Malicious script detection methods, equipment, media and products

By using coroutines to simulate threads in malicious script detection, the problems of low detection efficiency and high resource utilization in the existing technology are solved, and more efficient malicious script detection is achieved.

CN114969746BActive Publication Date: 2025-05-16ALIBABA CLOUD COMPUTING CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202210764941.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-29
Publication Date
2025-05-16
Estimated Expiration
2042-06-29

AI Technical Summary

Technical Problem

In the prior art, the execution effect of the target script is simulated by the threads required to execute the target script, resulting in high memory and computing resources occupied when detecting malicious scripts and low detection efficiency.

Method used

By obtaining the target script to be detected, determine the thread needed to run the target script, and create a coroutine corresponding to the thread, use coroutines to simulate threads to execute the target script, and determine whether the target script is a malicious script based on the execution results.

Benefits of technology

Since the execution of coroutines is controlled by the user, and the memory and computing resources occupied by the coroutine creation and switching process relative to the thread process is greatly reduced, the execution efficiency of the target script is effectively improved, the memory and computing resources required for detection are reduced, and the detection efficiency is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114969746B_ABST
    Figure CN114969746B_ABST
Patent Text Reader

Abstract

The present application provides a method, device, medium and product for detecting malicious scripts, the method comprising: obtaining a target script to be detected; determining the thread required to run the target script, and creating a coroutine corresponding to the thread; using the technology of coroutine simulating thread to execute the target script, and determining the execution result of the target script; determining whether the target script is a malicious script according to the execution result. It can be applied to detect malicious scripts in virtual cloud services, because a coroutine corresponding to the thread required to run the target script is created, and a coroutine simulating thread is used to execute the target script, and the execution of the coroutine is controlled by the user state, and the memory and computing resources occupied by the creation and switching process of the coroutine are greatly reduced, so the execution efficiency of the target script is effectively improved, thereby effectively reducing the memory and computing resources occupied by the detection of the target script and improving the detection efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to cloud computing technology, and in particular to a malicious script detection method, device, medium and product. Background Art

[0002] Malicious scripts are scripts that perform malicious operations on the cloud, terminal or other computer devices. For example, a typical malicious script Webshell can obtain the execution permission of the server and ultimately achieve the purpose of controlling the server. Malicious scripts can also affect the security of data or programs after running, so the detection of malicious scripts is very necessary.

[0003] In order to ensure the security of data or programs when detecting malicious scripts, the simulation execution technology is used to execute the target script to be detected to achieve the purpose of detection.

[0004] However, in the prior art, the execution effect of the target script is usually simulated by running the threads required to execute the target script. However, since the creation and switching of threads need to be completed in the kernel state of the operating system, the threads required to execute the target script will result in high memory and computing resources occupied, and low execution efficiency, which in turn leads to high memory and computing resources occupied when detecting malicious scripts, and low detection efficiency. Summary of the invention

[0005] The present application provides a malicious script detection method, device, medium and product to solve the problem in the prior art that the execution effect of the target script is simulated by executing the thread required by the target script, resulting in high memory and computing resources occupied when detecting malicious scripts and low detection efficiency.

[0006] In a first aspect, an embodiment of the present application provides a method for detecting a malicious script, comprising:

[0007] Get the target script to be detected;

[0008] Determine the thread required to run the target script, and create a coroutine corresponding to the thread;

[0009] Execute the target script using the coroutine simulation thread technology, and determine the execution result of the target script;

[0010] Determine whether the target script is a malicious script according to the execution result.

[0011] In a second aspect, an embodiment of the present application provides a malicious script detection device, including:

[0012] An acquisition module is used to obtain the target script to be detected;

[0013] A creation module is used to determine the thread required to run the target script and create a coroutine corresponding to the thread;

[0014] A simulation execution module, used to execute the target script using the coroutine simulation thread technology and determine the execution result of the target script;

[0015] A detection module is used to determine whether the target script is a malicious script according to the execution result.

[0016] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor;

[0017] The memory stores computer-executable instructions;

[0018] The processor executes the computer-executable instructions stored in the memory to implement the method according to the first aspect.

[0019] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, they are used to implement the method described in the first aspect.

[0020] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which implements the method described in the first aspect when executed by a processor.

[0021] The present application provides a method, device, medium and product for detecting malicious scripts, obtaining a target script to be detected; determining the thread required to run the target script, and creating a coroutine corresponding to the thread; using the technology of coroutine simulating thread to execute the target script, and determining the execution result of the target script; determining whether the target script is a malicious script according to the execution result. Since a coroutine corresponding to the thread required to run the target script is created, and the coroutine simulating thread is used to execute the target script, and the execution of the coroutine is controlled by the user state, and the memory and computing resources occupied by the creation and switching process of the coroutine are greatly reduced relative to the creation and switching process of the thread, the execution efficiency of the target script is effectively improved, thereby effectively reducing the memory and computing resources occupied by the detection of the target script, and improving the detection efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0023] Figure 1 A schematic diagram of an application scenario provided for an embodiment of the present application;

[0024] Figure 2 A flowchart of a malicious script detection method provided in Example 1 of the present application;

[0025] Figure 3 A flowchart of a malicious script detection method provided in Example 3 of the present application;

[0026] Figure 4 A flowchart of a malicious script detection method provided in Embodiment 4 of the present application;

[0027] Figure 5 A schematic diagram of coroutine switching provided in an embodiment of the present application;

[0028] Figure 6 A schematic diagram of the structure of a malicious script detection device provided in Example 6 of the present application;

[0029] Figure 7 This is a schematic diagram of the structure of an electronic device provided in Example 7 of the present application.

[0030] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0031] Here, exemplary embodiments will be described in detail, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. Instead, they are only examples of devices and methods consistent with some aspects of the present application.

[0032] The terms "first", "second", etc. are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. In the description of the following embodiments, "multiple" means more than two, unless otherwise clearly and specifically defined.

