Detection Method, Device, Storage Medium and Electronic Device for Target Malware
By obtaining the memory address and processor architecture information of the target operating system's system call interface and combining with the training model to identify the system call interface that has been attacked by rootkit, the problem of low rootkit detection accuracy is solved and effective detection of unknown rootkits is achieved.
Patent Information
- Application Number
- CN202211666495.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-23
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-12-23
AI Technical Summary
In the prior art, the detection results of rootkit detection are relatively low and it is impossible to effectively detect unknown rootkit attacks.
By obtaining the memory address of the kernel support function corresponding to each system call interface in the target operating system, and based on the target processor architecture type, the number of system call interfaces and the memory address, the training classification model determines the target category identification and target identification, and identify the system call interface that has been attacked by the target malware.
Improves detection accuracy of target malware, enables detection of at least some unknown rootkit attacks, and enhances the reliability of detection results.
Smart Images

Figure CN115935353B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and particularly to a method, apparatus, storage medium, and electronic device for detecting a target malware. Background Art
[0002] A rootkit is a special malware that enables an attacker to access an electronic device as an administrator. Usually, a rootkit works in kernel mode and can perform attack behaviors such as modifying kernel data and hiding itself and related programs.
[0003] Currently, detecting whether an operating system has been attacked by a rootkit is generally achieved through security protection software in the operating system. There are various rootkits. When the security protection software detects a rootkit, it detects the operating system based on a number of known rootkits stored in the database corresponding to the security protection software. If the data in the operating system is the same as any of the known rootkits, it can be determined that the operating system has been attacked by a rootkit.
[0004] However, since a rootkit will be updated according to the attacker's intention and attack conditions, etc., and the known rootkits in the database corresponding to the security protection software cannot be updated in real time completely synchronously with the update of the rootkit. Therefore, when an operating system is attacked by some unknown rootkits, after the security protection software detects the operating system, the operating system will be determined as an operating system not attacked by a rootkit, and thus the accuracy of the detection result for detecting a rootkit is relatively low. Summary of the Invention
[0005] In view of the above technical problem of relatively low accuracy of the detection result for detecting a rootkit, the technical solution adopted by the present invention is as follows:
[0006] According to one aspect of the present disclosure, there is provided a method for detecting a target malware, including:
[0007] Obtaining the memory address of the kernel support function corresponding to each system call interface in the target operating system.
[0008] Determining a target category identifier from a first category identifier and a second category identifier according to the target processor architecture type, the number of system call interfaces, and a number of memory addresses, and determining a target identifier from the system call interface identifiers corresponding to a number of system call interfaces and a preset identifier.
[0009] The type of the target processor architecture is the type of the processor architecture corresponding to the target operating system; the first category identifier is used to indicate that the target operating system has been attacked by the target malware, and the second category identifier is used to indicate that the target operating system has not been attacked by the target malware; if the target category identifier is the first category identifier, the target identifier is the system call interface identifier of the system call interface that has been attacked by the target malware, and if the target category identifier is the second category identifier, the target identifier is a preset identifier, and the preset identifier is used to indicate that each system call interface has not been attacked by the target malware.
[0010] According to another aspect of the present disclosure, there is also provided a detection device for target malware, including:
[0011] An acquisition module, configured to acquire the memory addresses of the kernel support functions corresponding to each system call interface in the target operating system.
[0012] A determination module, configured to determine a target category identifier from the first category identifier and the second category identifier according to the type of the target processor architecture, the number of system call interfaces, and a plurality of memory addresses, and determine a target identifier from the system call interface identifiers corresponding to the plurality of system call interfaces and a preset identifier, where the preset identifier is used to indicate that each system call interface has not been attacked by the target malware.
[0013] The type of the target processor architecture is the type of the processor architecture corresponding to the target operating system; the first category identifier is used to indicate that the target operating system has been attacked by the target malware, and the second category identifier is used to indicate that the target operating system has not been attacked by the target malware; if the target category identifier is the first category identifier, the target identifier is the system call interface identifier of the system call interface that has been attacked by the target malware, and if the target category identifier is the second category identifier, the target identifier is a preset identifier, and the preset identifier is used to indicate that each system call interface has not been attacked by the target malware.
[0014] According to another aspect of the present disclosure, there is also provided a non-transitory computer-readable storage medium, in which at least one instruction or at least one program segment is stored, and the at least one instruction or at least one program segment is loaded and executed by a processor to implement the above-mentioned detection method for target malware.
[0015] According to another aspect of the present disclosure, there is also provided an electronic device, including a processor and the above-mentioned non-transitory computer-readable storage medium.
