A Method for Obtaining the Executable File Type under Linux

By obtaining the basic attribute information of the executable file under the Linux system and matching the binary content feature value string, the problem of difficulty in accurately identifying the executable file type in the prior art is solved, and the file type is accurately identified and filtered, which improves the threat discovery ability of the system security software.

CN115390908BActive Publication Date: 2025-07-08SHANGHAI INST OF PROCESS AUTOMATION & INSTR
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211119060.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-13
Publication Date
2025-07-08
Estimated Expiration
2042-09-13

AI Technical Summary

Technical Problem

It is difficult for the prior art to accurately obtain the executable file types under Linux systems, which affects the screening and discovery of threat files by system security products.

Method used

By obtaining the basic attribute information of the target file, preprocessing it, the file content is read in binary mode, and using the feature binary value string and the file name feature string to judge the file type, including ELF, so dynamic library, jar, python, shell, and compressed package.

Benefits of technology

It realizes accurate identification of executable file types, helps system security software to discover and handle threat files more timely and accurately, narrows the scope of attention, and improves system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115390908B_ABST
    Figure CN115390908B_ABST
Patent Text Reader

Abstract

The present invention provides a method for obtaining the type of an executable file under Linux, which relates to the technical field of Linux system applications. The method includes: obtaining the basic attribute information of a target file and preprocessing the file; reading the content of the file in binary mode and matching the characteristic binary value string of the file with a preset characteristic value; selectively performing file name matching, binary file content matching, and text content matching according to the characteristic value matching result; and finally, selectively performing file name suffix matching according to the text content matching result. By comprehensively judging the type of the executable file from multiple dimensions such as the basic attribute information of the file, the characteristic value of the binary content of the file, the characteristic value of the readable string content of the file, and the characteristic value of the file name suffix, the type to which the executable file under Linux belongs can be accurately obtained, which further helps the effective implementation of functions such as the running blocking control of the executable file by the system security software.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of Linux system applications, and particularly relates to a method for obtaining the type of an executable file under Linux. Background Art

[0002] There are many existing security products for Linux systems that need to promptly discover and handle threatening executable files within the system. Accurately obtaining the type of an executable file can effectively screen threatening file programs, narrow the scope of files of concern, and facilitate more timely and accurate discovery of threatening files. However, it is difficult to accurately obtain the type of an executable file with existing technologies.

[0003] Therefore, it is necessary to propose a method for obtaining the type of an executable file under Linux to accurately obtain the type of an executable file and provide effective screening for the risk behaviors of executable files existing in system security. Summary of the Invention

[0004] The purpose of the present invention is to provide, in view of the deficiencies of the above-mentioned existing technologies, a method for obtaining the type of an executable file under Linux to solve the problem of accurately obtaining the type of an executable file under Linux.

[0005] To achieve the above purpose, the technical solution adopted by the present invention is as follows:

[0006] The present invention provides a method for obtaining the type of an executable file under Linux, which is used to obtain the type to which the executable file belongs. The method includes:

[0007] a) Obtain the basic attribute information of the target file, and preprocess the target file according to the basic attribute information to form a preprocessed file. The basic attribute information includes the size attribute information of the target file;

[0008] b) Read the content of the preprocessed file in binary mode. The size of the read file is greater than or equal to 4 bytes and less than or equal to 48 bytes. Match the characteristic binary value string of the read file with the characteristic value "\x7f\x45\x4c\x46". If the match is successful, proceed to step c). Otherwise, match the characteristic binary value string of the read file with the characteristic value "\x50\x4b\x03\x04". If the match is successful, proceed to step d). Otherwise, match the values at the 2nd and 3rd byte positions of the characteristic binary value string of the read file with the characteristic value "\x0d\0a". If the match is successful, the type of the read file is the pyc file type of python. Otherwise, proceed to step e);

[0009] c) If the file name of the read file contains the feature string ".so", the type of the read file is the so dynamic library file type under linux; otherwise, the type of the read file is the executable file ELF type;

[0010] d) If the binary file content of the read file contains the feature value "\x4d\x45\x54\x41\x2d\x49\x4e\x46", the type of the read file is the java jar file type; otherwise, the type of the read file is the compressed package file type;

[0011] e) If the text content of the read file contains " / bin / sh" or " / bin / bash", the type of the read file is the shell file type; otherwise, proceed to step f);

[0012] f) If the file name suffix of the read file successfully matches ".sh", the type of the read file is the shell file type; otherwise, match the file name suffix of the read file with ".py" or "pyc". If the file name suffix of the read file successfully matches ".py" or "pyc", the type of the read file is the python file type; otherwise, the type of the read file is the non-executable file type.

[0013] Optionally, in step a), preprocess the target file, including: filtering out files in the target file with a file size less than 4 bytes to filter out files with no readable attributes, and the filtered files are non-executable files.

