A Java Memory Trojan Detection Method, Terminal Device and Storage Medium

By building a class loader list and judging the class loader and class information of passive classes, the problem of not being able to identify Java memory Trojans in the existing technology is solved, achieving higher detection accuracy and rapid identification of intrusion threats.

CN114936368BActive Publication Date: 2025-07-11XIAMEN FUYUN INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210421397.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-21
Publication Date
2025-07-11
Estimated Expiration
2042-04-21

AI Technical Summary

Technical Problem

The existing Java memory Trojan detection methods cannot effectively identify passive memory Trojans that use JSP dynamic compilation or Java bytecode technology for dynamic injection, especially independent agent frameworks and tool classes for dynamically generating Class, resulting in insufficient detection accuracy.

Method used

By building a class loader list, recording the class loader information of the Java system and web container, combining the class loader and class information of the passive class, we can determine whether the passive class is an anonymous class or whether its parent class is an active class, and further judge whether there is a threat to the passive class through the class loader and package location.

Benefits of technology

Improve the accuracy of Java memory Trojan detection, avoid misjudgment caused by independent research and development components and the features of new Java versions, and quickly identify potential intrusion threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114936368B_ABST
    Figure CN114936368B_ABST
Patent Text Reader

Abstract

The present invention relates to a method for detecting Java memory Trojans, a terminal device, and a storage medium. The method includes: S1: constructing a list of class loaders; S2: making the following judgments for each passive class in the current Java process; S3: determining whether the passive class is an anonymous class. If so, proceed to S4; otherwise, determine whether the passive class is threatening based on the class loader information and class information of the passive class; S4: determining whether the parent class of the passive class is an active class. If so, determine whether the passive class is threatening based on the class loader information of its parent class; otherwise, proceed to S5; S5: determining whether the class loader of the parent class of the passive class is the same as the class loader of the passive class. If the same, determine whether the passive class is threatening based on the class loader information and class information of the parent class of the passive class; otherwise, determine that the passive class is threatening. The present invention can improve the accuracy of detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Trojan detection, and in particular to a method for detecting Java memory Trojans, a terminal device, and a storage medium. Background Art

[0002] A Java memory Trojan is a memory Trojan that uses JSP dynamic compilation or Java bytecode technology for dynamic injection. A common feature of dynamically injected memory Trojans is that after the compilation and injection are completed, no corresponding class file will be formed. Moreover, in order to be compatible with all versions of Web containers and Java versions, a source-free memory Trojan will not use new syntax and features to build the memory Trojan. Therefore, existing detection methods all judge whether there is a source file for this class, or whether there is an execution of a Shell script command, etc.

[0003] In the actual Java development process, bytecode tools, or anonymous inner classes, proxies, etc. may be used for actual business operations. The above operations will all dynamically generate source-free classes, but the generated source-free classes are normal and most of them are not threatening because the internal is making normal business logic calls. The industry generally only excludes dynamically generated proxy classes using Java dynamic proxies and frameworks such as Spring, and some self-developed proxy frameworks, or utility classes that dynamically generate and load classes cannot be recognized normally. Summary of the Invention

[0004] In order to solve the above problems, the present invention proposes a method for detecting Java memory Trojans, a terminal device, and a storage medium.

[0005] The specific solutions are as follows:

[0006] A method for detecting Java memory Trojans, comprising the following steps:

[0007] S1: Construct a list of class loaders for recording the class loaders of the Java system and the class loaders of the Web container;

[0008] S2: Read and record all source-free classes and corresponding class information in the current Java process, and perform the following steps of judgment on each source-free class;

[0009] S3: Judge whether the source-free class is an anonymous class. If so, enter S4; otherwise, obtain the class loader information and class information of the source-free class, and judge whether the source-free class is threatening according to the class loader information and class information;

[0010] S4: Determine whether the parent class of this passive class is an active class. If so, obtain the class loader information of its parent class and determine whether this passive class is threatening based on the class loader information; otherwise, proceed to S5.

[0011] S5: Determine whether the class loader of the parent class of this passive class is the same as the class loader of this passive class. If they are the same, obtain the class loader information and class information of the parent class of this passive class and determine whether this passive class is threatening based on the class loader information and class information; otherwise, determine that this passive class is threatening.

[0012] Furthermore, the method for determining whether this passive class is threatening based on the class loader information and class information is as follows: Only when it is determined that this passive class is not threatening based on both the class loader information and the class information, is it determined that this passive class is not threatening.

[0013] Furthermore, the method for determining whether this passive class is threatening based on the class loader information includes the following steps:

[0014] S101: Determine whether the class loader is a custom class loader. If so, proceed to S102; otherwise, proceed to S104.

