Script security detection method and device

CN115357892BActive Publication Date: 2026-09-29戎码科技(北京)有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211021426.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-24
Publication Date
2026-09-29
Estimated Expiration
2042-08-24

AI Technical Summary

Technical Problem

[0004]但上述现有技术中,AMSI检测依赖于杀毒软件,若杀毒软件被关闭,则AMSI检测也将失效,从而无法实现安全检测的全面性

Benefits of technology

[0051]本发明实施例提供的脚本安全检测方法及装置,先将目标程序集注入至PowerShell进程的当前应用程序域中,若目标程序集确定当前加载的当前应用程序域中包含与脚本执行相关的子程序集时,对子程序集中的脚本执行的相关方法进行挂钩操作,得到目标脚本内容,并对目标脚本内容进行安全检测。可知,本发明是通过目标程序集对PowerShell进程的脚本执行的相关方法进行挂钩操作,并对挂钩操作得到的目标脚本内容进行安全检测,使得脚本安全检测方法不依赖于杀毒软件,从而实现了安全检测的全面性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115357892B_ABST
    Figure CN115357892B_ABST
Patent Text Reader

Abstract

The embodiment of the present application provides a script security detection method and device, and relates to the technical field of security detection, wherein the method comprises the following steps: injecting a target program set into a current application domain of a PowerShell process; determining whether a subprogram set related to script execution is contained in the current application domain currently loaded by the target program set; when it is determined that the subprogram set is contained, performing hook operation on the related method of script execution in the subprogram set by the target program set to obtain target script content; and performing security detection on the target script content by the target program set. The present application performs hook operation on the related method of script execution of the PowerShell process by the target program set, and performs security detection on the target script content obtained by the hook operation, so that the script security detection method does not depend on an antivirus software, thereby realizing the comprehensiveness of security detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security detection technology, and in particular to a script security detection method and apparatus. Background Technology

[0002] PowerShell, as a built-in scripting tool, is easy to use and feature-rich, and is frequently used in various stages of attacks. However, malicious scripts used by attackers often contain extensive obfuscation and encoding of the script content, making it easy to bypass security software's analysis and detection of script content.

[0003] In existing technologies, such malicious scripts are typically detected through the Antimalware Scan Interface (AMSI). The specific working principle is as follows: when a PowerShell process is created, AMSI.DLL is loaded from the disk into the memory address space. AMSI.DLL includes functions for scanning script content. When commands are executed in the PowerShell process, all script content is first sent to this function before execution. Subsequently, this function calls antivirus software to perform security checks on the scanned script content.

[0004] However, in the aforementioned existing technologies, AMSI detection relies on antivirus software. If the antivirus software is turned off, AMSI detection will also fail, thus failing to achieve comprehensive security detection. Summary of the Invention

[0005] To address the problems in the prior art, embodiments of the present invention provide a script security detection method and apparatus.

[0006] Specifically, the embodiments of the present invention provide the following technical solutions:

[0007] In a first aspect, embodiments of the present invention provide a script security detection method, including:

[0008] Inject a target assembly into the current application domain of a PowerShell process; the target assembly is used for security checks; the current application domain includes all assemblies required for the PowerShell process to function normally.

[0009] The target assembly is used to determine whether the currently loaded application domain contains a subassembly related to script execution;

[0010] When it is determined that the currently loaded application domain contains the sub-program set, the relevant methods for script execution in the sub-program set are hooked through the target program set to obtain the target script content;

[0011] The target script content is subjected to security checks using the target program assembly.

[0012] Further, determining whether the currently loaded application domain contains a subassembly related to script execution through the target assembly includes:

[0013] When the target assembly is initialized, it is determined whether the currently loaded application domain contains subassemblies related to script execution.

[0014] Furthermore, the step of injecting the target assembly into the current application domain of the PowerShell process includes:

[0015] The target assembly is reflected into the current application domain of the PowerShell process via a first DLL module; the first DLL module is a module pre-injected into each process to determine the type of the process.

[0016] Furthermore, before the method reflectsively injects the target assembly into the current application domain of the PowerShell process via the first DLL module, the method further includes:

[0017] The first DLL module is used to obtain the list of modules loaded by the current process; the list of modules includes at least one second DLL module; the second DLL module is a module required for the current process to run normally;

[0018] When the current process is determined to be the PowerShell process based on the at least one second DLL module, the target assembly is obtained through the first DLL module.

