Attack detection method, device and security chip

By setting checkpoints for the target path of the target program and using the abstract algebra principle for modulo operations, the problem of difficulty in timely discovering program operation path attacks in the existing technology is solved, and effective protection of programs and data is achieved.

CN114741685BActive Publication Date: 2025-05-02SHENZHEN GOODIX TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110018513.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-01-07
Publication Date
2025-05-02
Estimated Expiration
2041-01-07

AI Technical Summary

Technical Problem

The existing technology is difficult to detect attacks on program running paths in a timely manner, resulting in program corruption or data leakage.

Method used

By presetting at least 2 checkpoints for the target path of the target program, including initial checkpoints and non-initial checkpoints, modulo operations are performed using the principle of abstract algebra, and the processing results are compared to determine whether the path is attacked.

Benefits of technology

It realizes attacks to promptly discover program running paths and protects program and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114741685B_ABST
    Figure CN114741685B_ABST
Patent Text Reader

Abstract

The embodiment of the present application provides an attack detection method, device and security chip, in which: the processing result of the first checkpoint of the target path during the operation of the target program is obtained, and the first expected processing result is obtained. The first expected processing result is the processing result of the last checkpoint of the target path when the target path is not attacked and the initial checkpoint obtains the first value. After the first processing result is compared with the first expected processing result and the result is inconsistent, it is determined that the target path of the program is attacked. The present application can timely discover the attack behavior against the running path of the program and protect the security of the program and data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to an attack detection method, device and security chip. Background Art

[0002] During the program running, it is possible to be attacked by attackers, which may change the program running path, such as the process or sequence, and thus cause program damage or data leakage. Therefore, it is very important to detect the attack on the program in time during the program running, and then take timely measures to protect the security of the program and data. Summary of the invention

[0003] The present application provides an attack detection method, device and security chip, which can timely detect attack behaviors against the running path of the program and protect the security of the program and data.

[0004] In a first aspect, the present application provides an attack detection method, which pre-sets at least two checkpoints for a target path of a target program, wherein the at least two checkpoints include: an initial checkpoint and at least one non-initial checkpoint, wherein the initial checkpoint is located before the first code segment of the target path, and the non-initial checkpoint is located after the last code segment of the target path or embedded between the code segments included in the target path, wherein the initial checkpoint is used to obtain a first numerical value, and the non-initial checkpoint is used to obtain a processing result of a previously triggered checkpoint, and a first modulo operation is performed on the obtained processing result and the prime number corresponding to the non-initial checkpoint to obtain the processing result of the non-initial checkpoint; the method further includes:

[0005] Obtaining a first processing result, where the first processing result is a processing result of a first checkpoint of the target path during the running of the target program; the first checkpoint is the last checkpoint of the target path that is triggered before obtaining the first processing result;

[0006] Obtaining a first expected processing result, where the first expected processing result is a processing result of a last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value;

[0007] After a comparison result between the first processing result and the first expected processing result is inconsistent, it is determined that the target path of the target program is attacked.

[0008] In this method, a first expected processing result and a first processing result obtained after the target path is run are obtained, and the two processing results are compared to determine whether the target path is attacked, so that attack behaviors against the program's running path can be discovered in time to protect the security of the program and data.

[0009] In a possible implementation manner, obtaining the first expected processing result includes:

[0010] Acquire a first value obtained at an initial checkpoint of the target path during the running of the target program;

[0011] The first expected processing result is calculated based on the second expected processing result and the third expected processing result preset for the target path, the second expected processing result is the processing result of the last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value of 0, and the third expected processing result is the processing result of the last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value of 1.

[0012] In a possible implementation, the first modular operation is a modular addition operation or a modular multiplication operation, and the non-initial checkpoint of the target path has the same modulus used for performing the first modular operation.

[0013] In a possible implementation, the first modular operations corresponding to two adjacent non-initial checkpoints of the target path are modular addition operations and modular multiplication operations, respectively.

[0014] In a possible implementation, the method further includes:

[0015] A first memory is preset for the target path, the initial checkpoint is specifically used to obtain a first value, and store the first value in the first memory; the non-initial checkpoint is specifically used to obtain a processing result of a previously triggered checkpoint from the first memory, perform a first modulus operation on the obtained processing result and a prime number corresponding to the non-initial checkpoint to obtain a processing result of the non-initial checkpoint, and store the calculated processing result of the non-initial checkpoint in the first memory;

[0016] The obtaining of the first processing result includes:

[0017] The first processing result is obtained from a first memory preset for the target path.

[0018] In a possible implementation, the method further includes:

[0019] A second memory is preset for the target path, and the initial checkpoint is further used to: store the first value in the second memory;

[0020] The obtaining of a first value obtained at an initial checkpoint of the target path during the running of the target program includes:

[0021] The first value is obtained from a second memory preset for the target path.

[0022] In a possible implementation, the method further includes:

[0023] A code segment for implementing the steps of obtaining the first processing result, obtaining the first expected processing result, and determining that the target path of the target program is attacked after the comparison result between the first processing result and the first expected processing result is inconsistent is set as a comparison point after the last non-initial checkpoint of the target path;

[0024] The method further comprises:

[0025] Obtaining the number of times the comparison point is triggered during the running of the target program;

[0026] After the comparison result between the number and the expected number is inconsistent, it is determined that the target path is attacked.

[0027] In a possible implementation, the method further includes:

[0028] A trigger point is set in advance for the target path, the trigger point is used to send a first instruction, the first instruction is used to trigger the execution of the steps of obtaining the first processing result, obtaining the first expected processing result, and determining that the target path of the target program is attacked after the comparison result between the first processing result and the first expected processing result is inconsistent; the trigger point is located after the last non-initial checkpoint of the target path; the first instruction includes the first processing result;

[0029] The obtaining of the first processing result includes:

[0030] receiving a first instruction, wherein the first instruction includes the first processing result;

[0031] The first processing result is obtained from the first instruction.

