A Backdoor Detection Method Based on Binary Sandbox

By setting up a binary sandbox in the target system and configuring activation functions, and dynamically loading suspicious programs for detection, the problem of insufficient accuracy and real-time accuracy of existing backdoor detection methods is solved, and more efficient malicious program detection and system security are achieved.

CN118585990BActive Publication Date: 2025-06-10CHINESE PEOPLES LIBERATION ARMY UNIT 61660
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410461031.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-17
Publication Date
2025-06-10
Estimated Expiration
2044-04-17

AI Technical Summary

Technical Problem

The existing backdoor detection methods have problems such as low accuracy and weak real-time performance.

Method used

The backdoor detection method based on binary sandbox is adopted. By setting up a binary sandbox in the target system, multiple activation functions are configured, and suspicious programs are implanted into the sandbox through a dynamic loading module to run, recording the activated data for feature analysis to determine whether it is a backdoor program.

Benefits of technology

Improves the security of the system, enhances the detection capabilities of malicious programs, reduces potential risks, and achieves higher detection accuracy and real-time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118585990B_ABST
    Figure CN118585990B_ABST
Patent Text Reader

Abstract

The present invention relates to a backdoor detection method based on a binary sandbox, belonging to the field of network security. In the target system, a binary sandbox is set up, and multiple activation functions are configured in the binary sandbox; in the way of dynamically loading modules, a suspicious program to be detected is implanted into the sandbox for running; by using the multiple activation functions, activation operations are performed on the suspicious program transplanted into the sandbox, and the activation data generated by the activated suspicious program is recorded; feature analysis is performed on the activation data, and then it is judged whether the activation data meets the backdoor features. The present invention makes use of the technical advantages of the binary sandbox, effectively improving the security of the system. At the same time, through the monitoring and analysis of the sandbox process, the existence of the backdoor can be discovered and prevented in time, further reducing the security risk of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security, and particularly relates to a backdoor detection method based on a binary sandbox. Background Art

[0002] A backdoor refers to a specific code or function that is accidentally or maliciously inserted into an application program, which can bypass normal verification and security mechanisms and provide attackers with the permission to illegally access or control the target device.

[0003] Backdoor detection methods mainly include simple manual detection methods and backdoor detection of reverse connections. The simple manual detection method requires carefully searching for every possible suspicious point in the system, such as auto-start items, observing suspicious startup services, suspicious startup program paths, etc. The backdoor detection of reverse connections usually listens on a specified port and requires tools to check.

[0004] Specifically, common backdoor detection methods include:

[0005] Checking abnormal accounts and network connections, such as judging whether there are abnormalities by viewing system users and login information, network connection status.

[0006] Using professional backdoor detection tools, such as chkrootkit and RKHunter, etc., these tools can detect whether there are backdoor programs in the system.

[0007] Analyzing the intrusion paths and reasons, and finding possible intrusion points and reasons by analyzing system logs and network traffic.

[0008] Restoring data and connecting to the network. After the server is attacked, it is necessary to back up user data, reinstall the operating system, repair program or system vulnerabilities, and then restore data and connect to the network.

[0009] The above detection methods have problems of low accuracy and weak real-time performance. Summary of the Invention

[0010] (1) Technical Problems to be Solved

[0011] The technical problem to be solved by the present invention is how to provide a backdoor detection method based on a binary sandbox to solve the problems of low accuracy and weak real-time performance existing in the existing detection methods.

[0012] (2) Technical Solutions

[0013] To solve the above technical problems, the present invention proposes a backdoor detection method based on a binary sandbox, and the method includes the following steps:

[0014] S1. Set up a binary sandbox in the target system and configure multiple activation functions in the binary sandbox;

[0015] S2. By means of dynamic loading of modules, implant the suspicious program to be detected into the sandbox for running;

[0016] S3. Utilize the multiple activation functions to perform activation operations on the suspicious program transplanted into the sandbox, and record the activation data generated by the activated suspicious program;

[0017] S4. Conduct feature analysis on the activation data, and then determine whether the activation data meets the backdoor features.

[0018] (III) Beneficial effects

[0019] The present invention proposes a backdoor detection method based on a binary sandbox. By combining multiple activation functions, the present invention can construct a powerful and highly controllable binary sandbox. This helps to enhance the security of the system, reduce potential risks, and improve the detection ability for malicious programs.

