Privilege escalation behavior identification method and device, equipment, storage medium and program product

CN115906057BActive Publication Date: 2026-09-22QI AN XIN TECHNOLOGY GROUP INC +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211427757.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-15
Publication Date
2026-09-22
Estimated Expiration
2042-11-15

AI Technical Summary

Technical Problem

[0004]本申请实施例的目的在于提供一种提权行为识别方法、装置、设备、存储介质及程序产品,用以解决现有技术中通过内核令牌检测的方法无法有效识别提权行为的问题,以提高网络的安全性

Benefits of technology

[0008]本申请实施例通过在监测到目标系统资源的访问行为后,判断该访问行为的对象的先前模式是否被篡改,如果被篡改则确定该访问行为为提权行为,从而,可以更早地发现提权行为,避免了恶意程序绕过内核令牌的检查以达到访问系统资源的目的。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115906057B_ABST
    Figure CN115906057B_ABST
Patent Text Reader

Abstract

The application provides a method, device and equipment for identifying privilege escalation behavior, a storage medium and a program product. The method comprises the following steps: after monitoring an access behavior of a target system resource, a previous mode of an object corresponding to the access behavior is acquired; it is judged whether the previous mode is tampered with; if the previous mode is tampered with, it is determined that the access behavior is a privilege escalation behavior. According to the application, after monitoring the access behavior of the target system resource, it is judged whether the previous mode of the object of the access behavior is tampered with; if the previous mode is tampered with, it is determined that the access behavior is a privilege escalation behavior. Therefore, the privilege escalation behavior can be found earlier, and the malicious program can be prevented from bypassing the kernel token check to access the system resource.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and more specifically, to a method, apparatus, device, storage medium, and program product for identifying privilege escalation behavior. Background Technology

[0002] Due to inherent flaws and deficiencies in hardware, software, protocols, and security policies, information products and systems inevitably contain security vulnerabilities, which are a significant factor contributing to information system security threats. To mitigate losses from vulnerability exploitation, it is essential to identify privilege escalation attempts that exploit vulnerabilities before the system or software is attacked.

[0003] Current methods for preventing privilege escalation vulnerabilities involve detecting whether the kernel token of the current process has been modified. If the kernel token is modified, privilege escalation is considered to have occurred. However, some exploit techniques bypass this method to achieve unauthorized privilege escalation, rendering the aforementioned method ineffective against such attacks. Summary of the Invention

[0004] The purpose of this application is to provide a method, apparatus, device, storage medium, and program product for identifying privilege escalation behavior, so as to solve the problem that the existing method of kernel token detection cannot effectively identify privilege escalation behavior, thereby improving network security.

[0005] In a first aspect, embodiments of this application provide a method for identifying privilege escalation behavior, including:

[0006] After detecting access behavior to target system resources, obtain the previous pattern of the object corresponding to the access behavior;

[0007] Determine whether the previous mode has been tampered with. If the previous mode has been tampered with, then determine that the access behavior is a privilege escalation behavior.

[0008] This application embodiment determines whether the previous pattern of the object of the access behavior has been tampered with after monitoring the access behavior of the target system resources. If it has been tampered with, the access behavior is determined to be a privilege escalation behavior. Thus, privilege escalation behavior can be detected earlier, avoiding malicious programs from bypassing kernel token checks to achieve the purpose of accessing system resources.

[0009] In any embodiment, determining whether the previous pattern has been tampered with includes:

[0010] Obtain the handle address of the object, and determine whether the previous pattern has been tampered with based on whether the attributes of the handle address match the previous pattern.

[0011] This application embodiment uses the handle address and previous mode to determine whether the previous mode has been tampered with, thereby enabling earlier detection of unauthorized privilege escalation behavior and ensuring the security of electronic devices.

[0012] In any embodiment, determining whether the previous pattern has been tampered with based on whether the attributes of the handle address match the previous pattern includes:

[0013] If the attribute of the handle address is a user address and the previous mode is kernel mode, then whether the attribute of the handle address does not match the previous mode determines that the previous mode has been tampered with.

