is obtained through the kernel stack, so as to judge whether there is attack code according to the return address. When attack code is detected, an alarm is generated in time to process the attack code in time and ensure system security.

[0076] Further, on the basis of the above embodiments, the obtaining of the function stack frame of the called function from the application layer includes:

[0077] Obtain the base address of the first function stack frame within the range of the target process stack from the user stack of the application layer as the second base address;

[0078] Obtain each function stack frame within the range of the target process stack starting from the second base address to obtain the function stack frame of the called function.

[0079] Specifically, the function stack frames within the range of the target process stack are stored in sequence according to the call relationship of the functions of the target process. Therefore, starting from the second base address and in accordance with the structural characteristics of the stack itself, each function stack frame from the stack start address to the stack top within the range of the target process stack can be traversed.

[0080] For the application layer, the (protection driver module) can obtain the return functions in each function stack frame within the range of the target process stack through the check function B to form a function call chain, traverse each return address of the function call chain, and judge whether there is any return address that does not belong to the system configuration address. Among them, the check function B is a function pre-injected into the target program to be detected for attack code. Specifically, after the (protection driver module) detects that the monitoring function is called through the call of the check code, it directly reads the stack frame base address bp through the check function B injected into the target process of the monitoring function, and traverses starting from the stack frame base address bp to obtain the entire function call chain.

[0081] In this embodiment, the application layer is used to obtain the return address of each calling function, and then determine whether there is attack code based on the return address. When attack code is detected, an alarm is generated in a timely manner to handle the attack code in a timely manner and ensure system security.

[0082] Further, based on the above embodiments, before the return address does not belong to the system configuration address, the following steps are further included:

[0083] Determine the virtual memory block structure corresponding to the return address through the virtual memory management structure in the memory, and determine whether the return address belongs to the system configuration address according to the address pointed to by the member describing the mapped file in the virtual memory block structure;

[0084] And / or, obtain a memory layout file representing the memory layout from the application layer, obtain the line content where the return address is located from the memory layout file, and determine whether the return address belongs to the system configuration address according to the file path in the line content.

[0085] When the address pointed to by the variable of the member describing the mapped file in the virtual memory block structure does not belong to the system configuration address, the return address does not belong to the system configuration address, and there is attack code in the system.

[0086] When the file path in the line content does not include a file path belonging to the system configuration address, the return address does not belong to the system configuration address, and there is attack code in the system.

[0087] Specifically, taking a Linux server as an example, the following method can be used to specifically determine whether the return address points to an executable file of the system for memory:

[0088] Obtain the virtual memory management structure mm_struct of the target process;

[0089] Traverse the red-black tree nodes on mm_struct to find the vm_area_struct structure (i.e., the virtual memory block structure) where the return address is located;

[0090] Check whether the vm_file member (i.e., the member describing the mapped file) variable of the vm_area_struct structure points to an ELF file. If not, it indicates that the return address may come from the shellcode being executed.

[0091] Among them, the red-black tree node is a binary search tree in the virtual memory management structure mm_struct, and the vm_area_struct structure where the return address is located can be quickly found through the red-black tree node.

[0092] Specifically, taking a Linux server as an example, for the application layer, the following method can be specifically used to determine whether the return address points to an executable file of the system:

[0093] Read the / proc / self / maps file (i.e., the memory layout file).

[0094] Parse each line of the memory layout file. Each line of the / proc / self / maps file represents a virtual memory block. The line content of each line includes the start address and end address of the virtual memory block. If it is a memory mapping of an ELF file, the path of the ELF file will also be displayed;

[0095] Judge whether there is a corresponding ELF file path in the line where the return address is located. If not, it means that the return address may come from the shellcode being executed.

[0096] In this embodiment, a process for judging whether there is attack code in the system is provided from the memory and the application layer, realizing the detection of attack code. Without modeling, the detection process is simple and the detection efficiency is relatively high.