[0020] By transplanting the suspicious program into the sandbox by means of dynamic loading of modules, the present invention can obtain better flexibility and control. This method helps to enhance the security of the system, reduce potential risks, and improve the detection ability for malicious programs. Remember to continuously monitor and update the system to cope with the changing threat environment.

[0021] Through the above steps, the present invention can conduct in-depth analysis on the activation data and accurately determine whether it is a backdoor program. This helps to enhance the security of the system, reduce potential risks, and improve the detection ability for malicious programs.

[0022] The backdoor detection method based on a binary sandbox of the present invention utilizes the technical advantages of the binary sandbox and effectively improves the security of the system. At the same time, by monitoring and analyzing the sandbox process, the existence of the backdoor can be discovered and prevented in a timely manner, further reducing the security risks of the system. Description of the drawings

[0023] Figure 1 is a flowchart of the present invention. Detailed implementation manners

[0024] To make the objectives, contents and advantages of the present invention clearer, the following further describes in detail the specific implementation manners of the present invention with reference to the drawings and embodiments.

[0025] As Figure 1 shown, the backdoor detection method based on a binary sandbox may include:

[0026] S1. Set up a binary sandbox in the target system and configure multiple activation functions in the binary sandbox.

[0027] A binary sandbox is a secure isolation environment used to protect the operating system kernel and other sensitive systems. Activation functions are specific codes that run within the binary sandbox and are responsible for controlling the processes and activities within the sandbox.

[0028] Set up the binary sandbox in the target system (e.g., operating system). The following steps may be included:

[0029] S101. Determine the requirements of the target system, including which operating systems are supported and what functions need to be implemented, etc.

[0030] S102. Select a suitable virtualization technology, such as VMware, VirtualBox, or KVM.

[0031] S103. Configure the environment variables, library files, startup scripts, etc. of the sandbox according to the requirements of the target system.

[0032] S104. Deploy the sandbox to the target system and conduct tests to ensure its normal operation.

[0033] Configure multiple activation functions in the binary sandbox (the number of activation functions can be set according to actual needs, and different activation functions can be used by users to activate different active processes). The following steps may be included:

[0034] S111. Select a framework suitable for configuring activation functions (selected according to actual needs, and different frameworks are selected for different operating systems), such as QEMU, Xen, or Windows Suite. These frameworks usually provide APIs for creating and managing activation functions.

[0035] S112. Write the code of the activation function using the APIs provided by the framework (there are many specific writing methods, which are not the focus of this patent), and make corresponding adjustments in the sandbox environment as needed.

[0036] S113. Import the written activation function into the sandbox environment and run it inside the sandbox.

[0037] S114. Monitor and manage the activation function to ensure its correct operation in the sandbox environment.

[0038] After configuration, the activation functions will help control the processes and activities within the binary sandbox, thereby improving the security of the target system. By simulating the actual environment in the sandbox, vulnerabilities and security loopholes can be detected more effectively.

[0039] S2. Implant the suspicious program to be detected into the sandbox for running by means of dynamically loading modules;

[0040] Implanting the suspicious program to be detected into the sandbox for running by means of dynamically loading modules may include the following:

[0041] S201. Identify which programs are the suspicious programs to be detected. These may be viruses, malware, unknown applications, etc.

[0042] S202. Develop or obtain a dynamically loading module (dynamic loading is an existing technology). This dynamically loading module will be responsible for loading and managing the programs running in the sandbox. It can be an independent program, a system service, or a driver. Integrate appropriate monitoring and logging functions into the dynamically loading module. In this way, information about the internal activities in the sandbox can be collected during runtime for subsequent analysis and auditing.

[0043] S203. Use the dynamically loading module to load the suspicious program into the sandbox for running. This step can be automated or done manually.

[0044] In this way, the suspicious program can be implanted into the sandbox for running dynamically and controllably, and comprehensive detection and analysis can be carried out. This helps to ensure the security and stability of the system while reducing potential risks and damages.

[0045] S3. Use the multiple activation functions to perform activation operations on the suspicious program transplanted into the sandbox, and record the activation data generated by the activated suspicious program;

[0046] Using multiple activation functions to perform activation operations on the suspicious program transplanted into the sandbox can provide a more comprehensive understanding of its behavior and functions. The following are the specific steps:

[0047] S301. Select suitable activation functions as needed. These activation functions can involve resource limitations, input control, environment simulation, etc. Configure appropriate parameters for each selected activation function. This includes determining the thresholds for resource limitations, the format and range of input data, etc.