[0033] In order to clearly understand the technical solution of the present application, the solution of the prior art is first introduced in detail.

[0034] Currently, hackers often use malicious script Webshells to obtain execution permissions on the server, such as executing system commands, stealing user data, deleting web pages, modifying homepages, etc.

[0035] Specifically, hackers upload a Webshell in the system to connect to the outside world, allowing hackers to insert more precise malicious scripts and execute the instructions they need. Alternatively, the Webshell can have a database or file browser, allowing hackers to view the code and data of the intrusion system.

[0036] Malicious scripts can affect the security of data or programs after running, so it is very necessary to detect malicious scripts. Since threads are managed by the operating system kernel, the threads required to run the target script occupy a high amount of memory and computing resources and have low efficiency. Furthermore, in the prior art, the execution effect of the target script is simulated by running the threads required to execute the target script, resulting in the problem that the memory and computing resources occupied by the detection of the target script are high, and the execution efficiency is low.

[0037] Exemplarily, if the target script in the target script needs to be executed by multithreading, then in order to accurately detect whether the target script is a malicious script, it is necessary to use simulated execution technology to create multithreading and switch to execute the target script through multithreading when executing the target script. Since the creation and switching processes of threads need to be completed in the kernel state of the operating system, the scheduling of threads needs to be frequently switched in and out between the kernel state and the user state, so the efficiency of using multithreading to execute the target script is low. And each thread needs to allocate stack space in memory, which is generally about 1 megabyte to 8 megabytes, and when creating a thread, the central processing unit (abbreviated as: CPU) needs to execute a large number of functions for switching, which will occupy a large amount of memory and computing resources, so the memory and computing resources occupied by detecting the target script are high, and the execution efficiency is low.

[0038] A coroutine is a lightweight thread in user mode. The scheduling of the coroutine is completely controlled by the user. There is no conflict in writing variables at the same time in the coroutine, so there is no need for synchronization primitives such as mutex locks and semaphores to guard key blocks, and no support from the operating system is required. Therefore, the use of coroutines to simulate threads to execute the target script can improve execution efficiency. The memory and computing resources occupied by the creation and switching process of coroutines are greatly reduced compared to the creation and switching process of threads. For example, creating a coroutine allocates stack space in memory, which is generally tens of kilobytes. Therefore, the memory and computing resources occupied by coroutines can be reduced when executing the target script. Therefore, the present application provides a method for detecting malicious scripts. After determining the thread required to run the target script, a coroutine corresponding to the thread is created; the target script is executed using the technology of coroutine simulation threads, and the execution result of the target script is determined; and whether the target script is a malicious script is determined based on the execution result. Since a coroutine corresponding to the thread required to run the target script is created, and a coroutine is used to simulate the thread to execute the target script, and the execution of the coroutine is controlled by the user state, and the memory and computing resources occupied by the coroutine creation and switching process are greatly reduced compared to the thread creation and switching process, the execution efficiency of the target script is effectively improved, which can effectively reduce the memory and computing resources occupied by the target script detection and improve the detection efficiency.

[0039] Figure 1 The following is a schematic diagram of an application scenario provided by an embodiment of the present application, such as Figure 1 As shown, the embodiment of the present application can be applied to detect malicious scripts in a virtual cloud service. Specifically, the application scenario includes a user terminal 1 and a cloud server 2. The administrator of the virtual cloud service can store a target script in the cloud server 2 through the user terminal 1, and detect whether the target script is a malicious script through the malicious script detection device in the cloud server 2. If it is not a malicious script, the cloud server 2 can store the target script and allow it to run; if it is a malicious script, the cloud server 2 can send a malicious script alert to the user terminal 1, so that the administrator can clear the malicious script, and then the malicious script will not affect the cloud server.

[0040] It is understandable that the malicious script detection method provided in the present application can also be applied to the detection of whether the application scripts installed in user terminals and other computer devices are malicious scripts, which is not limited in this embodiment.

[0041] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0042] Embodiment 1

[0043] Figure 2 A flowchart of a malicious script detection method provided in Example 1 of the present application is provided. The embodiment of the present application provides a malicious script detection method to address the problem that the execution effect of the target script is simulated by running the thread required by the target script in the prior art, resulting in high memory and computing resources occupied for detecting the target script and low efficiency. The execution subject of the malicious script detection method provided in this embodiment can be a malicious script detection device. In actual applications, the malicious script detection device can be implemented by a computer program, such as an application script, a detection engine, etc., or by a medium storing relevant computer programs, such as a USB flash drive, a CD, etc., or by a physical device integrated or installed with relevant computer programs, such as a chip, a board, etc.

[0044] In addition, the detection device of the malicious script can be located in an electronic device. The electronic device can be a digital computer and server representing various forms, such as a cloud server, a smart phone, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers.

[0045] like Figure 2 As shown, the malicious script detection method provided in this embodiment includes the following steps:

[0046] Step S101: Obtain a target script to be detected.

[0047] In the embodiment of the present application, the target script is a multi-threaded application script or a single multi-threaded application script that can be run by a computer.

[0048] The embodiment of the present application does not limit the form of the target script to be detected. Exemplarily, a file storing the target script can be obtained, and the target script can be obtained from the file, or the target script can be directly obtained.

[0049] The embodiments of the present application do not limit the method for obtaining the target script. For example, the target script in the specified storage space can be obtained regularly or periodically to detect the target script in the storage space, or the target script input by the user can be obtained.

[0050] Step S102: determine the thread required to run the target script, and create a coroutine corresponding to the thread.

[0051] In this embodiment, when determining the threads required to run the target script and creating the coroutines corresponding to the threads, the target script can be executed through simulation execution technology to dynamically obtain detailed information of the threads that need to be created during the running of the target script, obtain the start function for creating the corresponding threads, and create the coroutines corresponding to the threads required by the target script based on the detailed information and the start function, and the number of coroutines created is consistent with the number of threads required by the target script.