[0014] Optionally, in step b), when matching the feature binary value string of the read file with the feature value "\x7f\x45\x4c\x46", use the values at the 0th to 3rd byte positions of the feature binary value string of the read file to match with the feature value "\x7f\x45\x4c\x46".

[0015] Optionally, in step b), when matching the feature binary value string of the read file with the feature value "\x50\x4b\x03\x04", use the values at the 0th to 3rd byte positions of the feature binary value string of the read file to match with the feature value "\x50\x4b\x03\x04".

[0016] The beneficial effects of the present invention include:

[0017] The method for obtaining the type of an executable file under Linux provided by the present invention includes: a) obtaining the basic attribute information of the target file, and preprocessing the target file according to the basic attribute information to form a preprocessed file, where the basic attribute information includes the size attribute information of the target file; b) reading the content of the preprocessed file in binary mode, where the size of the read file is greater than or equal to 4 bytes and less than or equal to 48 bytes, and matching the characteristic binary value string of the read file with the characteristic value "\x7f\x45\x4c\x46". If the match is successful, step c) is performed; otherwise, the characteristic binary value string of the read file is further matched with the characteristic value "\x50\x4b\x03\x04". If the match is successful, step d) is performed; otherwise, the values at the 2nd and 3rd byte positions of the characteristic binary value string of the read file are matched with the characteristic value "\x0d\0a". If the match is successful, the type of the read file is the pyc file type of python; otherwise, step e) is performed; c) if the file name of the read file contains the characteristic string ".so", the type of the read file is the so dynamic library file type under linux; otherwise, the type of the read file is the executable file ELF type; d) if the binary file content of the read file contains the characteristic value "\x4d\x45\x54\x41\x2d\x49\x4e\x46", the type of the read file is the jar file type of java; otherwise, the type of the read file is the compressed package file type; e) if the text content of the read file contains " / bin / sh" or " / bin / bash", the type of the read file is the shell file type; otherwise, step f) is performed; f) if the file name suffix of the read file matches successfully with ".sh", the type of the read file is the shell file type; otherwise, the file name suffix of the read file is matched with ".py" or "pyc". If the file name suffix of the read file matches successfully with ".py" or "pyc", the type of the read file is the python file type; otherwise, the type of the read file is the non-executable file type. By comprehensively judging the type of the executable file from multiple dimensions such as the basic attribute information of the file, the characteristic value of the file binary content, the characteristic value of the file readable string content, and the file name suffix characteristic value, the type of the executable file under Linux can be accurately obtained, which helps to effectively implement functions such as the running block control of the executable file by the system security software. Description of the Drawings

[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0019] Figure 1 The flowchart of the method for obtaining the type of an executable file under Linux proposed in the embodiments of the present invention is shown. Detailed implementation manners

[0020] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0021] There are many existing security products for Linux systems that need to timely detect and process executable files that pose threats in the system. Accurately obtaining the type of an executable file can effectively screen out threatening file programs, narrow the scope of files to be concerned about, and facilitate more timely and accurate detection of threatening files. The present invention accurately obtains the type of an executable file by analyzing the file content, and provides effective screening for the risk behaviors of executable files existing in system security.

[0022] Figure 1 The flowchart of the method for obtaining the type of an executable file under Linux proposed in the embodiments of the present invention is shown. As Figure 1 shown, the present invention proposes a method for obtaining the type of an executable file under Linux, and this method is used to obtain the type to which the executable file belongs.

[0023] This method includes:

[0024] a) Obtain the basic attribute information of the target file, and according to the basic attribute information, preprocess the target file to form a preprocessed file. The basic attribute information includes the size attribute information of the target file;

[0025] b) Read the content of the preprocessed file in binary format. The size of the read file is greater than or equal to 4 bytes and less than or equal to 48 bytes. Match the characteristic binary value string of the read file with the characteristic value "\x7f\x45\x4c\x46". If the match is successful, proceed to step c). Otherwise, match the characteristic binary value string of the read file with the characteristic value "\x50\x4b\x03\x04". If the match is successful, proceed to step d). Otherwise, match the values at the 2nd and 3rd byte positions of the characteristic binary value string of the read file with the characteristic value "\x0d\0a". If the match is successful, the type of the read file is the pyc file type of python. Otherwise, proceed to step e);

[0026] c) If the file name of the read file contains the characteristic string ".so", the type of the read file is the so dynamic library file type under linux. Otherwise, the type of the read file is the executable file ELF type;

[0027] d) If the binary file content of the read file contains the characteristic value "\x4d\x45\x54\x41\x2d\x49\x4e\x46", the type of the read file is the jar file type of java. Otherwise, the type of the read file is the compressed package file type;

[0028] e) If the text content of the read file contains " / bin / sh" or " / bin / bash", the type of the read file is the shell file type. Otherwise, proceed to step f);

[0029] f) If the file name suffix of the read file matches successfully with ".sh", the type of the read file is the shell file type. Otherwise, match the file name suffix of the read file with ".py" or "pyc". If the file name suffix of the read file matches successfully with ".py" or "pyc", the type of the read file is the python file type. Otherwise, the type of the read file is the non-executable file type.