[0019] Furthermore, the step of reflectingly injecting the target assembly into the current application domain of the PowerShell process via the first DLL module includes:

[0020] The host object of the .NET runtime in the PowerShell process is obtained through the first DLL module;

[0021] The current application domain is obtained through the host object;

[0022] The first DLL module injects the target assembly into the current application domain, initializes the target assembly, and passes target parameters to the target assembly.

[0023] Further, determining whether the currently loaded application domain contains a subassembly related to script execution through the target assembly includes:

[0024] The target parameters are obtained through the target assembly, and it is determined whether the target parameters are valid.

[0025] When the target parameter is determined to be valid through the target program assembly, it is determined whether the currently loaded application domain contains a subprogram assembly related to script execution.

[0026] Furthermore, before performing security checks on the target script content through the target assembly, the method further includes:

[0027] If it is determined that the subset is not included in the currently loaded application domain, add a callback for the subset;

[0028] When the sub-program set is detected to be loaded via the callback, the relevant methods for script execution in the sub-program set are hooked through the target program set to obtain the target script content.

[0029] Furthermore, the methods related to script execution include methods for executing code blocks and methods for compiling code blocks;

[0030] The method of hooking the execution of scripts in the sub-program set through the target program set to obtain the target script content includes:

[0031] Obtain the target version information of the PowerShell process through the target assembly;

[0032] When the target version information is the first version information, the execution method of the code block is hooked through the target program assembly, and all first instructions in the code block are obtained based on the execution method of the code block, and all first instructions are determined as the target script content;

[0033] When the target version information is the second version information, the compilation method of the code block is hooked through the target program assembly, and all second instructions in the code block are obtained based on the compilation method of the code block. All second instructions are determined as the target script content; the version corresponding to the second version information is higher than the version corresponding to the first version information.

[0034] Furthermore, the security detection of the target script content through the target assembly includes:

[0035] The target script content is matched with instructions in a preset list using the target program assembly to obtain a matching result; the preset list includes a blacklist instruction list and / or a sensitive instruction list, the blacklist instruction list stores at least one instruction that is prohibited from execution; the sensitive instruction list stores at least one instruction that needs to be verified.

[0036] The target assembly determines whether the content of the target script is safe based on the matching results.

[0037] Further, the step of matching the target script content with instructions in a preset list through the target assembly to obtain a matching result includes:

[0038] When the target script content is determined to contain instructions from the blacklist instruction list and / or the sensitive instruction list through the target program assembly, the matching result is determined to be a successful match.

[0039] When the target script content is determined to not contain any instructions from the blacklist instruction list and / or the sensitive instruction list through the target program assembly, the matching result is determined to be a matching failure.

[0040] Further, the step of determining whether the content of the target script is safe based on the matching result through the target assembly includes:

[0041] When the matching result is a successful match, the target script content is determined to be unsafe through the target assembly.

[0042] When the matching result is a failure, the safety of the target script content is determined through the target program assembly.

[0043] Secondly, embodiments of the present invention also provide a script security detection device, comprising:

[0044] An injection unit is used to inject a target assembly into the current application domain of a PowerShell process; the target assembly is used for security detection; the current application domain includes all assemblies required for the PowerShell process to run normally.

[0045] The first determining unit is used to determine whether the currently loaded application domain contains a subroutine set related to script execution;

[0046] The first hooking unit is used to hook the relevant methods of script execution in the subprogram set when it is determined that the currently loaded application domain contains the subprogram set, so as to obtain the target script content;

[0047] The detection unit is used to perform security detection on the target script content.

[0048] Thirdly, embodiments of the present invention also provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the script security detection method as described in the first aspect.

[0049] Fourthly, embodiments of the present invention also provide a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the script security detection method as described in the first aspect.

[0050] Fifthly, embodiments of the present invention also provide a computer program product having executable instructions stored thereon, which, when executed by a processor, cause the processor to implement the script security detection method described in the first aspect.

