Backdoor Detection Method and System

Through monitoring target events, stack backtracking and cluster analysis, the backdoor program in the system is detected, which solves the problem of lack of effective backdoor detection in the existing technology, and realizes effective detection and protection of system backdoors.

CN114692145BActive Publication Date: 2025-06-24QI AN XIN SECURITY TECH ZHUHAI CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011578496.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-28
Publication Date
2025-06-24
Estimated Expiration
2040-12-28

AI Technical Summary

Technical Problem

The existing technology lacks effective backdoor detection methods, which makes it difficult for backdoor programs to be discovered and eliminated when they exist in the system, becoming a vulnerability for hackers.

Method used

By monitoring the target event, performing stack traceback, key functions and their call sequences are obtained, and suspicious backdoor sequences are output through cluster analysis to achieve effective detection of system backdoors.

Benefits of technology

This method can effectively detect backdoor programs in the system, make up for the backdoor detection vacancy in the prior art, and improve the protection ability of information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114692145B_ABST
    Figure CN114692145B_ABST
Patent Text Reader

Abstract

The present application provides a backdoor detection method, characterized in that the method includes: monitoring a target event; performing a stack traceback on the current thread of the target event to obtain key functions related to the target event and the call sequence of the key functions; performing clustering analysis on the key functions and the call sequence of the key functions, and outputting a suspicious backdoor sequence. The technical solution provided by the present application can effectively detect system backdoors and fill the gap in backdoor detection for the information security field by obtaining the call sequence of key functions through stack traceback and outputting a suspicious backdoor sequence through clustering analysis of the call sequence of the key functions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular, to a backdoor detection method, system, computer device, and computer-readable storage medium. Background Art

[0002] A backdoor program generally refers to a program method that bypasses security controls to obtain access to a program or system. During the software development stage, programmers often create backdoor programs in the software to modify defects in the program design. However, if these backdoors are known to others or not removed before the software is released, these backdoors become security risks and are easily exploited by hackers as vulnerabilities.

[0003] Backdoor discovery is a major problem in the field of information security, and there is currently no effective backdoor detection method. Summary of the Invention

[0004] The purpose of this application is to provide a backdoor detection method, system, computer device, and computer-readable storage medium for solving the backdoor detection problem in the field of information security.

[0005] An aspect of an embodiment of this application provides a backdoor detection method, the method including: monitoring a target event; performing a stack trace on the current thread of the target event to obtain key functions related to the target event and a call sequence of the key functions; performing clustering analysis on the key functions and the call sequence of the key functions, and outputting a suspicious backdoor sequence.

[0006] Optionally, the performing a stack trace on the current thread of the target event includes: traversing the function stack of the current thread to find key functions related to the target event and a call sequence of the key functions; recording the key functions and the call sequence of the key functions.

[0007] Optionally, the traversing the function stack of the current thread to find key functions related to the target event and a call sequence of the key functions includes: uniformly numbering all key functions involved in all target events to be monitored, and establishing a key function list; traversing function call information in the function stack, comparing it with the key function list, and finding key functions related to the target event; performing a traceback on the key functions to find a call sequence of the key functions.

[0008] Optionally, the call sequence of the key functions includes the RVA of at least one function called by the key function and module information to which it belongs.

[0009] Optionally, recording the critical function and the call sequence of the critical function includes: recording the serial number of the critical function, the RVA of at least one function called by the critical function, and the module information to which it belongs; transmitting the serial number of the critical function, the RVA of at least one function called by the critical function, and the module information to the server through the terminal.

[0010] Optionally, clustering analysis of the critical function and the call sequence of the critical function to output a suspicious backdoor sequence includes: performing clustering analysis on the call sequence of the critical function according to the operating system type of the terminal; performing clustering analysis on the call sequence of the critical function according to the behavior type of the target event.

[0011] Optionally, clustering analysis of the critical function and the call sequence of the critical function to output a suspicious backdoor sequence includes: if no suspicious call sequence appears for the critical function in the first time period and a suspicious call sequence appears for the critical function in the second time period, then output the suspicious call sequence as the suspicious backdoor sequence; or if the average number of times the suspicious call sequence appears for the critical function in the first time period is N and the number of times the suspicious call sequence appears for the critical function in the second time period is much greater than N, then output the suspicious call sequence of the critical function as the suspicious backdoor sequence.