[0032] In a possible implementation, the target program includes at least two target paths;

[0033] The first instruction includes: the first processing result, and identification information of a target path corresponding to the first processing result;

[0034] Acquiring the first processing result from the first instruction includes:

[0035] A first processing result of the target path is acquired according to the identification information of the target path.

[0036] In a second aspect, an embodiment of the present application provides an attack detection device, including:

[0037] At least two checkpoints are pre-set for a target path of a target program, the at least two checkpoints include: an initial checkpoint and at least one non-initial checkpoint, the initial checkpoint is located before a first code segment of the target path, the non-initial checkpoint is located after a last code segment of the target path or is embedded between code segments included in the target path, the initial checkpoint is used to obtain a first value, and the non-initial checkpoint is used to obtain a processing result of a previously triggered checkpoint, and a first modulo operation is performed on the obtained processing result and a prime number corresponding to the non-initial checkpoint to obtain a processing result of the non-initial checkpoint;

[0038] A first acquisition unit is used to acquire a first processing result, where the first processing result is a processing result of a first checkpoint of the target path during the running of the target program; the first checkpoint is a checkpoint of the target path;

[0039] A second acquisition unit is used to acquire a first expected processing result, where the first expected processing result is a processing result of a last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value;

[0040] The first attack judgment unit is used to determine that the target path of the program is attacked after a comparison result between the first processing result and the first expected processing result is inconsistent.

[0041] In a possible implementation, the second acquisition unit is specifically used to: obtain a first value obtained by the initial checkpoint of the target path during the running of the target program; calculate the first expected processing result based on a second expected processing result and a third expected processing result preset for the target path, the second expected processing result being the processing result of the last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value of 0, and the third expected processing result being the processing result of the last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value of 1.

[0042] In a possible implementation, the first modular operation is a modular addition operation or a modular multiplication operation, and the non-initial checkpoint of the target path has the same modulus used for performing the first modular operation.

[0043] In a possible implementation, the first modular operations corresponding to two adjacent non-initial checkpoints of the target path are modular addition operations and modular multiplication operations, respectively.

[0044] In a third aspect, an embodiment of the present application provides a security chip, including: a processor, wherein the processor is used to execute any method described in the first aspect.

[0045] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, which, when executed on a computer, enables the computer to execute any of the methods described in the first aspect.

[0046] In a fifth aspect, the present application provides a computer program, which, when executed by a computer, is used to execute the method described in the first aspect.

[0047] In one possible design, the program in the fifth aspect may be stored in whole or in part on a storage medium packaged together with the processor, or may be stored in whole or in part on a memory not packaged together with the processor. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1A This is an example diagram of the operation path of this application procedure;

[0049] Figure 1B This is an example diagram of the operation path of this application procedure;

[0050] Figure 2 This is an example diagram of the application process and operation path;

[0051] Figure 3 This is an example diagram of the application process and operation path;

[0052] Figure 4 A flowchart of an embodiment of the attack detection method of the present application;

[0053] Figure 5A This is an example diagram of the relationship between the comparison points and the check points for this application;

[0054] Figure 5B This is an example diagram of the relationship between the trigger point and the checkpoint for this application;

[0055] Fig. 6A This is an example diagram after the order of comparison points and check points is swapped for this application;

[0056] Figure 6B This is an example diagram after the order of comparison points and check points is swapped for this application;

[0057] Figure 7 A flowchart of another embodiment of the attack detection method of the present application;

[0058] Figure 8 This is a flow chart of an embodiment of an attack detection device of the present application. DETAILED DESCRIPTION

[0059] The terms used in the implementation section of this application are only used to explain the specific embodiments of this application and are not intended to limit this application.

[0060] First, the nouns involved in the embodiments of the present application are described in an illustrative but non-limiting manner.

[0061] A program refers to a coded instruction sequence that can be executed by a device with information processing capabilities such as a computer in order to obtain a certain result, or a symbolic instruction sequence or a symbolic statement sequence that can be automatically converted into a coded instruction sequence. All programs are based on machine language, which is a language composed of binary numbers (0 and 1). Generally, a program is written in a high-level language or assembly language, and then translated into machine language by a compiler / interpreter during the compilation process, so that it can be executed. A section of the instruction sequence included in the program can be called a code segment, that is, a program can be considered as a code segment, and any section of the instruction sequence in the program can also be called a code segment. In this application, a program is divided into several code segments, and the specific division rules are not limited in this application. For example, in C language, the code between two separators can be called a statement, such as a judgment statement, a branch statement, a loop statement, etc. In a possible implementation, when the program is divided into code segments, it can be divided according to statements as units, and the number of statements included in each code segment can be different.

[0062] The running path of a program refers to the code segments that the program runs when it is running and the running order of the code segments. For example, as shown in FIG1 , the running path of a program can be a tree structure, in which code segment 3 can be a code segment for executing judgment, and there are two judgment results. Based on the different judgment results of code segment 3, code segment 4 or code segment 6 is executed, so that the running path of the program is divided into two running paths starting from code segment 3. Figure 1A The program shown may include two complete execution paths, where execution path 1 is code segments 1, 2, 3, 4, and 5 that are executed in sequence, and execution path 2 is code segments 1, 2, 3, 6, and 7 that are executed in sequence.

[0063] In the embodiment of the present application, the target path refers to the running path that needs to be checked in one or more programs. The target program refers to the program to which the target path belongs. A target path can be included in a single target program or in multiple target programs.

[0064] The present application proposes an attack detection method, device and security chip, which implement attack detection on the program's running path based on the principle of abstract algebra, so that the attack can be processed accordingly in a timely manner to protect the security of the program and data.

[0065] First, the abstract algebraic principle on which the attack detection method in the embodiment of the present application is based is explained.