[0051] The script security detection method and apparatus provided in this invention first inject a target assembly into the current application domain of a PowerShell process. If the target assembly determines that the currently loaded application domain contains a subassembly related to script execution, it hooks the script execution methods within the subassembly to obtain the target script content, and then performs security detection on the target script content. It can be seen that this invention hooks the script execution methods of the PowerShell process using a target assembly and performs security detection on the obtained target script content, making the script security detection method independent of antivirus software, thereby achieving comprehensive security detection. Attached Figure Description

[0052] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0053] Figure 1 This is one of the flowcharts illustrating the script security detection method provided by the present invention;

[0054] Figure 2 This is the second flowchart of the script security detection method provided by the present invention;

[0055] Figure 3 This is the third flowchart of the script security detection method provided by the present invention;

[0056] Figure 4This is the fourth flowchart of the script security detection method provided by the present invention;

[0057] Figure 5 This is a schematic diagram of the script security detection method provided by the present invention;

[0058] Figure 6 This is a schematic diagram of the physical structure of the electronic device provided by the present invention. Detailed Implementation

[0059] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0060] Figure 1 This is one of the flowcharts illustrating the script security detection method provided by this invention, such as... Figure 1 As shown, the script security detection method includes the following steps:

[0061] Step 101: Inject the target assembly into the current application domain of the PowerShell process; the current application domain includes all assemblies required for the PowerShell process to run normally.

[0062] The target program set is used for security detection; the target program set is a collection of pre-written programs used to perform security detection on the script content.

[0063] For example, a pre-written target assembly is injected into the current application domain of the PowerShell process. The current application domain includes all assemblies required for the PowerShell process to run normally. All assemblies are a collection of programs other than the target assembly. After the target assembly is injected into the current application domain, the current application domain includes all assemblies required for the PowerShell process to run normally and the target assembly.

[0064] Step 102: Determine whether the currently loaded application domain contains a subassembly related to script execution through the target assembly.

[0065] For example, when the target assembly is injected, the identifier of each program in all assemblies in the currently loaded application domain is traversed. In each program's identifier, it is determined whether there is an identifier of a subroutine related to script execution. When it is determined that there is an identifier of a subroutine related to script execution in each program's identifier, the set of subroutines corresponding to each identifier of a subroutine related to script execution is determined as a subroutine set.

[0066] Step 103: When it is determined that the currently loaded application domain contains the sub-program set, hook the relevant methods for script execution in the sub-program set through the target program set to obtain the target script content.

[0067] For example, when determining the subset related to script execution, the relevant methods for script execution are obtained from the subset, and the relevant methods for script execution are hooked through the target set to obtain the target script content.

[0068] Step 104: Perform security checks on the target script content using the target program assembly.

[0069] For example, once the target script content is obtained, it can be used to perform security checks on the target script content through the target assembly to prevent malicious target script content from attacking the PowerShell process.

[0070] The script security detection method provided in this invention first injects a target assembly into the current application domain of a PowerShell process. If the target assembly determines that the currently loaded application domain contains a subassembly related to script execution, it hooks the script execution methods within the subassembly to obtain the target script content, and then performs security detection on the target script content. It can be seen that this invention hooks the script execution methods of the PowerShell process using a target assembly and performs security detection on the obtained target script content, making the script security detection method independent of antivirus software, thus achieving comprehensive security detection. Furthermore, the script security detection method of this invention does not rely on system-provided interfaces, so it can support all operating systems.

[0071] Optionally, step 102 above can be implemented in the following ways:

[0072] When the target assembly is initialized, it is determined whether the currently loaded application domain contains subassemblies related to script execution.

[0073] For example, while the injected target assembly is being initialized, it can be used to determine whether the currently loaded application domain contains subassemblies related to script execution. This eliminates the need to determine whether the current application domain contains subassemblies related to script execution after the target assembly is initialized, thus saving the execution time of the entire script security detection.

[0074] It should be noted that when the injected target assembly begins initialization, the target assembly injected into the current application domain can also be loaded.

[0075] Optionally, Figure 2 This is the second flowchart of the script security detection method provided by the present invention, as shown below. Figure 2 As shown, step 101 above can be implemented through the following steps:

[0076] Step 1011: Reflectively inject the target assembly into the current application domain of the PowerShell process through the first dynamic link library (DLL) module.

[0077] The first DLL module is a module pre-injected into each process to determine the type of the process.

[0078] Specifically, the host object of the .NET runtime in the PowerShell process is obtained through the first DLL module; the current application domain is obtained through the host object; the target assembly is injected into the current application domain through the first DLL module, the target assembly is initialized, and target parameters are passed to the target assembly.

[0079] The target parameter can be a preset string used to verify the legitimacy of the first DLL module.