[0012] Another aspect of the embodiments of the present application provides a backdoor detection system, which is characterized by including: a monitoring module for monitoring target events; a backtracking module for performing stack backtracking on the current thread of the target event to obtain the critical function related to the target event and the call sequence of the critical function; an analysis module for performing clustering analysis on the critical function and the call sequence of the critical function to output a suspicious backdoor sequence.

[0013] Another aspect of the embodiments of the present application provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the computer program, the steps of the above-mentioned backdoor detection method are implemented.

[0014] Another aspect of the embodiments of the present application provides a computer-readable storage medium, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the computer program, the steps of the above-mentioned backdoor detection method are implemented.

[0015] The backdoor detection method, system, device and computer-readable storage medium provided by the embodiments of the present application can obtain the call sequence of key functions through stack backtracking, and output a suspicious backdoor sequence by clustering and analyzing the call sequence of the key functions, which can effectively detect system backdoors and make up for the gap in backdoor detection in the information security field. Description of the Drawings

[0016] Figure 1 Schematically shows an application environment diagram of the backdoor detection method according to an embodiment of the present application;

[0017] Figure 2 Schematically shows a flowchart of the backdoor detection method according to Embodiment 1 of the present application;

[0018] Figure 3 For Figure 2 a sub-step diagram of step S202 in

[0019] Figure 4 For Figure 3 a sub-step diagram of steps S300 and S302 in

[0020] Figure 5 For Figure 2 a sub-step diagram of step S204 in

[0021] Figure 6 For Figure 2 another sub-step diagram of step S204 in

[0022] Figure 7 Schematically shows a specific example diagram of the terminal information collection process in the backdoor detection method;

[0023] Figure 8 Schematically shows a specific example diagram of the server analysis process in the backdoor detection method;

[0024] Figure 9 Schematically shows a block diagram of the backdoor detection system according to Embodiment 2 of the present application; and

[0025] Figure 10 Schematically shows a schematic diagram of the hardware architecture of a computer device suitable for implementing the backdoor detection method according to Embodiment 3 of the present application. Detailed Embodiments

[0026] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.

[0027] It should be noted that in the embodiments of the present application, the descriptions involving "first", "second", etc. are only for descriptive purposes, and should not be construed as indicating or implying their relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one such feature. Additionally, the technical solutions between various embodiments may be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement them. When the combination of technical solutions results in contradictions or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection required by the present application.

[0028] In the description of the present application, it should be understood that the numerical labels before the steps do not identify the sequence of execution of the steps, but are only used to conveniently describe the present application and distinguish each step. Therefore, it should not be construed as a limitation to the present application.

[0029] The following are the term explanations involved in the present application:

[0030] Memory, also known as internal memory and main memory, is used to load and run software, temporarily store the operation data of the processor, etc.

[0031] API: It is the abbreviation of Application Programming Interface, and it is the "interface between the program and the operating system" provided by the operating system to programmers.

[0032] RVA: It is the abbreviation of Relative Virtual Address, which is a relative address and can also be said to be an offset.

[0033] Target event: A key behavior on the execution path of malicious code attacks at the kernel layer (such as: the necessary path), such as: creating a process, opening a file, modifying the registry, loading dynamic libraries, modifying memory, etc.

[0034] Key function: Each target event can be implemented by calling API functions in the Windows operating system, and these API functions can be called key functions.

[0035] Thread: Target events are all executed through threads, and CPU resources and memory resources are scheduled in units of threads.

[0036] Call sequence of key functions: Also known as the call path of key functions, the memory instruction sequence of key functions, which refers to the set of functions called by key functions, and refers to the RVA and module information of at least one function called by the key function.

[0037] Function stack: It refers to the area in memory used to store function call information, including the key functions of the target event and the call sequence.

[0038] Stack backtrace refers to the process of deriving the hierarchical relationship of function calls between functions upwards.

[0039] Figure 1 Schematically shows an environmental application diagram of the backdoor detection method according to an embodiment of the present application. In an exemplary embodiment, as Figure 1 shown, the server 10 can be connected to multiple terminals (electronic devices) 16 through the network 12 to form a backdoor detection system.