[0016] The technical solutions provided by the embodiments of the present disclosure may include the following beneficial effects:
[0017] In the present disclosure, based on the target processor architecture type corresponding to the target operating system, the number of system call interfaces, and the memory address of each system call interface, a target category identifier and a target identifier can be determined. Among them, it is possible to determine whether the target operating system has been attacked by the target malware according to the target category identifier. If it is determined that the target operating system has been attacked by the target malware, it is also possible to determine the system call interface in the target operating system that has been attacked by the target malware according to the target identifier. In the related art, it is determined whether the target operating system has been attacked by the target malware by determining whether there is data in the target operating system that is the same as the known target malware. Furthermore, the detection of the target malware in the present disclosure takes into account the processor architecture type of the target operating system, the number of system call interfaces, and the memory address of each system call interface. Compared with the detection of the target malware in the related art that only considers the known target malware, in the present disclosure, for at least some unknown target malware, if it has attacked any system call interface in the target operating system and the kernel support function corresponding to the system call interface has been loaded and run in the running memory, it can basically be determined that the system call interface has been attacked by the target malware. That is, the present disclosure can detect the attack of at least some unknown target malware on the target operating system. Therefore, the accuracy of the detection result for detecting the target malware can be improved.
[0018] It should be understood that the above general description and the following detailed description are only exemplary and do not limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings. Here, the drawings are incorporated into the specification and constitute a part of this specification, showing the embodiments that conform to the present invention, and are used together with the specification to explain the principles of the present invention.
[0020] Figure 1 It is a flowchart of a method for detecting target malware shown according to an exemplary embodiment.
[0021] Figure 2 It is a schematic block diagram of a device for detecting target malware shown according to an exemplary embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present invention.
[0023] The embodiment of the present invention provides a method for detecting a target malware. Among them, this method can be completed by any one of the following or any combination thereof: a terminal, a server, and other devices with processing capabilities. The embodiments of the present invention do not make any limitations in this regard.
[0024] Next, reference will be made to Figure 1 the flowchart of the method for detecting a target malware shown in the figure to introduce the method for detecting a target malware.
[0025] This method includes the following steps:
[0026] S100, obtain the memory address of the kernel support function corresponding to each system call interface in the target operating system.
[0027] Specifically, the target operating system can be a Windows system or a Linux system, etc. The embodiments of the present disclosure do not make any limitations in this regard. The memory address of the kernel support function is the address of the kernel support function in the running memory of the electronic device where the target operating system is located.
[0028] A specific implementation manner of step S100 can be as follows: If the target operating system is a Windows system, the SSDT (System Services Descriptor Table) corresponding to the target operating system can be obtained, and this table can be traversed to obtain the memory address of the kernel support function corresponding to each system call interface in the target operating system. Among them, the SSDT can specifically adopt KeServiceDescriptorTable. The embodiments of the present disclosure do not make any limitations in this regard. In addition, if the target operating system is a Windows x64 system, the memory address of each kernel support function can also be obtained by finding the string offset of the kernel support function corresponding to each system call interface in the target operating system and summing them up.
[0029] Another specific implementation manner of step S100 can be as follows: If the target operating system is a Linux system, the sys_call_table corresponding to the target operating system can be obtained, and this table can be traversed to obtain the memory address of the kernel support function corresponding to each system call interface in the target operating system.
[0030] The above-mentioned method for obtaining the SSDT or sys_call_table can be achieved by executing a driver within the target operating system or by obtaining and parsing the physical memory from the target operating system. Specifically, the physical memory can be obtained by reading the computer's physical memory through the PCI Express bus, or by reading the physical memory through the IEEE 1394 interface, or by reading the physical memory in the form of software that loads a kernel module. Among them, the specific implementation method of reading the physical memory in the form of software that loads a kernel module can be: reading the physical memory based on software such as Lime on the Linux system or reading the physical memory based on tools such as dumpit on the Windows system. After obtaining the physical memory, the volatility tool is used to obtain the memory address of each kernel support function or the memory address corresponding to the system data structure corresponding to each kernel support function, and then parsing is performed to obtain the memory address of the kernel support function corresponding to each system call interface in the target operating system.
[0031] S200, determine the target category identifier from the first category identifier and the second category identifier according to the target processor architecture type, the number of system call interfaces, and several memory addresses, and determine the target identifier from the system call interface identifiers corresponding to several system call interfaces and the preset identifier.
[0032] Among them, the target processor architecture type is the type of the processor architecture corresponding to the target operating system; the first category identifier is used to indicate that the target operating system has been attacked by the target malware, and the second category identifier is used to indicate that the target operating system has not been attacked by the target malware; if the target category identifier is the first category identifier, the target identifier is the system call interface identifier of the system call interface that has been attacked by the target malware, and if the target category identifier is the second category identifier, the target identifier is the preset identifier, and the preset identifier is used to indicate that each system call interface has not been attacked by the target malware.