[0015] S102: Determine whether the class loader is an active class. If so, proceed to S103; otherwise, determine that this passive class is threatening.

[0016] S103: Determine whether the class loader and the parent class of this passive class are in the same package. If so, determine that this passive class is not threatening; otherwise, determine that this passive class is threatening.

[0017] S104: Determine whether the class loader is a class loader of the Java system or a class loader of a web container. If it is a class loader of the Java system, determine that this passive class is not threatening; if it is a class loader of a web container, determine that this passive class is threatening.

[0018] Furthermore, the method for determining whether the class loader is a custom class loader in step S101 is as follows: By matching the class loader with each class loader in the class loader list, when the class loader belongs to neither the class loader of the Java system nor the class loader of a web container, it is determined to be a custom class loader.

[0019] Furthermore, the method for determining whether this passive class is threatening based on the class information is as follows: Extract the package information of the class based on the class information, and find the corresponding package location based on the package information. Then, determine whether the package location is in the loading path when the web container starts. If it is not, determine that this passive class is threatening; if it is, determine that this passive class is not threatening.

[0020] A Java memory Trojan detection terminal device, including a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method in the above embodiments of the present invention are implemented.

[0021] A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the steps of the method in the above embodiments of the present invention are implemented.

[0022] By adopting the above technical solution, the present invention can avoid misdetection caused by some self-developed Java components or language features of new Java versions, improve the accuracy of detection, and help security personnel determine whether there is an intrusion threat faster. Description of the Drawings

[0023] Figure 1 The flowchart of the method in Embodiment 1 of the present invention is shown.

[0024] Figure 2 The flowchart of the method for judging whether the passive class is threatened according to the class loader information in this embodiment is shown. Detailed Embodiments

[0025] To further illustrate each embodiment, the present invention provides drawings. These drawings are part of the disclosure of the present invention, mainly used to illustrate the embodiments, and can be combined with the relevant descriptions in the specification to explain the operating principle of the embodiments. With reference to these contents, those of ordinary skill in the art should be able to understand other possible implementation manners and the advantages of the present invention.

[0026] Now, the present invention will be further described in combination with the drawings and specific embodiments.

[0027] Embodiment 1:

[0028] The embodiment of the present invention provides a Java memory Trojan detection method, as Figure 1 shown, which is the flowchart of the Java memory Trojan detection method described in the embodiment of the present invention. The method includes the following steps:

[0029] S1: Construct a class loader list for recording the class loaders of the Java system and the class loaders of the Web container.

[0030] S2: Read and record all passive classes and their corresponding class information in the current Java process, and perform the following steps of judgment on each passive class.

[0031] An active class refers to a class with an entity file, and a passive class refers to a class without an entity file.

[0032] S3: Determine whether the passive class is an anonymous class. If so, go to S4; otherwise, obtain the class loader information and class information of the passive class, and determine whether the passive class is threatening based on the class loader information and class information.

[0033] S4: Determine whether the superclass of the passive class is an active class. If so, obtain the class loader information of its superclass, and determine whether the passive class is threatening based on the class loader information; otherwise, go to S5.

[0034] S5: Determine whether the class loader of the superclass of the passive class is the same as the class loader of the passive class. If so, obtain the class loader information and class information of the superclass of the passive class, and determine whether the passive class is threatening based on the class loader information and class information; otherwise, determine that the passive class is threatening.

[0035] By performing the determination of whether each passive class is threatening through steps S3 - S5, all the threatening passive classes (i.e., passive memory trojans) in the current Java process can be obtained.

[0036] The method for determining whether the passive class is threatening based on the class loader information and class information is as follows: Only when it is determined that the passive class is not threatening according to both the class loader information and the class information, is it determined that the passive class is not threatening. When either of them determines that the passive class is threatening, then it is determined that the passive class is threatening.

[0037] (1) As Figure 2 shown, the method for determining whether the passive class is threatening based on the class loader information includes the following steps:

[0038] S101: Determine whether the class loader is a custom class loader. If so, go to S102; otherwise, go to S104.

[0039] According to the class loader list, when the class loader belongs to neither the class loader of the Java system nor the class loader of the web container, it is determined to be a custom class loader.

[0040] S102: Determine whether the class loader is an active class. If so, go to S103; otherwise, determine that the passive class is threatening.

[0041] S103: Determine whether the class loader and the superclass of the passive class are in the same package. If so, determine that the passive class is not threatening; otherwise, determine that the passive class is threatening.

[0042] S104: Determine whether the class loader is the class loader of the Java system or the class loader of the web container. If it is the class loader of the Java system, determine that the passive class is not threatening; if it is the class loader of the web container, determine that the passive class is threatening.