[0066] For a value r, if a modular operation based on the same modulus is performed several times using prime numbers, and the order of the modular operation, the prime numbers corresponding to the modular operation, and the modulus are determined, the calculation result is fixed and can be calculated in advance or in real time.

[0067] Further, assuming that the calculation result is Result(r); then the calculation result Result(r) corresponding to the value r, the calculation result Result(0) corresponding to the value r being 0, and the calculation result Result(1) corresponding to the value r being 1 have the relationship shown in the following formula: Result(r) = r*(Result(1)-Result(0))+Result(0). When the above-mentioned modular multiplication and / or modular addition calculations performed on the value r are certain, Result(0) and Result(1) can be calculated in advance, so that after the value r is known, Result(r) can be quickly calculated based on Result(0) and Result(1). This calculation formula can be applied to the above-mentioned pre-calculation or real-time calculation of the calculation result corresponding to the value r.

[0068] For example, suppose there are five prime numbers, namely X1, Y1, X2, X3, and Y2, and the modulus is A. For a value r, the following calculation is performed: Result(r) = ((r*X1+Y1)*X2*X3+Y2) mod A;

[0069] Then, we can calculate the calculation result corresponding to r being 0: Result(0) = ((0*X1+Y1)*X2*X3+Y2) mod A = (Y1*X2*X3+Y2) mod A; calculate the calculation result corresponding to r being 1: Result(1) = ((1*X1+Y1)*X2*X3+Y2) mod A = (X1*X2*X3+Y1*X2*X3+Y2) mod A;

[0070] It can be seen that r*(Result(1)–Result(0))+Result(0)=(r*X1*X2*X3+Y1*X2*X3+Y2)mod A=((r*X1+Y1)*X2*X3+Y2)mod A=Result(r).

[0071] The inventor applied the above-mentioned abstract algebra principles to the attack detection method of the present application, thereby realizing attack detection on the program running path.

[0072] The attack detection method of this application includes two stages:

[0073] The first stage is the pre-preparation stage, in which checkpoints need to be set for the target path in advance. The checkpoints of this application refer to the code segments used to implement the specified functions. The checkpoints are embedded in the target path before and after, or between the code segments included in the target path in a preset order. The target path can be a running path within a program, or it can be a path obtained by connecting the running paths of several programs in series.

[0074] The checkpoints of the target path may include: initial checkpoints and non-initial checkpoints. The initial checkpoint is the first checkpoint of the target path, and the initial checkpoint is used to obtain a first value. The first value can be specified in advance for the initial checkpoint, and in this case, the initial checkpoint can obtain a preset value as the first value. The first value can also be randomly generated by the initial checkpoint. Specifically, the initial checkpoint can use a true random value generator to generate a random number as the first value. The non-initial checkpoint is a checkpoint located after the initial checkpoint in the checkpoints of the target path. For each non-initial checkpoint, a corresponding prime number, a first modular operation rule, and a modulus of the first modular operation rule are preset. Each non-initial checkpoint is used to: for the processing result of the previous checkpoint of the non-initial checkpoint and the preset prime number corresponding to the non-initial checkpoint, use a preset modulus to perform a first modular operation to obtain the processing result of the non-initial checkpoint, and the first modular operation is a modular operation indicated by the first modular operation rule corresponding to the non-initial checkpoint. Among them, the processing result of the initial checkpoint is the first value obtained by the initial checkpoint.

[0075] The target path in the embodiment of the present application is a clear single-line path, and a single-line path refers to a path without forked paths, for example Figure 1A The execution paths 1 and 2 in are single-line paths, but the execution path composed of code segments 1, 2, 3, 4, and 6 is not a single-line path, but a forked path. The target path may include a cyclic path with a known number of loops, for example, see Figure 1B As shown in the figure, after code segments 1 and 2 are executed in sequence, code segments 3 and 4 are executed in sequence and looped for 5 times, and then code segment 6 is executed. Code segments 1 to 6 also form a single-line path without a forked path. In the case of no attack, when the program runs along the target path, the initial checkpoints and non-initial checkpoints set for the target path are triggered in sequence according to the preset order.

[0076] The following is an illustrative example of possible implementation of the target path and a method for setting the checkpoints of the target path.

[0077] The target path can be a running path within a program. Specifically, the target path can be the complete running path of the program. For example, the target path is the above Figure 1AAlternatively, the target path may be a partial path of the complete program path, for example, the target path may be a partial path of the program path 1: code segments 1, 2, and 3 that are run in sequence. Figure 2 As shown, the target path can be a running path within program A. There are n checkpoints set in program A, and n is a natural number greater than or equal to 2. Checkpoint 1 is the initial checkpoint, and checkpoints 2 to n are non-initial checkpoints. Checkpoints 1 to n are triggered in sequence during the sequential execution of code segments 1 to n. For each checkpoint in checkpoints 2 to n, a prime number corresponding to the checkpoint, a first modular operation rule, and a modulus of the first modular operation rule are preset. Checkpoints 2 to n are respectively used to: perform a first modular operation on the prime number corresponding to the checkpoint and the processing result of the previously triggered checkpoint according to the first modular operation rule corresponding to the checkpoint, and obtain the processing result of the checkpoint.

[0078] Optionally, the first modular operation rule is a modular multiplication operation or a modular addition operation. The first modular operation rules corresponding to different checkpoints in checkpoints 2 to n may be the same or different, and the modules corresponding to checkpoints 2 to n are the same, that is, the first modular operation rule of each checkpoint in checkpoints 2 to n may be a modular multiplication or a modular addition, but the modules used in the modular multiplication or the modular addition are the same value. Optionally, the modules corresponding to checkpoints 2 to n are prime numbers.