[0033] Specifically, the target malware is rootkit. Each kernel support function runs based on the processor architecture corresponding to the target operating system, and the processor architecture corresponding to the target operating system can be X86 architecture, ARM architecture, RISC-V architecture, MIPS architecture, etc. The target processor architecture type is a preset type of the processor architecture corresponding to the target operating system. For example, if the processor architecture corresponding to the target operating system is ARM architecture, the target processor architecture type is 1; if the processor architecture corresponding to the target operating system is X86 architecture, the target processor architecture type is 2, etc. The first category identifier and the second category identifier are different, and the preset identifier is different from the system call interface identifier corresponding to each system call interface. The system call interface identifier is the name and / or number of the corresponding system call interface, and the system call interface identifier can also be obtained by traversing the above SSDT or sys_call_table.
[0034] If the target category identifier is the first category identifier, the target identifier can be one or more, and each target identifier is the system call interface identifier of the system call interface that has been attacked by the target malware.
[0035] It can be seen from this that in the present disclosure, according to the target processor architecture type corresponding to the target operating system, the number of system call interfaces, and the memory address of each system call interface, the target category identifier and the target identifier can be determined. Among them, it can be determined whether the target operating system has been attacked by the target malware according to the target category identifier. If it is determined that the target operating system has been
[0036] attacked by the target malware, the system call interface that has been attacked by the target malware in the target operating system can also be determined according to the target identifier. In the related art, it is determined whether the target operating system has been attacked by the target malware by determining whether there is data in the target operating system that is the same as the known target malware. Furthermore, the detection of the target malware in the present disclosure takes into account the processor architecture type of the target operating system, the number of system call interfaces, and the memory address of each system call interface. Compared with the detection of the target malware in the related art that only considers the known target malware, in the present disclosure
[0037] for at least some unknown target malware, if it has attacked any system call interface in the target operating system, and the kernel support function corresponding to this system call interface has been loaded and run in the running memory, it can basically be determined that this system call interface has been attacked by the target malware, that is, the present disclosure can detect the attack of at least some unknown target malware on the target operating system. Therefore, the accuracy of the detection result for detecting the target malware can be improved.
[0038] Optionally, the above step S200 includes the following steps:
[0039] S210. Obtain the trained classification model.
[0040] 0S220. Input the target processor architecture type, the number of system call interfaces, and several memory addresses into the trained classification model.
[0041] S230. Obtain the target class identifier and the target identifier output by the trained classification model.
[0042] A specific implementation manner of the above step S210 may be as follows: Several training samples may be obtained based on several target malware and several operating systems. Specifically, any target malware may be installed in any operating system, and then the target malware may be run based on a processor architecture corresponding to the operating system, so that the target malware attacks a system call interface of the operating system. At this time, the processor architecture type of the processor architecture, the number of system call interfaces of the operating system, the memory address corresponding to each system call interface, the first class identifier, and the system call interface identifier of the attacked system call interface may be obtained as a training sample. It is also possible to randomly run the operating system corresponding to a processor architecture of any operating system without installing the target malware, and obtain the processor architecture type of the processor architecture, the number of system call interfaces of the operating system, the memory address corresponding to each system call interface, the second class identifier, and the preset identifier as a training sample.
[0043] After obtaining several training samples, the several training samples may be randomly divided, so that a part of the training samples among the several training samples are used as a training set, and the other part of the training samples are used as a test set. Then, the initial classification model is trained based on the training set and the test set until the model converges, and the trained classification model is obtained. Among them, the initial classification model may be a model using a neural network algorithm such as BP (BackPropagation), and the specific model adopted by the initial classification model in the embodiments of the present invention is not limited.
[0044] Exemplarily, when obtaining training samples, windows systems with different kernel versions may be used, and then after turning off the self-protection behavior in the windows system, rootkits that attack the SSDT table may be installed to obtain several training samples based on the windows system that has been attacked by the rootkit. It is also possible to obtain several training samples based on windows systems with different kernel versions and without installing rootkits.
[0045] When obtaining training samples, Linux systems with different kernel versions can also be used. Then, after disabling the self-protection behavior in the Linux system, install a rootkit that attacks the sys_call_table table to obtain several training samples based on the Linux system that has been attacked by the rootkit. Several training samples can also be obtained based on Linux systems with different kernel versions and without installing the rootkit. In addition, the random build method (such as using makerandconfig) is used for collection. In any case where a random configuration can be started, restart multiple times, and a training sample can be obtained after each startup.
