A State Detection Method and System for Stateful Algorithm Substitute Attacks
By detecting at the source code and executable file levels, using regular expressions and sandboxing technology to identify intermediate state storage behaviors and sensitive API calls, the problem of failure to effectively detect stateful algorithm replacement attacks in the prior art is solved, and detection of all known general stateful algorithm replacement attacks is realized.
Patent Information
- Application Number
- CN202211683851.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-27
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2042-12-27
AI Technical Summary
The prior art has failed to effectively detect stateful algorithms in actual deployment environments to replace attacks, and the known detection methods are mainly at the theoretical level and lack realization at the practical application level.
A state detection method and system for alternative attacks of stateful algorithms are proposed. The intermediate state storage behavior in the source code is detected through regular expression matching methods, and sensitive API calls in the executable file are detected in the sandbox virtual environment to identify the characteristics of the alternative attacks of stateful algorithms.
It realizes general detection of stateful algorithm replacement attacks, which can support the detection of all known generalized stateful algorithm replacement attacks at the software level, and provides important guiding significance for related research on cryptographic algorithm replacement attacks.
Smart Images

Figure CN116192454B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of cryptographic algorithm security detection, and particularly relates to a state detection method and system for stateful algorithm substitution attacks. Background Art
[0002] In the actual application process, a cryptographic product provider (such as Crypto AG) may maliciously modify the operations of a cryptographic algorithm to achieve large-scale eavesdropping. As a user of a cryptographic product, the user is often restricted by input / output access rights. In other words, for a black-box cryptographic implementation, the user must trust that the encryption algorithm implemented by the developer is honest and does not contain any backdoors. For this reason, substitution attacks and defenses for black-box cryptographic implementations have become a research hotspot in the academic community.
[0003] The purpose of an algorithm substitution attack (ASA) is to replace an honest implementation with a malicious implementation, thereby allowing the leakage of personal secret information while ensuring that the malicious implementation is indistinguishable from the honest implementation in a black-box (input / output) scenario. The malicious implementation is generally achieved by an attacker adding a backdoor during the design or implementation of the cryptographic algorithm. The security of the vast majority of cryptographic algorithms depends on the random numbers used in the algorithms, and usually a pseudorandom number generation algorithm is used to obtain the random numbers required in the cryptographic algorithm. Given the important position of random numbers in cryptographic algorithms, the algorithm substitution attack focuses on attacking the random number generator component in the cryptographic algorithm to further crack the secret information.
[0004] The algorithm substitution attacks given in the current literature can be divided into two categories according to whether there is additional intermediate state storage in the malicious implementation algorithm: stateless algorithm substitution attacks and stateful algorithm substitution attacks, and the proofs of undetectability and recoverability have been given at the theoretical level. However, the underlying security models of these proofs restrict the detector to only accessing the input and output of the cryptographic algorithm in a black-box manner. The stateful ASA substitution attack will attack by storing the intermediate states generated during the running process. In actual cryptographic applications, in addition to the input and output of the cryptographic algorithm, the detector can also take other means to detect whether there are malicious read and write operations during the running process of the algorithm. Therefore, in order to detect whether an algorithm has suffered a stateful algorithm substitution attack, there naturally exists such a problem: "For standardized cryptographic algorithms and quantum-resistant cryptographic algorithms that are being standardized, can the currently known stateful algorithm substitution attacks that have been proven (black-box) undetectable be detected during the actual deployment process?"