[0040] The server 10 can be composed of a single or multiple computer devices, such as rack-mounted servers, blade servers, tower servers, or cabinet servers (including independent servers, or server clusters composed of multiple servers), etc.

[0041] The network 12 can include various network devices, such as routers, switches, multiplexers, hubs, modems, bridges, repeaters, firewalls, proxy devices, and / or the like. The network 12 can include physical links, such as coaxial cable links, twisted pair cable links, fiber optic links, their combinations, and / or the like. The network 12 can include wireless links, such as cellular links, satellite links, Wi-Fi links, and / or the like.

[0042] The multiple terminals (electronic devices) 16 can be configured to access the content and services of the server 10. The multiple terminals (electronic devices) 16 can include any type of computer device, such as terminal devices: mobile devices, tablet devices, laptop computers, smart devices (e.g., smart clothing, smart watches, smart speakers, smart glasses), virtual reality headsets, gaming devices, set-top boxes, digital streaming devices, robots, in-vehicle terminals, smart TVs, TV boxes, e-book readers, MP3 (Moving Picture Experts Group Audio Layer III) players, MP4 (Moving Picture Experts Group Audio Layer IV) players, etc.

[0043] The present application aims to provide a backdoor detection solution. At multiple terminals 16, the call sequence of key functions is obtained through stack backtrace. For example, the key function can be an API function, and the call sequence of the key function can also be called the call path of the API function; at the server 10, the suspicious backdoor sequence is output by clustering and analyzing the call sequence of the key functions, which can effectively detect system backdoors and fill the gap in backdoor detection in the information security field.

[0044] Multiple embodiments will be provided below, and each of the embodiments provided below can be used to implement the backdoor detection scheme described above. For ease of understanding, the backdoor detection system composed of the terminal 16 and the server 10 will be used as the execution subject for exemplary description below.

[0045] Embodiment 1

[0046] Figure 2 The flowchart of the backdoor detection method according to Embodiment 1 of the present application is schematically shown.

[0047] As Figure 2 shown, the backdoor detection method of the backdoor detection system may include steps S200 to S204, where:

[0048] Step S200, monitor the target event.

[0049] As an example, the backdoor detection system monitors the target event at the kernel layer, and the target event refers to key behaviors on the execution path of malicious code attacks at the kernel layer (such as: the must path), such as: creating a process, opening a file, modifying the registry, loading a dynamic library, modifying memory, etc.

[0050] Step S202, perform a stack trace on the current thread of the target event to obtain the key functions related to the target event and the call sequence of the key functions.

[0051] As an example, all target events are executed through threads, and CPU resources and memory resources are scheduled in units of threads. If the target event is to create a process, when the process creation behavior (target event) occurs on the terminal (such as: a certain host), a stack trace is performed on the current thread of the process creation.

[0052] As an example, as Figure 3 shown, step S202 may include steps S300 to S302. Where: Step S300, traverse the function stack of the current thread to find the key functions related to the target event and the call sequence of the key functions; Step S302, record the key functions and the call sequence of the key functions.

[0053] As an example, as Figure 4As shown, step S300 may include steps S400 to S404, and step S302 may include steps S406 to S408. Among them: Step S400, uniformly number all the key functions involved in all target events to be monitored, and establish a key function list; Step S402, traverse the function call information in the function stack, compare it with the key function list, and find the key functions related to the target event; Step S404, backtrack the key functions to find the call sequence of the key functions. In an exemplary embodiment, the call sequence of the key functions includes the RVA and the module information of at least one function called by the key function. Step S406, record the serial number of the key function, the RVA and the module information of at least one function called by the key function; Step S408, transmit the serial number of the key function, the RVA and the module information of at least one function called by the key function to the server 10 through the terminal 16.

[0054] In an exemplary embodiment of the present application, each target event can be implemented by calling API functions (key functions) in the Windows operating system. For example, to implement the creation of a process, the API functions that can be called in the Windows operating system include: WinExec\CreateProcess\CreateProcessInternal\CreateProcessAsUser\NtCreateUserProcess, etc. That is to say, one or more of these API functions can be called to implement the creation of a process. Uniformly number all the key functions involved in all target events to be monitored. For example: No. 1 is WinExec, No. 2 is CreateProcess, No. 3 is CreateProcessInternal, No. 4 is CreateProcessAsUser, No. 5 is NtCreateUserProcess, and so on. Uniformly numbering the key functions of the target event is to facilitate the unified management of these key functions.