[0046] The above operating system can be the operating system of an electronic device or the operating system of a virtual machine. Among them, for the operating system of the virtual machine, training samples can be obtained based on qemu. The operating system can be a Windows system with an ARM architecture or an X86 architecture, or a Linux system with an X86 architecture, an ARM architecture, a RISC-V architecture, or a MIPS architecture.
[0047] It can be seen that in the present disclosure, it is determined whether the target operating system has been attacked by the target malware through the trained classification model. Since the trained classification model is trained with data of operating systems attacked by the target malware and data of operating systems not attacked by the target malware, the trained classification model can relatively accurately master the data characteristics of operating systems attacked by the target malware and the data characteristics of operating systems not attacked by the target malware. Therefore, the present disclosure can further improve the accuracy of the detection result for detecting the target malware.
[0048] Optionally, the above step S220 includes the following steps:
[0049] S221, if the number of memory addresses is greater than the preset number, delete at least some of the memory addresses among the several memory addresses to obtain the processed memory addresses with the preset number.
[0050] S222, obtain an input vector according to the target processor architecture type, the number of system call interfaces, and the preset number of processed memory addresses.
[0051] S223, input the input vector into the trained classification model.
[0052] Specifically, the value range of the preset number can be from 100 to 1000. Preferably, the preset number is 512.
[0053] A specific implementation manner of step S222 may be as follows. The target processor architecture type, the number of system call interfaces, and a preset number of processed memory addresses are sequentially used as elements in the input vector to obtain the input vector. For example, if the target processor architecture type is 1, the number of system call interfaces is 512, and the preset number of processed memory addresses are 0x00000100, 0x00000101,..., 0x00000300 respectively, then the input vector is (1, 512, 0x00000100, 0x00000101,..., 0x00000300).
[0054] Optionally, before step S222, the above step S220 further includes the following steps:
[0055] S224, if the number of memory addresses is less than the preset number, then several memory addresses and at least one preset memory address with a value of 0 are used as the processed memory addresses to obtain the preset number of processed memory addresses.
[0056] For example, if the preset number is 512, and the number of system call interfaces of any Windows XP is 284, then the memory addresses of the kernel support functions corresponding to the 284 system call interfaces of this Windows XP and 228 preset memory addresses with a value of 0 are used as 512 processed memory addresses. If the number of system call interfaces of any Windows 7 is 401, then the memory addresses of the kernel support functions corresponding to the 401 system call interfaces of this Windows XP and 111 preset memory addresses with a value of 0 are used as 512 processed memory addresses. If the number of system call interfaces of any Linux 5.15 is 449, then the memory addresses of the kernel support functions corresponding to the 449 system call interfaces of this Linux 5.15 and 63 preset memory addresses with a value of 0 are used as 512 processed memory addresses.
[0057] Optionally, before step S222, the above step S220 further includes the following steps:
[0058] S225, if the number of memory addresses is equal to the preset number, then several memory addresses are used as the processed memory addresses to obtain the preset number of processed memory addresses.
[0059] Optionally, the system call interface that has been attacked by the target malware is the system call interface whose corresponding executable file has been tampered with by the target malware; the executable file corresponding to the system call interface is stored in the storage memory of the electronic device where the target operating system is located, and the kernel support function corresponding to the system call interface is obtained by loading the executable file corresponding to the system call interface into the running memory of the electronic device.
[0060] Based on this, when obtaining training samples, attacking a system call interface of an operating system with a target malware can be used to control the tampering of an executable file corresponding to a system call interface of an operating system by the target malware.
[0061] Optionally, after step S200, the method further includes the following steps:
[0062] S300, if the target category identifier is the first category identifier, determine whether the tampered executable file corresponding to the target identifier has been hidden;
[0063] S400, if the tampered executable file corresponding to the target identifier has not been hidden, display the memory address and / or the target identifier of the kernel support function corresponding to the target identifier, and the name, base address, offset address, data length of the file content data, and / or file path of the tampered executable file corresponding to the target identifier.
[0064] A specific implementation manner of the above step S300 can be as follows: When the target category identifier is the first category identifier, it indicates that at least one system call interface of the target operating system has been attacked by the target malware. At this time, the obtained target identifier is the system call interface identifier of the system call interface that has been attacked by the target malware. Therefore, when the target category identifier is the first category identifier, the system call table corresponding to the target operating system can be obtained from a preset database according to the target operating system, and then based on the memory address of the kernel support function corresponding to the target identifier, it is determined whether there is data information of the tampered executable file corresponding to the target identifier in the system call table. Among them, the system call table can be a system call API (Application Programming Interface) list.