[0005] In the existing literature describing algorithm substitution attacks, the undetectability of the presented stateful algorithm substitution attacks has been proven at the theoretical level; there is currently no detection method for stateful algorithm substitution attacks at the practical application level; the specific forms of stateful algorithm substitution attacks are diverse. According to the different algorithms being attacked (symmetric encryption algorithms, signature algorithms, post-quantum algorithms, etc.), the forms of the substitution algorithms are diverse, and it is necessary to extract the characteristics of stateful algorithm substitution attacks to achieve general detection. Summary of the Invention
[0006] In view of the problems in the existing literature describing algorithm substitution attacks, where the undetectability of the presented stateful algorithm substitution attacks has been proven at the theoretical level; there is currently no detection method example for stateful algorithm substitution attacks at the practical application level; the specific forms of stateful algorithm substitution attacks are diverse. According to the different algorithms being attacked (symmetric encryption algorithms, signature algorithms, post-quantum algorithms, etc.), the forms of the substitution algorithms are diverse, and it is necessary to extract the characteristics of stateful algorithm substitution attacks to achieve general detection, the present invention proposes a state detection method and system for stateful algorithm substitution attacks.
[0007] To achieve the above object, the present invention adopts the following technical solutions:
[0008] On the one hand, the present invention proposes a state detection method for stateful algorithm substitution attacks, including:
[0009] Step 1, when the input file is the source code file of symmetric encryption and digital signature algorithms, use the regular expression matching method for intermediate state detection to detect whether there are library functions for storing data on the hard disk, log output-related functions, and functions related to uploading to the cloud in the source program. If any exist, it is reminded that there is a risk of stateful algorithm substitution attack.
[0010] Step 2, when the input file is the executable file generated by symmetric encryption and digital signature algorithms, construct a sandbox virtual environment for the operation of the program, isolate all sensitive APIs using redirection technology in the sandbox virtual environment, record all system write-related APIs called through the log file, and detect whether there are calls to sensitive APIs in the log file. If any exist, it is reminded that there is a risk of stateful algorithm substitution attack.
[0011] Further, the symmetric encryption and digital signature algorithms include standard AES encryption, RSA-PSS signature, and ECDSA signature algorithms, as well as post-quantum algorithms Dilithium, Falcon, and SPHINCS+.
[0012] Further, in step 2, the sensitive APIs include interfaces for files, registries, global Hooks, and driver loading of the host.
[0013] On the other hand, the present invention proposes a state detection system for stateful algorithm substitution attacks, including:
[0014] A source code state detection module, which is used to perform intermediate state detection by using a regular expression matching method when the input file is a source code file of a symmetric encryption and digital signature algorithm, and detect whether there are library functions for storing data on the hard disk, log output-related functions, and functions related to uploading to the cloud in the source program. If any exist, it reminds of the risk of stateful algorithm substitution attacks.
[0015] An executable file state detection module, which is used to construct a sandbox virtual environment for the operation of the program when the input file is an executable file generated by a symmetric encryption and digital signature algorithm. In the sandbox virtual environment, all sensitive APIs are isolated by using redirection technology, and all APIs related to system writing called are recorded through a log file, and detect whether there are calls to sensitive APIs in the log file. If any exist, it reminds of the risk of stateful algorithm substitution attacks.
[0016] Further, the symmetric encryption and digital signature algorithms include standard AES encryption, RSA-PSS signature, and ECDSA signature algorithms, as well as post-quantum algorithms Dilithium, Falcon, and SPHINCS+.
[0017] Further, in the executable file state detection module, the sensitive APIs include interfaces for files, registries, global Hooks, and driver loading of the host.