[0048] S302. In the sandbox environment, use the activation functions to activate the transplanted suspicious program. During the activation process, record the behavior and responses of the suspicious program through logging software. These records include file access, network communication, system calls, etc. of the suspicious program. Thus, the activation data generated by the activated suspicious program can be obtained.

[0049] S4. Perform feature analysis on the activation data, and then determine whether the activation data meets the backdoor features;

[0050] Performing feature analysis on activation data is an important step in determining whether a suspicious program has backdoor features. Feature analysis can help identify the behavior patterns, code features, or communication patterns of a suspicious program, thereby determining whether it has malicious behavior. The following are the detailed steps for performing feature analysis:

[0051] S401. Obtain activation data. This includes collecting and organizing all data such as logs, system calls, and network communication records generated when running the suspicious program in the sandbox.

[0052] S402. Extract key features from the activation data. These features can include file signatures, code snippets, network communication protocols, abnormal behavior patterns, etc.

[0053] S403. Compare the extracted features with known backdoor features. This can be done by using predefined rules, pattern matching algorithms, or machine learning models.

[0054] S404. Based on the results of feature classification, determine whether the activation data meets the backdoor features. This requires combining business knowledge and security experience, deeply analyzing the features, and making an accurate judgment.

[0055] S405. Generate a corresponding report according to the judgment results. The report should detail the features extracted from the activation data, the degree of matching with the backdoor features, and the final judgment conclusion.

[0056] S406. Provide feedback and optimization to the activation function and sandbox environment according to the report results. If the activation data is determined to have backdoor features, corresponding measures should be taken to remove malicious programs, strengthen the system, or update security policies.

[0057] The backdoor detection method based on binary sandbox of the present invention utilizes the technical advantages of binary sandbox, effectively improving the security of the system. At the same time, by monitoring and analyzing the sandbox process, the existence of backdoors can be discovered and prevented in a timely manner, further reducing the security risks of the system.

[0058] Example 1

[0059] Configuring multiple activation functions in the binary sandbox is to enhance the security and controllability of the system. By using different activation functions, programs in the sandbox can be detected and restricted from multiple angles. These activation functions (the generation methods of these activation functions are custom and not well-known) mainly include:

[0060] Resource limit activation function:

[0061] Limit the CPU resources used by the program within a certain period of time to prevent it from over-consuming system resources. Set an upper limit on the memory usage of the program to prevent it from occupying a large amount of memory and causing the system to crash. Limit the access rights of the program to specific directories or files to prevent it from maliciously modifying system files.

[0062] Input control activation function:

[0063] Clean and filter the input data of the program to remove potential malicious content. Limit the size and format of the input data received by the program to prevent it from receiving too much data and causing crashes or abnormal behaviors.

[0064] Environment simulation activation function:

[0065] Provide a simulated operating system environment for the program to run under controllable conditions. Simulate network connections and communications so that the program can only communicate with specific targets and limit its access to external networks.

[0066] Behavior monitoring activation function:

[0067] Monitor the system calls during the program execution to ensure that it does not perform malicious operations. Monitor the network communications of the program, analyze its communication content and purpose, and judge whether there are malicious behaviors.

[0068] Log recording activation function:

[0069] Record in detail the running process, system calls, network communications, etc. of the program for subsequent analysis and auditing. Aggregate and analyze the collected log data to detect abnormal behaviors and potential threats.

[0070] Dynamic analysis activation function:

[0071] Conduct dynamic code analysis on the program to detect malicious code or functions in it. Observe and analyze the behavior patterns of the program during runtime to judge whether it conforms to the expected behaviors or whether there are abnormalities.

[0072] Feedback and adjustment activation function:

[0073] According to the log records and analysis results, dynamically adjust the configuration of the activation function or optimize the sandbox environment. This helps to improve the accuracy and efficiency of detection and reduce false positives.

[0074] Update and continuous monitoring activation function:

[0075] Regularly or as needed update the configuration and parameters of the activation function to cope with new threats and variants. At the same time, continuously monitor the activities and program behaviors in the sandbox to ensure the security and stability of the system.

[0076] By combining multiple activation functions, a powerful and highly controllable binary sandbox can be constructed. This helps enhance the security of the system, reduce potential risks, and improve the detection ability for malicious programs.