[0065] A specific implementation manner of the above step S400 can be as follows: If the tampered executable file corresponding to the target identifier has not been hidden by the target malware, there is data information of the tampered executable file corresponding to the target identifier in the system call table. At this time, the name, base address, offset address, data length of the file content data, and / or file path of the tampered executable file corresponding to the target identifier are obtained, and the memory address and / or the target identifier of the kernel support function corresponding to the target identifier, and the name, base address, offset address, data length of the file content data, and / or file path of the tampered executable file corresponding to the target identifier are displayed.
[0066] It can be seen from this that after detecting that the target operating system has been attacked by the target malware, if the tampered executable file corresponding to the target identifier is not hidden, the name, base address, offset address, data length of the file content data, and / or file path of the tampered executable file corresponding to the target identifier can be obtained and displayed to display more information about the target malware, facilitating subsequent repair of the target operating system that has been attacked by the target malware.
[0067] After S300, the method further includes the following steps:
[0068] S500, if the tampered executable file corresponding to the target identifier has been hidden, display the memory address of the kernel support function corresponding to the target identifier and / or the target identifier.
[0069] If the tampered executable file corresponding to the target identifier has been hidden by the target malware, there is no data information of the tampered executable file corresponding to the target identifier in the system call table. At this time, the memory address of the kernel support function corresponding to the target identifier and / or the target identifier can be displayed.
[0070] Optionally, before displaying the memory address of the kernel support function corresponding to the target identifier and / or the target identifier, the memory address of the kernel support function corresponding to each system call interface other than the system call interface corresponding to the target identifier can also be displayed. So that the displayed data is richer, facilitating subsequent repair of the target operating system that has been attacked by the target malware.
[0071] Optionally, if the tampered executable file corresponding to the target identifier has been hidden, prompt whether to re-detect.
[0072] Furthermore, detection processing can also be used to detect the target malware, and the detection processing includes the following steps:
[0073] S600, regard the kernel support function corresponding to each system call interface in the target operating system as the target kernel support function.
[0074] Among them, the target kernel support function is stored in the operating memory of the electronic device where the target operating system is located.
[0075] S700, obtain the file path of the executable file corresponding to each target kernel support function.
[0076] Among them, the executable file is stored in the storage memory of the electronic device where the target operating system is located; the target kernel support function is obtained by loading its corresponding executable file into the operating memory of the electronic device.
[0077] For S800, if any file path does not meet the preset similarity condition with the kernel storage path, then determine the target operating system as the operating system that has been attacked by the target malware.
[0078] Among them, the kernel storage path is the storage path of the kernel corresponding to the target operating system in the storage memory of the above-mentioned electronic device.
[0079] Specifically, for an operating system that has not been attacked by the target malware, the file path of the executable file corresponding to each target kernel support function is the same as the kernel storage path. Based on this:
[0080] A specific implementation manner of the above step S800 can be as follows: If any file path is different from the kernel storage path, it means that the executable file corresponding to this file path has been tampered with by the target malware. At this time, the target operating system can be determined as the operating system that has been attacked by the target malware.
[0081] Another specific implementation manner of the above step S800 can be as follows: If the first x - level paths of any file path are different from the first x - level paths of the kernel storage path, it means that the executable file corresponding to this file path has been tampered with by the target malware. At this time, the target operating system can be determined as the operating system that has been attacked by the target malware, where x is a preset number.
[0082] Among them, the kernel storage path is the storage path of the kernel of the target operating system in the storage memory of the electronic device.
[0083] It can be seen from this that in the present disclosure, by determining whether the file path of the executable file corresponding to each kernel support function of the target operating system satisfies a preset similarity condition with the kernel storage path, it is determined whether the target operating system has been attacked by the target malware. If any file path does not conform to the preset similarity condition with the kernel storage path, the target operating system is determined to be an operating system that has been attacked by the target malware. In the related art, it is detected by security protection software whether the operating system has been attacked by the target malware and the detection result is displayed. If the target malware tampers with the detection method or detection result of the security protection software, the accuracy of the detection result for detecting the target malware is relatively low. Compared with the related art, in the present disclosure, if the target malware successfully attacks the target operating system, the target malware has tampered with the executable files corresponding to at least one target kernel support function. At this time, by determining whether the file path of the executable file corresponding to each target kernel support function is the same as the kernel storage path, it can be determined that the target operating system has been attacked by the target malware. Furthermore, in the present disclosure, there is no need to resist the tampering of the executable files by the target malware, that is, even when the target malware has tampered with the executable files, it can still be detected that the target operating system has been attacked by the target malware, which can improve the accuracy of the detection result for detecting the target malware.
[0084] Optionally, the above step S700 includes the following steps:
[0085] S710, obtain the memory address of each target kernel support function.
