A method, apparatus, medium, and electronic device for detecting malicious attacks

CN115203696BActive Publication Date: 2026-09-25BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210840941.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-18
Publication Date
2026-09-25
Estimated Expiration
2042-07-18

AI Technical Summary

Technical Problem

[0005]本申请实施例的目的在于提供一种检测恶意攻击的方法、装置、介质及电子设备,通过本申请实施例的技术方案可以解决如下技术问题:检测监控自定义协议URI启动脚本实现恶意程序运行绕过监控无法被溯源的问题

Benefits of technology

[0008]在一些实施例中,所述对与待检测工具对应的可执行文件进行安全性评估得到第一评估结果,包括:根据所述第一自定义协议的名称查找所述可执行文件的属性信息,其中,所述属性信息至少包括所述可执行文件的存放位置;通过所述存放位置得到所述可执行文件;根据所述可执行文件得到所述第一评估结果。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115203696B_ABST
    Figure CN115203696B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a method, device, medium and electronic equipment for detecting malicious attacks, the method comprising: performing security evaluation on an executable file corresponding to a tool to be detected, to obtain a first evaluation result, wherein the executable file is started through a first custom protocol, and the first evaluation result is used to represent the security of the executable file; obtaining a source address for starting the tool to be detected through the first custom protocol, and performing security evaluation on the source address to obtain a second evaluation result; and obtaining a target evaluation result according to the first evaluation result and the second evaluation result, wherein the target evaluation result is used to represent the security of the operation. The technical solution of the embodiments of the present application can solve the following technical problem: detecting that a custom protocol URI starting script implements a malicious program running bypassing monitoring and cannot be traced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security detection, and more specifically, the embodiments of this application relate to a method, apparatus, medium, and electronic device for detecting malicious attacks. Background Technology

[0002] Windows custom protocols allow applications to register with Uniform Resource Identifiers (URIs). In some cases, it may be necessary to invoke another application to handle the custom URI scheme. For this purpose, Windows custom protocols can register existing applications as URI pluggable protocol handlers and associate them with the custom URI scheme. Once the application starts successfully, it can be retrieved using command-line arguments.

[0003] Registry startup detection for malicious tools involves setting registry keys under *\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to enable automatic startup, allowing the tool to remain permanently running on the computer. Detection methods involve checking the corresponding registry key pairs to determine the disk location of the malicious tool. Understandably, this method, which only targets registry startup items, is relatively simple and easily fooled, as new persistence techniques constantly emerge in the fight against malware.

[0004] Therefore, improving the detection of malicious tools that use custom protocols to achieve persistence has become an urgent technical problem to be solved. Summary of the Invention

[0005] The purpose of this application is to provide a method, apparatus, medium, and electronic device for detecting malicious attacks. The technical solution of this application can solve the following technical problem: the problem that malicious programs that bypass monitoring and cannot be traced can be detected by starting a script with a custom protocol URI.

[0006] In a first aspect, embodiments of this application provide a method for detecting malicious attacks. The method includes: performing a security assessment on an executable file corresponding to a tool to be detected to obtain a first assessment result, wherein the executable file is launched via a first custom protocol, and the first assessment result is used to characterize the security of the executable file; obtaining the source address of the tool to be detected launched via the first custom protocol, and performing a security assessment on the source address to obtain a second assessment result; and obtaining a target evaluation result based on the first assessment result and the second assessment result, wherein the target evaluation result is used to characterize the security of the current operation.

[0007] Some embodiments of this application perform a security assessment on the tool to be tested and then perform a security test on the source address that attempts to launch the tool to be tested through a custom protocol, thereby identifying the tool to be tested that has been residing on the monitored device for a long time. Compared with the technical solutions of related technologies, this improves the accuracy of the assessment results.