[0055] It should be noted that the numbering method of the key functions of the target event in the present application can be various and is not limited to the above examples. For example: the key functions of the first target event (such as creating a process) can be uniformly numbered first, and then the key functions of the second target event (such as opening a file) can be uniformly numbered, or the key functions of the two target events can be numbered alternately.

[0056] In an exemplary embodiment of the present application, the call sequence of a key function, also known as the call path of the key function or the memory instruction sequence of the key function, refers to the set of functions called by the key function, corresponding to the memory addresses of the functions called by the key function. According to the current environment, the memory addresses can be converted into RVA data for calling functions of a certain module. Windows system modules such as kernerl32.dll, ntdll.dll, etc. export many functional API functions for users to call. For example, assuming that the call sequence of key function C is functions B and A, then the call sequence of key function C refers to: RVA1 of function B and the module information to which it belongs, RVA2 of function A and the module information to which it belongs. The modules to which RVA 1 and RVA 2 belong can be the same module or different modules.

[0057] Please go back to Figure 2 , step S204, perform clustering analysis on the key function and the call sequence of the key function, and output a suspicious backdoor sequence.

[0058] As an example, as Figure 5 shown, step S204 may include steps S500 to S502. Among them: step S500, perform clustering analysis on the call sequence of the key function according to the operating system type of the terminal. Step S502, perform clustering analysis on the call sequence of the key function according to the behavior type of the target event.

[0059] In an exemplary embodiment, (1) first perform clustering analysis on the call sequences of the key functions of terminals with the same operating system. For example: perform clustering analysis on the call sequences of the key functions of WIN7 terminals, and perform clustering analysis on the call sequences of the key functions of WIN10 terminals; (2) then perform clustering analysis on the call sequences of the key functions with the same behavior type. For example: perform clustering analysis on the call sequences of the key functions for creating processes, perform clustering analysis on the call sequences of the key functions for opening files, perform clustering analysis on the call sequences of the key functions for modifying the registry, perform clustering analysis on the call sequences of the key functions for loading dynamic libraries, and perform clustering analysis on the call sequences of the key functions for modifying memory.

[0060] As an example, as Figure 6As shown, step S204 may further include step S600. Step S600: If within the first time period, no suspicious call sequence has ever occurred for the critical function, but within the second time period, the suspicious call sequence has occurred for the critical function, then output the suspicious call sequence as the suspicious backdoor sequence; or if within the first time period, the average number of occurrences of the suspicious call sequence of the critical function is N, but within the second time period, the number of occurrences of the suspicious call sequence of the critical function is much greater than N, then output the suspicious call sequence of the critical function as the suspicious backdoor sequence.

[0061] In an exemplary embodiment of the present application, when the behavior of creating a process (target event) occurs on a certain host (terminal), perform a stack backtrace of the current thread, obtain the call sequence of the memory instructions of the current behavior (target event), and traverse from bottom to top to find the API calls related to the classification of the current behavior (i.e., find the critical functions related to the target behavior). For example, first find NtCreateUserProcess (the first critical function), then find CreateProcess (the second critical function), and then find WinExec (the third critical function). Record the API number where each critical function is located, the RVA of the upper few layers of calls that call this API, and the module information, and then package the data and send it to the server. The server receives the data sent by all terminal hosts, classifies and aggregates it according to the API number, module, RVA1, and RVA2, and performs dynamic monitoring to find two types of data that meet the conditions as the suspicious backdoor sequence: (1) There are very few call paths for a certain critical function call; (2) The call paths of a certain critical function are rarely triggered but suddenly appear in large numbers at a certain time. As an example, these two types of data can be found through Figure 6 step S600.