[0086] S720, obtain the file path of the executable file corresponding to each memory address in the corresponding executable file, so as to obtain the file path of the executable file corresponding to each target kernel support function.
[0087] A specific implementation manner of the above step S720 may be as follows: The registered module location list corresponding to the target operating system can be obtained, and then the file path of the executable file corresponding to each memory address can be found in the module location list, so as to obtain the file path of the executable file corresponding to each target kernel support function. Among them, for the Linux system, the registered module location list preferably avoids using the module linked list modules and preferably uses the mod_find binary tree. The module location list can be a system call list.
[0088] Optionally, before step S700, the detection process further includes the following steps:
[0089] S900, determine whether the executable file corresponding to each target kernel support function has been hidden.
[0090] Based on this, step S700 may include the following steps:
[0091] S730. If the executable files corresponding to each target kernel support function are not hidden, obtain the file paths of the executable files corresponding to each target kernel support function.
[0092] A specific implementation manner of step S900 may be as follows: Obtain the registered module location list corresponding to the target operating system, and determine the file paths of the executable files that can be found for each memory address in the module location list. If so, it means that the executable files corresponding to each target kernel support function are not hidden. Otherwise, it means that the executable files corresponding to at least one target kernel support function have been hidden.
[0093] A specific implementation manner of step S730 may be as follows: If the executable files corresponding to each target kernel support function are not hidden, steps S710 and S720 may be executed.
[0094] Optionally, after step S700, the detection process further includes the following steps:
[0095] S1000. If any file path does not meet the preset similarity condition with the kernel storage path, regard the executable files corresponding to each file path that does not meet the preset similarity condition with the kernel storage path as target executable files.
[0096] S1100. Display the memory addresses of the target kernel support functions corresponding to each target executable file, and / or the system call interface identifiers corresponding to each target executable file, as well as the names, base addresses, offset addresses, data lengths of the file content data, and / or file paths of each target executable file; the system call interface identifier is the name and / or system call interface number of the corresponding system call interface.
[0097] In addition, the system call interface identifiers corresponding to each file path that meets the preset similarity condition with the kernel storage path may also be displayed, so as to make the displayed data more abundant and facilitate the subsequent repair of the target operating system that has been attacked by the target malware.
[0098] A specific implementation of the above step S1000 may be as follows: If any file path does not meet the preset similarity condition with the kernel storage path, the system call table of the target operating system can be obtained, and based on this system call table, the name, base address, offset address, data length of the file content data, and / or file path of each target executable file can be obtained, and the memory address of the target kernel support function corresponding to each target executable file, and / or the system call interface identifier corresponding to each target executable file, as well as the name, base address, offset address, data length of the file content data, and / or file path of the tampered executable file corresponding to the target identifier are displayed.
[0099] It can be seen from this that if it is detected that the target operating system has been attacked by the target malware through the fact that any file path does not meet the preset similarity condition with the kernel storage path, the name, base address, offset address, data length of the file content data, and / or file path of the target executable file can be obtained and displayed to display more information about the target malware, facilitating subsequent repair of the target operating system that has been attacked by the target malware.
[0100] Optionally, step S700 may further include the following steps:
[0101] S740, if the executable file corresponding to any target kernel support function has been hidden, determine the target operating system as the operating system attacked by the target malware.
[0102] It can be seen from this that if the executable file corresponding to any target kernel support function has been hidden, it means that the executable files corresponding to at least one target kernel support function have basically been hidden by the target malware. At this time, it can be directly determined that the target operating system is the operating system attacked by the target malware.
[0103] Optionally, after step S700, the detection process further includes the following steps:
[0104] S1200, if the executable file corresponding to any target kernel support function has been hidden, display the memory address of each target kernel support function whose corresponding executable file has been hidden, and / or the system call interface identifier corresponding to each target kernel support function whose corresponding executable file has been hidden.
[0105] In addition, the system call interface identifier corresponding to each target kernel support function that has not been hidden can also be displayed to make the displayed data more abundant, facilitating subsequent repair of the target operating system that has been attacked by the target malware.
[0106] Optionally, after step S700, the detection process further includes the following steps:
[0107] S1300. If each file path and the kernel storage path meet the preset similarity conditions, the target operating system is determined to be an operating system not attacked by the target malware.
[0108] Optionally, before any memory address and / or system call interface identifier, the memory addresses of the kernel support functions corresponding to each system call interface other than the system call interface corresponding to the target identifier can also be displayed. So that the displayed data can be more abundant and facilitate subsequent repair of the target operating system attacked by the target malware.
[0109] Optionally, if the executable file corresponding to any target kernel support function has been hidden, prompt whether to re-detect.
