A method, device, equipment and readable storage medium for detecting terminal behavior

By conducting correlation analysis and attack attribute judgment on terminal events, behavior scenarios that meet preset conditions are destroyed, and the problem of large occupancy of real-time behavior detection resources on the terminal side is solved, and the effects of lightweight real-time detection and high accuracy are achieved.

CN114980112BActive Publication Date: 2025-06-20SANGFOR TECH INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210612171.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-31
Publication Date
2025-06-20
Estimated Expiration
2042-05-31

AI Technical Summary

Technical Problem

The prior art has problems in the real-time behavior detection of terminal side, which has a large resource occupation and a great impact on user experience, especially when ransomware detection, which lacks real-timeness, resulting in the encryption of important data.

Method used

By performing correlation analysis on the acquired terminal events to be detected, the behavior scenarios to be detected are obtained, and the attack attributes are determined based on the scene. If the attack attribute meets the preset conditions, the target behavior scenario is destroyed, thereby reducing resource occupancy and false positive rates.

Benefits of technology

It realizes lightweight real-time behavior detection on the terminal side, improves the accuracy of the detection results, significantly reduces the false alarm rate, and improves the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114980112B_ABST
    Figure CN114980112B_ABST
Patent Text Reader

Abstract

The present invention discloses a terminal behavior detection method, device, equipment and readable storage medium, which are applied to the field of terminal security technology. The method includes: performing correlation analysis on the obtained terminal events to be detected to obtain the behavior scenarios to be detected, so as to perform attack detection according to the behavior scenarios to be detected subsequently; for the behavior scenarios to be detected, determining the attack attributes of the behavior scenarios to be detected; if there is a target behavior scenario whose attack attributes meet the preset conditions, destroying the target behavior scenario; wherein, the target behavior scenario is any behavior scenario to be detected; by destroying the target behavior scenario whose attack attributes meet the preset conditions, the present invention can reduce the resource occupation of behavior detection, realize lightweight real-time behavior detection on the terminal side, and the present invention combines the behavior detection of terminal events with behavior scenarios, which can effectively improve the accuracy of behavior detection results, significantly reduce the false alarm rate of behavior detection, and improve the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of terminal security, and particularly relates to a method, device, equipment and readable storage medium for terminal behavior detection. Background Art

[0002] Currently, real-time behavior detection of malicious software mainly includes an active defense solution on the terminal side and a behavior detection solution on the server side or in the cloud.

[0003] The server-side / cloud behavior detection solution sends all the original event diaries collected by terminal monitoring to the server side / cloud, and then detects them through the server-side / cloud behavior detection system. The main disadvantage is that the massive data collected by terminal monitoring has a huge impact on the bandwidth performance; and a compromise balance will choose to discard some terminal collected data, which will lead to missed reports. In addition, the real-time performance of the system is not high after being processed and responded by the server side / cloud. There is a delay and lag in the detection of ransomware. Even if the ransomware is detected, many important documents have already been encrypted.

[0004] Therefore, the active defense solution on the terminal side has the real-time advantage that the server side / cloud does not have. However, how to achieve lightweight behavior detection on the terminal side and reduce the impact on the user's normal terminal experience is an urgent problem to be solved today. Summary of the Invention

[0005] The purpose of the present invention is to provide a method, device, equipment and readable storage medium for terminal behavior detection to achieve lightweight behavior detection on the terminal side and reduce the impact on the user's normal terminal experience.

[0006] To solve the above technical problems, the present invention provides a method for terminal behavior detection, including:

[0007] Performing correlation analysis on the obtained terminal events to be detected to obtain the behavior scenarios to be detected, so as to perform attack detection according to the behavior scenarios to be detected subsequently; wherein, each behavior scenario to be detected is composed of a plurality of associated terminal events to be detected;

[0008] For the behavior scenario to be detected, determining the attack attribute of the behavior scenario to be detected;

[0009] If there is a target behavior scenario whose attack attribute meets the preset condition, then destroying the target behavior scenario; wherein, the target behavior scenario is any one of the behavior scenarios to be detected.

[0010] Optionally, the step of if there is a target behavior scenario whose attack attribute meets the preset condition, then destroying the target behavior scenario includes:

[0011] If there is a target behavior scenario of "all processes have exited", then destroy the target behavior scenario.

[0012] Optionally, the if there is a target behavior scenario where the attack attribute meets the preset conditions, then destroy the target behavior scenario, includes:

[0013] If there is a target behavior scenario of "the attack possibility is lower than the preset ratio or the attack score is lower than the preset score", then destroy the target behavior scenario.

[0014] Optionally, the if there is a target behavior scenario where the attack attribute meets the preset conditions, then destroy the target behavior scenario, includes:

[0015] If there is a to-be-detected behavior scenario of "no attack is detected and the number of times or duration of no attack detection reaches the threshold", then destroy the to-be-detected behavior scenario.

[0016] Optionally, the performing attack detection according to the to-be-detected behavior scenario, includes:

[0017] Perform rule matching on the to-be-detected terminal events corresponding to each to-be-detected behavior scenario to determine the target rule corresponding to each to-be-detected behavior scenario;

[0018] According to the target rule, perform attack detection on each to-be-detected behavior scenario to determine whether it is an attack behavior scenario.

