A malicious behavior detection method and device, electronic equipment and storage medium
Patent Information
- Application Number
- CN202211242232.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-11
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2042-10-11
AI Technical Summary
这种方法虽然可以检测出一定的恶意行为,但存在如下缺点:由于病毒跨家族检测能力差,针对不同的变种,需要提出不同的特征检测,对于新出现的病毒检测能力不一定,需要重新获得特征
[0026] This invention provides a method, apparatus, electronic device, and storage medium for detecting malicious behavior. By acquiring a software installer generated by an installer creation program, extracting a script describing the installation behavior from the installer, determining whether malicious behavior exists based on the script content, and outputting a prompt message based on the determination result, this invention can detect whether a software installer generated by an installer creation program exhibits malicious behavior, thereby reducing the risk of users being maliciously attacked. Furthermore, this invention eliminates the need for feature detection and the establishment of a feature library, effectively reducing storage space usage and detection time.
Smart Images

Figure CN115510444B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer security technology, and in particular to a method, apparatus, electronic device, and storage medium for detecting malicious behavior. Background Technology
[0002] Nullsoft Scriptable Install System (NSIS) is an installer creation program that provides functions such as installation, uninstallation, system settings, and file decompression. NSIS uses its scripting language to describe the behavior and logic of the installer. While NSIS's scripting language has a similar structure and syntax to typical programming languages, it is specifically designed for applications like installers. NSIS can perform operations such as modifying the computer registry and creating / modifying files by requesting system functions. It can also use compression algorithms to add necessary files to the installer package, which are then decompressed to a specific folder during user installation.
[0003] While NSIS reduces the time developers spend creating installers for their programs, it also facilitates the spread of malware. Because NSIS can perform various operations that affect computer systems, malware developers can exploit these operations to carry out numerous attacks. For example, they can compress and embed standalone malware into the installer, releasing and executing the malware during installation. Therefore, there is an urgent need for a method to detect malicious behavior in software installers generated by installer creation programs, reducing the risk of users being maliciously attacked.
[0004] Existing malicious behavior detection methods primarily rely on file feature analysis, specifically: determining if a file contains malicious behavior; if so, detecting the specific location and characteristics of the malicious behavior, such as specific strings (e.g., some virus files contain their virus name at the beginning of the file) or special function calls; and then using hash algorithms to generate identifiers for these features and specific regions, typically MD5, SHA1, or SHA256. For subsequent samples, a string of the same length is extracted from the same location to generate an identifier, which is compared with the sample's identifier. If they match, it indicates the presence of the same special string, suggesting a high probability that the new sample exhibits the same malicious behavior as the original sample. While this method can detect certain malicious behaviors, it suffers from the following drawbacks: poor cross-virus detection capability, requiring different feature detection methods for different variants, and inconsistent detection capability for newly emerging viruses necessitating the acquisition of new features; it also requires storage space to store the feature library, and the comparison strategy needs optimization when there are too many features, otherwise the detection process will be too time-consuming. Summary of the Invention
[0005] In view of this, embodiments of the present invention provide a method, apparatus, electronic device and storage medium for detecting malicious behavior, which can detect whether the software installer generated by the installer creation program has malicious behavior, thereby reducing the risk of users being maliciously attacked, and does not require feature detection and the establishment of a feature library, which can effectively reduce the storage space occupied and the detection time.
[0006] In a first aspect, embodiments of the present invention provide a method for detecting malicious behavior, the method comprising:
[0007] Obtain the software installer generated by the installer creation program;
[0008] Extract the script describing the installation behavior from the software installer;
[0009] Determine whether there is malicious behavior in the software installer based on the script content;
[0010] Output a prompt message based on the judgment result.
[0011] Preferably, the step of determining whether there is malicious behavior in the software installer based on the script content includes: determining whether there is behavior of using string copying and concatenation to construct URLs or executable file names; if so, then malicious behavior is determined to exist; and / or, determining whether there is behavior of setting the software installer to automatically close, silently install and release the executable program, and then delete the executable program after execution; if so, then malicious behavior is determined to exist; and / or, determining whether there is behavior of using variable names to replace part of the statement content in system call function statements; if so, then malicious behavior is determined to exist.