[0062] Specifically, the first type of data may refer to: If within the first time period (for example: last month or last week, or it can also be the previous few months or weeks), no suspicious call sequence has ever occurred for the critical function, but within the second time period (for example: this month or this week), the suspicious call sequence has occurred for the critical function, then output the suspicious call sequence as the suspicious backdoor sequence. The second type of data may refer to: If within the first time period (for example: last month or last week, or it can also be the previous few months or weeks), the average number of occurrences of the suspicious call sequence of the critical function is N, but within the second time period (for example: this month or this week), the number of occurrences of the suspicious call sequence of the critical function is much greater than N (for example: it may be an exponential multiple of N), then output the suspicious call sequence of the critical function as the suspicious backdoor sequence.

[0063] In the above exemplary embodiments, the present case detects backdoors based on the call sequence of key functions. This call sequence is a vertical call sequence, rather than a horizontal call sequence. The horizontal call sequence is generally used for malicious behavior inspection, while the vertical call sequence can be used not only for malicious behavior inspection but also for discovering backdoors. The vertical call sequence refers to the API number where each key function is located, the RVA of the upper several layers of calls that call this API, and the module information where they are located.

[0064] As Figure 7 shown, for the convenience of understanding, a specific example of the terminal information collection process is provided below.

[0065] Step S700, intercept the occurrence of the target event at the kernel layer.

[0066] Step S702, perform a stack backtrace on the current thread.

[0067] Step S704, traverse the function stack.

[0068] Step S706, determine whether a key function (such as an API function) related to the target event is found in the function stack.

[0069] If a key function related to the target event is found, in step S708, record the key function and the call sequence.

[0070] If no key function related to the target event is found, in step S710, determine whether the function stack traversal is completed.

[0071] If the function stack traversal is not completed, return to step S704 to continue traversing the function stack.

[0072] If the function stack traversal is completed, in step S712, the terminal 16 sends the key function and the call sequence to the server 10.

[0073] As Figure 8 shown, for the convenience of understanding, a specific example of the server analysis process is provided below. The server receives the API call sequences (call sequences of key functions) of the first terminal, the second terminal, and the Nth terminal, performs clustering analysis on these API call sequences (call sequences of key functions), and outputs suspicious backdoor sequences. The server analysis process can be referred to the description in the previous text Figure 5 and Figure 6 therefore, it will not be elaborated here.

[0074] Embodiment 2

[0075] Figure 9A block diagram of a backdoor detection system according to Embodiment 2 of the present application is schematically shown. The backdoor detection system can be divided into one or more program modules. One or more program modules are stored in a storage medium and executed by one or more processors to complete the embodiments of the present application. The program modules referred to in the embodiments of the present application refer to a series of computer program instruction segments that can complete specific functions. The following description will specifically introduce the functions of each program module in this embodiment.

[0076] As Figure 9 shown, the backdoor detection system 900 may include a monitoring module 902, a backtracking module 904, and an analysis module 906.

[0077] The monitoring module 902 is used to monitor target events.

[0078] As an example, the monitoring module 902 is further used to monitor the target events at the kernel layer. The target events refer to key behaviors on the execution path of malicious code attacks at the kernel layer (such as: the must path), such as: creating a process, opening a file, modifying the registry, loading a dynamic library, modifying memory, etc.

[0079] The backtracking module 904 is used to perform stack backtracking on the current thread of the target event to obtain the key functions related to the target event and the call sequence of the key functions.

[0080] In an exemplary embodiment, the backtracking module 904 is further used to traverse the function stack of the current thread to find the key functions related to the target event and the call sequence of the key functions, and record the key functions and the call sequence of the key functions.

[0081] As an example, the backtracking module 904 is further used to uniformly number all the key functions involved in all the target events to be monitored, establish a key function list, traverse the function call information in the function stack, compare it with the key function list, find the key functions related to the target event, backtrack the key functions, and find the call sequence of the key functions.

[0082] In an exemplary embodiment, the call sequence of the key functions includes the RVA of at least one function called by the key function and the module information to which it belongs. The backtracking module 904 is further used to record the serial number of the key function, the RVA of at least one function called by the key function and the module information to which it belongs, and transmit the serial number of the key function, the RVA of at least one function called by the key function and the module information to which it belongs to the server through the terminal.

[0083] The analysis module 906 is used to perform clustering analysis on the key functions and the call sequence of the key functions, and output a suspicious backdoor sequence.

[0084] In an exemplary embodiment, the analysis module 906 is further configured to perform clustering analysis on the call sequences of the key functions according to the operating system type of the terminal, and perform clustering analysis on the call sequences of the key functions according to the behavior type of the target event.