[0019] Optionally, the performing rule matching on the to-be-detected terminal events corresponding to each to-be-detected behavior scenario to determine the target rule corresponding to each to-be-detected behavior scenario, includes:

[0020] Perform single-event rule and multi-event rule matching on the to-be-detected terminal events corresponding to some or all of the to-be-detected behavior scenarios to determine the target rule corresponding to each to-be-detected behavior scenario; wherein, the single-event rule matching is to only detect whether a single event conforms to a certain rule, and the multi-event rule matching is to detect whether multiple associated events correspond to a certain rule.

[0021] Optionally, the performing attack detection on each to-be-detected behavior scenario according to the target rule to determine whether it is an attack behavior scenario, includes:

[0022] Obtain the detection score corresponding to each to-be-detected behavior scenario according to the target rule corresponding to each to-be-detected behavior scenario and the preset rule score corresponding to each target rule;

[0023] Determine whether it is an attack behavior scenario according to the detection score.

[0024] The present invention also provides a terminal behavior detection device, including:

[0025] An association analysis module, configured to perform association analysis on the obtained terminal events to be detected, and obtain the behavior scenarios to be detected, so as to perform attack detection according to the behavior scenarios to be detected subsequently; wherein, each behavior scenario to be detected is composed of a plurality of associated terminal events to be detected;

[0026] An attribute determination module, configured to determine the attack attribute of the behavior scenario to be detected for the behavior scenario to be detected;

[0027] A scenario destruction module, configured to destroy the target behavior scenario if there is a target behavior scenario whose attack attribute meets a preset condition; wherein, the target behavior scenario is any one of the behavior scenarios to be detected.

[0028] The present invention also provides a terminal behavior detection device, including:

[0029] A memory, configured to store a computer program;

[0030] A processor, configured to implement the steps of the terminal behavior detection method as described above when executing the computer program.

[0031] In addition, the present invention also provides a readable storage medium, on which a computer program is stored, and the computer program, when executed by a processor, implements the steps of the terminal behavior detection method as described above.

[0032] A terminal behavior detection method provided by the present invention includes: performing association analysis on the obtained terminal events to be detected, and obtaining the behavior scenarios to be detected, so as to perform attack detection according to the behavior scenarios to be detected subsequently; wherein, each behavior scenario to be detected is composed of a plurality of associated terminal events to be detected; for the behavior scenario to be detected, determining the attack attribute of the behavior scenario to be detected (the so-called attack attribute is used to characterize the attack possibility); if there is a target behavior scenario whose attack attribute meets a preset condition, then destroying the target behavior scenario; wherein, the target behavior scenario is any one of the behavior scenarios to be detected;

[0033] It can be seen that, by destroying the target behavior scenario when there is a target behavior scenario whose attack attribute meets a preset condition, the present invention can reduce the resource occupation of behavior detection, realize lightweight real-time behavior detection on the terminal side, and combine the behavior detection of terminal events with behavior scenarios, which can effectively improve the accuracy of behavior detection results, significantly reduce the false alarm rate of behavior detection, and improve the user experience. In addition, the present invention also provides a terminal behavior detection device, device and readable storage medium, which also have the above beneficial effects. Description of the Drawings

[0034] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on the provided drawings.

[0035] Figure 1 It is a flowchart of a terminal behavior detection method provided by an embodiment of the present invention;

[0036] Figure 2 It is a schematic architecture diagram of another terminal behavior detection method provided by an embodiment of the present invention;

[0037] Figure 3 It is a structural block diagram of a terminal behavior detection device provided by an embodiment of the present invention;

[0038] Figure 4 It is a schematic structural diagram of a terminal behavior detection device provided by an embodiment of the present invention;

[0039] Figure 5 It is a specific schematic structural diagram of a terminal behavior detection device provided by an embodiment of the present invention. Detailed implementation manners

[0040] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0041] Please refer to Figure 1 , Figure 1 It is a flowchart of a terminal behavior detection method provided by an embodiment of the present invention. The method may include:

[0042] Step 101: Perform correlation analysis on the obtained terminal events to be detected to obtain the behavior scenarios to be detected, so as to perform attack detection based on the behavior scenarios to be detected subsequently; wherein, each behavior scenario to be detected is composed of multiple associated terminal events to be detected.

[0043] Step 102: Determine the attack attributes of the behavior scenarios to be detected for the behavior scenarios to be detected.

[0044] Step 103: If there is a target behavior scenario whose attack attribute meets the preset condition, destroy the target behavior scenario; where the target behavior scenario is any behavior scenario to be detected.

[0045] Among them, the terminal event to be detected in the embodiment can be a behavior event on the terminal side that requires behavior detection (i.e., attack detection). For the specific content of the terminal event to be detected in this embodiment, it can be set by the designer according to the usage scenario and user requirements. For example, the terminal event to be detected in the embodiment can be the original event on the terminal side (i.e., the original terminal event); for the convenience of behavior detection in this embodiment, the terminal event to be detected in this embodiment can also be the normalized event obtained after normalizing the original terminal event. This embodiment does not make any restrictions on this.

[0046] Specifically, for the specific event type of the terminal event to be detected in this embodiment, it can be set by the designer. For example, the terminal event to be detected can include process-related events such as process creation and process destruction, the terminal event to be detected can also include thread-related events such as thread creation, thread destruction, and remote thread creation, the terminal event to be detected can also include file-related events such as file creation, file creation time modification, file renaming, file movement, file reading, file modification, and file deletion, the terminal event to be detected can also include registry-related events such as registry creation, registry deletion, and registry modification, the terminal event to be detected can also include query events such as network connection query and DNS (Domain Name System) query. This embodiment does not make any restrictions on this.