[0110] An embodiment of the present invention also provides a detection device for target malware, and this device is used to implement the above-mentioned detection method for target malware. Refer to Figure 2 As shown in the schematic block diagram of the detection device for target malware, the detection device 1400 for target malware includes: an acquisition module 1401 and a determination module 1402.
[0111] The acquisition module 1401 is used to acquire the memory addresses of the kernel support functions corresponding to each system call interface in the target operating system.
[0112] The determination module 1402 is used to determine the target category identifier from the first category identifier and the second category identifier according to the target processor architecture type, the number of system call interfaces, and several memory addresses, and determine the target identifier from the system call interface identifiers corresponding to several system call interfaces and the preset identifier.
[0113] The target processor architecture type is the type of the processor architecture corresponding to the target operating system; the first category identifier is used to indicate that the target operating system has been attacked by the target malware, and the second category identifier is used to indicate that the target operating system has not been attacked by the target malware; if the target category identifier is the first category identifier, the target identifier is the system call interface identifier of the system call interface that has been attacked by the target malware, and if the target category identifier is the second category identifier, the target identifier is the preset identifier, and the preset identifier is used to indicate that each system call interface has not been attacked by the target malware.
[0114] Optionally, the determination module 1402 is further used for:
[0115] Obtain the trained classification model;
[0116] Input the target processor architecture type, the number of system call interfaces, and several memory addresses into the trained classification model;
[0117] Obtain the target category identifier and the target identifier output by the trained classification model.
[0118] Optionally, the determination module 1402 is further configured to:
[0119] If the number of memory addresses is greater than the preset number, delete at least some of the memory addresses among the several memory addresses to obtain the processed memory addresses with the preset number;
[0120] Obtain an input vector according to the target processor architecture type, the number of system call interfaces, and the preset number of processed memory addresses;
[0121] Input the input vector into the trained classification model.
[0122] Optionally, the determination module 1402 is further configured to: if the number of memory addresses is less than the preset number, use several memory addresses and at least one preset memory address with a value of 0 as the processed memory addresses to obtain the processed memory addresses with the preset number.
[0123] Optionally, the system call interface that has been attacked by the target malware is the system call interface corresponding to the executable file that has been tampered with by the target malware; the executable file corresponding to the system call interface is stored in the storage memory of the electronic device where the target operating system is located, and the kernel support function corresponding to the system call interface is obtained by loading the executable file corresponding to the system call interface into the running memory of the electronic device.
[0124] Optionally, the device further includes a hiding module, configured to:
[0125] If the target category identifier is the first category identifier, determine whether the tampered executable file corresponding to the target identifier has been hidden;
[0126] If the tampered executable file corresponding to the target identifier has not been hidden, display the memory address of the kernel support function corresponding to the target identifier and / or the target identifier, and the name, base address, offset address, data length of the file content data, and / or file path of the tampered executable file corresponding to the target identifier.
[0127] Optionally, the hiding module is further configured to:
[0128] If the tampered executable file corresponding to the target identifier has been hidden, display the memory address of the kernel support function corresponding to the target identifier and / or the target identifier.
[0129] An embodiment of the present invention further provides a non-transitory computer-readable storage medium, which can be disposed in an electronic device to store at least one instruction or at least one segment of a program related to a method in the method embodiment. The at least one instruction or the at least one segment of the program is loaded and executed by the processor to implement the method provided in the foregoing embodiment.
[0130] An embodiment of the present invention further provides an electronic device, including a processor and the foregoing non-transitory computer-readable storage medium.
[0131] Although some specific embodiments of the present invention have been described in detail by way of examples, those skilled in the art should understand that the above examples are for illustrative purposes only and not for limiting the scope of the present invention. Those skilled in the art should also understand that various modifications can be made to the embodiments without departing from the scope and spirit of the present invention. The scope of the present invention is defined by the appended claims.