[0097] This application monitors the process call chain in the way of kernel driver, and has better performance than other methods; traversing each return address on the call chain and making judgments can stably detect the shellcode code being executed.

[0098] Figure 5 It is a structural block diagram of an attack code detection device provided for this embodiment. See Figure 5 , which includes an acquisition module 501 and a determination module 502;

[0099] The acquisition module 501 is used to acquire the return address of the calling function; wherein, the calling function is a function called by the target process of the system;

[0100] The determination module 502 is used to determine that there is attack code in the system if the return address does not belong to the system configuration address; the system configuration address is the code segment address of the executable file loaded by the target process.

[0101] The attack code detection device provided in this embodiment is applicable to the attack code detection methods provided in the above embodiments, and will not be elaborated here.

[0102] This embodiment provides an attack code detection device, which obtains the return address of the called function within the process stack range of the system. If there is a return address that does not belong to the system configuration address for storing system executable files, it is determined that there is attack code in the system. By directly obtaining the return address of the called function, the detection of attack code is realized, without the need to establish a feature library, and the recognition process is simple, which is beneficial to improving the recognition efficiency of attack code.

[0103] According to the present invention, an attack code detection device is provided. On the above basis, before obtaining the return address of the called function, the method further includes:

[0104] Obtaining monitoring information on whether the monitoring function is called; wherein, the monitoring function is determined according to the historical call information of the function by the attack code.

[0105] If the monitoring information is that the monitoring function is called, the process that calls the monitoring function is used as the target process.

[0106] According to the present invention, an attack code detection device is provided. On the above basis, the obtaining of the return address of the called function includes:

[0107] Obtaining the function stack frame of the called function from the kernel and / or obtaining the function stack frame of the called function from the application layer;

[0108] Obtaining the return address according to the function stack frame of the called function.

[0109] According to the present invention, an attack code detection device is provided. On the above basis, the obtaining of the function stack frame of the called function from the kernel includes:

[0110] Obtaining the user-mode context structure saved in the kernel stack when the target process enters the kernel from the kernel stack;

[0111] Determining the base address of the first function stack frame within the target process stack range according to the user-mode context structure as the first base address;

[0112] Obtaining each function stack frame within the target process stack range starting from the first base address to obtain the function stack frame of the called function.

[0113] According to the present invention, an attack code detection device is provided. On the above basis, the obtaining of the function stack frame of the called function from the application layer includes:

[0114] Obtaining the base address of the first function stack frame within the target process stack range from the user stack of the application layer as the second base address;

[0115] Starting from the second base address, obtain each function stack frame within the range of the target process stack to obtain the function stack frame of the calling function.

[0116] According to the present invention, an attack code detection device is provided. On the basis described above, before the return address does not belong to the system configuration address, it further includes:

[0117] Determine the virtual memory block structure corresponding to the return address through the virtual memory management structure in the memory, and determine whether the return address belongs to the system configuration address according to the address pointed to by the member describing the mapped file in the virtual memory block structure;

[0118] And / or, obtain a memory layout file representing the memory layout from the application layer, obtain the line content where the return address is located from the memory layout file, and determine whether the return address belongs to the system configuration address according to the file path in the line content.

[0119] Figure 6 Illustrate a schematic diagram of the physical structure of an electronic device, as Figure 6 shown. The electronic device may include: a processor 610, a communication interface 620, a memory 630, and a communication bus 640. Among them, the processor 610, the communication interface 620, and the memory 630 complete mutual communication through the communication bus 640. The processor 610 can call the logical instructions in the memory 630 to execute the attack code detection method, and the method includes:

[0120] Obtain the return address of the calling function; wherein, the calling function is a function called by the target process of the system;

[0121] If the return address does not belong to the system configuration address, there is attack code in the system; the system configuration address is the code segment address of the executable file loaded by the target process.