[0077] Example 2

[0078] Transplanting a suspicious program into the sandbox by dynamically loading modules is a flexible and controllable method. This method allows programs in the sandbox to be loaded and managed at runtime while maintaining the isolation and security of the sandbox. The following are the basic steps for dynamically loading modules:

[0079] Select a dynamically loaded module: Select a dynamically loaded module that suits the requirements. This can be an independent program, a system service, or a driver. Ensure that the selected module has the required permissions and functions to correctly load and manage the programs in the sandbox.

[0080] Develop or obtain a suspicious program: Develop or obtain a suspicious program that needs to be detected. Ensure that you have the source code or binary file of the program so that it can be loaded into the sandbox.

[0081] Configure the dynamically loaded module: Configure the parameters and settings of the dynamically loaded module as needed. This may include setting the permissions of the module, configuring the input and output paths, specifying the sandbox environment, etc. Ensure that the configuration is correct so that the module can correctly load and manage the programs in the sandbox.

[0082] Integrate the activation function: Integrate the previously configured activation function into the dynamically loaded module. In this way, when loading and managing the programs in the sandbox, the activation function will be automatically applied to the programs.

[0083] Load the suspicious program into the sandbox: Use the dynamically loaded module to load the suspicious program into the sandbox. This step can be completed through an automated script or manually. Ensure that the suspicious program is correctly loaded and starts running in the sandbox environment.

[0084] Execute and observe: Run the suspicious program in the sandbox and closely observe its behavior and responses. Record all activities and outputs for subsequent analysis and auditing.

[0085] Analyze the results: Analyze the collected data and logs to evaluate the intent and potential risks of the suspicious program. Combine the results of the activation function to determine whether the suspicious program has malicious behavior or backdoor characteristics.

[0086] Feedback and adjustment: Based on the analysis results, adjust the configuration of the dynamically loaded module or optimize the sandbox environment. Update the rules or parameters of the activation function to improve the accuracy and efficiency of detection.

[0087] Continuous Monitoring and Update: Regularly execute the dynamically loaded module and observe suspicious programs in the sandbox. Keep an eye on new threats and variants, and update the dynamically loaded module and the sandbox environment to address new threats.

[0088] Transplanting suspicious programs into the sandbox by means of a dynamically loaded module can achieve better flexibility and control. This method helps enhance the security of the system, reduce potential risks, and improve the detection ability for malicious programs. Remember to continuously monitor and update the system to cope with the ever-changing threat environment.

[0089] Example 3

[0090] Analyzing activation data is a crucial step in determining backdoor programs. It is necessary to deeply analyze the behavior patterns, code features, communication patterns, etc. in the activation data, which mainly includes the following steps:

[0091] Behavior Pattern Analysis: Observe the behavior patterns of the program in the activation data, including system calls, file accesses, network communications, etc. Backdoor programs usually hide their true purposes and exhibit the behaviors of normal application programs. Therefore, it is necessary to carefully analyze their behavior patterns to identify potential malicious behaviors.

[0092] Code Feature Analysis: Deeply analyze the code in the activation data and extract key features, such as code snippets, encryption algorithms, hidden malicious instructions, etc. These features can be compared with the features of known backdoor programs to determine whether they conform to the feature patterns of backdoor programs.

[0093] Communication Pattern Analysis: Analyze the network communication records in the activation data and observe the communication content and frequency between the program and external targets. Backdoor programs usually communicate with control servers to transmit sensitive data or receive instructions. By analyzing the communication patterns, it can be determined whether the program is conducting suspicious network activities.

[0094] Abnormal Behavior Detection: Utilize system logs, process monitoring records, etc. in the activation data to detect abnormal behaviors. For example, the program accesses sensitive files without authorization, creates hidden processes, or executes unknown system calls, etc. These abnormal behaviors may indicate that the program has backdoor features.

[0095] Feature Matching and Classification: Match the extracted features with a known backdoor feature library, and use classification algorithms or machine learning models to classify the activation data. Through the classification results, it can be preliminarily determined whether the program has backdoor features.

[0096] Finally, combine the results of behavior pattern analysis, code feature analysis, communication pattern analysis, and abnormal behavior detection for a comprehensive judgment. The present invention considers various features and behavior patterns in the activation data, as well as their correlations.

[0097] By combining multiple activation functions, the present invention can construct a powerful and highly controllable binary sandbox. This helps enhance the security of the system, reduce potential risks, and improve the detection ability for malicious programs.