[0047] Correspondingly, before step 101 of the method provided in this embodiment, it can also include the process of obtaining the terminal event to be detected. For example, the processor can obtain the original terminal event; normalize the original terminal event to obtain the corresponding terminal event to be detected (i.e., the normalized event) for each original terminal event.

[0048] Specifically, for the specific manner in which the above-mentioned processor normalizes the original terminal event to obtain the to-be-detected terminal event corresponding to each original terminal event, it can be set by the designer according to the practical scenario and user requirements. For example, the processor can perform event format conversion and field normalization on the original terminal event to obtain the to-be-detected terminal event corresponding to each original terminal event. Among them, the to-be-detected terminal event is a preset event structure and the fields in the to-be-detected terminal event are complete long-path fields. That is to say, event normalization can include event format conversion and field normalization. Event format conversion can convert the externally defined original terminal event or diary structure into the preset event structure supported by the behavior detection in this embodiment. Field normalization can perform environment variable and long / short path conversion on the fields in the original terminal event, and uniformly convert them into complete long paths, so that string comparison can be conveniently performed during subsequent rule matching. For example, convert the environment variables in the fields of the original terminal event into file paths and convert the short paths in the fields into complete long paths.

[0049] It should be noted that the to-be-detected behavior scenario in step 101 can be the behavior scenario detected by the to-be-detected terminal event through association analysis. Among them, each to-be-detected behavior scenario is composed of multiple associated to-be-detected terminal events, that is, the to-be-detected behavior scenario can be a set of behaviors of a series of related processes. For example, the behavior scenario can be represented by a graph structure. The nodes in the graph represent processes, and the connections represent the association relationships between processes, such as control flow association relationships and data flow association relationships. The control flow association relationships can include process creation, injection, COM (Component Object Model) call, WMI (a system plug-in) call, scheduled task, and self-start item, etc. The data flow association relationships can include decompression and mirror startup, etc.

[0050] Specifically, for the specific manner in which the processor in this embodiment performs association analysis on the obtained to-be-detected terminal event to obtain the to-be-detected behavior scenario, it can be set by the designer according to the practical scenario and user requirements. For example, the processor can perform graph association analysis on the obtained to-be-detected terminal event to detect the to-be-detected behavior scenario corresponding to each associated to-be-detected terminal event, and implement behavior scenario detection, thereby improving the association scope through the correlation within the behavior scenario. Figure 2 As shown, the processor in this embodiment can use a state machine to perform graph association analysis on the to-be-detected terminal event obtained by event normalization of the original event (i.e., the original terminal event) to obtain the to-be-detected behavior scenario corresponding to each to-be-detected terminal event. The events (Event) input into the state machine, such as ProcessCreate and FileCreat, can be processed through the Event Bus to detect the corresponding behavior scenario.

[0051] Correspondingly, for the specific scenario type of the behavior scenario to be detected in this embodiment, that is, the specific type of the behavior scenario that can be detected in the pre-set behavior scenario detection, it can be set by the designer. For example, the behavior scenario to be detected may include a normal scenario and an abnormal scenario. That is, in step 101, the processor can perform correlation analysis on the obtained terminal events to be detected, construct a behavior scenario, and determine all the constructed behavior scenarios as the behavior scenarios to be detected. The behavior scenario to be detected may also include an abnormal scenario. That is, in step 101, the processor can perform correlation analysis on the obtained terminal events to be detected, construct a behavior scenario, and determine the abnormal scenarios among all the behavior scenarios as the behavior scenarios to be detected. That is to say, in this embodiment, it can be determined by detecting the behavior scenario to be detected, and filter out the normal scenarios (i.e., white behavior scenarios) that do not need to be detected for attacks in the constructed behavior scenarios, so as to avoid detecting attacks on normal scenarios, further reduce resource occupancy, thereby improving the accuracy of behavior detection and reducing the false alarm rate. Among them, the abnormal scenario is divided into one or more behavior scenarios. For example, the abnormal scenario may include an attack scenario and a suspicious scenario.

[0052] It can be understood that in this embodiment, the processor can perform attack detection according to the behavior scenario to be detected after step 101 to implement the behavior detection of the terminal events to be detected corresponding to the behavior scenario to be detected. That is to say, the processor can combine the behavior detection of the terminal events to be detected with the behavior scenario by performing attack detection according to the behavior scenario to be detected, so as to perform comprehensive attack detection by using the behavior detection results of the terminal events to be detected in the behavior scenario to be detected. Thus, it can use the attack detection results of the behavior scenario to replace the behavior detection results of the terminal events to be detected in the behavior scenario, which can effectively improve the accuracy of the behavior detection results, significantly reduce the false alarm rate of the behavior detection, and improve the user experience.

[0053] Specifically, for the specific method of the processor performing attack detection according to the behavior scenario to be detected, it can be set by the designer according to the practical scenario and user requirements. For example, in this step, the processor can perform rule matching on the terminal events to be detected corresponding to each behavior scenario to be detected to determine the target rule corresponding to each behavior scenario to be detected; according to the target rule, perform attack detection on each behavior scenario to be detected to determine whether it is an attack behavior scenario. That is to say, the processor can use the rules corresponding to the terminal events to be detected in the behavior scenario to be detected obtained by rule matching (i.e., the target rule) to determine whether each behavior scenario to be detected is a behavior scenario that needs to be alarmed (i.e., an attack behavior scenario), such as a behavior scenario that matches the target rule, or a behavior scenario whose number or score of the matched target rule reaches the threshold.