[0012] Preferably, obtaining the software installer generated by the installer creation program includes: obtaining a portable executable PE file; if the PE file includes a specific string corresponding to the installer creation program, then the PE file is determined to be a software installer generated by the installer creation program.
[0013] Preferably, the step of extracting the script describing the installation behavior from the software installer includes: using decompression software to extract the script describing the installation behavior from the software installer.
[0014] Preferably, the method further includes: if extracting the script describing the installation behavior from the software installer using decompression software fails, extracting the auxiliary content that does not conform to the PE file format and exists at the end of the PE file from the software installer, and decompressing the auxiliary content using the decompression software to obtain the script describing the installation behavior.
[0015] In a second aspect, embodiments of the present invention provide a malicious behavior detection device, the device comprising:
[0016] The acquisition unit is used to acquire the software installer generated by the installer creation program.
[0017] An extraction unit is used to extract scripts describing installation behavior from the software installer;
[0018] The judgment unit is used to determine whether there is malicious behavior in the software installer based on the script content;
[0019] The output unit is used to output prompt information based on the judgment result.
[0020] Preferably, the judgment unit is specifically used to: determine, based on the script, whether there is any behavior of using string copying and concatenation to construct a URL or executable file name; if so, determine that malicious behavior exists; and / or, based on the script, determine whether there is any behavior of setting the software installer to automatically close, silently install and release the executable program, and then delete the executable program after execution; if so, determine that malicious behavior exists; and / or, based on the script, determine whether there is any behavior of using variable names to replace part of the statement content in the system call function statement; if so, determine that malicious behavior exists.
[0021] Preferably, the acquisition unit is specifically used to: acquire a portable executable PE file; if the PE file includes a specific string corresponding to the installer creation program, then determine that the PE file is a software installer generated by the installer creation program.
[0022] Preferably, the extraction unit is specifically used to: extract a script describing the installation behavior from the software installer using decompression software.
[0023] Preferably, the extraction unit is further configured to: if extracting the script describing the installation behavior from the software installer using decompression software fails, extract the auxiliary content in the software installer that does not conform to the PE file format and exists at the end of the PE file, and decompress the auxiliary content using the decompression software to obtain the script describing the installation behavior.
[0024] In a third aspect, embodiments of the present invention provide an electronic device, the electronic device comprising: a housing, a processor, a memory, a circuit board, and a power supply circuit, wherein the circuit board is disposed within the space enclosed by the housing, and the processor and the memory are disposed on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, for executing the malicious behavior detection method described in the first aspect above.
[0025] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing one or more programs, which can be executed by one or more processors to implement the malicious behavior detection method described in the first aspect.
[0026] This invention provides a method, apparatus, electronic device, and storage medium for detecting malicious behavior. By acquiring a software installer generated by an installer creation program, extracting a script describing the installation behavior from the installer, determining whether malicious behavior exists based on the script content, and outputting a prompt message based on the determination result, this invention can detect whether a software installer generated by an installer creation program exhibits malicious behavior, thereby reducing the risk of users being maliciously attacked. Furthermore, this invention eliminates the need for feature detection and the establishment of a feature library, effectively reducing storage space usage and detection time. Attached Figure Description
[0027] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0028] Figure 1 A flowchart illustrating a malicious behavior detection method provided for an embodiment of the present invention;
[0029] Figure 2 A schematic diagram of the structure of a malicious behavior detection device provided for an embodiment of the present invention;
[0030] Figure 3 This is a schematic diagram of the structure of an embodiment of the electronic device of the present invention. Detailed Implementation
[0031] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0032] It should be understood that the described embodiments are merely some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0033] Figure 1 This is a flowchart illustrating a malicious behavior detection method provided as an embodiment of the present invention. This malicious behavior detection method can be applied to electronic devices.
[0034] like Figure 1 As shown, the malicious behavior detection method in this embodiment may include:
[0035] Step 101: Obtain the software installer generated by the installer creation program.
[0036] Specifically, the installer creation program can be NSIS.
[0037] Preferably, step 101 may specifically include: obtaining a portable executable PE file; if the PE file contains a specific string corresponding to the installer creation program, then the PE file is determined to be a software installer generated by the installer creation program.