[0079] When not attacked, starting from the initial checkpoint of the target path to the last non-initial checkpoint of the target path, the path check processing result with the first numerical value as the starting condition is calculated, and this final processing result is calculable. When the target program is attacked, some code segments contained in the target program are skipped and not executed, then the checkpoints on the target path may also be skipped as the code segments are skipped, or some code segments contained in the target program are swapped in running order, and the checkpoints on the target path may also be swapped in the order of being triggered as the code segments are swapped in execution order, resulting in the path check processing result with the first numerical value as the starting condition being inconsistent with the above-mentioned final processing result, thereby judging that the target path of the target program has been attacked, and subsequent processing for the attack can be performed based on this. The processing method for the attack is not limited in this application.

[0080] For example, four checkpoints are preset for the target path, the initial checkpoint obtains the first value r, the prime number corresponding to the non-initial checkpoint 1 is X1, and a modular multiplication operation is performed, the prime number corresponding to the non-initial checkpoint 2 is Y1, and a modular addition operation is performed, and the prime number corresponding to the non-initial checkpoint 3 is X2, and a modular multiplication operation is performed. The modulus of the modular operation of the three non-initial checkpoints is A. If the target path is not attacked, the checkpoints are triggered in sequence during the operation of the target program according to the target path, and the processing result obtained by the non-initial checkpoint 3 is Result(r)=((r*X1+Y1)*X2)mod A=r*(Result(1)–Result(0))+Result(0), Result(r) can be calculated according to the above formula; if the code segment on the target path is skipped or the execution order is swapped, the execution order of the four checkpoints will change with the attack. This change may be that a certain checkpoint is skipped and not triggered, or the triggering order of the checkpoints is changed. At this time, after the target path is run, the path check result with the first value as the starting condition will be inconsistent with Result(r), so it can be determined that the target path of the target program is attacked.

[0081] It should be noted that if there are m consecutive checkpoints in the target path whose corresponding first modular operation rules are the same, for example, all are modular multiplication or all are modular addition, then the change in the running order of the code segments between the m consecutive checkpoints cannot be detected, and m is a natural number greater than or equal to 3. Figure 1A For example, assuming that the first modular operation rules corresponding to checkpoints 3 to 6 are all modular multiplication, and the code segments between checkpoints 3 to 6 are code segments 4 and 5, if the execution order between code segments 4 and 5 is swapped, the path checking method of the embodiment of the present application cannot detect this situation. Therefore, the path checking method is more suitable for target paths that do not require checking the execution order of code segments, such as Figure 1B The target path shown includes a loop path with a determined number of loops of 5: code segment 3, code segment 4. A checkpoint can be set between code segment 3 and code segment 4, and each loop triggers the checkpoint to perform the same modular operation, such as modular addition operation. Accordingly, after looping 5 times, it can be considered that 5 checkpoints of modular addition operations are triggered continuously. At this time, it can be checked whether the path has looped 5 times.

[0082] If the path checking method of the embodiment of the present application needs to check whether the running order of the code segments in the target path has changed and whether the code segments have been executed, the first modulo operation rules corresponding to two adjacent checkpoints in checkpoints 2 to n are preferably different. At this time, the path checking method of the embodiment of the present application can detect whether each code segment in the target path has been executed, and can check whether the running order of the code segments 2 to n between checkpoints 1 to n has changed, so that the path checking method has better path checking accuracy and improves the detection accuracy of whether the program has been attacked.

[0083] See also Figure 3 As shown, the target path can be a running path across programs. Figure 3 In the example, the target path is obtained by concatenating the running path in program A and the running path in program B. Figure 2 The difference is that after checkpoint n-1 of program A, program B is triggered to execute. At this time, the target path can be: code segments 2 to n of program A, code segments 1 to p of program B, and the checkpoints of the target path include: checkpoint 1 to checkpoint n-1 in program A, and checkpoint 1 to checkpoint p in program B. The implementation of checkpoint 1 to checkpoint n-1 in program A can refer to the relevant description in Figure 1, which is not repeated here.

[0084] In a possible implementation, each of the checkpoints 1 to P in program B can be a non-initial checkpoint. The implementation of each checkpoint can refer to the description of non-initial checkpoints such as checkpoints 2 to n-1 of program A in FIG1 , which will not be described here. When program A and program B are not attacked, in the cross-program target path, for checkpoint 1 of program B, it is necessary to perform a first calculation according to the first modulo operation rule corresponding to checkpoint 1 based on the prime number corresponding to checkpoint 1 and the processing result of the previous checkpoint, that is, checkpoint n-1 of program A, to obtain the processing result of checkpoint 1.

[0085] In another possible implementation, checkpoint 1 of program B may be an initial checkpoint, and checkpoints 2 to P of program B are non-initial checkpoints. In this case, when program A and program B are not attacked, in the cross-program target path, for checkpoint 1 of program B, checkpoint 1 may be used to: use the processing result of checkpoint n-1 of program A as the first value obtained by checkpoint 1.

[0086] It should be noted that there may be one or more target paths to be checked in a program, and similarly, there may be one or more target paths to be checked between multiple programs. Since the target path in the embodiment of the present application is a clear single-line path, if the running path of the program is a tree structure, for example Figure 1AAs shown, each running path or part of the running path can be used as a target path. In a program, the target path of the program can be set according to the critical path of the program running, and the attack detection of the target path can be realized; if other programs are triggered to be executed during the running of a program, the cross-program target path can be set according to the cross-program running path, and the attack detection of the cross-program running path between multiple programs can be realized through the attack detection of the target path.

[0087] On the overlapping paths of multiple target paths, multiple target paths can share checkpoints. For example, see Figure 3 , assuming that one target path is code segments 2 to n of program A, and the other target path is code segments 2 to n-1 of program A and code segments 1 to p of program B, where code segments 2 to n-1 are the overlapping paths of the two target paths, and checkpoint 1 to checkpoint n-1 of program A are checkpoints shared by the two target paths.