[0052] The created coroutine is used to simulate the thread required to run the target script.

[0053] Exemplarily, if it is determined that thread A and thread B are required to run the target script, two coroutines corresponding to thread A and thread B are created.

[0054] In the embodiment of the present application, the creation of the coroutine can be completed by creating a coroutine structure corresponding to the coroutine and determining the corresponding stack space. For example, the stack space can be created and the created stack space can be allocated to the coroutine to determine the stack space corresponding to the coroutine, or the stack space corresponding to the thread corresponding to the malicious script detection engine can be allocated to the coroutine to determine the corresponding stack space, which is not specifically limited in the embodiment of the present application.

[0055] Step S103: execute the target script using the coroutine simulation thread technology, and determine the execution result of the target script.

[0056] Specifically, before using the coroutine simulation thread technology to execute the target script, the operating environment, interpreter, and related resources required to execute the target script are constructed, and then the coroutine simulation thread is used to make the target script run in a virtual environment, so that the simulated execution result does not affect the device equipped with the target script, that is, if the target script is a malicious script, the execution of this malicious script will not affect the device equipped with the target script.

[0057] The embodiments of the present application do not limit the specific method of executing the target script using the technology of coroutine simulation thread. For example, when using coroutine to simulate single thread, a single coroutine can be created to simulate the creation of a single thread, and a single coroutine can be used to execute the target script to achieve the effect of simulating the execution of the target script script target script by a single thread mode. When using coroutine to simulate multithreading, the switching between multithreads can be simulated by switching between multi-coroutines, so as to achieve the effect of simulating the execution of the target script script target script by multi-threading mode.

[0058] Step S104: Determine whether the target script is a malicious script according to the execution result.

[0059] In an embodiment of the present application, various required detection strategies can be added to detect the target script, and the execution result of the malicious script under the detection strategy can be set. Whether the target script is a malicious script can be determined based on whether the execution result of the target script conforms to the execution result of the malicious script under the detection strategy, so that the target script can expose as many malicious behaviors as possible.

[0060] Exemplarily, a taint transfer method may be used to detect whether the target script is a malicious script. If it is determined through the execution result that there is a taint transfer process, it may be determined to be a malicious script.

[0061] Optionally, after being determined to be a malicious script, a malicious script alert may be sent to a user terminal used by an administrator, so that the administrator can remove the malicious script.

[0062] The malicious script detection method provided in the embodiment of the present application obtains the target script to be detected; determines the thread required to run the target script, and creates a coroutine corresponding to the thread; uses the coroutine simulation thread technology to execute the target script, and determines the execution result of the target script; determines whether the target script is a malicious script based on the execution result. Since a coroutine corresponding to the thread required to run the target script is created, and the coroutine simulation thread is used to execute the target script, and the execution of the coroutine is controlled by the user state, and the memory and computing resources occupied by the creation and switching process of the coroutine are greatly reduced relative to the creation and switching process of the thread, the execution efficiency of the target script is effectively improved, and thus the memory and computing resources occupied by the detection of the target script can be effectively reduced, and the detection efficiency can be improved.

[0063] In the prior art, when using simulation execution technology to create multiple threads and execute target scripts, if the target scripts are not written in a standardized manner, multiple threads will be deadlocked. In order to successfully exit the deadlock state, complex fault-tolerant processing is required in the kernel state to successfully exit the deadlock.

[0064] Therefore, in the embodiment of the present application, optionally, a deadlock detection can be performed during the execution of the target script; if a deadlock is determined to have occurred, all coroutines are forcibly awakened and the main coroutine is used for operation.

[0065] The embodiments of the present application do not limit the manner of performing deadlock detection. For example, it is possible to detect in user mode whether all coroutines are in a blocked state, or it is possible to detect in user mode whether any coroutine is in a running state.

[0066] For example, during the execution of the target script, it can be detected in the user state whether any coroutine is in the running state. If any coroutine is in the running state, no deadlock occurs. If no coroutine is in the running state, a deadlock occurs, and all coroutines are forced to be awakened, and the main coroutine is used to run to exit the execution of the target script.

[0067] The malicious script detection method provided in the embodiment of the present application performs deadlock detection during the execution of the target script; if it is determined that a deadlock occurs, all coroutines are forcibly awakened, and the main coroutine is used to run. When a deadlock occurs, all coroutines can be forcibly awakened in the user state, and the main coroutine is used to run to exit the execution of the target script. Therefore, it can effectively avoid the deadlock caused by non-standard writing of the target script, and complex fault-tolerant processing can be performed to exit the deadlock state, thereby avoiding long-term deadlock.

[0068] Optionally, after executing the target script using the coroutine simulation thread technology, if it is monitored that the target script has been executed, all related resources corresponding to the coroutines are recovered and the corresponding coroutines are deleted.

[0069] Exemplarily, the stack space allocated to the coroutine can be reclaimed, the corresponding coroutine structure can be deleted, and other methods can be used to reclaim the relevant resources corresponding to all coroutines, and then delete the corresponding coroutine.

[0070] The malicious script detection method provided by the embodiment of the present application, if the target script is detected to be executed, then the relevant resources corresponding to all the coroutines are recovered and the corresponding coroutines are deleted. By recovering the relevant resources corresponding to all the coroutines and deleting the corresponding coroutines, the occupation of memory resources and computing resources by the coroutines corresponding to the detected target script can be avoided, thereby further saving memory space and computing resources.

[0071] Embodiment 2

[0072] On the basis of any of the above embodiments, the embodiment of the present application relates to a refinement of the implementation method of creating a coroutine corresponding to a thread in step S102. When the number of threads required to run the target script is one, an implementation method of creating a coroutine corresponding to a thread may include the following steps:

[0073] Step S201: Obtain the thread corresponding to the malicious script detection engine.