[0054] It should be noted that for the specific method of matching rules for the to-be-detected terminal events corresponding to each to-be-detected behavior scenario above to determine the target rule corresponding to each to-be-detected behavior scenario, it can be set by designers according to the practical scenario and user requirements. For example, the processor performs single-event rule and multi-event rule matching on the to-be-detected terminal events corresponding to some or all of the to-be-detected behavior scenarios to determine the target rule corresponding to each to-be-detected behavior scenario. Among them, single-event rule matching is to determine whether only a single event (i.e., the to-be-detected terminal event) conforms to a certain rule (i.e., the single-event rule); multi-event rule matching is to detect whether multiple associated events correspond to a certain rule (i.e., the multi-event rule), that is, whether multiple events associated together correspond to a certain rule. For example, the processor can use the Rete (a pattern matching algorithm) rule matching algorithm to perform single-event rule and multi-event rule matching on the to-be-detected terminal events corresponding to some or all of the to-be-detected behavior scenarios to determine the target rule corresponding to each to-be-detected behavior scenario. That is, the processor can use the Rete rule matching algorithm to perform Rete rule matching on the to-be-detected terminal events to obtain the rule (i.e., the target rule) corresponding to each to-be-detected terminal event, so as to determine the target rule corresponding to each to-be-detected behavior scenario. The processor can also use other rule matching algorithms to perform single-event rule and multi-event rule matching on the corresponding to-be-detected terminal events to obtain the rule corresponding to each to-be-detected terminal event, and this embodiment does not make any restrictions on this.

[0055] Specifically, for the specific process of using the Rete rule matching algorithm above to perform single-event rule and multi-event rule matching on the to-be-detected terminal events corresponding to some or all of the to-be-detected behavior scenarios to determine the target rule corresponding to each to-be-detected behavior scenario, it can be set by designers according to the practical scenario and user requirements. For example, the processor can input the current to-be-detected terminal event into the Rete rule matching network; use the Alpha network in the Rete rule matching network to perform single-event rule matching on the current to-be-detected terminal event to obtain the single-event rule matching result corresponding to the current to-be-detected terminal event; use the Beta network in the Rete rule matching network to perform multi-event rule matching on the current to-be-detected terminal event to obtain the multi-event rule matching result corresponding to the current to-be-detected terminal event; determine the target rule corresponding to the current to-be-detected terminal event according to the single-event rule matching result and the multi-event rule matching result. Among them, the current to-be-detected terminal event is any to-be-detected terminal event, such as any to-be-detected terminal event corresponding to the to-be-detected behavior scenario.

[0056] Among them, for the specific manner in which the above-mentioned processor uses the Alpha network and the Beta network in the Rete rule matching network to perform single-event rule matching and multi-event rule matching on the current terminal event to be detected, it can be set by the designer according to the practical scenario and user requirements. For example, the processor can first use the Alpha network to perform single-event rule matching on the current terminal event to be detected; then use the Beta network to perform multi-event rule matching on the current terminal event to be detected. For example, the processor can first send the current terminal event to be detected in the current behavior scenario to be detected into the Alpha network to perform single-event rule matching on the current terminal event to be detected, and obtain the single-event rule matching result corresponding to the current terminal event to be detected; and use the Alpha network to detect whether the current terminal event to be detected can match the multi-event rule, that is, detect whether there is a field of any event in the multi-event rule for the current terminal event to be detected; if a match is found, send the current terminal event to be detected into the Beta network to perform multi-event rule matching on the current terminal event to be detected, and obtain the multi-event rule matching result corresponding to the current terminal event to be detected; if no match is found, the target rule corresponding to the current terminal event to be detected can be determined according to the single-event rule matching result corresponding to the current terminal event to be detected; where the current behavior scenario to be detected is any behavior scenario to be detected. The processor can also use the Alpha network and the Beta network respectively to perform single-event rule matching and multi-event rule matching on the current terminal event to be detected at the same time, that is, the processor can send the current terminal event to be detected into the Alpha network and the Beta network at the same time. This embodiment does not make any restrictions on this.

[0057] Correspondingly, for the above-mentioned processor to send the currently to-be-detected terminal event into the Beta network and perform multi-event rule matching on the currently to-be-detected terminal event to obtain the multi-event rule matching result corresponding to the currently to-be-detected terminal event, the specific method can be set by the designer. For example, the processor can use the Beta network to determine the target multi-event rule according to the target to-be-detected terminal event in the currently to-be-detected behavior scenario; according to the target multi-event rule, determine the multi-event rule matching results corresponding to each target to-be-detected terminal event; wherein, the target to-be-detected terminal event can be the to-be-detected terminal event in the currently to-be-detected behavior scenario that can match the multi-event rule, that is, the to-be-detected terminal event with any event field in the multi-event rule; each target multi-event rule can be a target multi-event rule matched by a corresponding plurality of target to-be-detected terminal events, that is, in this embodiment, the processor can use the target to-be-detected terminal event in the currently to-be-detected behavior scenario to match the multi-event rule (i.e., the target multi-event rule) through the Beta network, so that the multi-event rule matching result corresponding to the target to-be-detected terminal event that jointly matches the multi-event rule with other target to-be-detected terminal events can include the multi-event rule, and the multi-event rule matching result corresponding to the target to-be-detected terminal event that does not jointly match the multi-event rule with other target to-be-detected terminal events can be that no multi-event rule is matched.