[0122] In addition, when the logical instructions in the above-mentioned memory 630 can be implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0123] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the attack code detection method provided by each of the above methods. The method includes:

[0124] Obtain the return address of the calling function; wherein, the calling function is a function called by the target process of the system;

[0125] If the return address does not belong to the system configuration address, there is attack code in the system; the system configuration address is the code segment address of the executable file loaded by the target process.

[0126] On another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is implemented to execute the attack code detection method provided by each of the above. The method includes:

[0127] Obtain the return address of the calling function; wherein, the calling function is a function called by the target process of the system;

[0128] If the return address does not belong to the system configuration address, there is attack code in the system; the system configuration address is the code segment address of the executable file loaded by the target process.

[0129] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative labor.

[0130] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0131] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or equivalently replace some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for detecting attack codes, characterized in that, Including: Obtain the return address of the calling function; wherein, the calling function is a function called by the target process of the system; If the return address does not belong to the system configuration address, there is attack code in the system; the system configuration address is the code segment address of the executable file loaded by the target process; Before obtaining the return address of the calling function, the method further includes: Obtain monitoring information on whether the monitoring function is called; wherein, the monitoring function is determined according to the historical call information of the function by the attack code; If the monitoring information indicates that the monitoring function is called, the process that calls the monitoring function is used as the target process; Before the return address does not belong to the system configuration address, it further includes: Determine the virtual memory block structure corresponding to the return address through the virtual memory management structure in the memory, and determine whether the return address belongs to the system configuration address according to the address pointed to by the member describing the mapped file in the virtual memory block structure; And / or, obtain a memory layout file representing the memory layout from the application layer, obtain the line content where the return address is located from the memory layout file, and determine whether the return address belongs to the system configuration address according to the file path in the line content.

2. The attack code detection method according to claim 1, wherein The obtaining of the return address of the calling function includes: Obtain the function stack frame of the calling function from the kernel and / or obtain the function stack frame of the calling function from the application layer; Obtain the return address according to the function stack frame of the calling function.

3. The attack code detection method according to claim 2, wherein The obtaining of the function stack frame of the calling function from the kernel includes: Obtain the user-mode context structure saved in the kernel stack when the target process enters the kernel from the kernel stack; Determine the base address of the first function stack frame within the target process stack range according to the user-mode context structure as the first base address; Obtain each function stack frame within the target process stack range starting from the first base address to obtain the function stack frame of the calling function.

4. The attack code detection method according to claim 2, wherein The obtaining of the function stack frame of the calling function from the application layer includes: Obtain the base address of the first function stack frame within the target process stack range from the user stack in the application layer as the second base address; Obtain each function stack frame within the target process stack range starting from the second base address to obtain the function stack frame of the calling function.

5. An attack code detection device, characterized in that, Including: An obtaining module, configured to obtain the return address of the calling function; wherein, the calling function is a function called by the target process of the system; A determining module, configured to determine that there is attack code in the system if the return address does not belong to the system configuration address; the system configuration address is the code segment address of the executable file loaded by the target process; Before obtaining the return address of the calling function, it further includes: Obtain monitoring information on whether the monitoring function is called; wherein, the monitoring function is determined according to the historical call information of the function by the attack code; If the monitoring information indicates that the monitoring function is called, the process that calls the monitoring function is used as the target process; Before the return address does not belong to the system configuration address, it further includes: Determine the virtual memory block structure corresponding to the return address through the virtual memory management structure in the memory, and determine whether the return address belongs to the system configuration address according to the address pointed to by the member describing the mapped file in the virtual memory block structure; And / or, obtain a memory layout file representing the memory layout from the application layer, obtain the line content where the return address is located from the memory layout file, and determine whether the return address belongs to the system configuration address according to the file path in the line content.

6. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the attack code detection method according to any one of claims 1 to 4.

7. A non-transitory readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by a processor, it implements the steps of the attack code detection method according to any one of claims 1 to 4.

8. A computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the attack code detection method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Aggression detection device and method using vulnerable point of program

    JP2015141718A