[0018] Compared with the prior art, the present invention has the following beneficial effects:
[0019] In current existing literature, no detection scheme for stateful algorithm substitution attacks in an actual deployment environment has been given. Cryptographic libraries such as OpenSSL have open-source complexity, and the number of experts reviewing the code is very small, making it very likely that algorithm substitution attacks will target open-source software. In addition, even if the code looks "clean", there is always a possibility of being damaged during compilation or runtime by damaging the compiler or interpreter. The present invention extracts features of stateful ASA and finds that the key lies in the existence of intermediate state storage behaviors. Based on this unified feature, the present invention gives a detection approach for state detection and successfully realizes the detection of general algorithms; in addition, keyword matching detection schemes and sandbox detection schemes are given according to the type of the input file to be detected. The present invention supports the detection of all known general stateful algorithm substitution attacks at the software level. The implementation of this detection platform has important guiding significance for related research on cryptographic algorithm substitution attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1Flowchart of a state detection method for stateful algorithm substitution attacks according to an embodiment of the present invention;
[0021] Figure 2 Schematic diagram of the detection principle according to an embodiment of the present invention;
[0022] Figure 3 Display of the detection program according to an embodiment of the present invention;
[0023] Figure 4 Display of the normal program log file according to an embodiment of the present invention;
[0024] Figure 5 Display of the program results under stateful algorithm substitution attacks according to an embodiment of the present invention;
[0025] Figure 6 Display of the program log file under stateful algorithm substitution attacks according to an embodiment of the present invention;
[0026] Figure 7 Schematic diagram of the architecture of a state detection system for stateful algorithm substitution attacks according to an embodiment of the present invention. Detailed implementation manners
[0027] The present invention will be further explained and illustrated below in conjunction with the accompanying drawings and specific embodiments:
[0028] In this solution, we propose a state detection method for stateful algorithm substitution attacks. Since stateful ASA substitution attacks will attack by storing states, we want to detect such algorithm substitution attacks by detecting whether there is a behavior of storing intermediate states. And for the dangerous behavior of whether there are relevant output values of the algorithm stored in the device, which reduces the signature security later. We have adopted a series of means to detect the intermediate states of the algorithm. In the implementation idea of the detection, if the file to be detected is a source code file, this solution uses regular expression matching functions for detection. If the input file to be detected is an executable file, referring to the principle of the sandbox in the field of network security, attack detection is carried out.
[0029] The detection flowchart of the solution is given in Figure 1 as follows. The specific solution is as follows:
[0030] Since stateful ASA substitution attacks will attack by storing states, we want to detect such algorithm substitution attacks by detecting whether there is a behavior of storing intermediate states. And for the dangerous behavior of whether there are relevant output values of the algorithm stored in the device, which reduces the signature security later. We have adopted a series of means to detect the intermediate states of the algorithm. In the implementation idea of the detection, the basic idea of the sandbox in the field of network security is mainly referred to.
[0031] Sandboxie is a virtual system program, which is a security mechanism in the field of computer security and provides an isolated environment for running programs. In network security, a sandbox refers to a tool in an isolated environment used to test the behavior of programs that are untrusted, destructive, or whose intentions cannot be determined.
[0032] (1) Main detection directions
[0033] After analysis, we believe that under the current computer system, if an attacker wants to save the relevant values output by encryption or signature algorithms (specifically symmetric encryption and digital signature algorithms, such as the standard AES encryption, RSA-PSS signature, and ECDSA signature algorithms in the OpenSSL library, as well as post-quantum algorithms like Dilithium, Falcon, SPHINCS+) for subsequent encryption or signature attacks, there are roughly three directions: storing in memory, storing on the hard disk (external storage device), and uploading to cloud storage. However, for memory, due to the physical structure of the RAM that makes up the memory, the data stored in it will be lost when the power is off.
[0034] And during the operation of the computer, due to reasons such as process virtual base address relocation, setting the data save address in memory and protecting it from being overwritten by data generated by other processes during computer operation cannot be determined and implemented manually. Therefore, we mainly focus the detection directions on hard disk write detection and cloud upload detection.