[0043] (2) The method for determining whether a passive class is threatening based on class information is as follows: extract the package information of the class according to the class information, find the corresponding package location according to the package information, and then determine whether the package location is in the loading path when the Web container starts. If not, it is determined that the passive class is threatening; if so, it is determined that the passive class is not threatening.

[0044] The embodiments of the present invention can avoid false detection caused by some self-developed Java components or language features of new versions of Java, improve the accuracy of detection, and help security personnel determine whether there is an intrusion threat faster.

[0045] Embodiment 2:

[0046] The present invention also provides a Java memory Trojan detection terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps in the above method embodiment of Embodiment 1 of the present invention are implemented.

[0047] Further, as an executable solution, the Java memory Trojan detection terminal device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The Java memory Trojan detection terminal device may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the composition structure of the above Java memory Trojan detection terminal device is only an example of the Java memory Trojan detection terminal device, and does not limit the Java memory Trojan detection terminal device. It may include more or fewer components than the above, or combine some components, or different components. For example, the Java memory Trojan detection terminal device may also include input / output devices, network access devices, a bus, etc. The embodiments of the present invention do not limit this.

[0048] Further, as an executable solution, the so-called processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the Java memory Trojan detection terminal device, and connects various parts of the entire Java memory Trojan detection terminal device through various interfaces and lines.

[0049] The memory can be used to store the computer program and / or module. The processor realizes various functions of the Java memory Trojan detection terminal device by running or executing the computer program and / or module stored in the memory, and by calling the data stored in the memory. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the mobile phone, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, memory, plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, at least one magnetic disk storage device, flash device, or other volatile solid-state storage devices.

[0050] The present invention also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the method in the above embodiments of the present invention are implemented.

[0051] If the modules / units integrated in the Java memory trojan detection terminal device are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-described embodiment methods of the present invention, it can also be completed by a computer program instructing relevant hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), and software distribution medium, etc.

[0052] Although the present invention has been specifically shown and described in conjunction with the preferred embodiments, those skilled in the art should understand that various changes can be made to the present invention in terms of form and details without departing from the spirit and scope of the present invention defined by the appended claims, and all such changes are within the protection scope of the present invention.

Claims

1. A Java memory Trojan detection method, characterized in that It includes the following steps: S1: Construct a list of class loaders to record the class loaders of the Java system and the class loaders of the web container; S2: Read and record all passive classes and corresponding class information in the current Java process, and perform the following steps of judgment on each passive class; S3: Judge whether the passive class is an anonymous class. If so, go to S4; otherwise, obtain the class loader information and class information of the passive class, and judge whether the passive class is threatening according to the class loader information and class information; S4: Judge whether the superclass of the passive class is an active class. If so, obtain the class loader information of its superclass, and judge whether the passive class is threatening according to the class loader information; otherwise, go to S5; S5: Judge whether the class loader of the superclass of the passive class is the same as the class loader of the passive class. If the same, obtain the class loader information and class information of the superclass of the passive class, and judge whether the passive class is threatening according to the class loader information and class information; otherwise, determine that the passive class is threatening; The method for judging whether the passive class is threatening according to the class loader information includes the following steps: S101: Judge whether the class loader is a custom class loader. If so, go to S102; otherwise, go to S104; S102: Judge whether the class loader is an active class. If so, go to S103; otherwise, determine that the passive class is threatening; S103: Judge whether the class loader and the superclass of the passive class are in the same package. If so, determine that the passive class is not threatening; otherwise, determine that the passive class is threatening; S104: Judge whether the class loader is a class loader of the Java system or a class loader of the web container. If it is a class loader of the Java system, determine that the passive class is not threatening. If it is a class loader of the web container, determine that the passive class is threatening.

2. The Java memory Trojan detection method according to claim 1, wherein: The method for judging whether the passive class is threatening according to the class loader information and class information is: Only when it is judged that the passive class is not threatening according to both the class loader information and the class information, determine that the passive class is not threatening.

3. The Java memory Trojan detection method according to claim 1, characterized in that: The method for judging whether the class loader is a custom class loader in step S101 is: Match the class loader with each class loader in the class loader list. When the class loader belongs to neither the class loader of the Java system nor the class loader of the web container, it is determined to be a custom class loader.

4. The Java memory Trojan detection method according to claim 1, wherein: The method for judging whether the passive class is threatening according to the class information is: Extract the package information of the class according to the class information, and find the corresponding package location according to the package information, and then judge whether the package location is in the loading path when the web container starts. If not, determine that the passive class is threatening. If so, determine that the passive class is not threatening.

5. A Java memory Trojan detection terminal device, characterized in that: It includes a processor, a memory, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.

6. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • File-free Trojan searching and killing method and device

    CN114065204A