[0014] If the attribute of the handle address is a kernel address and the previous mode is the kernel mode, then whether the attribute of the handle address matches the previous mode determines that the previous mode has not been tampered with.

[0015] This application embodiment uses the handle address and previous mode to determine whether the previous mode has been tampered with, thereby enabling earlier detection of unauthorized privilege escalation behavior and ensuring the security of electronic devices.

[0016] In any embodiment, after determining that the access behavior is a privilege escalation behavior, the method further includes:

[0017] The access behavior is blocked.

[0018] In this embodiment of the application, when an access behavior is determined to be an illegal privilege escalation behavior, the access behavior will be blocked to ensure the security of electronic devices.

[0019] In any embodiment, the method further includes:

[0020] The target system resources are monitored through hook functions set at the target system resources.

[0021] This application embodiment utilizes hook functions to monitor whether target system resources are accessed, thereby enabling timely detection of malicious programs' illegal privilege escalation behavior.

[0022] In any embodiment, obtaining the previous pattern of the object corresponding to the access behavior includes:

[0023] The previous pattern is obtained from the thread kernel structure corresponding to the object.

[0024] In any embodiment, after obtaining the previous pattern of the object corresponding to the access behavior, the method further includes:

[0025] If the previous pattern has not been tampered with, subsequent access operations are allowed.

[0026] This application embodiment determines whether the previous pattern of the object of the access behavior has been tampered with after monitoring the access behavior of the target system resources. If it has been tampered with, the access behavior is determined to be a privilege escalation behavior. Thus, privilege escalation behavior can be detected earlier, avoiding malicious programs from bypassing kernel token checks to achieve the purpose of accessing system resources.

[0027] Secondly, embodiments of this application provide a privilege escalation behavior identification device, comprising:

[0028] The pattern acquisition module is used to acquire the previous pattern of the object corresponding to the access behavior after detecting the access behavior of the target system resources.

[0029] The behavior recognition module is used to determine whether the previous pattern has been tampered with. If the previous pattern has been tampered with, the access behavior is determined to be a privilege escalation behavior.

[0030] Thirdly, embodiments of this application provide an electronic device, including: a processor, a memory, and a bus, wherein,

[0031] The processor and the memory communicate with each other via the bus;

[0032] The memory stores program instructions that can be executed by the processor, and the processor can execute the method of the first aspect by calling the program instructions.

[0033] Fourthly, embodiments of this application provide a non-transitory computer-readable storage medium, comprising:

[0034] The non-transitory computer-readable storage medium stores computer instructions that cause the computer to perform the method of the first aspect.

[0035] Fifthly, embodiments of this application provide a computer program product, including a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions, which, when executed by a computer, enable the computer to perform the method described in the first aspect.

[0036] Other features and advantages of this application will be set forth in the following description and will be apparent in part from the description or may be learned by practicing embodiments of this application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description

[0037] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0038] Figure 1 A schematic diagram of the system call method flow provided for existing technologies;

[0039] Figure 2 A flowchart illustrating the existing method for accessing system resources by modifying the previous model;

[0040] Figure 3 This is a schematic flowchart of a privilege escalation behavior identification method provided in an embodiment of this application;

[0041] Figure 4 A schematic diagram of another privilege escalation behavior identification method provided in this application embodiment;

[0042] Figure 5 A schematic diagram of a privilege escalation behavior identification device provided in this application embodiment;

[0043] Figure 6 This is a schematic diagram of the physical structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0044] The embodiments of the technical solution of this application will now be described in detail with reference to the accompanying drawings. These embodiments are only used to more clearly illustrate the technical solution of this application and are therefore merely examples, and should not be used to limit the scope of protection of this application.

[0045] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the application; the terms “comprising” and “having”, and any variations thereof, in the specification, claims, and foregoing description of the drawings are intended to cover non-exclusive inclusion.

[0046] In the description of the embodiments of this application, technical terms such as "first" and "second" are used only to distinguish different objects and should not be construed as indicating or implying relative importance or implicitly specifying the number, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, "multiple" means two or more, unless otherwise explicitly defined.