[0088] Based on the above description, once the target path is determined and the checkpoint of the target path is set in the code segment of the target path, the prime number corresponding to each non-initial checkpoint of the target path, the first calculation rule and the modulus of the first calculation rule are determined. At this time, the processing result of the last checkpoint of the target path can be calculated when the target path is not attacked, assuming that the first value obtained by the initial checkpoint is 0, and the calculated processing result is recorded as: the expected processing result Result(0) of the target path based on the random number 0. Similarly, the expected processing result Result(1) of the target path based on the random number 1 is calculated and recorded.

[0089] Optionally, in order for the triggered non-initial checkpoint to obtain the processing result of the previously triggered checkpoint when the program runs according to the target path, a first memory can be set for the target path to store the processing results of each checkpoint. Then, the initial checkpoint in the target path can be specifically used to: obtain a first numerical value, and store the first numerical value in the first memory; the non-initial checkpoint can be specifically used to: obtain the processing result of the previous checkpoint from the first memory, use a preset modulus to perform a modulus operation indicated by the first modulus operation rule on the processing result of the previous checkpoint and the prime number corresponding to itself, and use the calculated processing result to update the processing result stored in the first memory. The above-mentioned first memory can be implemented by ordinary memory or registers. Optionally, the modulus used for the first modulus operation of each non-initial checkpoint can be any prime number between 2^16 and 2^32. At this time, the first memory preferably supports 64-bit operation.

[0090] Optionally, in order to store the first value obtained at the initial checkpoint of the target path when the program runs according to the target path, a second memory may be provided for the target path to store the first value obtained at the initial checkpoint. The second memory may be implemented by a common memory or a register.

[0091] After setting the checkpoint for the target path, after the target program starts to execute, if the target path is executed, the checkpoint set for the target path will be triggered when the target program runs according to the target path. When the above target path is not attacked, the target program runs according to the target path sequence, and the initial checkpoint and non-initial checkpoint of the target path are triggered in sequence according to the setting sequence of the checkpoints in the target path. At this time, the last non-initial checkpoint of the target path is the last checkpoint triggered in the running of the target path, and the processing result of the checkpoint is the actual processing result corresponding to the target path after the running, which is referred to as the first processing result hereinafter; and when the above target path is attacked, since the running path of the code segments in the target path or the running sequence between each other may be changed, at this time, the target path cannot run according to the preset sequence, and the checkpoints set for the target path cannot be triggered in sequence according to the preset sequence, but are triggered in the order after being attacked. The last checkpoint triggered in the running of the target path is uncertain, but the processing result of the last checkpoint triggered will be used as the first processing result of the target path.

[0092] The second stage is the data comparison stage. In this stage, the attack detection of the target path can be performed based on the processing result of the last triggered checkpoint in the checkpoint of the target path during the operation, such as Figure 4 As shown, the method may include:

[0093] Step 401: Obtain a first processing result, where the first processing result is a processing result of a first checkpoint of a target path during the execution of a target program; the first checkpoint is a checkpoint in the target path that is last triggered before the attack detection code segment is executed.

[0094] Step 402: Obtain a first expected processing result, where the first expected processing result is a processing result of the last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value;

[0095] Step 403: After the comparison result between the first processing result and the expected processing result is inconsistent, it is determined that the target path of the target program is attacked.

[0096] Among them, the realization Figure 4 The attack detection code segment of the method shown can be set as a comparison point in the target program. Specifically, it can be set after the last non-initial checkpoint in the target path. Figure 5A As shown, Figure 2 As an example, the target path and checkpoint setting method shown in the figure can be located after the checkpoint n. Alternatively, Figure 4 The attack detection code segment of the method shown can also be set outside the target program, and a trigger point is set after the last non-initial checkpoint in the target path. The trigger point is a code segment that implements a specified function. Specifically, the trigger point is used to trigger the execution of the above attack detection code segment, for example, see Figure 5B As shown, Figure 2 As an example of the target path and checkpoint setting method shown in FIG. 1 , the trigger point can be located after the checkpoint n, and the implementation Figure 4 The attack detection code segment of the method shown is a program X, and the execution of the program X is triggered by a trigger point.

[0097] For step 401:

[0098] If the target path is not attacked, the first checkpoint is the checkpoint located at the end of the target path, that is, the checkpoint after the last code segment of the target path. Figure 2 Taking the target path and checkpoint setting method shown as an example, the first checkpoint is checkpoint n.

[0099] If the target path is attacked, some checkpoints in the target path may have their trigger order swapped, some checkpoints may be skipped and not triggered, etc. Therefore, the first checkpoint may be any checkpoint in the target path, depending on the attack situation.

[0100] If achieved Figure 4 The code segment of the method shown is set as a comparison point in the target program, and the first checkpoint is the checkpoint of the target path that was last triggered before the comparison point was triggered. Figure 5A Taking the target path, checkpoint, and comparison point setting method shown in FIG. 1 as an example, the comparison point is set after checkpoint n. Program A is attacked, resulting in the order of checkpoint n, the comparison point after checkpoint n, and checkpoint n-1 being swapped, as shown in FIG. Fig. 6A As shown, a checkpoint of the target path that is triggered before the trigger comparison point is checkpoint n, and the first checkpoint is checkpoint n.

[0101] If achieved Figure 4 The attack detection code segment of the method shown is set outside the target program, and is triggered by the trigger point when the target program executes to the trigger point. Figure 4 In the attack detection code segment of the method shown in FIG. 4 , the first checkpoint is the checkpoint of the target path that was last triggered before the trigger point was executed, that is, the last checkpoint of the target path that was triggered before the trigger point triggered the execution step 401. Figure 5BTaking the target path, checkpoint, and comparison point setting method shown in FIG. 1 as an example, the trigger point is set after checkpoint n, and program A is attacked, resulting in the order of checkpoint n, the trigger point after checkpoint n, and checkpoint n-1 being swapped, as shown in FIG. Figure 6B As shown, the trigger point is triggered Figure 4 In the method shown, if the checkpoint of the target path that was triggered before was checkpoint n, then the first checkpoint is checkpoint n.