[0080] For example, the first DLL module reads the target assembly responsible for hooking the relevant methods for script execution and obtains the host object of the .NET runtime in the PowerShell process. If the host object is successfully obtained, the pre-configured current application domain is obtained through the host object, and the previously read target assembly is injected into the current application domain. At this point, the current application domain includes the target assembly and all assemblies required by the PowerShell process runtime. Finally, the first DLL module calls the initialization method in the target assembly to initialize the target assembly and passes the target parameters to the target assembly, thus completing the operation of reflectively injecting the target assembly into the current application domain of the PowerShell process. Specifically, the reflection is mainly reflected in obtaining the host object of the .NET runtime in the PowerShell process, obtaining the pre-configured current application domain through the host object, and injecting the previously read target assembly into the current application domain.

[0081] The script security detection method provided in this embodiment of the invention uses a first DLL module to reflectively inject the target program assembly used to perform security detection into the current application domain of the PowerShell process. In this way, when a malicious script traverses the DLL module, it cannot detect the target program assembly, and therefore cannot modify the target program assembly, further ensuring the comprehensiveness of the security detection.

[0082] Optionally, before performing step 1011 above, the script security detection method further includes the following steps:

[0083] The first DLL module is used to obtain the list of modules loaded by the current process; the list of modules includes at least one second DLL module; the second DLL module is a module required for the current process to run normally;

[0084] When the current process is determined to be the PowerShell process based on the at least one second DLL module, the target assembly is obtained through the first DLL module.

[0085] For example, in the driver, a pre-specified first DLL module is injected into each process via APC. All second DLL modules loaded by the current process at runtime are obtained through the first DLL module. Since the DLL modules loaded by the PowerShell process at runtime are different from those loaded by other processes at runtime, it is possible to determine whether the current process is a PowerShell process based on the identifier of each second DLL module. When it is determined that the current process is a PowerShell process, the pre-written target assembly is obtained through the first DLL module.

[0086] The script security detection method provided in this embodiment of the invention determines whether the current process is a PowerShell process based on each second DLL module loaded by the current process. The script security detection method steps are executed only when the current process is determined to be a PowerShell process.

[0087] Optionally, step 102 above can be implemented in the following ways:

[0088] The target parameters are obtained through the target assembly, and it is determined whether the target parameters are valid.

[0089] When the target parameter is determined to be valid through the target program assembly, it is determined whether the currently loaded application domain contains a subprogram assembly related to script execution.

[0090] For example, when the injected target assembly begins initialization, the target parameters passed to the target assembly by the first DLL module are obtained. These target parameters are then matched with pre-agreed parameters. If the target parameters match the pre-agreed parameters, the target parameters are deemed valid, meaning the first DLL module is a valid module injected into each process. Subsequent operations are then performed, such as determining whether the currently loaded application domain contains subassemblies related to script execution. If the target parameters do not match the pre-agreed parameters, the target parameters are deemed invalid, meaning the first DLL module is not a valid module injected into each process. In this case, no further operations are performed, and a warning message indicating the first DLL module is invalid can be output, allowing relevant personnel to take appropriate action against the invalid first DLL module.

[0091] The script security detection method provided in this embodiment of the invention verifies the legality of the target parameters passed by the first DLL module. Only when the target parameters are legal is it determined whether the currently loaded application domain contains a sub-assembly related to script execution, thereby preventing other DLL modules from using the target assembly and ensuring the security of the target assembly.

[0092] Optionally, Figure 3 This is a third flowchart illustrating the script security detection method provided in this embodiment of the invention. Before executing step 104, the script security detection method further includes the following steps:

[0093] Step 105: If it is determined that the subset is not included in the currently loaded application domain, add a callback for the subset.

[0094] For example, if it is determined that there is no identifier for a subroutine related to script execution in the identifier of each program, it means that the current application domain does not contain a subroutine set related to script execution. In this case, a callback for subroutine set loading is added to monitor the loading status of the subroutine set.

[0095] Step 106: When the sub-program set is detected to be loaded through the callback, the relevant methods for script execution in the sub-program set are hooked through the target program set to obtain the target script content.

[0096] For example, if a subassembly is detected to be loaded via a callback, the relevant methods of the script execution in the loaded subassembly are hooked through the target assembly to obtain the target script content.

[0097] The script security detection method provided in this embodiment of the invention, when it is determined that the currently loaded application domain does not contain a subroutine set related to script execution, monitors whether the subroutine set is loaded by adding a callback. When the subroutine set is detected to be loaded, the relevant methods for script execution in the subroutine set are hooked through the target set, so as to facilitate the real-time loading of the relevant methods for script execution.