[0047] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0048] In the description of the embodiments in this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.

[0049] In the description of the embodiments of this application, the term "multiple" refers to two or more (including two), similarly, "multiple sets" refers to two or more (including two sets), and "multiple pieces" refers to two or more (including two pieces).

[0050] In the description of the embodiments of this application, the technical terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "clockwise," "counterclockwise," "axial," "radial," and "circumferential" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing the embodiments of this application and simplifying the description, and are not intended to indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the embodiments of this application.

[0051] In the description of the embodiments of this application, unless otherwise expressly specified and limited, technical terms such as "installation," "connection," "joining," and "fixing" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. For those skilled in the art, the specific meaning of the above terms in the embodiments of this application can be understood according to the specific circumstances.

[0052] To facilitate understanding of this application, the following explanations of terms will be provided before introducing the solutions presented in this application:

[0053] Previous Mode: This indicates the source of the system call made by the current thread. If it's an application call, it's user mode; if it's a kernel driver call, it's kernel mode. It's stored in the current thread's kernel structure `_KTHREAD` and identified by `PreviousMode`. For example, if `PreviousMode` is 1, it means the current thread's previous mode is user mode; if it's 0, it means the current thread's previous mode is kernel mode. It should be noted that the values ​​of `PreviousMode` for user mode and kernel mode can also be other values, and this embodiment does not specifically limit this.

[0054] User Mode: Applications run in user mode. In user mode, access to system resources undergoes strict security checks, such as kernel token verification for user-mode access. It is identified using UserMode, with a value of 1.

[0055] Kernel mode: Core system components / drivers run in kernel mode, which grants full access to system resources. It is identified using the `KernelMode` flag, with a value of 0.

[0056] System calls: The collection of all system calls implemented by the operating system, also known as the Application Programming Interface (API), is the interface between applications and the system. The main function of the operating system is to manage hardware resources and provide a good environment for application developers to ensure better application compatibility. To achieve this, the kernel provides a series of multi-kernel functions with predefined functions, presented to the user through a set of interfaces called system calls. System calls pass the application's request to the kernel, invoke the corresponding kernel function to complete the required processing, and return the result to the application.

[0057] Handles are fundamental to Windows programming. A handle is a unique integer value, typically 4 bytes (8 bytes in 64-bit programs), used to identify different objects or instances of the same type within an application. Examples include windows, buttons, icons, scroll bars, output devices, controls, and files. Applications can access information about the corresponding object through the handle, but a handle is not a pointer; programs cannot directly read information from a file using a handle. A handle is useless if it's not used in I / O files. Windows uses a large number of handles to identify objects created or used in applications.

[0058] The system allocates a specific region in memory for each process to store handles, which are 32-bit unsigned integer values ​​(in a 32-bit operating system). This region is further divided into two parts: one part stores user-mode handles, and the other part stores kernel-mode handles. The value corresponding to the handle stored in this region is called the handle address.

[0059] Privilege escalation: Raising one's privileges on a server. This is mainly used during website intrusion. When intruding into a website, one can use various vulnerabilities to escalate webshell privileges in order to gain control of the server.

[0060] Hook function: A hook function is a piece of code used to handle system messages. It is used to capture an event at the system level when it is triggered, and then perform some operations.

[0061] Figure 1 A flowchart illustrating the system call method provided for existing technologies, such as Figure 1 As shown. Applications typically run in user mode. When an application needs to access system resources, it can use the user-mode interface ZwOpenProcess to call the system call interface (NtOpenProcess for example, the interface for opening a system process) to enter kernel mode. Similarly, if a kernel driver needs to access system resources, it can use the kernel-mode interface ZwOpenProcess to call the system call interface (NtOpenProcess for example, the interface for opening a system process) to enter kernel mode. The system call will determine the origin of the call based on the previous mode. If it originates from kernel mode, maximum privileges are granted, allowing the access to be processed normally; if it originates from user mode, the system call will perform a strict security check. If the check succeeds, it will be processed normally, i.e., the corresponding process will be opened; if the check fails, the process will be refused to be opened.