[0074] In the embodiment of the present application, the thread corresponding to the malicious script detection engine is a thread for detecting malicious scripts. Optionally, the thread corresponding to the malicious script detection engine can be a main thread running the target script. The malicious script detection engine can be run in a malicious script detection device, and the thread corresponding to the malicious script detection engine for detecting malicious scripts can be obtained.

[0075] Step S202: Create a main coroutine structure corresponding to the main coroutine in the corresponding thread, and allocate the stack space of the corresponding thread to the main coroutine to complete the creation of the main coroutine.

[0076] Among them, the main coroutine is a coroutine that simulates the main thread running the main function (abbreviated as: main function) in the target script. The main coroutine structure includes the main function that the main coroutine needs to execute and the main coroutine's status, virtual ID, variable information and other related information of the main coroutine.

[0077] The embodiment of the present application completes the creation of the main coroutine by creating a main coroutine structure corresponding to the main coroutine and using the stack space of the corresponding thread as the stack space corresponding to the main coroutine. Instead of creating a stack space for the main coroutine, the thread stack space corresponding to the malicious script detection engine is allocated to the main coroutine, which can reduce the occupation of memory resources.

[0078] The malicious script detection method provided in the embodiment of the present application obtains the thread corresponding to the malicious script detection engine; creates a main coroutine structure corresponding to the main coroutine in the corresponding thread, and allocates the stack space of the corresponding thread to the main coroutine to complete the creation of the main coroutine. When the number of threads required by the target script is one, a coroutine corresponding to the thread can be created, and since stack space is not created for the main coroutine, and the thread stack space corresponding to the malicious script detection engine is allocated to the main coroutine, the occupation of memory resources can be reduced.

[0079] Optionally, when the number of threads required to run the target script is multiple, an implementation method of creating a coroutine corresponding to the thread may also include: creating a sub-coroutine structure corresponding to at least one sub-coroutine in the corresponding thread, and allocating corresponding stack space to each sub-coroutine to complete the creation of each sub-coroutine.

[0080] In the embodiment of the present application, when the number of threads is multiple, the threads required to execute the target script include a main thread and at least one sub-thread. Therefore, it is necessary to create a main coroutine corresponding to the main thread and at least one sub-coroutine corresponding to at least one sub-thread.

[0081] Specifically, the creation of the main coroutine is completed by adopting step S201 and step S202. After the main coroutine is created, a sub-coroutine structure corresponding to each sub-coroutine is created in the thread corresponding to the malicious script detection engine, and a stack space corresponding to each sub-coroutine is created to complete the creation of each sub-coroutine.

[0082] In the embodiment of the present application, the sub-coroutine is the coroutine required by the simulated thread to run the sub-function in the target script. Exemplarily, the coroutines corresponding to the thread required by the target script include coroutine A, coroutine B, and coroutine C. If coroutine A is determined to be the main coroutine, then coroutine B and coroutine C can be determined as sub-coroutines, and the sub-coroutine structures corresponding to coroutines B and coroutine C can be created, and the stack space corresponding to coroutines B and coroutine C can be created to complete the creation of each sub-coroutine.

[0083] The malicious script detection method provided in the embodiment of the present application creates a sub-coroutine structure corresponding to at least one sub-coroutine in the thread corresponding to the malicious script detection engine, and allocates corresponding stack space to each sub-coroutine to complete the creation of each sub-coroutine. When the number of threads required for the target script is multiple, the sub-coroutine and the main coroutine can be created in the same thread, so that when switching between threads, the target coroutine can be found in the same thread, thereby improving the efficiency of switching threads, and further improving the efficiency of detecting the target script.

[0084] Embodiment 3

[0085] Figure 3 A flowchart of a malicious script detection method provided in Embodiment 3 of the present application. Based on any of the above embodiments, the embodiment of the present application involves a refinement of an implementation method of executing a target script using the technology of coroutine simulation thread in step S103, such as Figure 3 As shown, the specific steps include:

[0086] Step S301: Use the main coroutine to simulate the main thread to execute the target script.

[0087] Step S302: If it is monitored that the target script is executed to the point where at least one sub-thread is used to continue executing the subsequent target script through the main-sub-thread switching, the main-sub-coroutine switching is used to simulate the main-sub-thread switching, the main coroutine is switched to the current target sub-coroutine, and at least the current target sub-coroutine is used to continue executing the subsequent target script.

[0088] In an embodiment of the present application, when the technology of coroutine simulation thread is adopted to execute the target script, the main coroutine is adopted to simulate the main thread to execute the target script; if the number of threads is multiple, it is monitored whether the target script is executed to adopt at least one sub-thread to continue to execute the subsequent target script through the main-sub-thread switching; if so, the main coroutine is switched to the current target sub-coroutine, and at least the current target sub-coroutine is adopted to continue to execute the subsequent target script; if not, the main coroutine is continued to be adopted to simulate the main thread to execute the target script.

[0089] Among them, the current target sub-coroutine is the first sub-coroutine that executes the subsequent target script through the main-sub-coroutine switching after the main coroutine executes the target script.

[0090] Exemplarily, if the created coroutine includes: main coroutine A, sub-coroutine B, and sub-coroutine C, and it is monitored that the target script is executed to continue to execute the subsequent target script by switching the main sub-thread with at least one sub-thread, then the main coroutine A is switched to sub-coroutine B, and at least sub-coroutine B is used to continue to execute the subsequent target script. When at least sub-coroutine B is used to continue to execute the subsequent target script, sub-coroutine B, or sub-coroutine B and sub-coroutine C, or sub-coroutine B and main coroutine A, etc., one or more coroutines including at least sub-coroutine B can be used to continue to execute the subsequent target script.