Claims
1. A detection method for a target malware, characterized in that, The method includes: Obtaining the memory addresses of the kernel support functions corresponding to each system call interface in the target operating system; Determining a target category identifier from a first category identifier and a second category identifier, and determining a target identifier from the system call interface identifiers corresponding to a plurality of the system call interfaces and a preset identifier according to the target processor architecture type, the number of the system call interfaces, and a plurality of the memory addresses; The target processor architecture type is the type of the processor architecture corresponding to the target operating system; the first category identifier is used to indicate that the target operating system has been attacked by a target malware, and the second category identifier is used to indicate that the target operating system has not been attacked by the target malware; if the target category identifier is the first category identifier, the target identifier is the system call interface identifier of the system call interface that has been attacked by the target malware, and if the target category identifier is the second category identifier, the target identifier is the preset identifier, and the preset identifier is used to indicate that each of the system call interfaces has not been attacked by the target malware; The system call interface that has been attacked by the target malware is the system call interface whose corresponding executable file has been tampered with by the target malware; the executable file corresponding to the system call interface is stored in the storage memory of the electronic device where the target operating system is located, and the kernel support function corresponding to the system call interface is obtained by loading the executable file corresponding to the system call interface into the running memory of the electronic device; If the target category identifier is the first category identifier, determining whether the tampered executable file corresponding to the target identifier has been hidden; If the tampered executable file corresponding to the target identifier has not been hidden, displaying the memory address of the kernel support function corresponding to the target identifier and / or the target identifier, and the name, base address, offset address, data length of the file content data, and / or file path of the tampered executable file corresponding to the target identifier; If the tampered executable file corresponding to the target identifier has been hidden, displaying the memory address of the kernel support function corresponding to the target identifier and / or the target identifier.
2. The method according to claim 1, characterized in that, The determining a target category identifier from a first category identifier and a second category identifier, and determining a target identifier from the system call interface identifiers corresponding to a plurality of the system call interfaces and a preset identifier according to the target processor architecture type, the number of the system call interfaces, and a plurality of the memory addresses includes: Obtaining a trained classification model; Inputting the target processor architecture type, the number of the system call interfaces, and a plurality of the memory addresses into the trained classification model; Obtaining the target category identifier and the target identifier output by the trained classification model.
3. The method according to claim 2, wherein The inputting the target processor architecture type, the number of the system call interfaces, and a plurality of the memory addresses into the trained classification model includes: If the number of the memory addresses is greater than a preset number, at least some of the memory addresses among the several memory addresses are deleted to obtain a preset number of processed memory addresses; An input vector is obtained according to the target processor architecture type, the number of the system call interfaces, and the preset number of processed memory addresses; The input vector is input into the trained classification model.
4. The method according to claim 3, wherein Before obtaining the input vector according to the target processor architecture type, the number of the system call interfaces, and the preset number of processed memory addresses, inputting the target processor architecture type, the number of the system call interfaces, and several of the memory addresses into the trained classification model further includes: If the number of the memory addresses is less than the preset number, several of the memory addresses and at least one preset memory address with a value of 0 are used as the processed memory addresses to obtain a preset number of processed memory addresses.
5. A detection device for a target malware, characterized in that, The device includes: An obtaining module, configured to obtain memory addresses of kernel support functions corresponding to each system call interface in a target operating system; A determining module, configured to determine a target category identifier from a first category identifier and a second category identifier according to the target processor architecture type, the number of the system call interfaces, and several of the memory addresses, and determine a target identifier from system call interface identifiers corresponding to the several system call interfaces and a preset identifier; The target processor architecture type is the type of the processor architecture corresponding to the target operating system; the first category identifier is used to indicate that the target operating system has been attacked by a target malware, and the second category identifier is used to indicate that the target operating system has not been attacked by the target malware; if the target category identifier is the first category identifier, the target identifier is the system call interface identifier of the system call interface that has been attacked by the target malware, and if the target category identifier is the second category identifier, the target identifier is the preset identifier, and the preset identifier is used to indicate that each system call interface has not been attacked by the target malware; The system call interface that has been attacked by the target malware is a system call interface whose corresponding executable file has been tampered with by the target malware; the executable file corresponding to the system call interface is stored in a storage memory of an electronic device where the target operating system is located, and the kernel support function corresponding to the system call interface is obtained by loading the executable file corresponding to the system call interface into a running memory of the electronic device; A hiding module, configured to determine whether a tampered executable file corresponding to the target identifier has been hidden if the target category identifier is the first category identifier; The hiding module is further configured to display the memory address of the kernel support function corresponding to the target identifier and / or the target identifier, and the name, base address, offset address, data length of file content data, and / or file path of the tampered executable file corresponding to the target identifier if the tampered executable file corresponding to the target identifier has not been hidden; The hidden module is further configured to, if the tampered executable file corresponding to the target identifier has been hidden, display the memory address of the kernel support function corresponding to the target identifier and / or the target identifier.
6. A non-transitory computer-readable storage medium storing at least one instruction or at least one program segment, the at least one instruction or the at least one program segment being loaded and executed by a processor to implement the method according to any one of claims 1-4.
7. An electronic device, characterized in that, Comprising a processor and the non-transitory computer-readable storage medium according to claim 6.
Citation Information
Patent Citations
Malicious program recognition method and device, storage medium and electronic equipment
CN113010268A
Malicious software detection optimization method and system, terminal and storage medium
CN115168857A