[0035] (2) Detection methods
[0036] When the input file is the source code file corresponding to symmetric encryption and digital signature algorithms, the regular expression matching method is adopted. During the implementation process, since it is noted that the library functions for writing data to the hard disk or uploading to the cloud are relatively fixed in each language, we currently implement it by detecting whether there are functions for writing data to the hard disk and functions for uploading to the cloud in the source program. Taking the C and Python languages as examples, since the library function interfaces provided to users for storing data on the hard disk are relatively fixed in these two languages, we have traversed and sorted out the following functions:
[0037] Table 1
[0038]
[0039] In addition, since it is also considered that attackers may use functions related to log storage programs for output to achieve the purpose of attacks, we have also added the functions related to log output in the Python language to the detection list. The functions involved are as follows:
[0040] Table 2
[0041]
[0042] Finally, in the detection of relevant functions uploaded to the cloud, we adopted the following detection ideas: At present, when using basic programming languages for network communication or sending network requests, the new Socket method is used. Therefore, we focused the detection on the Socket function set. In addition, to prevent attackers from using browser-related location storage data, the two request methods of URLs were also included in the scope of sensitive functions. The relevant functions are as follows:
[0043] Table 3
[0044]
[0045] When the input file is an executable file, we can imitate the implementation idea of the sandbox to build a virtual environment for the program to run. In this environment, relatively sensitive interfaces such as the host's files, registry, global Hooks, and driver loading are all isolated using redirection technology, that is, the purpose of having no impact on the host's all states after the program runs is achieved. In addition, since the program runs in a completely controllable virtual environment we built, all APIs related to system writing it calls, such as CreateFile, can be directly recorded, and then the log files generated by the sandbox can be detected later. The detection principle is as Figure 2 shown.
[0046] Detect the source code of the above algorithm and the generated executable program, and use the source code detection program and the sandbox to analyze the executable program. When detecting the source code, the detection targets mainly focus on the library functions of Python and C languages for writing to the hard disk, uploading to the cloud, and generating log files. The detection method is to match the above library functions with regular expressions.
[0047] When detecting the executable file, put the executable file into the sandbox to run, and check the recorded log generated by the sandbox after the run to detect whether there is a call to sensitive system APIs in the log. If either of the above two exists, an alarm will be issued: there is a risk of stateful ASA attack! If neither the call of relevant library functions in the source code nor the call of sensitive APIs in the sandbox is detected, the program is considered safe.
[0048] Test Data and Results
[0049] In terms of state detection, according to the characteristics of the programs suffering from stateful ASA attacks extracted previously, methods such as sandboxes and code audits are used to perform intermediate state detection on the input algorithm at the software level, and the detection sample results of the attacked and non-attacked programs, as well as the log records of the program behavior by the sandbox, are shown.
[0050] For intermediate state detection, the detection scheme does not change with different target algorithms of the attacker, that is, the state detection is universal for the ASA of all algorithms. Therefore, in the following test demonstrations, we only take the ECDSA512 algorithm as an example.
[0051] (1) Display of normal program results
[0052] First, the detection results of sensitive functions and sensitive API calls in the source program of the normal program are shown respectively.
[0053] The detection process for the source program is as follows: We select the file to be detected, and then the software calls the method of detecting whether there are sensitive library functions and sensitive APIs to detect it. The results are as Figure 3 shown.
[0054] In the log file (as Figure 4 shown), we can see that the program only creates intermediate files during runtime, but this file is not visible to the user, and the intermediate file will be deleted after the program runs to completion.
[0055] (2) Display of results of the attacked program
[0056] Based on the same detection principle as above, we detected an attacked sample. The results are shown as Figure 5 shown.
[0057] It can be seen that in the log file (as Figure 6 shown), after the program runs, it modifies the file system, including creating.txt files, that is, there is a behavior of saving data to the hard disk, and there is a risk of being attacked.
[0058] Based on the above embodiments, as Figure 7 shown, the present invention also proposes a state detection system for stateful algorithm replacement attacks, including:
[0059] A source code state detection module, which is used to perform intermediate state detection by using a regular expression matching method when the input file is a source code file of a symmetric encryption and digital signature algorithm, and detect whether there are library functions for saving data to the hard disk, log output related functions, and functions related to uploading to the cloud in the source program. If any exist, it reminds of the risk of stateful algorithm replacement attacks;
[0060] The executable file status detection module is used to build a sandbox virtual environment for the program's operation when the input file is an executable file generated by symmetric encryption and digital signature algorithms. In the sandbox virtual environment, all sensitive APIs are isolated using redirection technology. All APIs related to system writing called are recorded in a log file, and whether there are calls to sensitive APIs in the log file is detected. If so, it reminds of the risk of stateful algorithm substitution attacks.