[0091] In the embodiment of the present application, it is possible to monitor whether the target script is executed to continue to execute the subsequent target script by using at least one sub-thread through the main-sub-thread switching by detecting whether the blocking functions such as the sleep function, the wait lock function, and the coroutine switching function are executed. If it is determined that any one of the blocking functions such as the sleep function, the wait lock function, and the coroutine switching function is executed, it can be determined that the target script is executed to continue to execute the subsequent target script by using at least one sub-thread through the main-sub-thread switching.

[0092] The malicious script detection method provided in the embodiment of the present application adopts the main coroutine to simulate the main thread to execute the target script; if it is monitored that the target script is executed to use at least one sub-thread to continue to execute the subsequent target script through the main-sub-thread switching, the main-sub-coroutine switching is adopted to simulate the main-sub-thread switching, the main coroutine is switched to the current target sub-coroutine, and at least the current target sub-coroutine is used to continue to execute the subsequent target script. The main-sub-coroutine switching can be used to simulate the main-sub-thread switching, thereby realizing the simulation of the main-sub-thread switching when executing multi-threaded scripts.

[0093] In an optional implementation, the main coroutine switches to the current target sub-coroutine, including: switching the context information corresponding to the main coroutine to the context information corresponding to the current target sub-coroutine in the user state, so as to complete the switching from the main coroutine to the current target sub-coroutine.

[0094] The context information includes the variables, status, and current running location of the coroutine.

[0095] Specifically, if it is determined to switch the main coroutine to the current target sub-coroutine, the main-sub-coroutine switching operation is performed, the context information corresponding to the main coroutine is saved, and the context information corresponding to the current target sub-coroutine is switched. In the embodiment of the present application, the specific method of switching context information is not limited. For example, the context information can be switched by switching the stack.

[0096] The malicious script detection method provided by the embodiment of the present application switches the context information corresponding to the main coroutine to the context information corresponding to the current target sub-coroutine in the user state to complete the switch from the main coroutine to the current target sub-coroutine. Since the main coroutine and the sub-coroutine are executed in the same thread, the switch from the main coroutine to the current target sub-coroutine occurs in the user state, which can improve the efficiency of simulating thread switching compared to switching threads in the kernel state, and further improve the efficiency of detecting the target script.

[0097] Embodiment 4

[0098] Figure 4 A flowchart of a malicious script detection method provided in Embodiment 4 of the present application. Based on any of the above embodiments, the embodiment of the present application involves a refinement of an implementation method of using at least the current target subroutine to continue to execute a subsequent target script in step S302, such as Figure 4 As shown, the specific steps include:

[0099] Step S401: Use the current target sub-coroutine to simulate the current target sub-thread to execute the target script.

[0100] Step S402: monitor whether the target script is executed to the point where the next target sub-thread is adopted to continue executing the subsequent target script by switching between sub-threads.

[0101] If yes, then execute step S403 and step S404 of simulating switching between sub-threads by switching between sub-coroutines; if no, execute step S405.

[0102] Step S403: Switching between sub-coroutines is used to simulate switching between sub-threads, the current target sub-coroutine is switched to the next target sub-coroutine, and the next target sub-coroutine is used to continue executing the subsequent target script.

[0103] Step S404: Update the next target sub-coroutine to the current target sub-coroutine.

[0104] After the next target sub-coroutine is updated to the current target sub-coroutine, S402 is executed to continue monitoring whether the target script is executed to continue executing the subsequent target script by switching between sub-threads and adopting the next target sub-thread.

[0105] Step S405: Continue to execute the target script until the main thread is switched to continue to execute the subsequent target script through the sub-main thread.

[0106] In the embodiment of the present application, the method of executing the switching between sub-coroutines to simulate the switching between sub-threads is similar to the method of executing the switching between main sub-coroutines to simulate the switching between main sub-threads, and will not be repeated here.

[0107] In an embodiment of the present application, when the current target sub-coroutine is used to execute the target script, if it is monitored that the target script is executed to continue to execute the subsequent target script by switching between sub-threads and adopting the next target sub-thread, step S402 and the subsequent steps of simulating switching between sub-threads by switching between sub-coroutines are executed to continue to execute the subsequent target script by adopting the next target sub-coroutine; if it is not monitored that the target script is executed to continue to execute the subsequent target script by switching between sub-threads and adopting the next target sub-thread, it is determined whether it is monitored that the target script is executed to continue to execute the subsequent target script by switching between sub-main threads and adopting the main thread, and if so, step S405 is executed to simulate the sub-main thread switching by switching between sub-main coroutines, so as to continue to execute the subsequent target script by adopting the main coroutine. After executing step S402, step S403 can be executed to continue to monitor whether the target script is executed to continue executing the subsequent target script by switching between sub-threads and adopting the next target sub-thread. If so, step S403 is executed to simulate switching between sub-threads by switching between sub-coroutines, so as to continue executing the subsequent target script by adopting the next target sub-coroutine; it is determined whether it is monitored that the target script is executed to continue executing the subsequent target script by switching between sub-main threads and adopting the main thread. If so, step S405 is executed to simulate switching between sub-main coroutines by switching between sub-main coroutines, so as to continue executing the subsequent target script by adopting the main coroutine.

[0108] Exemplarily, taking the created coroutine including: main coroutine A, sub-coroutine B, sub-coroutine C, and using sub-coroutine B to simulate the execution of the target script as an example, if it is monitored that the target script is executed to the point where the next target sub-thread is used to continue to execute the subsequent target script by switching between sub-threads, then sub-coroutine C is used to continue to execute the subsequent target script; sub-coroutine C is determined as the current target sub-coroutine, and the target script is continued to be monitored whether it is executed to the point where the next target sub-thread is used to continue to execute the subsequent target script by switching between sub-threads, or whether it is executed to the point where the main thread is used to continue to execute the subsequent target script by switching between sub-main threads; if it is executed to the point where the next target sub-thread is used to continue to execute the subsequent target script by switching between sub-threads, then sub-coroutine B is used to continue to execute the subsequent target script; if it is executed to the point where the main thread is used to continue to execute the subsequent target script by switching between sub-main threads, then sub-main coroutine A is used to continue to execute the subsequent target script.