[0058] That is to say, after the processor sends the current to-be-detected terminal event (i.e., the target to-be-detected terminal event) in the current to-be-detected behavior scenario that can match multiple event rules into the Beta network, it can determine the matching result of the multiple event rules corresponding to the current to-be-detected terminal event after all the multiple event rules that the current to-be-detected terminal event can match are jointly matched with other target to-be-detected terminal events in the corresponding current to-be-detected behavior scenario, or after all the target to-be-detected terminal events in the current to-be-detected behavior scenario are sent into the Beta network; for example, the matching result of the multiple event rules corresponding to the current to-be-detected terminal event can include all the matchable multiple event rules, that is, the current to-be-detected terminal event and other target to-be-detected terminal events in the corresponding current to-be-detected behavior scenario jointly match all the multiple event rules that the current to-be-detected terminal event can match; the matching result of the multiple event rules corresponding to the current to-be-detected terminal event can also include some matchable multiple event rules, that is, after all the target to-be-detected terminal events in the current to-be-detected behavior scenario are sent into the Beta network, the current to-be-detected terminal event and other target to-be-detected terminal events in the corresponding current to-be-detected behavior scenario jointly match some of the multiple event rules that the current to-be-detected terminal event can match; the matching result of the multiple event rules corresponding to the current to-be-detected terminal event can also be that no multiple event rules are matched, that is, after all the target to-be-detected terminal events in the current to-be-detected behavior scenario are sent into the Beta network, the current to-be-detected terminal event cannot jointly match the multiple event rules that the current to-be-detected terminal event can match with other target to-be-detected terminal events in the current to-be-detected behavior scenario.

[0059] Specifically, as Figure 2 shown, this embodiment can reduce the occupancy of the processor and memory by combining graph association analysis and Rete rule matching, further ensure lightweight real-time behavior detection on the terminal side, and improve the accuracy of behavior detection results; correspondingly, in this step, the to-be-detected terminal events corresponding to the to-be-detected terminal events determined after graph association analysis can be sent into the Rete network (i.e., the Rete rule matching network) in a streaming manner, and flow in the Rete network for rule matching; the Alpha network (Rete Alpha network) in the Rete network corresponds to simple event matching (i.e., single event rule matching), and the Beta network (Rete Beta network) in the Rete network corresponds to complex event matching (i.e., multiple event rule matching); that is to say, if a rule is a single event rule, its matching process mainly occurs in the Alpha network; if a rule is a multiple event rule, its matching process will first occur in the Alpha network for single event related field matching, and the events that meet the multiple event rule matching conditions will flow to the Beta network for multi-event related field matching.

[0060] Correspondingly, the method provided in this embodiment may further include the creation process of the Rete rule matching network. For example, the processor may load the rule file when starting the terminal behavior detection, and construct the Rete rule matching network according to the rules preset in the rule file. The Rete rule matching network only needs to be constructed once, and then the input terminal events to be detected can be subjected to rule matching.

[0061] Specifically, for the specific content of the target rule in this embodiment, that is, the specific content of the rules preset in the Rete rule matching network, it can be set by the designer according to the usage scenario and user requirements. For example, the rules can be divided into <facts>(i.e., single event rule) and <joins>(i.e., the multi-event rule) consists of two parts; each <fact>(Single event rule) can correspond to a type of event, and the event type can be represented by the Type field. That is to say, <fact>A segment can correspond to 1 layer of association, i.e., a single event match; the fields in the event are <field>Segment representation, where Name represents the field name, and Select represents the matching selector, including but not limited to StrRegExp (regular expression string), StrEndWith (ending string), StrStartWith (starting string), StrContains (containing string), StrEqual (comparing string), StrNotEqual (inequality string), StrNotContains (not containing string), IntEqual (comparing numbers), IntGreater (sorting numbers from largest to smallest), IntLess (sorting numbers from smallest to largest), etc.; <field>This section of content represents the value to be matched, <field>The fields can be combined arbitrarily. The boolean operator is represented by Operator, which can be of two types: And (AND) | Or (OR). <join>It can correspond to two-level association, that is, multiple events match, <join>The following paragraphs describe their matching relationships. The Left field represents the left part, and is expressed in the Fact.Field format to indicate a certain field of a certain event; the Right field represents the right part, which can include a certain field of an associated event and the Select field used to represent the matching selector; that is, each multi-event rule in this embodiment can be formed by one or more <join>The segment represents the associated matching relationship of fields in two events among two or more corresponding events.

[0062] It can be understood that for the above-mentioned processor to perform attack detection on each behavior scenario to be detected according to the target rules and determine whether it is an attack behavior scenario, the specific method can be set by the designer according to the practical scenario and user requirements. For example, in this embodiment, the scores corresponding to each rule in the rule matching (i.e., the preset rule scores) can be preset in advance. In this step, the processor can obtain the detection score corresponding to each behavior scenario to be detected according to the target rule corresponding to each behavior scenario to be detected and the preset rule score corresponding to each target rule; determine whether it is an attack behavior scenario according to the detection score; for example, the processor can calculate the sum of the preset rule scores of the target rules corresponding to the terminal events to be detected in each behavior scenario to be detected to obtain the detection score corresponding to each behavior scenario to be detected; determine the behavior scenario to be detected with the detection score reaching the score threshold as an attack behavior scenario. In this step, the behavior scenarios to be detected corresponding to the target rules can also be regarded as attack behavior scenarios. For example, the processor can obtain the detection score corresponding to each behavior scenario to be detected according to the behavior scenario to be detected, the target rule, and the preset rule score corresponding to each target rule; determine the alarm level corresponding to the behavior scenario to be detected according to the detection score; thereby obtain the detection alarm information according to the target rule and the alarm level corresponding to the behavior scenario to be detected; where the detection alarm information can include alarm level information; for example, in this step, the processor can calculate the sum of the preset rule scores of the target rules corresponding to the terminal events to be detected in each behavior scenario to be detected to obtain the detection score corresponding to each behavior scenario to be detected; determine the alarm level of the behavior scenario to be detected with the detection score reaching the score threshold as the strong detection level, and determine the alarm level of the behavior scenario to be detected with the detection score not reaching the score threshold as the weak detection level; obtain the detection alarm information of each behavior scenario to be detected (i.e., the attack behavior scenario). This embodiment does not make any restrictions on this.