[0085] As an example, if no suspicious call sequence of the key function appears in the first time period, but a suspicious call sequence of the key function appears in the second time period, the analysis module 906 outputs the suspicious call sequence as the suspicious backdoor sequence. If the average number of occurrences of the suspicious call sequence of the key function in the first time period is N, but the number of occurrences of the suspicious call sequence of the key function in the second time period is much greater than N, the analysis module 906 outputs the suspicious call sequence of the key function as the suspicious backdoor sequence.

[0086] Embodiment III

[0087] Figure 10 Schematically shows a hardware architecture diagram of a computer device 1000 suitable for implementing the backdoor detection method according to Embodiment III of the present application. The computer device 1000 can be a backdoor detection system composed of a terminal 16 and a server 10, or can be a part of the backdoor detection system. In this embodiment, the computer device 1000 is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions. For example, it can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a rack server, a blade server, a tower server or a cabinet server (including an independent server, or a server cluster composed of multiple servers), a gateway, etc. As Figure 10 shown, the computer device 1000 at least includes, but is not limited to: a memory 1010, a processor 1020, a network interface 1030, and a vibration element 1040 that can be communicatively linked to each other through a system bus. Among them:

[0088] The memory 1010 includes at least one type of computer-readable storage medium. The readable storage medium includes flash memory, hard disk, multimedia card, card-type memory (such as SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disc, etc. In some embodiments, the memory 1010 may be an internal storage module of the computer device 1000, such as the hard disk or memory of the computer device 1000. In other embodiments, the memory 1010 may also be an external storage device of the computer device 1000, such as a plug-in hard disk equipped on the computer device 1000, a Smart Media Card (SMC for short), a Secure Digital (SD) card, a Flash Card, etc. Of course, the memory 1010 may also include both the internal storage module and the external storage device of the computer device 1000. In this embodiment, the memory 1010 is generally used to store the operating system installed on the computer device 1000 and various application software, such as the program code of the backdoor detection method, etc. In addition, the memory 1010 may also be used to temporarily store various data that have been output or will be output.

[0089] In some embodiments, the processor 1020 may be a central processing unit (CPU for short), a controller, a microcontroller, a microprocessor, or other data processing chips. The processor 1020 is generally used to control the overall operation of the computer device 1000, such as performing control and processing related to data interaction or communication with the computer device 1000. In this embodiment, the processor 1020 is used to run the program code stored in the memory 1010 or process data.

[0090] The network interface 1030 may include a wireless network interface or a wired network interface, which is generally used to establish a communication link between the computer device 1000 and other computer devices. For example, the network interface 1030 is used to connect the computer device 1000 to an external terminal via a network, and to establish a data transmission channel and a communication link between the computer device 1000 and the external terminal. The network may be a wireless or wired network such as an enterprise intranet (Intranet), the Internet, the Global System of Mobile communication (GSM for short), Wideband Code Division Multiple Access (WCDMA for short), a 4G network, a 5G network, Bluetooth, Wi-Fi, etc.

[0091] It should be noted that Figure 10 Only the computer device with components 1010 - 1030 is shown, but it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively.

[0092] In this embodiment, the backdoor detection method stored in the memory 1010 can also be divided into one or more program modules and executed by one or more processors (processor 1020 in this embodiment) to complete the embodiments of the present application.

[0093] Embodiment 4

[0094] The present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the backdoor detection method in the embodiment are implemented.

[0095] In this embodiment, the computer-readable storage medium includes flash memory, hard disk, multimedia card, card-type memory (such as SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the computer-readable storage medium may be an internal storage unit of a computer device, such as the hard disk or memory of the computer device. In other embodiments, the computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk equipped on the computer device, a Smart Media Card (abbreviated as SMC), a Secure Digital (abbreviated as SD) card, a Flash Card, etc. Of course, the computer-readable storage medium may also include both the internal storage unit and the external storage device of the computer device. In this embodiment, the computer-readable storage medium is generally used to store the operating system and various application software installed on the computer device, such as the program code of the backdoor detection method in the embodiment. In addition, the computer-readable storage medium can also be used to temporarily store various data that have been output or will be output.

