A method and device for monitoring process memory, and a storage medium
By collecting and comparing hash values separately during the process loading and running stages, the blind spots of process memory monitoring in the existing technology are solved, and security monitoring of the entire process is realized, especially effective monitoring of dynamic library files, improving the security of the system.
Patent Information
- Application Number
- CN202411154837.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-21
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-08-21
AI Technical Summary
There are blind spots in the existing process memory monitoring system, which cannot effectively protect the security of processes during the loading and running stages, especially the code and data segments of dynamic library files cannot be monitored.
The reference value of the target program is collected in the process loading and running stages, and the first hash value and the second hash value are obtained through hash calculation, and compared with the reference value to determine the monitoring results of the process memory, including the code segments and data segments in the target program itself and the dynamic library file.
It realizes the full process monitoring of process memory, improves the security of process operation, ensures monitoring of code segments and data segments of dynamic library files, and prevents malicious operations.
Smart Images

Figure CN119065925B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to the field of security monitoring, and particularly to a method, a device, and a storage medium for monitoring process memory. Background Art
[0002] In recent years, with the rapid development of computer systems, host security issues have become increasingly prominent. In particular, the attack means against process memory have been constantly evolving, posing a severe challenge to system security. Process memory, as the core area where programs execute, stores program code, data, and runtime status information, and is the main target for attackers to perform malicious operations. Traditional process memory monitoring systems often have some limitations, resulting in blind spots in security protection. Summary of the Invention
[0003] In view of the above defects or deficiencies in the prior art, it is desirable to provide a method, a device, and a storage medium for monitoring process memory.
[0004] In a first aspect, a method for monitoring process memory is provided. The method includes:
[0005] When a target process loads a target program, collecting a reference value of the target program;
[0006] During the loading stage of the target program, obtaining the code segment and data segment corresponding to the target program, and performing hash calculation to obtain a first hash value;
[0007] During the running stage of the target program, obtaining the code segment and data segment corresponding to the target program, and performing hash calculation to obtain a second hash value;
[0008] Comparing the first hash value with the reference value to obtain a first comparison result;
[0009] Comparing the second hash value with the reference value to obtain a second comparison result;
[0010] Determining a monitoring result of the target process memory according to the first comparison result and the second comparison result.
[0011] The method for determining a surveying and mapping behavior provided by this application takes into account that the current monitoring of a process only stays at the program loading stage. This application provides a method for monitoring a process. In the case where a target process loads a target program, this method collects a reference value of the target program; and respectively in the loading stage and the running stage of the target program, obtains the code segment and data segment corresponding to the target program, and performs hash calculation to obtain a first hash value and a second hash value, and then determines the monitoring result of the target process by comparing the first hash value and the second hash value with the reference value respectively. The method for monitoring a process provided by this application not only monitors the process memory in the stage where the target process loads the target program, but also monitors the process memory in the stage where the target process runs the target program. On the one hand, it expands the monitoring time of the target process memory, and on the other hand, it expands the monitoring content of the target process memory, thereby realizing the full-process monitoring of the target process memory and improving the security of the process memory.
[0012] In a second aspect, a device for monitoring process memory is provided. The device includes:
[0013] A collection module, configured to collect the reference value of the target program in the case where a target process loads the target program;
[0014] An acquisition module, configured to obtain the code segment and data segment corresponding to the target program in the loading stage of the target program, and perform hash calculation to obtain a first hash value; and in the running stage of the target program, obtain the code segment and data segment corresponding to the target program, and perform hash calculation to obtain a second hash value;
[0015] A comparison module, configured to compare the first hash value with the reference value to obtain a first comparison result; and compare the second hash value with the reference value to obtain a second comparison result;
[0016] A determination module, configured to determine the monitoring result of the target process memory according to the first comparison result and the second comparison result.