[0008] In some embodiments, the step of performing a security assessment on the executable file corresponding to the tool to be tested to obtain a first assessment result includes: searching for the attribute information of the executable file based on the name of the first custom protocol, wherein the attribute information includes at least the storage location of the executable file; obtaining the executable file through the storage location; and obtaining the first assessment result based on the executable file.

[0009] Some embodiments of this application obtain the storage location of the executable file through the name of the first custom protocol, and read the executable file according to the storage location to obtain the first evaluation result based on the executable file, which can improve the accuracy of the obtained evaluation result.

[0010] In some embodiments, obtaining the first evaluation result based on the executable file includes: obtaining a signature from the executable file; if the signature fails the preliminary security verification, obtaining the first evaluation result at least based on the category of the signature.

[0011] Some embodiments of this application perform preliminary security authentication based on the signature information on the executable file, thereby improving the accuracy of the first evaluation result.

[0012] In some embodiments, the signature failing the initial security verification includes: the signature not being in the whitelist, or the signature being in the blacklist, wherein the whitelist is used to record signatures that have been pre-determined to be secure, and the blacklist is used to record signatures that have been determined to be insecure.

[0013] Some embodiments of this application use whitelists or blacklists to confirm whether the signature is dangerous, thereby improving the accuracy and operability of the preliminary security verification results.

[0014] In some embodiments, the categories include: no signature, general signature, and custom signature, wherein the security level of the no signature is lower than that of the general signature, the security level of the general signature is lower than that of the custom signature, and the signature category belongs to one of the no signature, the general signature, and the custom signature.

[0015] Some embodiments of this application categorize signatures into multiple classes according to security levels and assign values ​​to the signatures to be evaluated based on the security levels, thereby improving the accuracy of the security evaluation results based on signatures.

[0016] In some embodiments, the attribute information further includes execution parameters corresponding to the executable file, wherein obtaining the first evaluation result at least based on the signature category includes: obtaining a first value based on the signature category, wherein the first value is used to characterize the security level corresponding to the signature category; if the executable file is confirmed to be a secure file by scanning, then obtaining an execution function based on the execution parameters and obtaining a second value based on the execution function, wherein the second value is used to characterize the potential risks that the executable file may cause by calling the execution function; and obtaining the first evaluation result based on the first value and the second value.

[0017] Some embodiments of this application obtain a first evaluation result by combining the signature type and the execution function, thereby improving the accuracy of the obtained first evaluation result.

[0018] In some embodiments, obtaining the first evaluation result based on the first value and the second value includes: weighted summing of the first value and the second value to obtain the first evaluation result.

[0019] Some embodiments of this application use a weighted summation of the first and second values ​​to obtain an index for evaluating the security of executable files. Obtaining the evaluation result of executable file security through a weighted summation method can improve the versatility of the technical solution.

[0020] In some embodiments, the execution parameters and the storage location are obtained by collecting custom protocol registry entries from the registry.

[0021] Some embodiments of this application provide a method for obtaining execution parameters and their storage location.

[0022] In some embodiments, the step of performing a security assessment on the source address to obtain a second assessment result includes: obtaining the target state of the source address, wherein the target state belongs to one of three states: malicious, whitelisted, or unknown; and using the score corresponding to the target state as the second assessment result.

[0023] Some embodiments of this application provide a technical solution for security assessment of source addresses, thereby improving the accuracy of the obtained second assessment results.

[0024] In some embodiments, the source address is obtained by detecting hypertext transfer protocol link tags, wherein the content of the link tags is the same as the name of the first custom protocol.

[0025] Some embodiments of this application provide a method for obtaining a source address.

[0026] In some embodiments, obtaining the target evaluation result based on the first evaluation result and the second evaluation result includes: weighting and summing the first evaluation result and the second evaluation result to obtain the target evaluation result.

[0027] Some embodiments of this application provide a quantitative method for obtaining target evaluation results by integrating first evaluation results and second evaluation results, thereby improving the accuracy and objectivity of the obtained target evaluation results.