[0062] Through extensive research, the inventors of this application have discovered that existing malicious programs, in order to circumvent kernel token detection, change the current thread's previous mode from user mode to kernel mode. In this case, the system recognizes it as being in kernel mode, and system calls originating from user mode are no longer subject to system security mechanisms, meaning they will not undergo kernel token detection. This allows malicious programs to open critical system processes, inject DLLs, execute malicious code, or modify system files, thus enabling unauthorized privilege escalation. Figure 2 This is a flowchart illustrating the existing method for accessing system resources by modifying previous patterns, such as... Figure 2As shown. Taking opening a process as an example, the malicious program initially has a "previous mode" of user mode (1). By exploiting a system vulnerability, it changes the "previous mode" of its current thread to kernel mode (0) and opens a system process by calling NtOpenProcess through the system interface. Because the previous mode is kernel mode, it bypasses the system security mechanism, successfully opens the process, injects a DLL, and executes malicious code.

[0063] To address the aforementioned technical problems, the inventors of this application propose a method for identifying privilege escalation behavior. This method determines whether privilege escalation behavior has occurred by judging whether the previous mode of the object accessing the target system resource has been tampered with. Since if an application changes its previous mode from user mode to kernel mode before accessing system resources, the system will not perform further checks, thus bypassing the system security mechanism and achieving successful access to system resources.

[0064] The following details the scheme of this application:

[0065] Figure 3 This is a schematic flowchart of a privilege escalation behavior identification method provided in an embodiment of this application, as shown below. Figure 3 As shown, this method can be applied to electronic devices, including terminals and servers. Specifically, the terminal can be a smartphone, tablet, computer, personal digital assistant (PDA), etc.; the server can be an application server or a web server. The method includes:

[0066] Step 301: After detecting access behavior to the target system resources, obtain the previous pattern of the object corresponding to the access behavior.

[0067] In an operating system, states are divided into supervisor mode (kernel mode) and user mode. User programs run only in user mode and sometimes need to access core system functions, which is done through system call interfaces. Therefore, target system resources refer to those running within the core system functions, such as opening a process, creating or opening a system file, etc. In this application, the actions of using core system functions are collectively referred to as access actions to target system resources.

[0068] The object can be the initiator of the access behavior, for example, it can be a thread corresponding to a user program. When an electronic device detects an access behavior to a target system resource, it will intercept the access behavior before processing it. By obtaining the previous mode of the object corresponding to the access behavior, it can be understood that the previous mode can be obtained from the kernel structure of the object, and the previous mode can be either user mode or kernel mode.

[0069] Step 302: Determine whether the previous mode has been tampered with. If the previous mode has been tampered with, then determine that the access behavior is a privilege escalation behavior.

[0070] Understandably, the modification of the previous mode primarily involves changing the target's previous mode from user mode to kernel mode, and of course, it also includes changing the previous mode from kernel mode back to user mode. In practical applications, malicious programs often switch from user mode to kernel mode in order to gain greater privileges.

[0071] Once an electronic device determines that the previous mode has been tampered with, it considers the access behavior to be an escalation of privileges.

[0072] This application embodiment determines whether the previous pattern of the object of the access behavior has been tampered with after monitoring the access behavior of the target system resources. If it has been tampered with, the access behavior is determined to be a privilege escalation behavior. Thus, privilege escalation behavior can be detected earlier, avoiding malicious programs from bypassing kernel token checks to achieve the purpose of accessing system resources.

[0073] Based on the above embodiments, determining whether the previous pattern has been tampered with includes:

[0074] Obtain the handle address of the object, and determine whether the previous pattern has been tampered with based on whether the attributes of the handle address match the previous pattern.

[0075] In the specific implementation process, when an object accesses the target system resources, it will pass parameters when calling the system interface. Among these parameters are the handle address corresponding to the object, so the electronic device can obtain the handle address from the passed parameters.