[0098] Optionally, the methods for script execution include methods for executing code blocks and methods for compiling code blocks; step 103 above can be implemented in the following ways:

[0099] Obtain the target version information of the PowerShell process through the target assembly;

[0100] When the target version information is the first version information, the execution method of the code block is hooked through the target program assembly, and all first instructions in the code block are obtained based on the execution method of the code block, and all first instructions are determined as the target script content;

[0101] When the target version information is the second version information, the compilation method of the code block is hooked through the target program assembly, and all second instructions in the code block are obtained based on the compilation method of the code block. All second instructions are determined as the target script content; the version corresponding to the second version information is higher than the version corresponding to the first version information.

[0102] The first instruction and the second instruction can be the same instruction.

[0103] For example, when hooking methods related to script execution, different methods are hooked depending on the version of the PowerShell process. Therefore, the first step is to obtain the target version information of the PowerShell process through the target assembly. If the target version information is determined to be the first version corresponding to a lower version, the execution method of the code block is hooked. The execution method of the code block includes all the first instructions executed by the code block, so all the first instructions in the code block can be obtained based on the execution method of the code block, and all the first instructions can be merged to obtain the final target script content. If the target version information is determined to be the second version corresponding to a higher version, since the higher version of the PowerShell process introduces a compilation mechanism, the compilation method of the code block is hooked. The compilation method of the code block includes the compilation process of each instruction, so all the second instructions included in the code block can be obtained directly based on the compilation method of the code block, and all the second instructions can be merged to obtain the final target script content.

[0104] It should be noted that the target script content obtained above was obtained before the code block was executed, so as to facilitate subsequent determination of whether to execute the corresponding code block based on the security detection of the target script content.

[0105] It should be noted that the final target script content obtained is plaintext script content. Each instruction in the code block can be encrypted and / or obfuscated, or it can be unencrypted and / or unobfuscated. If each instruction in the code block is encrypted and / or obfuscated, the corresponding script will encrypt the encrypted and / or obfuscated instructions to ensure that the target script content obtained by the target assembly is plaintext script content.

[0106] The script security detection method provided in this invention performs hooking operations at different locations on different versions of PowerShell processes, enabling the script security detection method of this invention to support the detection of all versions of PowerShell processes and has a wide range of applications.

[0107] Optionally, Figure 4 This is the fourth flowchart of the script security detection method provided in this embodiment of the invention, as shown below. Figure 4 As shown, step 104 above can be implemented through the following steps:

[0108] Step 1041: Match the target script content with the instructions in the preset list using the target program assembly to obtain the matching result.

[0109] The preset list includes a blacklist instruction list and / or a sensitive instruction list. The blacklist instruction list stores at least one instruction that is prohibited from execution; the sensitive instruction list stores at least one instruction that needs to be verified.

[0110] Specifically, when the target script content is determined to include instructions from the blacklist instruction list and / or the sensitive instruction list through the target program assembly, the matching result is determined to be a successful match;

[0111] When the target script content is determined to not contain any instructions from the blacklist instruction list and / or the sensitive instruction list through the target program assembly, the matching result is determined to be a matching failure.

[0112] It should be noted that both the blacklist and sensitive command lists mentioned above can be configured using external configuration files, which improves the flexibility of configuring the blacklist and sensitive command lists.

[0113] It should be noted that when matching the target script content with the instructions in the preset list through the target program assembly, it is possible to match only the blacklist instruction list, or only the sensitive instruction list, or both the blacklist instruction list and the sensitive instruction list. This invention does not limit this.

[0114] Step 1042: Determine whether the content of the target script is safe based on the matching result using the target program assembly.

[0115] Specifically, when the matching result is a successful match, the target script content is determined to be insecure by the target program assembly; when the matching result is a failed match, the target script content is determined to be secure by the target program assembly.