[0096] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the embodiments of the present application can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. Optionally, they can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order from here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to implement. In this way, the embodiments of the present application are not limited to any specific combination of hardware and software.

[0097] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application accordingly. Any equivalent structural or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be similarly included in the patent protection scope of the present application.

Claims

1. A backdoor detection method, characterized in that, The method includes: Monitoring a target event; Performing a stack trace on the current thread of the target event to obtain key functions related to the target event and the call sequence of the key functions; Performing clustering analysis on the key functions and the call sequence of the key functions, and outputting a suspicious backdoor sequence; wherein, the call sequence of the key functions is the call path of the key functions, the memory instruction sequence of the key functions, the set of functions called by the key functions, the RVA of at least one function called by the key functions, and the module information to which it belongs; The performing clustering analysis on the key functions and the call sequence of the key functions, and outputting a suspicious backdoor sequence includes: Performing clustering analysis on the call sequence of the key functions according to the operating system type of the terminal; Performing clustering analysis on the call sequence of the key functions according to the behavior type of the target event; The performing clustering analysis on the key functions and the call sequence of the key functions, and outputting a suspicious backdoor sequence includes: If no suspicious call sequence appears for the key function in the first time period and a suspicious call sequence appears for the key function in the second time period, then output the suspicious call sequence as the suspicious backdoor sequence; or If the average number of occurrences of the suspicious call sequence of the key function in the first time period is N and the number of occurrences of the suspicious call sequence of the key function in the second time period is much greater than N, then output the suspicious call sequence of the key function as the suspicious backdoor sequence.

2. The backdoor detection method according to claim 1, wherein The performing a stack trace on the current thread of the target event includes: Traversing the function stack of the current thread to find key functions related to the target event and the call sequence of the key functions; Recording the key functions and the call sequence of the key functions.

3. The backdoor detection method according to claim 2, wherein The traversing the function stack of the current thread to find key functions related to the target event and the call sequence of the key functions includes: Uniformly numbering all key functions involved in all target events to be monitored and establishing a key function list; Traversing the function call information in the function stack and comparing it with the key function list to find key functions related to the target event; Performing a backtrace on the key functions to find the call sequence of the key functions.

4. The backdoor detection method according to claim 3, characterized in that, The call sequence of the key functions includes the RVA of at least one function called by the key functions and the module information to which it belongs.

5. The backdoor detection method according to claim 4, wherein The recording the key functions and the call sequence of the key functions includes: Recording the serial number of the key function, the RVA of at least one function called by the key function, and the module information to which it belongs; Transmitting the serial number of the key function, the RVA of at least one function called by the key function, and the module information to which it belongs to the server through the terminal.

6. A backdoor detection system, characterized in that, It includes: A monitoring module for monitoring target events; A backtrace module for performing a stack trace on the current thread of the target event to obtain key functions related to the target event and the call sequence of the key functions; An analysis module is used to perform clustering analysis on the key function and the call sequence of the key function, and output a suspicious backdoor sequence; wherein, the call sequence of the key function is the call path of the key function, the memory instruction sequence of the key function, the set of functions called by the key function, the RVA of at least one function called by the key function, and the module information to which it belongs. The performing clustering analysis on the key function and the call sequence of the key function, and outputting a suspicious backdoor sequence includes: Performing clustering analysis on the call sequence of the key function according to the operating system type of the terminal. Performing clustering analysis on the call sequence of the key function according to the behavior type of the target event. The performing clustering analysis on the key function and the call sequence of the key function, and outputting a suspicious backdoor sequence includes: If no suspicious call sequence appears for the key function in the first time period and a suspicious call sequence appears for the key function in the second time period, then output the suspicious call sequence as the suspicious backdoor sequence; or If the average number of occurrences of the suspicious call sequence of the key function in the first time period is N and the number of occurrences of the suspicious call sequence of the key function in the second time period is much greater than N, then output the suspicious call sequence of the key function as the suspicious backdoor sequence.

7. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, it is used to implement the steps of the backdoor detection method according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and the computer program can be executed by at least one processor, so that the at least one processor executes the steps of the backdoor detection method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Variable information extraction method and apparatus

    CN107515769A

  • Behavior stack information acquisition method and device

    CN109784054A