[0109] The detection method of malicious scripts provided by the embodiment of the present application adopts the current target sub-coroutine to simulate the current target sub-thread to execute the target script; if it is monitored that the target script is executed to the point where the next target sub-thread is used to continue to execute the subsequent target script by switching between sub-threads, the switching between sub-coroutines is used to simulate the switching between sub-threads, the current target sub-coroutine is switched to the next target sub-coroutine, and the next target sub-coroutine is used to continue to execute the subsequent target script; the next target sub-coroutine is updated to the current target sub-coroutine, and the target script is continuously monitored to see whether it is executed to the point where the next target sub-thread is used to continue to execute the subsequent target script by switching between sub-threads; if so, the step of simulating the switching between sub-threads by switching between sub-coroutines is executed; if not, the target script is continuously executed until the main thread is used to continue to execute the subsequent target script by switching the sub-main thread. The switching between sub-coroutines is realized to simulate the switching between sub-threads, and since the sub-coroutines are all executed in one thread, the switching of the sub-coroutine to another sub-coroutine occurs in the user state, which can improve the efficiency of simulating the switching of threads relative to switching threads in the kernel state, and further improve the efficiency of detecting the target script.

[0110] Optionally, if it is monitored that the target script is executed to the point where the main thread is used to continue executing the subsequent target script through the sub-main thread switching, the malicious script detection method also includes: using the sub-main coroutine switching to simulate the sub-main thread switching, switching the current target sub-coroutine to the main coroutine, and using the main coroutine to continue executing the subsequent target script until the target script is executed.

[0111] In the embodiment of the present application, the method of using sub-main coroutine switching to simulate sub-main thread switching is similar to the method of using main-sub coroutine switching to simulate main-sub thread switching, which will not be repeated here.

[0112] In an embodiment of the present application, after the main coroutine is used to continue to execute the subsequent target script, it is also possible to monitor whether the target script is executed to the point where at least one sub-thread is used to continue to execute the subsequent target script through the main-sub-thread switching, and execute subsequent steps. If the target script is monitored to be executed to the point where at least one sub-thread is used to continue to execute the subsequent target script through the main-sub-thread switching, S302 is executed until the target script is executed.

[0113] Figure 5 The schematic diagram of the coroutine switching provided in the embodiment of the present application is exemplarily as follows: Figure 5As shown, a main coroutine A and a sub-coroutine B can be created in the thread corresponding to the malicious script detection engine. A blocking function is provided between script fragment 1 and script fragment 2 in the main coroutine A, and a blocking function is provided between script fragment 1 and script fragment 2 in the sub-coroutine B. The main coroutine A can be used to simulate the main thread to execute script fragment 1 in the target script; after executing script fragment 1 in the main coroutine A, when the blocking function is executed, the main-sub coroutine switching is used to simulate the main-sub thread switching, and the sub-coroutine B is used to simulate the sub-thread to execute script fragment 1; after coroutine B is used to execute script fragment 1 and the blocking function is executed, the sub-main coroutine switching is used to simulate the sub-main thread switching, and the main coroutine A is used to simulate the main thread to continue to execute script fragment 2, and the execution of the corresponding script fragment by the main coroutine A is completed; after the main coroutine A is used to simulate the main thread to execute script fragment 2, the main-sub coroutine switching is used to simulate the main-sub thread switching, and the sub-coroutine B is used to simulate the main thread to execute script fragment 2 in the target script, and the execution of the sub-coroutine B is completed, and the execution of the target script is further completed. In this example, the target script is not monitored to be executed until the next target sub-thread is adopted to continue to execute the subsequent target script through switching between sub-threads.

[0114] The malicious script detection method provided in the embodiment of the present application adopts sub-main coroutine switching to simulate sub-main thread switching, switches the current target sub-coroutine to the main coroutine, and adopts the main coroutine to continue to execute the subsequent target script until the target script is executed. The sub-main coroutine switching can be used to simulate the sub-main thread switching. Compared with switching threads in kernel state, the efficiency of simulating switching threads can be improved, and further, the efficiency of detecting target scripts can be improved.

[0115] Embodiment 5

[0116] Based on any of the above embodiments, the embodiment of the present application relates to a refinement of an implementation method of determining whether the target script is a malicious script according to the execution result in step S104, which specifically includes the following steps:

[0117] Step S501: Determine whether there is a taint transfer process based on the execution result.

[0118] Step S502: If it is determined that there is a taint transfer process, the target script is determined to be a malicious script.

[0119] Step S503: If it is determined that there is no taint transfer process, it is determined that the target script is not a malicious script.

[0120] For example, if the target script is a malicious script, a tainted parameter will be passed into the malicious script, and there will be a tainted transfer process during the execution of the target script. Therefore, in the embodiment of the present application, after determining the execution result, it can be determined whether there is a tainted transfer process in the execution result. If it is determined that there is a tainted transfer process, it is determined that the target script is a malicious script; if it is determined that there is no tainted transfer process, it is determined that the target script is not a malicious script.

[0121] It should be understood that when the number of threads required to run the target script is multiple, if the simulation execution technology is used to execute the target script through a single thread, the execution order of multiple threads cannot be determined, resulting in missed detection and false detection of the taint transfer process in the target script. Therefore, it is necessary to use multiple threads to execute the target script so that taint transfer can be accurately detected when it exists in the target script.

[0122] The malicious script detection method provided by the embodiment of the present application determines whether there is a taint transfer process according to the execution result; if it is determined that there is a taint transfer process, the target script is determined to be a malicious script; if it is determined that there is no taint transfer process, the target script is determined not to be a malicious script. When the taint transfer method is used to detect whether the multi-threaded target script corresponding to the target script is a malicious script, it can be determined by the execution result whether there is a taint transfer process, and it can be accurately determined whether the target script is a malicious script.