[0116] For example, after obtaining the plaintext script content, it can be detected by the target assembly. During detection, the plaintext script content is matched against instructions in the blacklist and / or sensitive instruction list. If the plaintext script content includes instructions from the blacklist, it means that the plaintext script content contains prohibited instructions, the matching result is successful, and the target script content is determined to be insecure. At this time, the prohibited instructions contained in the plaintext script content are reported, and an exception is thrown to intercept the prohibited instructions. An exception message can also be printed. If the plaintext script content includes instructions from the sensitive instruction list, it means that the plaintext script content contains instructions to be verified, the matching result is successful, and the target script content is determined to be insecure. In addition, the instructions to be verified are risky instructions, which may be instructions that can be executed normally or instructions that are prohibited from being executed. Therefore, the instructions to be verified need to be reported, and relevant personnel determine whether the reported instructions are legitimate.

[0117] If the plaintext script content does not contain instructions from the blacklist or the sensitive instruction list, the matching result is determined to be a failure, indicating that the target script content is safe. In this case, the corresponding code block can be executed based on the target script content.

[0118] The script security detection method provided in this embodiment of the invention detects the legality of the target script content based on a blacklist instruction list and / or a sensitive instruction list when the target script content is obtained, thereby achieving security detection of the target script content.

[0119] Figure 5 This is a schematic diagram of the script security detection device provided by the present invention, as shown below. Figure 5 As shown, the script security detection device includes an injection unit 501, a first determination unit 502, a first hook unit 503, and a detection unit 504; wherein:

[0120] Injection unit 501 is used to inject a target assembly into the current application domain of a PowerShell process; the target assembly is used for security detection; the current application domain includes all assemblies required for the PowerShell process to run normally;

[0121] The first determining unit 502 is used to determine whether the currently loaded application domain contains a subroutine set related to script execution;

[0122] The first hooking unit 503 is used to hook the relevant methods of script execution in the subprogram set when it is determined that the currently loaded application domain contains the subprogram set, so as to obtain the target script content;

[0123] The detection unit 504 is used to perform security detection on the target script content.

[0124] The script security detection device provided in this embodiment of the invention first injects a target assembly into the current application domain of a PowerShell process. During the initialization of the target assembly, if the target assembly determines that the currently loaded application domain contains a subassembly related to script execution, it hooks the script execution methods within the subassembly to obtain the target script content, and then performs security detection on the target script content. It can be seen that this invention hooks the script execution methods of the PowerShell process using a target assembly and performs security detection on the obtained target script content, making the script security detection method independent of antivirus software, thereby achieving comprehensive security detection.

[0125] Based on any of the above embodiments, the first determining unit 502 is specifically used for:

[0126] When the target assembly is initialized, it is determined whether the currently loaded application domain contains a subassembly related to script execution.

[0127] Based on any of the above embodiments, the injection unit 501 is specifically used for:

[0128] The target assembly is reflected and injected into the current application domain of the PowerShell process; the first DLL module is a module pre-injected into each process to determine the type of the process.

[0129] Based on any of the above embodiments, the device further includes:

[0130] The first acquisition unit is used to acquire a list of modules loaded by the current process; the list of modules includes at least one second DLL module; the second DLL module is a module required for the current process to run normally;

[0131] The second determining unit is used to obtain the target assembly when the current process is determined to be the PowerShell process based on the at least one second DLL module.

[0132] Based on any of the above embodiments, the injection unit 501 is specifically used for:

[0133] Obtain the host object of the .NET runtime in the PowerShell process;

[0134] The current application domain is obtained through the host object;

[0135] The target assembly is injected into the current application domain, the target assembly is initialized, and the target parameters are passed to the target assembly.

[0136] Based on any of the above embodiments, the first determining unit 502 is specifically used for:

[0137] Obtain the target parameter and determine whether the target parameter is valid;

[0138] If the target parameter is found to be valid, determine whether the currently loaded application domain contains a set of subroutines related to script execution.

[0139] Based on any of the above embodiments, the device further includes:

[0140] An add unit is used to add a callback for the subroutine set when it is determined that the subroutine set is not contained in the currently loaded application domain.

[0141] The second hooking unit is used to hook the relevant methods of script execution in the sub-program set through the target program set when the sub-program set is detected to be loaded through the callback, so as to obtain the target script content.

[0142] The hook unit, wherein the script execution methods include code block execution methods and code block compilation methods; the first hook unit 503 or the second hook unit is specifically used for:

[0143] Obtain the target version information of the PowerShell process;

[0144] When the target version information is the first version information, the execution method of the code block is hooked, and all first instructions in the code block are obtained based on the execution method of the code block, and all first instructions are determined as the target script content;

[0145] When the target version information is the second version information, the compilation method of the code block is hooked, and all the second instructions in the code block are obtained based on the compilation method of the code block. All the second instructions are determined as the target script content; the version corresponding to the second version information is higher than the version corresponding to the first version information.