[0063] Correspondingly, after determining that the behavior scenario to be detected is an attack behavior scenario, the processor can also obtain the detection warning information of the attack behavior scenario; wherein, the detection warning information includes the event information corresponding to the attack behavior scenario. For the specific content of the detection warning information of the attack behavior scenario in this embodiment, designers can set it according to the practical scenario and user requirements. For example, the detection warning information can include the event information corresponding to the attack behavior scenario, such as the information of the original terminal event corresponding to the attack behavior scenario; the detection warning information can also include the scenario description information of the attack behavior scenario to facilitate users to understand the behavior scenario of the original terminal event; the detection warning information can also include the rule description information of the target rule corresponding to the attack behavior scenario, that is, the rule description information of the rule matched by the terminal event to be detected in the attack behavior scenario, to facilitate users to understand the rule description matched by the original terminal event, that is, the specific problems existing in the detected terminal-side behavior; the detection warning information can also include other information such as the above warning level information.

[0064] It should be noted that the terminal behavior detection method provided in this embodiment can be applied to a terminal device, that is, the processor in the terminal device can execute the method provided in this embodiment to detect its own behavior and achieve real-time detection of terminal behavior; the terminal behavior detection method provided in this embodiment can also be applied to a server connected to the terminal device, that is, the processor in the server can execute the method provided in this embodiment to detect the behavior of the terminal device. This embodiment does not make any restrictions on this.

[0065] It can be understood that the attack attribute of the behavior scenario to be detected determined in step 102 in this embodiment can be an attribute used to characterize the attack possibility, that is, an attribute related to the attack behavior, such as any one or more of the process running status in the behavior scenario to be detected, the attack possibility corresponding to the behavior scenario to be detected obtained by attack detection, the attack score (such as the above detection score), and the number of attacks.

[0066] Specifically, the target behavior scenario in step 102 in this embodiment can be a behavior scenario to be detected whose attack attribute meets a preset condition. That is to say, the processor can monitor the behavior scenario to be detected obtained in step 101. When the attack attribute of a certain behavior scenario to be detected meets the preset condition, it is determined that the behavior scenario is the target behavior scenario, and thus the behavior scenario is destroyed to reduce resource occupation.

[0067] It should be noted that for the specific detection method of the target behavior scenario in step 103, that is, the specific setting of the preset conditions, it can be set by the designer according to the practical scenario and user requirements. For example, the preset conditions can include: all processes have exited. That is, in step 103, the processor can destroy the target behavior scenario when there is a target behavior scenario of "all processes have exited". That is to say, since if all processes in the behavior scenario have exited, there will surely be no attack behavior, and there is no need to continue to detect attacks on this behavior scenario. When the processor monitors that all processes in a behavior scenario to be detected have exited, it can determine that the behavior scenario to be detected is the target behavior scenario and destroy the behavior scenario to be detected. For example, the processor monitors all the behavior scenarios to be detected obtained in step 101, and when all processes in the behavior scenario to be detected have exited, it destroys the entire scenario, including all the messages maintained by the scenario. Correspondingly, when a certain process in the behavior scenario to be detected exits and there are processes that have not exited, the entire scenario can still survive. For example, the root node of the scenario exits, but the entire scenario will continue to be monitored and detected.

[0068] Correspondingly, the preset conditions can also include: the attack possibility is lower than the preset ratio or the attack score is lower than the preset score. That is, in step 103, when there is a target behavior scenario of "the attack possibility is lower than the preset ratio or the attack score is lower than the preset score", the processor can destroy the target behavior scenario. That is to say, the processor can monitor the behavior scenarios to be detected obtained in step 101. When it monitors that the attack possibility in the attack detection result of a certain behavior scenario to be detected is lower than the preset ratio, or the attack score (such as the above detection score) is lower than the preset score, it can determine that the behavior scenario to be detected is the target behavior scenario and destroy the behavior scenario to be detected, so as to destroy the behavior scenarios with low attack possibility and reduce resource occupancy.

[0069] Correspondingly, the preset conditions can also include: no attack is detected and the number of times or duration of no attack detection reaches the threshold. That is, in step 103, when there is a target behavior scenario of "no attack is detected and the number of times or duration of no attack detection reaches the threshold", the processor can destroy the target behavior scenario. That is to say, the processor can monitor the behavior scenarios to be detected obtained in step 101. When it monitors that no attack is detected continuously for a certain period of time in the attack detection process of a behavior scenario to be detected, that is, no attack behavior (such as not matching the target rule) is currently detected for the terminal event to be detected corresponding to this behavior scenario and the number of consecutive times or duration of no attack detection for the terminal event to be detected corresponding to this behavior scenario reaches the threshold, it can determine that the behavior scenario to be detected is the target behavior scenario, and thus destroy the behavior scenario to be detected to reduce resource occupancy.