[0123] Embodiment 6

[0124] Figure 6 A schematic diagram of the structure of a malicious script detection device provided in Example 6 of the present application is shown in FIG. Figure 6 As shown, the malicious script detection device 60 provided in this embodiment includes: an acquisition module 601, a creation module 602, a simulation execution module 603 and a detection module 604.

[0125] The acquisition module 601 is used to acquire the target script to be detected.

[0126] The creation module 602 is used to determine the thread required to run the target script and create a coroutine corresponding to the thread.

[0127] The simulation execution module 603 is used to execute the target script using the coroutine simulation thread technology and determine the execution result of the target script.

[0128] The detection module 604 is used to determine whether the target script is a malicious script according to the execution result.

[0129] In an optional implementation, the creation module 602 is specifically used to: obtain the thread corresponding to the malicious script detection engine; create a main coroutine structure corresponding to the main coroutine in the corresponding thread, and allocate the stack space of the corresponding thread to the main coroutine to complete the creation of the main coroutine.

[0130] In an optional implementation, the creation module 602 is further specifically used to: create a sub-coroutine structure corresponding to at least one sub-coroutine in the corresponding thread, and allocate corresponding stack space to each sub-coroutine to complete the creation of each sub-coroutine.

[0131] In an optional implementation, the simulation execution module 603 is specifically used to: use the main coroutine to simulate the main thread to execute the target script; if it is monitored that the target script is executed to use at least one sub-thread to continue to execute the subsequent target script through the main-sub-thread switching, the main-sub-coroutine switching is used to simulate the main-sub-thread switching, the main coroutine is switched to the current target sub-coroutine, and at least the current target sub-coroutine is used to continue to execute the subsequent target script.

[0132] In an optional implementation, the simulation execution module 603 is specifically used to: switch the context information corresponding to the main coroutine to the context information corresponding to the current target sub-coroutine in the user state, so as to complete the switching from the main coroutine to the current target sub-coroutine.

[0133] In an optional implementation manner, the simulation execution module 603 is specifically used to: use the current target sub-coroutine to simulate the current target sub-thread to execute the target script; if it is monitored that the target script is executed to the point where the next target sub-thread is used to continue to execute the subsequent target script through switching between sub-threads, then switching between sub-coroutines is used to simulate switching between sub-threads, the current target sub-coroutine is switched to the next target sub-coroutine, and the next target sub-coroutine is used to continue to execute the subsequent target script; the next target sub-coroutine is updated to the current target sub-coroutine, and it is continued to monitor whether the target script is executed to the point where the next target sub-thread is used to continue to execute the subsequent target script through switching between sub-threads; if so, the step of simulating switching between sub-threads by switching between sub-coroutines is executed; if not, the target script is continued to be executed until the main thread is used to continue to execute the subsequent target script through switching between the sub-main thread.

[0134] In an optional implementation, the simulation execution module 603 is further specifically used to: use sub-main coroutine switching to simulate sub-main thread switching, switch the current target sub-coroutine to the main coroutine, and use the main coroutine to continue executing subsequent target scripts until the target script is executed.

[0135] In an optional implementation, the malicious script detection device 60 includes a deadlock detection module, which is used to: perform deadlock detection during the execution of the target script; if a deadlock is determined to have occurred, forcibly wake up all coroutines and run them using the main coroutine.

[0136] In an optional implementation, the detection module 604 is specifically used to: determine whether there is a taint transfer process based on the execution result; if it is determined that there is a taint transfer process, determine that the target script is a malicious script; if it is determined that there is no taint transfer process, determine that the target script is not a malicious script.

[0137] In an optional implementation manner, the malicious script detection device 60 includes a deletion module, and the deletion module is used to: if it is monitored that the target script is executed, reclaim the relevant resources corresponding to all coroutines and delete the corresponding coroutines.

[0138] It should be noted that the technical solution and effects of the malicious script detection device provided in this embodiment can be found in the relevant contents of the aforementioned method embodiment, which will not be repeated here.

[0139] Embodiment 7

[0140] Figure 7 This is a schematic diagram of the structure of an electronic device provided in Embodiment 7 of the present application, such as Figure 7 As shown, the present application also provides an electronic device 70 , including: a memory 701 and a processor 702 .

[0141] The memory 701 is used to store programs. Specifically, the program may include a program target script, and the program target script includes computer execution instructions. The memory 701 may include a high-speed RAM memory, and may also include a non-volatile memory, such as at least one disk memory.

[0142] The processor 702 is used to execute the program stored in the memory 701 .

[0143] The computer program is stored in the memory 701 and is configured to be executed by the processor 702 to implement the malicious script detection method provided in any embodiment of the present application. The relevant description can be understood by referring to the relevant descriptions and effects corresponding to the steps in the accompanying drawings, and no further details are given here.

[0144] In this embodiment, the memory 701 and the processor 702 are connected via a bus. The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 7Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0145] An embodiment of the present application also provides a computer-readable storage medium on which computer execution instructions are stored. The computer execution instructions are executed by a processor to implement the malicious script detection method provided in any embodiment of the present application.

[0146] An embodiment of the present application also provides a computer program product, including a computer program, which, when executed by a processor, implements the malicious script detection method provided by any embodiment of the present application.

[0147] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of modules is only a logical function division. There may be other division methods in actual implementation, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.

[0148] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0149] In addition, each functional module in each embodiment of the present application can be integrated into a processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The above integrated modules can be implemented in the form of hardware or in the form of hardware plus script functional modules.

[0150] The program target scripts for implementing the method of the present application can be written in any combination of one or more programming languages. These program target scripts can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable malicious script detection device, so that when the program target script is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program target script can be executed entirely on the machine, partially on the machine, as a separate script package partially on the machine and partially on a remote machine, or completely on a remote machine or server.