[0146] Based on any of the above embodiments, the detection unit 504 is specifically used for:

[0147] The target script content is matched with instructions in a preset list to obtain a matching result; the preset list includes a blacklist instruction list and / or a sensitive instruction list, the blacklist instruction list stores at least one instruction that is prohibited from execution; the sensitive instruction list stores at least one instruction that needs to be verified.

[0148] Based on the matching results, it is determined whether the content of the target script is safe.

[0149] Based on any of the above embodiments, the detection unit 504 is specifically used for:

[0150] When it is determined that the target script content includes instructions from the blacklist instruction list and / or the sensitive instruction list, the matching result is determined to be a successful match.

[0151] If the target script content does not contain any instructions from the blacklist and / or the sensitive instruction list, the matching result is determined to be a matching failure.

[0152] Based on any of the above embodiments, the detection unit 504 is specifically used for:

[0153] If the matching result is a successful match, it is determined that the content of the target script is unsafe.

[0154] If the matching result is a failure, the target script content is determined to be safe.

[0155] Figure 6 This is a schematic diagram of the physical structure of the electronic device provided by the present invention, such as... Figure 6 As shown, the electronic device may include a processor 610, a communications interface 620, a memory 630, and a communication bus 640, wherein the processor 610, the communications interface 620, and the memory 630 communicate with each other via the communication bus 640. The processor 610 can call logical instructions in the memory 630 to execute the following methods:

[0156] Inject a target assembly into the current application domain of a PowerShell process; the target assembly is used for security checks; the current application domain includes all assemblies required for the PowerShell process to function normally.

[0157] The target assembly is used to determine whether the currently loaded application domain contains a subassembly related to script execution;

[0158] When it is determined that the currently loaded application domain contains the sub-program set, the relevant methods for script execution in the sub-program set are hooked through the target program set to obtain the target script content;

[0159] The target script content is subjected to security checks using the target program assembly.

[0160] Furthermore, the logical instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0161] On the other hand, the present invention also provides a computer program product, the computer program product comprising a computer program that can be stored on a non-transitory computer-readable storage medium, wherein when the computer program is executed by a processor, the computer is capable of executing the script security detection method provided by the above methods, the method comprising: injecting a target program assembly into the current application domain of a PowerShell process; the target program assembly being used for security detection; the current application domain including all program assemblies required for the PowerShell process to run normally;

[0162] The target assembly is used to determine whether the currently loaded application domain contains a subassembly related to script execution;

[0163] When it is determined that the currently loaded application domain contains the sub-program set, the relevant methods for script execution in the sub-program set are hooked through the target program set to obtain the target script content;

[0164] The target script content is subjected to security checks using the target program assembly.

[0165] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the script security detection method provided by the methods described above, the method comprising: injecting a target program assembly into the current application domain of a PowerShell process; the target program assembly being used for security detection; the current application domain including all program assemblies required for the PowerShell process to run normally;

[0166] The target assembly is used to determine whether the currently loaded application domain contains a subassembly related to script execution;

[0167] When it is determined that the currently loaded application domain contains the sub-program set, the relevant methods for script execution in the sub-program set are hooked through the target program set to obtain the target script content;

[0168] The target script content is subjected to security checks using the target program assembly.

[0169] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0170] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0171] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A script security detection method, characterized in that, include: Inject the target assembly into the current application domain of the PowerShell process; The target program assembly is used for security testing; The current application domain includes all assemblies required for the PowerShell process to run normally; The target assembly is used to determine whether the currently loaded application domain contains a subassembly related to script execution; When it is determined that the currently loaded application domain contains the sub-program set, the relevant methods for script execution in the sub-program set are hooked through the target program set to obtain the target script content; The target script content is subjected to security checks using the target assembly. The step of injecting the target assembly into the current application domain of the PowerShell process includes: The host object of the .NET runtime in the PowerShell process is obtained through the first DLL module, which is a module pre-injected into each process to determine the type of the process; The current application domain is obtained through the host object; The first DLL module injects the target assembly into the current application domain, initializes the target assembly, and passes target parameters to the target assembly. The target parameters are preset strings used to verify the legitimacy of the first DLL module.