[0030] Optionally, in step a), preprocess the target file, including: filtering out files with a file size less than 4 bytes in the target file to filter out files without readable attributes. The filtered files are non-executable files.

[0031] Optionally, in step b), when matching the characteristic binary value string of the read file with the characteristic value "\x7f\x45\x4c\x46", the values at the 0th to 3rd byte positions of the characteristic binary value string of the read file are used for the matching with the characteristic value "\x7f\x45\x4c\x46".

[0032] Optionally, in step b), when matching the characteristic binary value string of the read file with the characteristic value "\x50\x4b\x03\x04", the values at the 0th to 3rd byte positions of the characteristic binary value string of the read file are used for the matching with the characteristic value "\x50\x4b\x03\x04".

[0033] The core idea of the present invention for differentiating file types: The binary content and attributes of a file are the basis for determining what kind of executable file the file is. The file name characteristics and readable content strings are auxiliary evidence for the specific file type result. By obtaining the basic attribute information of the target file and preprocessing the file; reading the content of the file in binary mode and matching the characteristic binary value string of the file with a preset characteristic value; according to the characteristic value matching result, selectively performing file name matching, binary file content matching, and text content matching; finally, according to the text content matching result, selectively performing file name suffix matching. The present invention can accurately obtain the type of the executable file under Linux by comprehensively judging the type of the executable file from multiple dimensions such as the file basic attribute information, the file binary content characteristic value, the file readable string content characteristic value, and the file name suffix characteristic value, and further helps the effective implementation of functions such as running blocking control of the executable file by the system security software.

[0034] The above embodiments are only used to illustrate the technical concept and characteristics of the present invention, and their purpose is to enable those of ordinary skill in the art to understand the content of the present invention and implement it. It cannot be used to limit the protection scope of the present invention. Any equivalent changes or modifications made according to the spirit and essence of the present invention should be covered within the protection scope of the present invention.

Claims

1. A method for obtaining the type of an executable file under Linux, characterized in that, The method is used to obtain the type to which an executable file belongs, and the method includes: a) Obtain the basic attribute information of the target file, and according to the basic attribute information, preprocess the target file to form a preprocessed file, where the basic attribute information includes the size attribute information of the target file; b) Read the content of the preprocessed file in binary mode. The size of the read file is greater than or equal to 4 bytes and less than or equal to 48 bytes. Match the characteristic binary value string of the read file with the characteristic value "\x7f\x45\x4c\x46". If the match is successful, proceed to step c). Otherwise, match the characteristic binary value string of the read file with the characteristic value "\x50\x4b\x03\x04" again. If the match is successful, proceed to step d). Otherwise, match the values at the 2nd and 3rd byte positions of the characteristic binary value string of the read file with the characteristic value "\x0d\0a". If the match is successful, the type of the read file is the pyc file type of python. Otherwise, proceed to step e); c) If the file name of the read file contains the characteristic string ".so", the type of the read file is the so dynamic library file type under linux. Otherwise, the type of the read file is the executable file ELF type; d) If the binary file content of the read file contains the characteristic value "\x4d\x45\x54\x41\x2d\x49\x4e\x46", the type of the read file is the jar file type of java. Otherwise, the type of the read file is the compressed package file type; e) If the text content of the read file contains " / bin / sh" or " / bin / bash", the type of the read file is the shell file type. Otherwise, proceed to step f); f) If the file name suffix of the read file matches successfully with ".sh", the type of the read file is the shell file type. Otherwise, match the file name suffix of the read file with ".py" or "pyc". If the file name suffix of the read file matches successfully with ".py" or "pyc", the type of the read file is the python file type. Otherwise, the type of the read file is the non-executable file type.

2. The method for obtaining the executable file type under Linux according to claim 1, wherein In step a), preprocessing the target file includes: filtering out files in the target file with a file size less than 4 bytes to filter out files without readable attributes, and the filtered files are non-executable files.

3. The method for obtaining the executable file type under Linux according to claim 1, characterized in that, In step b), when matching the characteristic binary value string of the read file with the characteristic value "\x7f\x45\x4c\x46", use the values at the 0th to 3rd byte positions of the characteristic binary value string of the read file to match with the characteristic value "\x7f\x45\x4c\x46".

4. The method for obtaining the executable file type under Linux according to claim 1, characterized in that, In step b), when matching the binary value string of the features of the read file with the feature value "\x50\x4b\x03\x04", the values at the 0th to 3rd byte positions of the binary value string of the features of the read file are used for the matching with the feature value "\x50\x4b\x03\x04".

Citation Information

Patent Citations

  • Attack feature extraction method

    CN112437084A

  • Malicious script detection method and device, equipment and storage medium

    CN113051565A