[0028] In some embodiments, after obtaining the target evaluation result based on the first evaluation result and the second evaluation result, the method further includes: obtaining the hazard level corresponding to the current operation based on the target evaluation result; and providing the hazard level.

[0029] Some embodiments of this application also provide a technical solution that provides the user with the danger level of this operation, alerting the user and thus protecting the host security.

[0030] Secondly, some embodiments of this application provide an apparatus for detecting malicious attacks. The apparatus includes: an executable file security assessment result acquisition module, configured to perform a security assessment on an executable file corresponding to a tool to be detected, and obtain a first assessment result, wherein the executable file is launched via a first custom protocol, and the first assessment result is used to characterize the security of the executable file; a source security assessment result acquisition module, configured to acquire the source address of the tool to be detected launched via the first custom protocol, and perform a security assessment on the source address to obtain a second assessment result; and a target evaluation result acquisition module, configured to obtain a target evaluation result based on the first assessment result and the second assessment result, wherein the target evaluation result is used to characterize the security of the current operation.

[0031] Thirdly, some embodiments of this application provide a computer storage medium having a computer program stored thereon, which, when executed by a processor, can implement the method described in any embodiment of the first aspect.

[0032] Fourthly, some embodiments of this application provide an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, can implement the method as described in any embodiment of the first aspect. Attached Figure Description

[0033] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0034] Figure 1 This is one of the flowcharts for a method of detecting malicious attacks provided in the embodiments of this application;

[0035] Figure 2 The second flowchart of the method for detecting malicious attacks provided in the embodiments of this application;

[0036] Figure 3 A block diagram illustrating the composition of the apparatus for detecting malicious attacks provided in this application embodiment;

[0037] Figure 4 This is a schematic diagram illustrating the composition of an electronic device provided in an embodiment of this application. Detailed Implementation

[0038] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0039] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0040] New persistent technologies have emerged that use phishing websites to send deceptive messages, allowing malicious programs to execute via custom protocols and bypass security checks. While there are certain limitations to this method of inducing users to execute programs, it is more difficult to detect and monitor, and it is easier for the program to remain on the computer for a long time, causing incalculable harm.

[0041] Some embodiments of this application provide a method for long-term protection of a computer from attacks by malicious tools using custom URI protocols. For example, in some embodiments of this application, by detecting custom protocols recorded under the Classes path in the registry, by detecting the certificate of the tool to be detected, performing EDR scanning, and detecting the custom protocol startup source address, a security score is given to the tool to be detected that uses the custom protocol, and finally a security rating is performed to determine whether it is a malicious tool, providing the user with tool security feedback, thereby protecting host security.

[0042] The following is combined with Figure 1This paper exemplifies a method for detecting malicious attacks performed by the monitored device.

[0043] Please refer to Figure 1 , Figure 1 A method for detecting malicious attacks is provided in this application embodiment. The method includes: S101, performing a security assessment on an executable file corresponding to a tool to be detected to obtain a first assessment result; S102, obtaining the source address of the tool to be detected being launched through a first custom protocol, and performing a security assessment on the source address to obtain a second assessment result; S103, obtaining a target evaluation result based on the first assessment result and the second assessment result, wherein the target evaluation result is used to characterize the security of this operation.

[0044] Some embodiments of this application perform a security assessment on the tool to be tested and then perform a security test on the source address that attempts to launch the tool to be tested through a custom protocol, thereby identifying the tool to be tested that has been residing on the monitored device for a long time. Compared with the technical solutions of related technologies, this improves the accuracy of the assessment results.

[0045] The implementation process of each of the above steps is illustrated below.

[0046] The executable file described in S101 is launched via a first custom protocol, and the first evaluation result is used to characterize the security of the executable file.

[0047] In some embodiments of this application, S101 includes, for example:

[0048] The first step is to locate the attribute information of the executable file based on the name of the first custom protocol, wherein the attribute information includes at least the storage location of the executable file.