[0102] If achieved Figure 4 The code segment of the method shown is set in the target program as a comparison point, and the above-mentioned first memory is set for the target path. Then this step may include: obtaining the first processing result from the first memory of the target path.

[0103] If achieved Figure 4 The attack detection code segment of the method shown is set outside the target program, and is triggered by the trigger point when the target program executes to the trigger point. Figure 4 The attack detection code segment of the method shown, this step may include:

[0104] receiving a first instruction, where the first instruction is used to indicate a first processing result;

[0105] A first processing result is obtained from the first instruction.

[0106] The first instruction may be sent by a trigger point. If the target path is provided with the first memory, the trigger point may be specifically used to: obtain the first processing result from the first memory, send the first instruction to the attack detection code segment, the first instruction includes the first processing result, and the first instruction is used to trigger the attack detection code segment to perform attack detection on the target path according to the first processing result.

[0107] If the target program includes at least two target paths, the first instruction may include: a first processing result, and identification information of the target path corresponding to the first processing result. The implementation method of the identification information of the target path is not limited, as long as different target paths can be distinguished. Accordingly, in step 401, the first processing result corresponding to the target path can be obtained from the first instruction according to the identification information of the target path.

[0108] For step 402:

[0109] If the first value obtained at the initial checkpoint of the target path is pre-specified for the initial checkpoint, then, when the target path is not attacked, the processing result of the last checkpoint of the target path obtained with the first value as the starting condition is fixed and can be calculated in advance, that is, the first expected processing result is fixed and can be calculated in advance. At this time, the first expected processing result of the target path can be pre-calculated and set, and step 402 may include: obtaining the pre-set first expected processing result of the target path.

[0110] If the first value of the initial checkpoint of the target path is pre-assigned to the initial checkpoint or randomly generated by the initial checkpoint, the first expected processing result can be calculated in real time according to the first value. In this case, step 402 may include:

[0111] Obtain a first value obtained by an initial checkpoint of a target path during the running of a target program, and calculate a first expected processing result according to a second expected processing result and a third expected processing result preset for the target path, the second expected processing result being a processing result of a last checkpoint of the target path when the target path is run without being attacked and the first value obtained by the initial checkpoint is 0, and the third expected processing result being a processing result of the last checkpoint of the target path when the target path is run without being attacked and the first value obtained by the initial checkpoint is 1.

[0112] Continue with the instructions in step 401. If Figure 4 The attack detection code segment of the method shown is set outside the target program, and when the target program executes to the trigger point, the trigger point triggers the execution of the attack detection code segment. At this time, the first instruction may include the first value, and obtaining the first value obtained at the initial checkpoint of the target path during the running of the target program may include: obtaining the first value from the first instruction. At this time, if the second memory is set for the target path, the trigger point may obtain the first value from the second memory preset for the target path, and carry the first value in the first instruction.

[0113] Continue with the instructions in step 401. If Figure 4 The attack detection code segment of the method shown is set as a comparison point in the target program, and the above-mentioned second memory is set for the target path. Then, obtaining the first value obtained at the initial checkpoint of the target path during the running of the target program may include: obtaining the first value from the second memory preset for the target path.

[0114] In step 402, the third expected processing result Result(r) can be calculated according to the second expected processing result Result(0) and the third expected processing result Result(1) using the following formula: Result(r)=r*(Result(1)-Result(0))+Result(0), where r is the first value. Thus, the first expected processing result when the first value r is any value can be calculated in real time through the preset second expected processing result and the third expected processing result.

[0115] There is no restriction on the execution order between step 401 and step 402.

[0116] For step 403:

[0117] If the comparison result of the first processing result and the first expected processing result is consistent, it is determined that the target path of the target program has not been attacked.

[0118] Figure 4 In the method shown, a first expected processing result is obtained when the target path is not attacked, and a first processing result is obtained after the target path is run. The two processing results are compared to determine whether the target path is attacked, so that attack behaviors against the program's running path can be discovered in time to protect the security of the program and data.

[0119] Figure 4 The method shown is triggered and executed once to detect whether the target path is attacked during the execution of the target path. In some programs, a certain path in the program may be executed multiple times when the program is executed once. If the target path can be executed multiple times during the execution of the target program, Figure 4 The attack detection code segment of the method shown is set as a comparison point after the last non-initial checkpoint of the target path. In order to detect whether the comparison point is attacked, a counter for recording the number of times the comparison point is triggered can be further set for the comparison point; accordingly, see Figure 7 As shown, after step 403, the following may also be included:

[0120] Step 701: Obtain the number of times the comparison point is triggered during the running of the target program, and compare the above number with the expected number. If the comparison result is inconsistent, it is determined that the target path is attacked, otherwise, it is determined that the target path is not attacked.

[0121] The above expected number of times is the number of times the target path is triggered to run when the target program runs once if the target program is not attacked.

[0122] Optionally, step 701 may be triggered after the target program has been run once to obtain an accurate comparison result.

[0123] Figure 7 The method shown can also be applied to the case where the attack detection code segment is set outside the target program. In this case, the comparison point can be replaced by the trigger point to detect whether the trigger point is attacked.

[0124] It is to be understood that some or all of the steps or operations in the above embodiments are merely examples, and the present application embodiments may also perform other operations or variations of various operations. In addition, the various steps may be performed in different orders presented in the above embodiments, and it is possible that not all of the operations in the above embodiments need to be performed.