[0070] It can be seen that in the embodiment of the present invention, when there is a target behavior scenario where the attack attribute meets the preset condition, destroying the target behavior scenario can reduce the resource occupancy of behavior detection, achieve lightweight real-time behavior detection on the terminal side. Moreover, in this embodiment, combining the behavior detection of terminal events with the behavior scenario can effectively improve the accuracy of the behavior detection result, significantly reduce the false alarm rate of behavior detection, and enhance the user experience.

[0071] Corresponding to the above method embodiment, the embodiment of the present invention further provides a terminal behavior detection device. A terminal behavior detection device described below can be mutually corresponding and referred to with a terminal behavior detection method described above.

[0072] Please refer to Figure 3 , Figure 3 which is a structural block diagram of a terminal behavior detection device provided by the embodiment of the present invention. The device may include:

[0073] An association analysis module 10, configured to perform association analysis on the acquired terminal events to be detected to obtain the behavior scenarios to be detected, so as to perform attack detection according to the behavior scenarios to be detected subsequently; wherein, each behavior scenario to be detected is composed of a plurality of associated terminal events to be detected;

[0074] An attribute determination module 20, configured to determine the attack attribute of the behavior scenario to be detected for the behavior scenario to be detected;

[0075] A scenario destruction module 30, configured to destroy the target behavior scenario if there is a target behavior scenario whose attack attribute meets the preset condition; wherein, the target behavior scenario is any behavior scenario to be detected.

[0076] Optionally, the scenario destruction module 30 may include:

[0077] A first destruction sub-module, configured to destroy the target behavior scenario if there is a target behavior scenario of "all processes have exited".

[0078] Optionally, the scenario destruction module 30 may include:

[0079] A second destruction sub-module, configured to destroy the target behavior scenario if there is a target behavior scenario of "the attack possibility is lower than the preset ratio or the attack score is lower than the preset score".

[0080] Optionally, the scenario destruction module 30 may include:

[0081] A third destruction sub-module, configured to destroy the behavior scenario to be detected if there is a behavior scenario to be detected of "no attack is detected and the number or duration of times of no attack detection reaches the threshold".

[0082] Optionally, the device may further include:

[0083] An attack detection module, configured to perform attack detection according to the behavior scenarios to be detected;

[0084] Wherein, the attack detection module may include:

[0085] A rule matching sub-module, configured to perform rule matching on the terminal events to be detected corresponding to each behavior scenario to be detected, and determine the target rule corresponding to each behavior scenario to be detected;

[0086] An attack detection sub-module, configured to perform attack detection on each behavior scenario to be detected according to the target rule, and determine whether it is an attack behavior scenario.

[0087] Optionally, the rule matching sub-module may be specifically configured to perform single-event rule and multi-event rule matching on the terminal events to be detected corresponding to some or all of the behavior scenarios to be detected, and determine the target rule corresponding to each behavior scenario to be detected; wherein, single-event rule matching is to only detect whether a single event conforms to a certain rule, and multi-event rule matching is to detect whether multiple associated events correspond to a certain rule.

[0088] Optionally, the attack detection sub-module may include:

[0089] A score matching unit, configured to obtain the detection score corresponding to each behavior scenario to be detected according to the target rule corresponding to each behavior scenario to be detected and the preset rule score corresponding to each target rule;

[0090] An attack determination unit, configured to determine whether it is an attack behavior scenario according to the detection score.

[0091] The terminal behavior detection device provided in this embodiment may be a software module deployed in any device, such as a software module deployed in the Hypervisor (virtual machine monitor) layer of a cloud platform.

[0092] In this embodiment, in the embodiment of the present invention, when there is a target behavior scenario whose attack attribute meets the preset condition, the scenario destruction module 30 destroys the target behavior scenario, which can reduce the resource occupation of behavior detection, realize lightweight real-time behavior detection on the terminal side, and in this embodiment, combining the behavior detection of terminal events with behavior scenarios can effectively improve the accuracy of behavior detection results, significantly reduce the false alarm rate of behavior detection, and enhance the user experience.

[0093] Corresponding to the above method embodiment, the embodiment of the present invention further provides a terminal behavior detection device, and a terminal behavior detection device described below can be mutually referred to with a terminal behavior detection method described above.

[0094] Please refer to Figure 4 , Figure 4 , which is a schematic structural diagram of a terminal behavior detection device provided by an embodiment of the present invention. The terminal behavior detection device may include:

[0095] A memory D1 for storing a computer program;

[0096] A processor D2 for implementing the steps of the terminal behavior detection method provided by the above method embodiment when executing the computer program.

[0097] Specifically, please refer to Figure 5 , Figure 5 , which is a specific structural diagram of a terminal behavior detection device provided by an embodiment of the present invention. The terminal behavior detection device may vary greatly due to configuration or performance, and may include one or more processors (central processing units, CPUs) 322 (for example, one or more processors) and a memory 332, and one or more storage media 330 for storing application programs 342 or data 344 (for example, one or more mass storage devices). Among them, the memory 332 and the storage media 330 may be transient storage or persistent storage. The program stored in the storage media 330 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the data processing device. Further, the central processor 322 may be configured to communicate with the storage media 330 and execute a series of instruction operations in the storage media 330 on the terminal behavior detection device 310.