[0038] Step 102: Extract the scripts describing the installation behavior from the software installer.
[0039] Specifically, this script can be an NSIS script.
[0040] Preferably, step 102 may specifically include: using decompression software to extract a script describing the installation behavior from the software installer; if extracting the script describing the installation behavior from the software installer using decompression software fails, extracting the auxiliary content in the software installer that does not conform to the PE file format and exists at the end of the PE file, and using decompression software to decompress the auxiliary content to obtain the script describing the installation behavior.
[0041] Step 103: Determine whether there is malicious behavior in the software installer based on the script content.
[0042] Preferably, step 103 may specifically include:
[0043] The script determines whether there is any behavior that uses string copying and concatenation to construct URLs or executable filenames; if so, malicious behavior is confirmed; and / or,
[0044] The script determines whether the software installer is configured to automatically close, silently install, release the executable program, and then delete the executable program after execution; if so, malicious behavior is confirmed; and / or,
[0045] The script is used to determine if variable names are used to replace parts of the statements in system call function statements; if so, malicious behavior is confirmed.
[0046] Step 104: Output a prompt message based on the judgment result.
[0047] The following specific examples illustrate the malicious behavior detection method provided by the embodiments of the present invention.
[0048] Download PE software from the internet and determine if the PE file is a software installer packaged by NSIS. Specifically, you can use string matching to determine this. Generally, software installers packaged by NSIS will contain phrases such as "Nullsoft.NSIS". Using these specific strings, you can determine whether the PE file is a software installer packaged by NSIS.
[0049] This method uses 7zip to extract NSIS scripts from software installers. 7zip is an open-source decompression and compression software. Because 7zip provides a command-line version, it allows programming languages to call command-line functions to compress software installers. 7zip also supports NSIS compression algorithms for decompression. Therefore, software installers packaged with NSIS are considered a type of compressed archive. However, some NSIS-packaged installers may have undergone additional processing, preventing direct decompression from yielding the NSIS script. Successful NSIS script extraction can be determined by checking the return value of the command-line function and whether the target folder is empty. If unsuccessful, the overlay portion of the installer (the content at the end of a PE file that doesn't conform to the PE file format) can be extracted and re-extracted. Overlay extraction relies on string matching; all NSIS-packaged installers have a specific string at the beginning of the overlay. Copying all content after this string into a new file extracts the overlay portion. Then, try decompressing the overlay portion to extract the NSIS script. If this still fails, exit and check the next file.
[0050] The main types of malicious behavior currently existing include:
[0051] Malicious Behavior 1: To evade detection, some samples utilize string concatenation and copying in NSIS scripts to concatenate URLs or executable filenames and store them in variables. This avoids detection tools directly detecting the corresponding URLs and processing the samples. To counter this behavior, we detect multiple consecutive copy-assignment statements, replacing variables with the corresponding strings, and checking if the final string conforms to the URL or executable filename format. Samples matching this format are identified as malicious.
[0052] Malicious Behavior 2: Within a section (i.e., the part of the NSIS script that describes optional components of the installer), the malicious sample sets the installer to automatically close upon completion, performs a silent installation, sets the file extraction path, extracts the included executable file, executes the executable file, and waits for its return result. After obtaining the execution result, i.e., after the executable file finishes execution, the installer deletes the executable file or the entire folder corresponding to the extraction path. This entire behavior constitutes malicious behavior; it is extremely rare for a legitimate sample to exploit the installer to extract, execute, and then delete the executable file.
[0053] Malicious Behavior 3: Utilizing statements calling system functions in the NSIS installer script language, combined with the privileges acquired by the installer during installation, malicious samples can perform malicious acts such as remote downloading and memory injection by calling system functions. To avoid statement-based detection, these samples use NSIS global variables to split and concatenate related command statements, rendering ordinary string-matching detection ineffective. However, NSIS installer script variables have distinct characteristics: all variables must begin with "$", and statements calling system functions must begin with "System::Call". Regular expression matching can detect this behavior. Normal function calls don't need to use this method. Except for some repetitive function calls, the NSIS compiler performs optimizations, replacing parts of two very similar functions with variables and using comparison jumps to reduce function call overhead. These special cases can also be excluded using regular expression matching.