[0076] The attribute of a handle address indicates whether it belongs to a user address or a kernel address. When the operating system allocates areas for storing handles, both the area for storing user-mode handles and the area for storing kernel-mode handles are contiguous blocks of space. For example, user-mode handles can be stored in addresses 1-50, and kernel-mode handles in addresses 51-100. If the handle address obtained by the electronic device is 40, it indicates that it belongs to user-mode, and the attribute of this handle address is user address. If the handle address obtained by the electronic device is 55, it indicates that it belongs to kernel-mode, and the attribute of this handle address is kernel address. Therefore, this handle address can, to some extent, reflect whether the object belongs to a kernel driver or an application; that is, if the handle address is a user address, then the object is an application; if the handle address is a kernel address, then the object is a kernel driver.

[0077] After obtaining the handle address, the electronic device can determine whether the previous mode has been tampered with based on whether the attributes of the handle address match the previous mode.

[0078] Understandably, whether a match is found refers to whether the attributes of the handle address and the previous mode belong to the same state, i.e., user mode or kernel mode.

[0079] The specific judgment method is as follows:

[0080] If the handle address attribute is a user address and the previous mode was kernel mode, then the handle address attribute does not match the previous mode, indicating that the previous mode has been tampered with.

[0081] If the handle address attribute is a kernel address and the previous mode was kernel mode, then the handle address attribute matches the previous mode, confirming that the previous mode has not been tampered with.

[0082] Another method to determine whether a previous pattern has been tampered with is as follows:

[0083] In the process callback function, it checks whether the current call originates from NtOpenProcess in user mode. If so, it checks the value of the PreviousMode field. If the value of the PreviousMode field is 0, it means that the previous mode was kernel mode and the previous mode has been tampered with. If the value of the PreviousMode field is 1, it means that the previous mode was user mode and the previous mode has not been tampered with.

[0084] Figure 4 A schematic diagram of another privilege escalation behavior identification method provided in this application embodiment is shown below. Figure 4 As shown, the method includes:

[0085] Step 401: Intercept system calls; the electronic device monitors whether the target system resources are being accessed, for example: whether there are threads calling the target system interface, which can be NtOpenProcess, etc.

[0086] Step 402: Determine if the handle address is a user address; the electronic device obtains the handle address and determines whether it is a user address or a kernel address based on the handle address. If it is a user address, it is considered that the object has the permission to access the target system resources, and step 403 is executed; if it is a kernel address, it means that the object belongs to the kernel driver and is considered to have the permission to access the target system resources, and the process ends.

[0087] Step 403: Determine if the previous mode was kernel mode; The electronic device determines whether the previous mode was kernel mode by obtaining the member variable PreviousMode from the kernel structure corresponding to the object. If the value of PreviousMode is 1, it indicates that the previous mode was user mode; if the value of PreviousMode is 0, it indicates that the previous mode was kernel mode. It is understood that the specific value of PreviousMode and the specific previous mode can be interchanged, and other values ​​can also be used. This application embodiment does not specifically limit this. If it is user mode, it means that the previous mode has not been tampered with, the privilege escalation behavior identification process ends, and the subsequent detection process continues; if the previous mode is kernel mode, it means that the handle address attribute does not match the previous mode, and it is determined that the access behavior of the object is illegal privilege escalation, that is, step 404 is executed.

[0088] Step 404: Determine that the access behavior constitutes an unauthorized privilege escalation.

[0089] This application embodiment uses the handle address and previous mode to determine whether the previous mode has been tampered with, thereby enabling earlier detection of unauthorized privilege escalation behavior and ensuring the security of electronic devices.

[0090] Based on the above embodiments, after determining that the access behavior is a privilege escalation behavior, the method further includes:

[0091] The access behavior is blocked.

[0092] In the specific implementation process, after the electronic device determines that the access behavior of the target is an escalation behavior, in order to ensure the security of the electronic device, the electronic device will block the access behavior, that is, it will not allow access to the target system resources.

[0093] Based on the above embodiments, the method further includes:

[0094] The target system resources are monitored through hook functions set at the target system resources.