[0049] The second step is to obtain the executable file from the storage location.

[0050] The third step is to obtain the first evaluation result based on the executable file.

[0051] For example, in some embodiments of this application, the aforementioned attribute information includes the storage location, then the third step typically includes:

[0052] First, obtain the signature from the executable file.

[0053] Secondly, if the signature fails the initial security verification, the first evaluation result is obtained at least based on the category of the signature (e.g., the score corresponding to the category of the signature is used as the first evaluation result at that point). For example, the signature failing the initial security verification includes: the signature not being in the whitelist, or the signature being in the blacklist, wherein the whitelist is used to record signatures pre-determined to be secure, and the blacklist is used to record signatures determined to be insecure. For example, the categories include: no signature, generic signature, and custom signature, where the security level of the no-signature is lower than that of the generic signature, the security level of the generic signature is lower than that of the custom signature, and the signature category belongs to one of the no-signature, generic, and custom signature categories.

[0054] For example, in some embodiments of this application, the aforementioned attribute information includes the storage location and the execution parameters corresponding to the executable file. Therefore, the third step typically includes:

[0055] First, a first value is obtained based on the category of the signature, wherein the first value is used to characterize the security level corresponding to the category of the signature.

[0056] Secondly, if the executable file is confirmed to be a safe file through scanning, an execution function is obtained based on the execution parameters, and a second value is obtained based on the execution function. The second value characterizes the potential risks that the executable file may cause by calling the execution function. The first evaluation result is then obtained based on the first value and the second value. For example, obtaining the first evaluation result based on the first value and the second value includes: performing a weighted summation of the first value and the second value to obtain the first evaluation result.

[0057] Some embodiments of this application obtain a first evaluation result by comprehensively considering the signature type and the execution function, thereby improving the accuracy of the first evaluation result. Some embodiments of this application also obtain an index for evaluating the security of an executable file by weighted summation of the first and second values. Obtaining the evaluation result of executable file security through weighted summation improves the versatility of the technical solution.

[0058] It should be noted that, in some embodiments of this application, the execution parameters and the storage location are obtained by collecting custom protocol registry entries from the registry.

[0059] It is understood that some embodiments of this application perform preliminary security authentication based on the signature information on the executable file, improving the accuracy of the first evaluation result. Some embodiments of this application use whitelists or blacklists to confirm whether the signature is dangerous, improving the accuracy and operability of the preliminary security verification result. Some embodiments of this application categorize signatures according to security levels and assign values ​​to the signatures to be evaluated according to their security levels, improving the accuracy of the security evaluation result based on the signature. Some embodiments of this application obtain the storage location of the executable file through the name of the first custom protocol, read the executable file according to the storage location, and obtain the first evaluation result based on the executable file, which can improve the accuracy of the obtained evaluation result.

[0060] The implementation process of S102 is illustrated below.

[0061] In some embodiments of this application, S102 includes, for example, obtaining the target state of the source address, wherein the target state is one of three states: malicious, whitelisted, or unknown; and using the score corresponding to the target state as the second evaluation result.

[0062] Some embodiments of this application provide a technical solution for security assessment of source addresses, thereby improving the accuracy of the obtained second assessment results.

[0063] For example, in some embodiments of this application, the source address is obtained by detecting hypertext transfer protocol link tags, wherein the content of the link tags is the same as the name of the first custom protocol.

[0064] Some embodiments of this application provide a method for obtaining a source address.

[0065] The implementation process of S103 is illustrated below.

[0066] In some embodiments of this application, S103 includes, for example, weighted summation of the first evaluation result and the second evaluation result to obtain the target evaluation result.

[0067] Some embodiments of this application provide a quantitative method for obtaining target evaluation results by integrating first evaluation results and second evaluation results, thereby improving the accuracy and objectivity of the obtained target evaluation results.