[0054] For the three types of malicious behavior mentioned above, detecting just one is sufficient to determine the presence of malicious behavior in the software installer. Specifically, detection can be performed using regular expression matching, string matching, and other methods. The detailed implementation plan is as follows:
[0055] For malicious behavior 1, the copy statement is used to concatenate URLs or executable filenames in an NSIS script. The main detection method is to check for consecutive occurrences of statements starting with "StrCpy" after reading line by line, with three consecutive occurrences considered valid. For this statement block, two lists are used to store the target variable of the "StrCpy" statement and the value to be copied. The method to obtain the target variable and the value to be copied is based on the definition of the "StrCpy" statement in the NSIS script:
[0056] StrCpy user_var(destination)str[maxlen][start_offset]
[0057] According to the relevant definitions, the value to be copied, `str`, is truncated and stored in the `dst` list. The target variable is processed by separating statements by spaces and stored in the `src` list. Because processing is done line by line, the index values of the value to be copied and the target variable in their respective lists are consistent. Then, by traversing the `src` and `dst` lists, variable values in the statements are eliminated as much as possible, so that the final value corresponding to all target variables does not contain any variable. After processing, these values are compared using regular expressions to see if they conform to the URL format or contain the `.exe` suffix, thus determining whether there is any malicious concatenation behavior. If such behavior is detected, it is judged as malicious behavior.
[0058] For malicious behavior 2: During detection, the NSIS script is read line by line. If a statement starting with "ExecWait" exists between lines beginning with "Section" and "SectionEnd," that section of statements is examined. If statements starting with "SetOutPath," "File," "ExecWait," "Delete," and "RmDir" appear in a specified order, the parameters of the "ExecWait" statement are checked to see if the file released by "File" is included. This step relies on the processing of statements during the previous line-by-line reading. By splitting the entire line of statements using spaces and reading the operation commands and parameters according to the NSIS scripting language definition, the desired content can be obtained. If an executable file (i.e., a file ending in ".exe") is released to a specific folder by "File" in this statement, then executed by "ExecWait," and finally deleted as a single file by "Delete" or the entire folder by "RmDir," then suspicious behavior is identified. Furthermore, if the entire installation file is configured for silent installation and automatic shutdown through statements, then malicious behavior is identified.
[0059] Regarding malicious behavior 3: First, it's necessary to understand the parameters of NSIS's System statements. NSIS provides users with System-related statements designed to help them quickly call system-related functions to perform operations such as file creation. To facilitate calling system functions, NSIS provides different parameter formats:
[0060] System::Call Dll::Function
[0061] System::Call::Address
[0062] System::Call*Address
[0063] System::Call*
[0064] System::Call IPTR->IDX
[0065] System::Call <nothing>
[0066] System::Call PROC
[0067] The meaning of these parameters is not important; we only need to know where it is reasonable for variable names starting with "$" to appear. According to the official definition, variable names starting with "$" can appear in forms 2, 3, 5, and 7, while forms 4 and 6 contain only a symbol and nothing, respectively. Therefore, the key is to exclude all System::Call statements in forms 2, 3, 4, 5, 6, and 7. If variable names starting with "$" still exist in System::Call statements, then malicious behavior is suspected. The specific detection method uses regular expressions. Based on line-by-line reading, all lines starting with a System::Call statement are checked. Regular expressions are set according to the characteristics of forms 2-7. The specific expressions are shown in Table 1 for the regular expressions to be excluded.
[0068]
[0069]
[0070] Table 1 Regular expressions to be excluded
[0071] Regular expressions are used to exclude statements that need to be excluded. After excluding these rules, the regular expression r'\$[0-9]|\$R([0-9])|\$\_[0-9]+\_' is used to match variable names that meet the requirements. If these statements starting with System::Call are not excluded and related variable names still exist, it can be determined that there is malicious behavior.
[0072] If any one of the three malicious behaviors mentioned above is detected, it can be determined that there is malicious behavior in the software installer; otherwise, it can be determined that there is no malicious behavior in the software installer. Then, based on the determination result, the corresponding prompt information is output.