[0151] In the context of the present application, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0152] In addition, although each operation is described in a specific order, this should be understood as requiring such operation to be performed in the specific order shown or in a sequential order, or requiring that all illustrated operations should be performed to obtain desired results. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the application. Some features described in the context of a separate embodiment can also be implemented in a single implementation in combination. On the contrary, the various features described in the context of a single implementation can also be implemented in multiple implementations individually or in any suitable sub-combination mode.

[0153] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any modification, use or adaptation of the present application, which follows the general principles of the present application and includes common knowledge or customary techniques in the art that are not disclosed in the present application. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present application are indicated by the following claims.

[0154] It should be understood that the present application is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. A method for detecting malicious scripts, characterized in that: include: Get the target script to be detected; Determine the thread required to run the target script, and create a coroutine corresponding to the thread, wherein the coroutine corresponding to the thread is created according to the detailed information of the thread that needs to be created during the running of the target script and the acquired start function for creating the corresponding thread, the detailed information is dynamically acquired by executing the target script through the simulated execution technology, the number of threads of the created coroutine is consistent with that of the target script, and the created coroutine is used to simulate the threads required to run the target script; Execute the target script using the coroutine simulation thread technology, and determine the execution result of the target script; Determine whether the target script is a malicious script according to the execution result.

2. The method according to claim 1, characterized in that The number of threads is one, and the step of creating a coroutine corresponding to the thread includes: Get the thread corresponding to the malicious script detection engine; A main coroutine structure corresponding to the main coroutine is created in the corresponding thread, and the stack space of the corresponding thread is allocated to the main coroutine to complete the creation of the main coroutine.

3. The method according to claim 2, characterized in that There are multiple threads, and creating a coroutine corresponding to the threads further includes: At least one sub-coroutine structure corresponding to the sub-coroutine is created in the corresponding thread, and corresponding stack space is allocated to each sub-coroutine to complete the creation of each sub-coroutine.

4. The method according to claim 1, characterized in that: The method of using a coroutine to simulate a thread to execute the target script includes: The main coroutine is used to simulate the main thread to execute the target script; If it is monitored that the target script is executed to the point where at least one sub-thread is used to continue executing the subsequent target script through the main-sub-thread switching, the main-sub-coroutine switching is used to simulate the main-sub-thread switching, the main coroutine is switched to the current target sub-coroutine, and at least the current target sub-coroutine is used to continue executing the subsequent target script.

5. The method according to claim 4, characterized in that The main coroutine switches to the current target sub-coroutine, including: In user mode, the context information corresponding to the main coroutine is switched to the context information corresponding to the current target sub-coroutine to complete the switch from the main coroutine to the current target sub-coroutine.

6. The method according to claim 4, characterized in that The adopting at least the current target sub-coroutine to continue executing the subsequent target script includes: The current target sub-coroutine is used to simulate the current target sub-thread to execute the target script; If it is monitored that the target script is executed to the point where the next target sub-thread is used to continue executing the subsequent target script through switching between sub-threads, the sub-coroutine switching is used to simulate the sub-thread switching, the current target sub-coroutine is switched to the next target sub-coroutine, and the next target sub-coroutine is used to continue executing the subsequent target script; Update the next target sub-coroutine to the current target sub-coroutine, and continue to monitor whether the target script is executed to continue executing the subsequent target script by switching between sub-threads and using the next target sub-thread; If yes, then executing the step of simulating switching between sub-threads by switching between sub-coroutines; If not, the target script continues to be executed until the main thread is switched to continue executing the subsequent target script through the sub-main thread.

7. The method according to claim 6, characterized in that If it is monitored that the target script is executed to the point where the main thread is switched through the sub-main thread to continue executing the subsequent target script, the method further includes: The sub-main coroutine switching is used to simulate the sub-main thread switching, the current target sub-coroutine is switched to the main coroutine, and the main coroutine is used to continue to execute the subsequent target script until the target script is executed.

8. The method according to any one of claims 1 to 7, characterized in that: Also includes: Perform deadlock detection during the execution of the target script; If deadlock is determined, all coroutines are forced to wake up and run as the main coroutine.

9. The method according to any one of claims 1 to 7, characterized in that: The determining whether the target script is a malicious script according to the execution result includes: Determine whether there is a taint transfer process according to the execution result; If it is determined that there is a taint transfer process, then the target script is determined to be a malicious script; If it is determined that there is no taint transfer process, it is determined that the target script is not a malicious script.

10. The method according to any one of claims 1 to 7, characterized in that: Also includes: If it is detected that the target script has been executed, all related resources corresponding to the coroutines will be recovered and the corresponding coroutines will be deleted.

11. A malicious script detection device, characterized in that: include: An acquisition module is used to obtain the target script to be detected; A creation module, used to determine the threads required to run the target script, and create a coroutine corresponding to the thread, wherein the coroutine corresponding to the thread is created according to the detailed information of the thread that needs to be created during the running of the target script and the acquired start function for creating the corresponding thread, the detailed information is dynamically acquired by executing the target script through the simulation execution technology, the number of threads of the created coroutine is consistent with that of the target script, and the created coroutine is used to simulate the threads required to run the target script; A simulation execution module, used to execute the target script using the coroutine simulation thread technology and determine the execution result of the target script; A detection module is used to determine whether the target script is a malicious script according to the execution result.

12. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 10.

13. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 10 when executed by a processor.

14. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.

Citation Information

Patent Citations

  • Coroutine implementation method, terminal device and storage medium

    CN108021449A

  • Abnormal script detection method and device, computer equipment and storage medium

    CN112817877A

  • Game server pressure testing method and device

    CN114253814A

  • System and method for malware analysis using thread-level event monitoring

    US10671726B1