[0125] Figure 8 This is a flow chart of an embodiment of the attack detection device of the present application, as shown in FIG. Figure 8 As shown, the device 80 may include:

[0126] At least two checkpoints are pre-set for a target path of a target program, the at least two checkpoints include: an initial checkpoint and at least one non-initial checkpoint, the initial checkpoint is located before a first code segment of the target path, the non-initial checkpoint is located after a last code segment of the target path or is embedded between code segments included in the target path, the initial checkpoint is used to obtain a first value, and the non-initial checkpoint is used to obtain a processing result of a previously triggered checkpoint, and a first modulo operation is performed on the obtained processing result and a prime number corresponding to the non-initial checkpoint to obtain a processing result of the non-initial checkpoint;

[0127] A first acquisition unit 81 is used to acquire a first processing result, where the first processing result is a processing result of a first checkpoint of the target path during the running of the target program; the first checkpoint is the last checkpoint of the target path that is triggered before the first acquisition unit 81 acquires the first processing result;

[0128] A second acquisition unit 82 is used to acquire a first expected processing result, where the first expected processing result is a processing result of the last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value;

[0129] The first attack judgment unit 83 is used to determine that the target path of the program is attacked after the comparison result between the first processing result and the first expected processing result is inconsistent.

[0130] Optionally, the second acquisition unit 82 can be specifically used to: obtain a first value obtained by the initial checkpoint of the target path during the running of the target program; calculate the first expected processing result based on a second expected processing result and a third expected processing result preset for the target path, the second expected processing result being the processing result of the last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value of 0, and the third expected processing result being the processing result of the last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value of 1.

[0131] Optionally, the first modular operation is a modular addition operation or a modular multiplication operation, and the non-initial checkpoint of the target path has the same modular operation as that used for the first modular operation.

[0132] Optionally, the first modular operations corresponding to two adjacent non-initial checkpoints of the target path are modular addition operations and modular multiplication operations respectively.

[0133] Optionally, the first acquisition unit 81 may be specifically configured to: receive a first instruction, where the first instruction is used to indicate that the target program has finished running, and the first instruction includes: the first processing result; and acquire the first processing result from the first instruction.

[0134] Optionally, the target program includes at least two target paths; the first instruction includes: the first processing result, and identification information of the target path corresponding to the first processing result;

[0135] The first acquisition unit 81 may be specifically configured to acquire a first processing result of the target path according to the identification information of the target path.

[0136] Optionally, it also includes:

[0137] A first memory is preset for the target path, the initial checkpoint is specifically used to obtain a first value, and store the first value in the first memory; the non-initial checkpoint is specifically used to obtain a processing result of a previously triggered checkpoint from the first memory, perform a first modulus operation on the obtained processing result and a prime number corresponding to the non-initial checkpoint to obtain a processing result of the non-initial checkpoint, and store the calculated processing result of the non-initial checkpoint in the first memory;

[0138] The first acquiring unit 81 may be specifically configured to acquire the first processing result from a first memory preset for the target path.

[0139] Optionally, it further includes: presetting a second memory for the target path, and the initial checkpoint is further used to: store the first value in the second memory;

[0140] The second acquiring unit 82 may be specifically configured to acquire the first value from a second memory preset for the target path.

[0141] Optionally, the device further includes: implementation code segments of the first acquisition unit 81, the second acquisition unit 82 and the first attack judgment unit 83 are set as comparison points after the last non-initial checkpoint of the target path;

[0142] The device may also include: a second attack judgment unit, used to record the number of times the comparison point is triggered during the running of the target program; after the comparison result of the number is inconsistent with the expected number, it is determined that the target path is attacked.

[0143] Figure 8 The device 80 provided in the embodiment shown can be used to implement the present application Figure 4 to Figure 7 The technical solution of the method embodiment shown, its implementation principle and technical effects can be further referred to the relevant description in the method embodiment.

[0144] It should be understood that the above Figure 8 The division of the various units of the device shown is only a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. And these units can all be implemented in the form of software calling through processing elements; they can also be all implemented in the form of hardware; some units can also be implemented in the form of software calling through processing elements, and some units can be implemented in the form of hardware. For example, the first acquisition unit can be a separately established processing element, or it can be integrated in a chip of an electronic device. The implementation of other units is similar. In addition, all or part of these units can be integrated together, or they can be implemented independently. In the implementation process, each step of the above method or the above units can be completed by the hardware integrated logic circuit in the processor element or the instructions in the form of software.

[0145] For example, the above units may be one or more integrated circuits configured to implement the above methods, such as one or more application specific integrated circuits (ASIC), or one or more microprocessors (DSP), or one or more field programmable gate arrays (FPGA). For another example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0146] The present application also provides a security chip, including: a processor, for executing the present application Figure 4 to Figure 7 The method provided by the illustrated embodiment.

[0147] The security chip can be set in an electronic device, which may be a mobile phone, a tablet computer, a personal computer (PC), a wearable device, etc.

[0148] The present application also provides a computer-readable storage medium, in which a computer program is stored. When the computer-readable storage medium is run on a computer, the computer executes the present application. Figure 4 to Figure 7 The method provided by the illustrated embodiment.

[0149] The present application also provides a computer program product, which includes a computer program, which, when executed on a computer, enables the computer to execute the present application. Figure 4 to Figure 7 The method provided by the illustrated embodiment.

[0150] In the embodiments of the present application, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent the existence of A alone, the existence of A and B at the same time, and the existence of B alone. Among them, A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b and c can be represented by: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, c can be single or multiple.

[0151] Those of ordinary skill in the art will appreciate that the various units and algorithm steps described in the embodiments disclosed herein can be implemented in a combination of electronic hardware, computer software, and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0152] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0153] In several embodiments provided in the present application, if any function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory; hereinafter referred to as: ROM), random access memory (Random Access Memory; hereinafter referred to as: RAM), disk or optical disk, and other media that can store program codes.

[0154] The above is only a specific implementation of the present application. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. The protection scope of the present application should be based on the protection scope of the claims.