[0073] By utilizing the malicious behavior detection method provided in this embodiment of the invention, a software installer generated by an installer creation program is obtained. A script describing the installation behavior is extracted from the software installer. The presence of malicious behavior is determined based on the script content, and a prompt message is output according to the determination result. Based on this, the malicious behavior detection method provided in this embodiment of the invention can detect whether a software installer generated by an installer creation program exhibits malicious behavior, thereby reducing the risk of users being maliciously attacked. Furthermore, the malicious behavior detection method provided in this embodiment of the invention does not require feature detection or the establishment of a feature library, which can effectively reduce the storage space occupied and the detection time.
[0074] Figure 2 This is a schematic diagram of a malicious behavior detection device provided in an embodiment of the present invention. This device can be applied to electronic devices.
[0075] like Figure 2 As shown, the malicious behavior detection device in this embodiment may include:
[0076] Acquisition unit 201 is used to acquire the software installer generated by the installer creation program;
[0077] Extraction unit 202 is used to extract scripts describing installation behavior from the software installer;
[0078] Judgment unit 203 is used to determine whether there is malicious behavior in the software installer based on the script content;
[0079] Output unit 204 is used to output prompt information based on the judgment result.
[0080] Preferably, the judgment unit 203 is specifically used to: determine, based on the script, whether there is any behavior of using string copying and concatenation to construct a URL or executable file name; if so, determine that there is malicious behavior; and / or, based on the script, determine whether there is any behavior of setting the software installer to automatically close, silently install and release the executable program, and then delete the executable program after execution; if so, determine that there is malicious behavior; and / or, based on the script, determine whether there is any behavior of using variable names to replace part of the statement content in the system call function statement; if so, determine that there is malicious behavior.
[0081] Preferably, the acquisition unit 201 is specifically used to: acquire a portable executable PE file; if the PE file includes a specific string corresponding to the installer creation program, then determine that the PE file is a software installer generated by the installer creation program.
[0082] Preferably, the extraction unit 202 is specifically used to: extract a script describing the installation behavior from the software installer using decompression software.
[0083] Preferably, the extraction unit 202 is further configured to: if extracting the script describing the installation behavior from the software installer using decompression software fails, extract the auxiliary content in the software installer that does not conform to the PE file format and exists at the end of the PE file, and decompress the auxiliary content using the decompression software to obtain the script describing the installation behavior.
[0084] By utilizing the malicious behavior detection device provided in this embodiment of the invention, a software installer generated by an installer creation program is obtained. A script describing the installation behavior is extracted from the software installer, and the presence of malicious behavior is determined based on the script content. A prompt message is then output based on the determination result. Based on this, the malicious behavior detection device provided in this embodiment of the invention can detect whether a software installer generated by an installer creation program exhibits malicious behavior, thereby reducing the risk of users being maliciously attacked. Furthermore, the malicious behavior detection device provided in this embodiment of the invention does not require feature detection or the establishment of a feature database, which can effectively reduce the storage space occupied and the detection time.
[0085] This invention also provides an electronic device. Figure 3 This is a schematic diagram of the structure of an embodiment of the electronic device of the present invention, which can realize the present invention. Figure 1 The process of the illustrated embodiment is as follows: Figure 3 As shown, the above-mentioned electronic device may include: a housing 31, a processor 32, a memory 33, a circuit board 34, and a power supply circuit 35, wherein the circuit board 34 is disposed inside the space enclosed by the housing 31, and the processor 32 and the memory 33 are disposed on the circuit board 34; the power supply circuit 35 is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory 33 is used to store executable program code; the processor 32 runs a program corresponding to the executable program code by reading the executable program code stored in the memory 33, for executing the method described in any of the foregoing embodiments.
[0086] This electronic device exists in various forms, including but not limited to:
[0087] (1) Mobile communication devices: These devices are characterized by their mobile communication capabilities and primarily aim to provide voice and data communication. These terminals include: smartphones (e.g., iPhones), multimedia phones, feature phones, and low-end phones, etc.
[0088] (2) Ultra-mobile personal computer devices: These devices fall under the category of personal computers, possessing computing and processing capabilities, and generally also have mobile internet access features. These terminals include PDAs, MIDs, and UMPCs, such as the iPad.
[0089] (3) Portable entertainment devices: These devices can display and play multimedia content. This category includes: audio and video playback modules (e.g., iPod), handheld game consoles, e-book readers, as well as smart toys and portable car navigation devices.