[0098] The terminal behavior detection device 310 may further include one or more power supplies 326, one or more wired or wireless network interfaces 350, one or more input / output interfaces 358, and / or one or more operating systems 341. For example, Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.

[0099] Among them, the terminal behavior detection device 310 may specifically be a terminal device. Of course, the terminal behavior detection device described in the present application may also be in the form of a cluster, such as a cloud computing platform composed of multiple computers.

[0100] The steps in the terminal behavior detection method described above may be implemented by the structure of the terminal behavior detection device.

[0101] Corresponding to the above method embodiments, an embodiment of the present invention further provides a readable storage medium. A readable storage medium described below can be correspondingly referred to with a terminal behavior detection method described above.

[0102] A readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the terminal behavior detection method in the above method embodiments are implemented.

[0103] The readable storage medium can specifically be various readable storage media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.

[0104] The embodiments in the specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the devices, equipment, and readable storage media disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple. For the relevant parts, reference can be made to the description in the method part.

[0105] The above has introduced in detail a terminal behavior detection method, device, equipment, and readable storage medium provided by the present invention. Specific examples are used herein to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the claims of the present invention.< / join> < / join> < / join> < / field> < / field> < / field> < / fact> < / fact> < / joins> < / facts>

Claims

1. A terminal behavior detection method, characterized in that, Including: Performing correlation analysis on the obtained terminal events to be detected to obtain the behavior scenarios to be detected, so as to perform attack detection according to the behavior scenarios to be detected subsequently; wherein, each behavior scenario to be detected is composed of multiple terminal events to be detected associated therewith; the behavior scenarios to be detected are abnormal scenarios among all behavior scenarios; For the behavior scenarios to be detected, determining the attack attributes of the behavior scenarios to be detected; If there is a target behavior scenario whose attack attribute meets the preset condition, then destroying the target behavior scenario; wherein, the target behavior scenario is any one of the behavior scenarios to be detected.

2. The terminal behavior detection method according to claim 1, characterized in that, The "if there is a target behavior scenario whose attack attribute meets the preset condition, then destroying the target behavior scenario" includes: If there is a target behavior scenario of "all processes have exited", then destroying the target behavior scenario.

3. The terminal behavior detection method according to claim 1, characterized in that, The "if there is a target behavior scenario whose attack attribute meets the preset condition, then destroying the target behavior scenario" includes: If there is a target behavior scenario of "the attack possibility is lower than the preset ratio or the attack score is lower than the preset score", then destroying the target behavior scenario.

4. The terminal behavior detection method according to claim 1, characterized in that, The "if there is a target behavior scenario whose attack attribute meets the preset condition, then destroying the target behavior scenario" includes: If there is a behavior scenario to be detected of "no attack is detected and the number or duration of times of no attack detected reaches the threshold", then destroying the behavior scenario to be detected.

5. The terminal behavior detection method according to any one of claims 1 to 4, characterized in that, The "performing attack detection according to the behavior scenarios to be detected" includes: Performing rule matching on the terminal events to be detected corresponding to each behavior scenario to be detected to determine the target rule corresponding to each behavior scenario to be detected; According to the target rule, performing attack detection on each behavior scenario to be detected to determine whether it is an attack behavior scenario.

6. The terminal behavior detection method according to claim 5, characterized in that, The "performing rule matching on the terminal events to be detected corresponding to each behavior scenario to be detected to determine the target rule corresponding to each behavior scenario to be detected" includes: Performing single-event rule and multi-event rule matching on the terminal events to be detected corresponding to some or all of the behavior scenarios to be detected to determine the target rule corresponding to each behavior scenario to be detected; wherein, the single-event rule matching is to only detect whether a single event conforms to a certain rule, and the multi-event rule matching is to detect whether multiple associated events correspond to a certain rule.

7. The terminal behavior detection method according to claim 5, characterized in that, The "performing attack detection on each behavior scenario to be detected according to the target rule to determine whether it is an attack behavior scenario" includes: Obtaining the detection score corresponding to each behavior scenario to be detected according to the target rule corresponding to each behavior scenario to be detected and the preset rule score corresponding to each target rule; Determining whether it is an attack behavior scenario according to the detection score.

8. A terminal behavior detection device, characterized in that, Including: A correlation analysis module, configured to perform correlation analysis on the obtained terminal events to be detected to obtain the behavior scenarios to be detected, so as to perform attack detection according to the behavior scenarios to be detected subsequently; wherein, each behavior scenario to be detected is composed of multiple terminal events to be detected associated therewith; the behavior scenarios to be detected are abnormal scenarios among all behavior scenarios; An attribute determination module, configured to determine an attack attribute of the to-be-detected behavior scenario for the to-be-detected behavior scenario; A scenario destruction module, configured to destroy the target behavior scenario if there is a target behavior scenario whose attack attribute meets a preset condition; wherein, the target behavior scenario is any one of the to-be-detected behavior scenarios.

9. A terminal behavior detection device, characterized in that, Comprising: A memory, configured to store a computer program; A processor, configured to implement the steps of the terminal behavior detection method according to any one of claims 1 to 7 when executing the computer program.

10. A readable storage medium, characterized in that, A computer program is stored on the readable storage medium, and when the computer program is executed by the processor, the steps of the terminal behavior detection method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Dynamical recovery method and device for operating system of intelligent electronic device

    CN105630636A