[0095] In the specific implementation process, staff can set hook functions in advance at the target system resources to monitor whether the target system resources are accessed, thereby timely detecting the illegal privilege escalation behavior of malicious programs.

[0096] The names of hook functions are fixed, and they are automatically called when a system message is triggered. For example, React's componentWillUpdate function. Users only need to write the function body of componentWillUpdate, and the system will call componentWillUpdate when the component's state changes and needs to be updated.

[0097] Based on the above embodiments, after obtaining the previous pattern of the object corresponding to the access behavior, the method further includes:

[0098] If the previous pattern has not been tampered with, subsequent access operations are allowed.

[0099] In the specific implementation process, the following situations are considered where the previous mode has not been tampered with: (1) the handle address attribute is a user address and the previous mode is user mode; (2) the handle address attribute is a kernel address and the previous mode is kernel mode. For the above situations where the previous mode has not been tampered with, the electronic device allows subsequent access operations. The subsequent access operations differ depending on the previous mode. If the previous mode is user mode, the subsequent access operation involves further checks on the corresponding object, such as checking the object's token kernel to determine if it is a malicious program's access behavior. If the previous mode is kernel mode, the corresponding object is allowed to access the target system resources.

[0100] This application embodiment determines whether the previous pattern of the object of the access behavior has been tampered with after monitoring the access behavior of the target system resources. If it has been tampered with, the access behavior is determined to be a privilege escalation behavior. Thus, privilege escalation behavior can be detected earlier, avoiding malicious programs from bypassing kernel token checks to achieve the purpose of accessing system resources.

[0101] Figure 5 This is a schematic diagram of a privilege escalation behavior identification device provided in an embodiment of this application. The device can be a module, program segment, or code on an electronic device. It should be understood that this device is similar to the one described above. Figure 3 The method implementation corresponds to this and can be executed. Figure 3 The specific functions of the device involved in the method embodiments can be found in the description above; to avoid repetition, detailed descriptions are omitted here. The device includes: a pattern acquisition module 501 and a behavior recognition module 502; wherein:

[0102] The pattern acquisition module 501 is used to acquire the previous pattern of the object corresponding to the access behavior after detecting the access behavior of the target system resource;

[0103] The behavior recognition module 502 is used to determine whether the previous pattern has been tampered with. If the previous pattern has been tampered with, the access behavior is determined to be an escalation behavior.

[0104] Based on the above embodiments, the behavior recognition module 502 is specifically used for:

[0105] Obtain the handle address of the object, and determine whether the previous pattern has been tampered with based on whether the attributes of the handle address match the previous pattern.

[0106] Based on the above embodiments, the behavior recognition module 502 is specifically used for:

[0107] If the attribute of the handle address is a user address and the previous mode is kernel mode, then the attribute of the handle address does not match the previous mode, and it is determined that the previous mode has been tampered with.

[0108] If the attribute of the handle address is a kernel address and the previous mode is the kernel mode, then the attribute of the handle address matches the previous mode, and it is determined that the previous mode has not been tampered with.

[0109] Based on the above embodiments, the device further includes a blocking module for:

[0110] The access behavior is blocked.

[0111] Based on the above embodiments, the device further includes a monitoring module, used for:

[0112] The target system resources are monitored through hook functions set at the target system resources.

[0113] Based on the above embodiments, the pattern acquisition module 501 is specifically used for:

[0114] The previous pattern is obtained from the thread kernel structure corresponding to the object.

[0115] Based on the above embodiments, the device further includes a processing module for:

[0116] If the previous pattern has not been tampered with, subsequent access operations are allowed.

[0117] Figure 6 This is a schematic diagram of the physical structure of the electronic device provided in the embodiments of this application, such as... Figure 6 As shown, the electronic device includes: a processor 601, a memory 602, and a bus 603; wherein,

[0118] The processor 601 and the memory 602 communicate with each other through the bus 603;

[0119] The processor 601 is used to call program instructions in the memory 602 to execute the methods provided in the above method embodiments, such as: after detecting access behavior of target system resources, obtaining the previous mode of the object corresponding to the access behavior; determining whether the previous mode has been tampered with; if the previous mode has been tampered with, determining that the access behavior is a privilege escalation behavior.