[0090] (4) Server: A device that provides computing services. The components of a server include a processor, hard disk, memory, system bus, etc. Servers are similar to general computer architectures, but because they need to provide highly reliable services, they have higher requirements in terms of processing power, stability, reliability, security, scalability, and manageability.
[0091] (5) Other electronic devices with data interaction functions.
[0092] This invention provides a computer-readable storage medium storing one or more programs that can be executed by one or more processors to implement the methods described in any of the foregoing embodiments.
[0093] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0094] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the apparatus embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0095] For ease of description, the above apparatus is described by dividing it into various functional units / modules. Of course, in implementing this invention, the functions of each unit / module can be implemented in one or more software and / or hardware.
[0096] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.
[0097] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.< / nothing>
Claims
1. A method for detecting malicious behavior, characterized in that, The method includes: Obtain the software installer generated by the installer creation program; obtaining the software installer generated by the installer creation program includes: obtaining a portable executable PE file; if the PE file contains a specific string corresponding to the installer creation program, then the PE file is determined to be the software installer generated by the installer creation program; Extract the script describing the installation behavior from the software installer; The script content is used to determine whether the software installer contains malicious behavior. This determination includes: judging whether the script contains behavior that involves copying and concatenating URLs or executable filenames; if so, then malicious behavior is confirmed; and / or, judging whether the script contains behavior that allows the software installer to automatically close, silently install and then release the executable program, and then delete the executable program after execution; if so, then malicious behavior is confirmed; and / or, judging whether the script contains behavior that involves using variable names to replace parts of system call function statements; if so, then malicious behavior is confirmed. Output a prompt message based on the judgment result.
2. The method according to claim 1, characterized in that, The step of extracting the script used to describe the installation behavior from the software installer includes: Use decompression software to extract scripts describing the installation behavior from the software installer.
3. The method according to claim 2, characterized in that, The method further includes: If extracting the script describing the installation behavior from the software installer using decompression software fails, extract the auxiliary content that does not conform to the PE file format and exists at the end of the PE file from the software installer, and decompress the auxiliary content using the decompression software to obtain the script describing the installation behavior.
4. A malicious behavior detection device, characterized in that, The device includes: The acquisition unit is used to acquire the software installer generated by the installer creation program and to acquire the portable executable PE file; if the PE file includes a specific string corresponding to the installer creation program, then the PE file is determined to be the software installer generated by the installer creation program. An extraction unit is used to extract scripts describing installation behavior from the software installer; The judgment unit is used to determine whether there is malicious behavior in the software installer based on the script content, and whether there is behavior of using string copying and concatenation to construct URLs or executable file names; if so, it is determined that there is malicious behavior; and / or, based on the script, whether there is behavior of setting the software installer to automatically close, silently install and release the executable program, and then delete the executable program after execution; if so, it is determined that there is malicious behavior; and / or, based on the script, whether there is behavior of using variable names to replace part of the statement content in system call function statements; if so, it is determined that there is malicious behavior. The output unit is used to output prompt information based on the judgment result.
5. The apparatus according to claim 4, characterized in that, The extraction unit is specifically used for: Use decompression software to extract scripts describing the installation behavior from the software installer.
6. The apparatus according to claim 5, characterized in that, The extraction unit is further specifically used for: If extracting the script describing the installation behavior from the software installer using decompression software fails, extract the auxiliary content that does not conform to the PE file format and exists at the end of the PE file from the software installer, and decompress the auxiliary content using the decompression software to obtain the script describing the installation behavior.
7. An electronic device, characterized in that, The electronic device includes: a housing, a processor, a memory, a circuit board, and a power supply circuit, wherein the circuit board is disposed inside the space enclosed by the housing, and the processor and the memory are disposed on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, for executing the malicious behavior detection method according to any one of claims 1-3.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores one or more programs, which can be executed by one or more processors to implement the malicious behavior detection method according to any one of claims 1-3.
Citation Information
Patent Citations
Method and system for processing mobile phone rogue programs
CN103679016A
Malicious script detection method and device
CN110119618A
Malicious attack detection method and device, electronic equipment, and readable storage medium
CN113987496A