[0068] It should be noted that, in order to promptly remind users, in some embodiments of this application, after S103, the method for detecting malicious attacks further includes: obtaining the danger level corresponding to the current operation based on the target evaluation result; and providing the danger level.

[0069] Some embodiments of this application also provide a technical solution that provides the user with the danger level of this operation, alerting the user and thus protecting the host security.

[0070] The following is combined with Figure 2 This section provides an example of a method for detecting malicious attacks.

[0071] The first step is to obtain the data to be processed.

[0072] Specifically, such as Figure 2 As shown, the registry's Classes key values ​​are traversed to extract the contents of all URL protocol key values. Specifically, by traversing the custom protocols recorded under the Classes path in the registry, the custom protocol name, executable file path, and execution parameters corresponding to each custom protocol are obtained.

[0073] For example, iterate through all existing custom protocols under the registry path * / Classes to extract the key-value pairs of the URLProtocol field for each custom protocol. These key-value pairs include: the custom protocol name (e.g., URL Protocol name), the executable file path under / shell / open / command (i.e., the location of the executable file), and the execution parameters (i.e., the execution parameters of the executable file). Save this information to the database.

[0074] The second step is to obtain the first assessment result through testing tool certificates and EDR scanning.

[0075] like Figure 2 As shown, the security of tools under a custom protocol (i.e., the tool to be tested corresponds to the executable file) is verified. A preliminary judgment is made, and relevant information and results are recorded in the database. Figure 2 As shown, the first evaluation result was obtained through EDR scanning, whitelist detection, and tool signature check.

[0076] The second step involves a security scan of the executable file obtained in the first step. First, it checks if the signature in the executable file is on the whitelist. If so, the verification ends, and the tool to be verified (the executable file) is marked as safe. Second, it uses EDR to perform a detailed scan for malicious activity. If malicious, it is removed; otherwise, a security score is given based on the file's execution function. Finally, the signature in the executable file is verified, and scores are given for three scenarios: no signature, using a generic signature, and using a custom signature. The scores obtained in this step are summed and recorded in the database.

[0077] The third step is to define a custom protocol startup source address and score the security of tools that use the custom protocol.

[0078] like Figure 2As shown, the system monitors Hypertext Transfer Protocol (HRF) links (HRF tags), locates the target link based on the custom protocol name, and ensures that the HRF content of the target link matches the custom protocol. It then checks the reliability of the source, performs a secondary assessment, and issues the user a warning corresponding to the appropriate risk level to protect host security.

[0079] Because launching local tools using a custom protocol requires the use of the Hypertext Transfer Protocol, when a local application on a computer is launched using a custom protocol, the source address of the request can be checked, and the program can be scored according to three states: malicious, whitelisted, and unknown. Then, the scores calculated in the second step are added together. If the final score is greater than or equal to 100, the program is marked as malicious; if it is less than 100 but greater than 50, it is marked as suspicious; and if it is less than 50, it is marked as safe. Finally, the user is provided with the danger level of this operation, which alerts the user and thus protects the host security.

[0080] Some embodiments of this application can be used in protection products such as threat detection. For example, such protection products can be used to implement the method for detecting malicious attacks provided in some embodiments of this application. The method includes, for example, collecting registry entries for custom protocols to obtain the custom protocol name, executable file path, and executable file execution parameters; verifying whether the tool to be verified is secure, performing a security score, recording, and saving; monitoring the Hypertext Transfer Protocol (HRF) tag, performing a secondary security score, providing security prompts to the user, and protecting host security.

[0081] It is understood that some embodiments of this application detect persistent malicious programs by using custom URI protocols, making virus tracing more efficient and gaining an advantage in combating malicious samples.