[0120] Processor 601 can be an integrated circuit chip with signal processing capabilities. The processor 601 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor.

[0121] The memory 602 may include, but is not limited to, random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc.

[0122] This embodiment discloses a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the methods provided in the above-described method embodiments, such as: after detecting access behavior of a target system resource, obtaining the previous pattern of the object corresponding to the access behavior; determining whether the previous pattern has been tampered with; if the previous pattern has been tampered with, determining that the access behavior is a privilege escalation behavior.

[0123] This embodiment provides a non-transitory computer-readable storage medium storing computer instructions that cause the computer to execute the methods provided in the above-described method embodiments. For example, the instructions include: after detecting access behavior to target system resources, obtaining the previous mode of the object corresponding to the access behavior; determining whether the previous mode has been tampered with; and if the previous mode has been tampered with, determining that the access behavior is a privilege escalation behavior.

[0124] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.

[0125] Furthermore, the units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0126] Furthermore, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0127] In this document, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, without necessarily requiring or implying any such actual relationship or order between these entities or operations.

[0128] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for identifying privilege escalation behavior, characterized in that, include: After detecting access behavior to target system resources, obtain the previous pattern of the object corresponding to the access behavior; Determine whether the previous pattern has been tampered with; if the previous pattern has been tampered with, then determine that the access behavior is a privilege escalation behavior. The determination of whether the previous pattern has been tampered with includes: Obtain the handle address of the object, and determine whether the previous pattern has been tampered with based on whether the attributes of the handle address match the previous pattern; The step of determining whether the previous pattern has been tampered with based on whether the attributes of the handle address match the previous pattern includes: If the attribute of the handle address is a user address and the previous mode is kernel mode, then the attribute of the handle address does not match the previous mode, and it is determined that the previous mode has been tampered with. If the attribute of the handle address is a kernel address and the previous mode is the kernel mode, then the attribute of the handle address matches the previous mode, and it is determined that the previous mode has not been tampered with.

2. The method according to claim 1, characterized in that, The method further includes: The target system resources are monitored through hook functions set at the target system resources.

3. The method according to claim 1, characterized in that, The step of obtaining the previous pattern of the object corresponding to the access behavior includes: The previous pattern is obtained from the thread kernel structure corresponding to the object.

4. The method according to any one of claims 1-3, characterized in that, After determining that the access behavior is a privilege escalation behavior, the method further includes: The access behavior is blocked.

5. A privilege escalation behavior identification device, characterized in that, include: The pattern acquisition module is used to acquire the previous pattern of the object corresponding to the access behavior after detecting the access behavior of the target system resources. The behavior recognition module is used to determine whether the previous pattern has been tampered with. If the previous pattern has been tampered with, the access behavior is determined to be an escalation behavior. The behavior recognition module is specifically used for: Obtain the handle address of the object, and determine whether the previous pattern has been tampered with based on whether the attributes of the handle address match the previous pattern; The step of determining whether the previous pattern has been tampered with based on whether the attributes of the handle address match the previous pattern includes: If the attribute of the handle address is a user address and the previous mode is kernel mode, then the attribute of the handle address does not match the previous mode, and it is determined that the previous mode has been tampered with. If the attribute of the handle address is a kernel address and the previous mode is the kernel mode, then the attribute of the handle address matches the previous mode, and it is determined that the previous mode has not been tampered with.

6. An electronic device, characterized in that, include: Processor, memory, and bus, among which, The processor and the memory communicate with each other via the bus; The memory stores program instructions that can be executed by the processor, and the processor can execute the method as described in any one of claims 1-4 by calling the program instructions.

7. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions that, when executed by a computer, cause the computer to perform the method as described in any one of claims 1-4.

8. A computer program product, characterized in that, The method includes a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer, enable the computer to perform the method as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Method and device for detecting privilege lifting vulnerability, equipment and medium

    CN113378182A

  • Application program detection method and device, electronic equipment and storage medium

    CN114238948A