[0098] By transplanting suspicious programs into the sandbox in the way of dynamically loading modules, the present invention can obtain better flexibility and control. This method helps enhance the security of the system, reduce potential risks, and improve the detection ability for malicious programs. Remember to continuously monitor and update the system to cope with the ever-changing threat environment.

[0099] Through the above steps, the present invention can deeply analyze the activation data and accurately determine whether it is a backdoor program. This helps enhance the security of the system, reduce potential risks, and improve the detection ability for malicious programs.

[0100] The backdoor detection method based on the binary sandbox of the present invention utilizes the technical advantages of the binary sandbox and effectively improves the security of the system. At the same time, by monitoring and analyzing the sandbox process, the existence of the backdoor can be discovered and prevented in a timely manner, further reducing the security risks of the system.

[0101] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

Claims

1. A backdoor detection method based on binary sandbox, characterized in that: The method comprises the following steps: S1. Set up a binary sandbox in the target system and configure multiple activation functions in the binary sandbox; S2. By dynamically loading modules, the suspicious program to be detected is implanted into the sandbox for running; S3, using the multiple activation functions to activate the suspicious program transplanted into the sandbox, and recording the activation data generated by the activated suspicious program; S4, performing feature analysis on the activation data, and then determining whether the activation data meets the backdoor feature; in, In S1, configuring multiple activation functions in the binary sandbox specifically includes the following steps: S111. Select a framework for configuring activation functions, including: QEMU, Xen or Windows suite, which provides APIs for creating and managing activation functions; S112. Use the API provided by the framework to write the code of the activation function, and make corresponding adjustments in the sandbox environment as needed; S113, importing the written activation function into the sandbox environment, and running it inside the sandbox; S114. Monitor and manage the activation function to ensure its correct operation in the sandbox environment; Activation functions include: resource limitation activation function, input control activation function, environment simulation activation function, behavior monitoring activation function, logging activation function, dynamic analysis activation function, feedback and adjustment activation function, and update and continuous monitoring activation function; The S3 specifically includes the following steps: S301, selecting a suitable activation function as needed, and configuring appropriate parameters for each selected activation function, including: determining a threshold value of resource constraints, a format and range of input data; S302: In the sandbox environment, an activation function is used to activate the transplanted suspicious program. During the activation process, the behavior and response of the suspicious program are recorded by log software, thereby obtaining activation data generated by the activated suspicious program.

2. The binary sandbox-based backdoor detection method according to claim 1, characterized in that: In S1, setting a binary sandbox in the target system specifically includes the following steps: S101. Determine the requirements of the target system, including: which operating systems to support and which functions to implement; S102, selecting appropriate virtualization technology; S103, configuring the sandbox environment variables, library files, and startup scripts according to the requirements of the target system; S104. Deploy the sandbox to the target system and perform tests to ensure that it operates properly.

3. The backdoor detection method based on binary sandbox as claimed in claim 1, characterized in that: The S2 specifically includes the following steps: S201. Identify suspicious programs that need to be detected, including viruses, malware, and unknown applications. S202, developing or obtaining a dynamic loading module, which will be responsible for loading and managing programs running in the sandbox, and integrating appropriate monitoring and logging functions in the dynamic loading module to collect information about activities inside the sandbox during runtime; S203: Use a dynamic loading module to load the suspicious program into a sandbox for execution.

4. The backdoor detection method based on binary sandbox as claimed in claim 3, characterized in that: The S4 specifically includes the following steps: S401, obtaining activation data: The activation data includes collecting and organizing all logs, system calls, and network communication records generated when the suspicious program is run in the sandbox; S402, extracting key features from activation data; Key features include file signatures, code snippets, network communication protocols, and anomalous behavior patterns; S403, comparing the extracted features with known backdoor features by using predefined rules, pattern matching algorithms, or machine learning models to complete the comparison; S404: Based on the result of feature classification, determine whether the activated data meets the backdoor feature; S405, generating a corresponding report according to the judgment result; The report should detail the features extracted from the activation data, the degree of match with the backdoor features, and the final judgment conclusion; S406. Based on the report results, feedback and optimization are performed on the activation function and the sandbox environment; if the activation data is judged to have backdoor characteristics, corresponding measures should be taken to remove malicious programs, strengthen the system, or update security policies.