2. The script security detection method according to claim 1, characterized in that, The step of determining whether the currently loaded application domain contains a subassembly related to script execution through the target assembly includes: When the target assembly is initialized, it is determined whether the currently loaded application domain contains subassemblies related to script execution.

3. The script security detection method according to claim 1, characterized in that, Before the step of reflectingly injecting the target assembly into the current application domain of the PowerShell process via the first DLL module, the method further includes: The first DLL module is used to obtain the list of modules loaded by the current process; the list of modules includes at least one second DLL module; the second DLL module is a module required for the current process to run normally; When the current process is determined to be the PowerShell process based on the at least one second DLL module, the target assembly is obtained through the first DLL module.

4. The script security detection method according to claim 1, characterized in that, The step of determining whether the currently loaded application domain contains a subassembly related to script execution through the target assembly includes: The target parameters are obtained through the target assembly, and it is determined whether the target parameters are valid. When the target parameter is determined to be valid through the target program assembly, it is determined whether the currently loaded application domain contains a subprogram assembly related to script execution.

5. The script security detection method according to claim 1, characterized in that, Before performing security checks on the target script content through the target assembly, the method further includes: If it is determined that the subset is not included in the currently loaded application domain, add a callback for the subset; When the sub-program set is detected to be loaded via the callback, the relevant methods for script execution in the sub-program set are hooked through the target program set to obtain the target script content.

6. The script security detection method according to claim 1, characterized in that, The methods related to script execution include methods for executing code blocks and methods for compiling code blocks; The method of hooking the execution of scripts in the sub-program set through the target program set to obtain the target script content includes: Obtain the target version information of the PowerShell process through the target assembly; When the target version information is the first version information, the execution method of the code block is hooked through the target program assembly, and all first instructions in the code block are obtained based on the execution method of the code block, and all first instructions are determined as the target script content; When the target version information is the second version information, the compilation method of the code block is hooked through the target program assembly, and all second instructions in the code block are obtained based on the compilation method of the code block. All second instructions are determined as the target script content; the version corresponding to the second version information is higher than the version corresponding to the first version information.

7. The script security detection method according to any one of claims 1-6, characterized in that, The security detection of the target script content through the target assembly includes: The target script content is matched with instructions in a preset list using the target program assembly to obtain a matching result; the preset list includes a blacklist instruction list and / or a sensitive instruction list, the blacklist instruction list stores at least one instruction that is prohibited from execution; the sensitive instruction list stores at least one instruction that needs to be verified. The target assembly determines whether the content of the target script is safe based on the matching results.

8. The script security detection method according to claim 7, characterized in that, The step of matching the target script content with instructions in a preset list through the target program assembly to obtain a matching result includes: When the target script content is determined to contain instructions from the blacklist instruction list and / or the sensitive instruction list through the target program assembly, the matching result is determined to be a successful match. When the target script content is determined to not contain any instructions from the blacklist instruction list and / or the sensitive instruction list through the target program assembly, the matching result is determined to be a matching failure.

9. The script security detection method according to claim 8, characterized in that, The step of determining whether the content of the target script is safe based on the matching result using the target assembly includes: When the matching result is a successful match, the target script content is determined to be unsafe through the target assembly. When the matching result is a failure, the safety of the target script content is determined through the target program assembly.

10. A script security detection device, characterized in that, include: The injection unit is used to inject a target assembly into the current application domain of a PowerShell process; The target program assembly is used for security testing; The current application domain includes all assemblies required for the PowerShell process to run normally; The first determining unit is used to determine whether the currently loaded application domain contains a subroutine set related to script execution; The first hooking unit is used to hook the relevant methods of script execution in the subprogram set when it is determined that the currently loaded application domain contains the subprogram set, so as to obtain the target script content; The detection unit is used to perform security detection on the target script content; The injection unit is specifically used for: The host object of the .NET runtime in the PowerShell process is obtained through the first DLL module, which is a module pre-injected into each process to determine the type of the process; The current application domain is obtained through the host object; The first DLL module injects the target assembly into the current application domain, initializes the target assembly, and passes target parameters to the target assembly. The target parameters are preset strings used to verify the legitimacy of the first DLL module.

11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the script security detection method as described in any one of claims 1 to 9.

12. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the script security detection method as described in any one of claims 1 to 9.

13. A computer program product having executable instructions stored thereon, characterized in that, When executed by the processor, this instruction causes the processor to implement the script security detection method as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Script identification method and device, equipment and storage medium

    CN113127868A