[0082] Please refer to Figure 3 , Figure 3 This application illustrates an apparatus for detecting malicious attacks, as provided in an embodiment. It should be understood that this apparatus is similar to the one described above. Figure 1 Corresponding to the method embodiments, it can execute the various steps involved in the above method embodiments. The specific functions of the device can be found in the description above. To avoid repetition, detailed descriptions are appropriately omitted here. The device includes at least one software function module that can be stored in the memory or embedded in the device's operating system in the form of software or firmware. The device for detecting malicious attacks includes: an executable file security assessment result acquisition module 101, a source security assessment result acquisition module 102, and a target evaluation result acquisition module 103.

[0083] The executable file security assessment result acquisition module 101 is configured to perform a security assessment on the executable file corresponding to the tool to be tested and obtain a first assessment result, wherein the executable file is started through a first custom protocol and the first assessment result is used to characterize the security of the executable file.

[0084] The source security assessment result acquisition module 102 is configured to acquire the source address of the tool to be detected launched through the first custom protocol, and to perform a security assessment on the source address to obtain a second assessment result.

[0085] The target evaluation result acquisition module 103 is configured to obtain a target evaluation result based on the first evaluation result and the second evaluation result, wherein the target evaluation result is used to characterize the security of the tool to be tested.

[0086] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the aforementioned method, and will not be elaborated further here.

[0087] Some embodiments of this application provide a computer storage medium having a computer program stored thereon, which, when executed by a processor, can implement the methods described in any of the embodiments of the method for detecting malicious attacks described above.

[0088] Some embodiments of this application provide a computer program product, which includes a computer program, wherein when the computer program is executed by a processor, it can implement the method described in any of the embodiments of the method for detecting malicious attacks described above.

[0089] like Figure 4 As shown, some embodiments of this application provide an electronic device 300, including a memory 310, a processor 320, and a computer program stored on the memory 310 and executable on the processor 320, wherein when the processor 320 reads the program from the memory 310 via a bus 330 and executes the program, it can implement the method described in the embodiments of the above-described method for detecting malicious attacks.

[0090] Processor 320 can process digital signals and may include various computing architectures. For example, it may be a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements multiple instruction set combinations. In some examples, processor 320 may be a microprocessor.

[0091] The memory 310 can be used to store instructions executed by the processor 320 or data related to the execution of instructions. These instructions and / or data may include code used to implement some or all of the functions of one or more modules described in the embodiments of this application. The processor 320 of the embodiments of this disclosure can be used to execute the instructions in the memory 310 to implement… Figure 1 The method shown. Memory 310 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memory well known to those skilled in the art.

[0092] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0093] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0094] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0095] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0096] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0097] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A method for detecting malicious attacks, characterized in that, The method includes: A security assessment is performed on the executable file corresponding to the tool to be tested to obtain a first assessment result, wherein the executable file is launched through a first custom protocol, and the first assessment result is used to characterize the security of the executable file; Obtain the source address of the tool to be detected that was launched through the first custom protocol, and perform a security assessment on the source address to obtain a second assessment result; The target evaluation result is obtained based on the first evaluation result and the second evaluation result, wherein the target evaluation result is used to characterize the safety of this operation; The step of performing a security assessment on the executable file corresponding to the tool to be tested to obtain a first assessment result includes: The executable file's attribute information is located based on the name of the first custom protocol, wherein the attribute information includes at least the storage location of the executable file; The executable file is obtained from the storage location; The first evaluation result is obtained based on the executable file; Obtaining the first evaluation result based on the executable file includes: Obtain the signature from the executable file; If the signature fails the initial security verification, the first evaluation result is obtained at least based on the category of the signature; The attribute information also includes execution parameters corresponding to the executable file, wherein, The step of obtaining the first evaluation result based at least on the category of the signature includes: A first value is obtained based on the category of the signature, wherein the first value is used to characterize the security level corresponding to the category of the signature; If the executable file is confirmed to be a safe file through scanning, then the execution function is obtained based on the execution parameters and a second value is obtained based on the execution function, wherein the second value is used to characterize the potential risks that may be caused by the executable file calling the execution function; The first evaluation result is obtained based on the first value and the second value; The step of performing a security assessment on the source address to obtain a second assessment result includes: Obtain the target status of the source address, wherein the target status belongs to one of the three states: malicious, whitelisted, or unknown; The score corresponding to the target state is used as the second evaluation result.