Claims

1. An attack detection method, characterized in that: At least two checkpoints are set in advance for a target path of a target program, the at least two checkpoints include: an initial checkpoint and at least one non-initial checkpoint, the initial checkpoint is located before the first code segment of the target path, the non-initial checkpoint is located after the last code segment of the target path or embedded between code segments included in the target path, the initial checkpoint is used to obtain a first value, the non-initial checkpoint is used to obtain a processing result of a previously triggered checkpoint, a first modulo operation is performed on the obtained processing result and a prime number corresponding to the non-initial checkpoint, and the processing result of the non-initial checkpoint is obtained; the method further includes: Obtaining a first processing result, where the first processing result is a processing result of a first checkpoint of the target path during the running of the target program; the first checkpoint is the last checkpoint of the target path that is triggered before obtaining the first processing result; Obtaining a first expected processing result, where the first expected processing result is a processing result of a last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value; After a comparison result between the first processing result and the first expected processing result is inconsistent, it is determined that the target path of the target program is attacked.

2. The method according to claim 1, characterized in that The obtaining of the first expected processing result includes: Acquire a first value obtained at an initial checkpoint of the target path during the running of the target program; The first expected processing result is calculated based on the second expected processing result and the third expected processing result preset for the target path, the second expected processing result is the processing result of the last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value of 0, and the third expected processing result is the processing result of the last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value of 1.

3. The method according to claim 1 or 2, characterized in that: The first modular operation is a modular addition operation or a modular multiplication operation, and the non-initial checkpoint of the target path has the same modular operation as that used for the first modular operation.

4. The method according to claim 3, characterized in that The first modular operations corresponding to the two adjacent non-initial checkpoints of the target path are modular addition operation and modular multiplication operation respectively.

5. The method according to any one of claims 1 to 4, characterized in that: Also includes: A first memory is preset for the target path, the initial checkpoint is specifically used to obtain a first value, and store the first value in the first memory; the non-initial checkpoint is specifically used to obtain a processing result of a previously triggered checkpoint from the first memory, perform a first modulus operation on the obtained processing result and a prime number corresponding to the non-initial checkpoint to obtain a processing result of the non-initial checkpoint, and store the calculated processing result of the non-initial checkpoint in the first memory; The obtaining of the first processing result includes: The first processing result is obtained from a first memory preset for the target path.

6. The method according to claim 2, characterized in that Also includes: A second memory is preset for the target path, and the initial checkpoint is further used to: store the first value in the second memory; The obtaining of a first value obtained at an initial checkpoint of the target path during the running of the target program includes: The first value is obtained from a second memory preset for the target path.

7. The method according to any one of claims 1 to 6, characterized in that: Also includes: A code segment for implementing the steps of obtaining the first processing result, obtaining the first expected processing result, and determining that the target path of the target program is attacked after the comparison result between the first processing result and the first expected processing result is inconsistent is set as a comparison point after the last non-initial checkpoint of the target path; The method further comprises: Obtaining the number of times the comparison point is triggered during the running of the target program; After the comparison result between the number and the expected number is inconsistent, it is determined that the target path is attacked.

8. The method according to any one of claims 1 to 4, characterized in that: Also includes: Pre-setting a trigger point for the target path, the trigger point is used to send a first instruction, the first instruction is used to trigger the steps of obtaining the first processing result, obtaining the first expected processing result, and determining that the target path of the target program is attacked after the comparison result between the first processing result and the first expected processing result is inconsistent; The trigger point is located after the last non-initial checkpoint of the target path; The first instruction includes the first processing result; The obtaining of the first processing result includes: receiving a first instruction, wherein the first instruction includes the first processing result; The first processing result is obtained from the first instruction.

9. The method according to claim 8, characterized in that The target program includes at least 2 target paths; The first instruction includes: the first processing result, and identification information of a target path corresponding to the first processing result; Acquiring the first processing result from the first instruction includes: A first processing result of the target path is acquired according to the identification information of the target path.

10. An attack detection device, characterized in that: include: At least two checkpoints are pre-set for a target path of a target program, the at least two checkpoints include: an initial checkpoint and at least one non-initial checkpoint, the initial checkpoint is located before a first code segment of the target path, the non-initial checkpoint is located after a last code segment of the target path or is embedded between code segments included in the target path, the initial checkpoint is used to obtain a first value, and the non-initial checkpoint is used to obtain a processing result of a previously triggered checkpoint, and a first modulo operation is performed on the obtained processing result and a prime number corresponding to the non-initial checkpoint to obtain a processing result of the non-initial checkpoint; A first acquisition unit is used to acquire a first processing result, where the first processing result is a processing result of a first checkpoint of the target path during the running of the target program; the first checkpoint is a checkpoint of the target path; A second acquisition unit is used to acquire a first expected processing result, where the first expected processing result is a processing result of a last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value; The first attack judgment unit is used to determine that the target path of the program is attacked after a comparison result between the first processing result and the first expected processing result is inconsistent.

11. The device according to claim 10, characterized in that The second acquisition unit is specifically used to: obtain a first value obtained by the initial checkpoint of the target path during the running of the target program; calculate the first expected processing result based on a second expected processing result and a third expected processing result preset for the target path, the second expected processing result being the processing result of the last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value of 0, and the third expected processing result being the processing result of the last checkpoint of the target path when the target path is run without being attacked and the initial checkpoint obtains a first value of 1.

12. The device according to claim 10 or 11, characterized in that The first modular operation is a modular addition operation or a modular multiplication operation, and the non-initial checkpoint of the target path has the same modular operation as that used for the first modular operation.

13. The device according to claim 12, characterized in that The first modular operations corresponding to the two adjacent non-initial checkpoints of the target path are modular addition operation and modular multiplication operation respectively.

14. A security chip, characterized in that: include: A processor, wherein the processor is configured to execute the method according to any one of claims 1 to 9.

15. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which, when executed on a computer, enables the computer to execute the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Program running interception method, terminal equipment and computer storage medium

    CN110232276A

  • Network behavior detection method and device, computer equipment and storage medium

    CN111131314A