[0061] Further, the symmetric encryption and digital signature algorithms include standard AES encryption, RSA-PSS signature, and ECDSA signature algorithms, as well as post-quantum algorithms Dilithium, Falcon, and SPHINCS+.
[0062] Further, in the executable file status detection module, the sensitive APIs include interfaces for the host's files, registry, global Hook, and driver loading.
[0063] In summary, in the current existing literature, no detection scheme for stateful algorithm substitution attacks in the actual deployment environment has been given. Cryptographic libraries such as OpenSSL have open-source complexity, and the number of experts reviewing the code is small, making it very likely that algorithm substitution attacks are carried out against open-source software. In addition, even if the code looks "clean", there is always a possibility of being damaged during compilation or runtime by destroying the compiler or interpreter. The present invention extracts features of stateful ASA and finds that the key lies in the existence of intermediate state storage behavior. Based on this unified feature, the present invention gives a detection approach for state detection and successfully realizes the detection of general algorithms. In addition, keyword matching detection schemes and sandbox detection schemes are given according to the type of the file to be detected input. The present invention supports the detection of all known general stateful algorithm substitution attacks at the software level. The implementation of this detection platform has important guiding significance for the related research on cryptographic algorithm substitution attacks.
[0064] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A state detection method for stateful algorithm substitution attacks, characterized in that, Including: Step 1, when the input file is the source code file of symmetric encryption and digital signature algorithms, use the regular expression matching method for intermediate state detection to detect whether there are library functions for storing data on the hard disk, log output related functions, and functions related to uploading to the cloud in the source program. If any exist, it is reminded that there is a risk of stateful algorithm substitution attack; Step 2, when the input file is an executable file generated by symmetric encryption and digital signature algorithms, construct a sandbox virtual environment for the program's operation. In the sandbox virtual environment, all sensitive APIs are isolated using redirection technology, and all APIs related to system writing called are recorded through a log file. Detect whether there are calls to sensitive APIs in the log file. If any exist, it is reminded that there is a risk of stateful algorithm substitution attack.
2. The state detection method for stateful algorithm substitution attacks according to claim 1, characterized in that, The symmetric encryption and digital signature algorithms include standard AES encryption, RSA-PSS signature, and ECDSA signature algorithms, as well as post-quantum algorithms Dilithium, Falcon, and SPHINCS+.
3. The state detection method for stateful algorithm substitution attacks according to claim 1, characterized in that, In Step 2, the sensitive APIs include interfaces for the host's files, registry, global Hook, and driver loading.
4. A state detection system for stateful algorithm substitution attacks, characterized in that, Including: A source code status detection module, which is used to, when the input file is the source code file of symmetric encryption and digital signature algorithms, use the regular expression matching method for intermediate state detection to detect whether there are library functions for storing data on the hard disk, log output related functions, and functions related to uploading to the cloud in the source program. If any exist, it is reminded that there is a risk of stateful algorithm substitution attack; An executable file status detection module, which is used to, when the input file is an executable file generated by symmetric encryption and digital signature algorithms, construct a sandbox virtual environment for the program's operation. In the sandbox virtual environment, all sensitive APIs are isolated using redirection technology, and all APIs related to system writing called are recorded through a log file. Detect whether there are calls to sensitive APIs in the log file. If any exist, it is reminded that there is a risk of stateful algorithm substitution attack.
5. The state detection system for stateful algorithm substitution attacks according to claim 4, characterized in that, The symmetric encryption and digital signature algorithms include standard AES encryption, RSA-PSS signature, and ECDSA signature algorithms, as well as post-quantum algorithms Dilithium, Falcon, and SPHINCS+.
6. The state detection system for stateful algorithm substitution attacks according to claim 4, characterized in that, In the executable file status detection module, the sensitive APIs include interfaces for the host's files, registry, global Hook, and driver loading.
Citation Information
Patent Citations
Sandbox detection alarming method and system based on main engine characteristic
CN104766011A
Sandbox of algorithm competition online evaluation system and implementation method of sandbox
CN114329441A