2. The method as described in claim 1, characterized in that, The signature failing the initial security verification includes: the signature not being in the whitelist, or the signature being in the blacklist, wherein the whitelist is used to record signatures that are pre-determined to be secure, and the blacklist is used to record signatures that are determined to be insecure.

3. The method as described in claim 2, characterized in that, The categories include: no signature, general signature, and custom signature. The security level of the no signature is lower than that of the general signature, and the security level of the general signature is lower than that of the custom signature. The signature category belongs to one of the no signature, the general signature, and the custom signature.

4. The method as described in claim 1, characterized in that, The step of obtaining the first evaluation result based on the first value and the second value includes: weighting and summing the first value and the second value to obtain the first evaluation result.

5. The method as described in claim 1, characterized in that, The execution parameters and the storage location are obtained by collecting custom protocol registry entries from the registry.

6. The method as described in claim 1, characterized in that, The source address is obtained by detecting the link tags of the Hypertext Transfer Protocol, wherein the content of the link tags is the same as the name of the first custom protocol.

7. The method as described in claim 1, characterized in that, The step of obtaining the target evaluation result based on the first evaluation result and the second evaluation result includes: weighting and summing the first evaluation result and the second evaluation result to obtain the target evaluation result.

8. The method as described in claim 1, characterized in that, After obtaining the target evaluation result based on the first evaluation result and the second evaluation result, the method further includes: The hazard level corresponding to this operation is obtained based on the target evaluation results. Provide the aforementioned hazard level.

9. A device for detecting malicious attacks, characterized in that, The device includes: The executable file security assessment result acquisition module is configured to perform a security assessment on the executable file corresponding to the tool to be tested and obtain a first assessment result, wherein the executable file is started through a first custom protocol and the first assessment result is used to characterize the security of the executable file; The source security assessment result acquisition module is configured to acquire the source address of the tool to be detected that was launched through the first custom protocol, and to perform a security assessment on the source address to obtain a second assessment result; The target evaluation result acquisition module is configured to obtain a target evaluation result based on the first evaluation result and the second evaluation result, wherein the target evaluation result is used to characterize the security of this operation; The executable file security assessment result acquisition module is configured to: search for the attribute information of the executable file based on the name of the first custom protocol, wherein the attribute information includes at least the storage location of the executable file; obtain the executable file through the storage location; and obtain the first assessment result based on the executable file. The executable file security assessment result acquisition module is configured to obtain a signature from the executable file; if the signature fails the preliminary security verification, the first assessment result is obtained at least based on the category of the signature; The attribute information also includes execution parameters corresponding to the executable file, wherein, The executable file security assessment result acquisition module is configured to obtain a first value based on the signature category, wherein the first value is used to characterize the security level corresponding to the signature category; if the executable file is confirmed to be a secure file through scanning, then an execution function is obtained based on the execution parameters and a second value is obtained based on the execution function, wherein the second value is used to characterize the potential risks that the executable file may cause by calling the execution function; and the first assessment result is obtained based on the first value and the second value. The source security assessment result acquisition module is configured to acquire the target status of the source address, wherein the target status is one of three states: malicious, whitelisted, or unknown; and the score corresponding to the target status is used as the second assessment result.

10. A computer storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it can implement the method described in any one of claims 1-8.

11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein, When the processor executes the program, it can implement the method described in any one of claims 1-8.

Citation Information

Patent Citations

  • A program protocol white list linkage method and device for an industrial control host

    CN109766694A

  • Security system for adaptive targeted multi-attribute based identification of online malicious electronic content

    US20220027428A1