5. The binary sandbox-based backdoor detection method according to claim 4, characterized in that: Resource limit activation function: limit the CPU resources used by the program within a period of time, set a memory usage limit for the program, and limit the program's access rights to predetermined directories or files; Input control activation function: cleans and filters the program's input data, removes potential malicious content, and limits the size and format of the input data received by the program; Environment simulation activation function: provides a simulated operating system environment for the program so that it can run under controllable conditions, simulates network connection and communication, so that the program can only communicate with the predetermined target and restricts its access to the external network; Behavior monitoring activation function: monitors system calls during program execution to ensure that they do not perform malicious operations; monitors the program's network communications, analyzes the content and purpose of the communications, and determines whether there is malicious behavior; Logging activation function: records the program's running process, system calls, and network communication information in detail for subsequent analysis and auditing; Aggregate and analyze collected log data to detect abnormal behavior and potential threats; Dynamic analysis activation function: Perform dynamic code analysis on the program to detect malicious code or functions, observe and analyze the behavior pattern of the program at runtime, and determine whether it conforms to the expected behavior or whether there are any anomalies; Feedback and adjustment of activation functions: Dynamically adjust the configuration of activation functions or optimize the sandbox environment based on log records and analysis results; Update and continuously monitor activation functions: Update the configuration and parameters of activation functions regularly or as needed to respond to new threats and variants. At the same time, continuously monitor the activities and program behaviors in the sandbox to ensure the security and stability of the system.

6. The backdoor detection method based on binary sandbox as claimed in claim 4, characterized in that: The steps to dynamically load a module include: Select a dynamically loaded module: Select a dynamically loaded module that suits your needs and ensure that the selected module has the required permissions and functions to correctly load and manage programs in the sandbox; Develop or obtain suspicious programs: Develop or obtain suspicious programs that need to be detected, and ensure that you have the source code or binary file of the program so that you can load it into the sandbox; Configure the dynamic loading module: Configure the parameters and settings of the dynamic loading module as needed, including setting the module's permissions, configuring the input and output paths, and specifying the sandbox environment; ensure that the configuration is correct so that the module can correctly load and manage programs in the sandbox; Integrate activation function: Integrate the previously configured activation function into the dynamic loading module, so that when loading and managing programs in the sandbox, the activation function will be automatically applied to the program; Load suspicious programs into the sandbox: Use the dynamic loading module to load suspicious programs into the sandbox to ensure that the suspicious programs are correctly loaded and start running in the sandbox environment; Execution and observation: Run the suspicious program in the sandbox and closely observe its behavior and response, recording all activities and outputs for subsequent analysis and auditing; Analysis results: Analyze the collected data and logs to evaluate the intentions and potential risks of suspicious programs. Combined with the results of the activation function, determine whether the suspicious program has malicious behavior or backdoor characteristics; Feedback and adjustment: Based on the analysis results, adjust the configuration of the dynamic loading module or optimize the sandbox environment, and update the rules or parameters of the activation function to improve the accuracy and efficiency of detection; Continuous monitoring and updating: Regularly execute dynamic loading modules and observe suspicious programs in the sandbox, keep an eye on new threats and variants, and update dynamic loading modules and sandbox environment to respond to new threats.

7. The backdoor detection method based on binary sandbox as claimed in claim 4, characterized in that: The S4 specifically includes the following steps: Behavioral pattern analysis: observe the behavior patterns of programs in activation data, including: system calls, file access, and network communications; Code feature analysis: In-depth analysis of the code in the activation data, extraction of key features, and comparison of these features with known backdoor program features to determine whether they match the characteristic patterns of backdoor programs; Communication pattern analysis: Analyze the network communication records in the activation data, observe the content and frequency of the program's communication with external targets, and determine whether the program is conducting suspicious network activities by analyzing the communication pattern; Abnormal behavior detection: Use system logs and process monitoring records in activation data to detect abnormal behavior, which may indicate that the program has backdoor characteristics; Feature matching and classification: Match the extracted features with the known backdoor feature library, use the classification algorithm or machine learning model to classify the activated data, and preliminarily determine whether the program has backdoor features based on the classification results; Finally, a comprehensive judgment is made based on the results of behavior pattern analysis, code feature analysis, communication pattern analysis, and abnormal behavior detection.

8. The binary sandbox-based backdoor detection method according to claim 7, characterized in that: Abnormal behavior includes: the program accessing sensitive files without authorization, creating hidden processes, or executing unknown system calls.

Citation Information

Patent Citations

  • Equipment backdoor detection method for traffic for network security detection

    CN113904796A