[0017] In a third aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the method of the first aspect is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, objects, and advantages of this application will become more obvious:
[0019] Figure 1 It is an application scenario diagram of a method for monitoring process memory provided by this application;
[0020] Figure 2The flowchart of steps of a process memory monitoring method provided by this application;
[0021] Figure 3 The flowchart of steps of a process memory monitoring method provided by this application;
[0022] Figure 4 The flowchart of steps of a process memory monitoring method provided by this application;
[0023] Figure 5 The flowchart of steps of a process memory monitoring method provided by this application;
[0024] Figure 6 The structural block diagram of a process memory monitoring device provided by this application;
[0025] Figure 7 The structural schematic diagram of a computer system of a monitoring device provided by this application. Specific embodiments
[0026] The following further elaborates on this application in conjunction with the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are merely for explaining the related invention and not for limiting the invention. Additionally, it should be noted that for ease of description, only parts related to the invention are shown in the drawings.
[0027] It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be combined with each other. The following will detail this application with reference to the accompanying drawings and embodiments.
[0028] Please refer to Figure 1 , Figure 1 which is an application scenario diagram of a process monitoring method provided by this application. This application scenario diagram includes a device to be monitored 100 and a monitoring device 200. The monitoring device 200 is used to obtain the reference value of the device to be monitored 100 when loading a program through a process. During the program loading stage, the corresponding code segment and data segment of the program are obtained, and during the program running stage, the corresponding code segment and data segment of the program are obtained, and the corresponding hash calculations are respectively performed to obtain a first hash value and a second hash value. Finally, the first hash value and the second hash value are respectively compared with the reference value to determine whether the process memory is secure based on the comparison result. Among them, the device to be monitored is, for example, a laptop computer, a desktop computer, a server, a host computer, etc.; the monitoring device is, for example, a single server or a server cluster.
[0029] Program loading refers to the process of reading program code from a disk or storage medium into the memory of a computer and executing the program.
[0030] The process of program loading generally includes the following steps:
[0031] 1. Open the program file: First, the computer locates the program file in the storage medium according to the user's request and opens the file.
[0032] 2. Read the program code: The computer reads the program code line by line from the file to the corresponding positions in memory according to the format and structure of the file. These codes usually exist in the form of instructions, which are used to tell the computer what operations should be performed.
[0033] 3. Allocate memory space: Before reading the program code into memory, the computer first allocates a continuous block of memory space for the program to store the code, data, and other resources required during runtime. This can ensure that the program can access this information smoothly during runtime.
[0034] 4. Convert instructions: After storing the program code in memory, the computer parses and converts the code, transforming the machine code instructions into instructions that the computer can understand and execute internally. This process is usually completed by a compiler or an interpreter.
[0035] 5. Execute the program: Once the program code is converted into instructions that the computer can execute internally, the computer can start executing the program according to the order of these instructions. These instructions may include operations such as data reading, calculation, and storage, until the execution of the entire program is completed.
[0036] It can be seen that the monitoring device can execute the loading process of the target program and the running process of the program through the target process. Therefore, attackers may attack the original code segment and original data segment of the target program during these two processes, affecting the security of system operation. In the existing methods for monitoring processes, only the process is monitored during the loading stage of the program, resulting in blind spots in security protection.
[0037] To solve this problem, the present application provides a process monitoring method. The following combines Figure 2 to provide an exemplary description of the process monitoring method provided by the present application. Figure 2 is a flowchart of the steps of a process monitoring method provided by the present application. Taking the case where this method is applied to Figure 1 the monitoring device in as an example to illustrate this method, this method includes the following steps:
[0038] Step S20, when the target process loads the target program, collect the reference value of the target program;
[0039] Among them, first, an explanation is given on how the prior art collects the baseline value of the target program: The prior art will pre-import the code segment and data segment corresponding to the target program, and then perform a simulated loading on the code segment and data segment of the target program. After the simulated loading is completed, a mapping table is obtained. The mapping table records the starting address and ending address of the storage of each code segment and each data segment of the target program in the computer memory space, that is, the virtual mapping address in the computer memory space. The monitoring device then reads the code segment and data segment of the target program from the computer memory space according to the starting address and ending address recorded in the mapping table, and performs a hash calculation, taking the hash value as the baseline value.
[0040] However, this application does not need to perform a simulated loading on the target program. Instead, it collects the baseline value of the target program when the target process actually executes the operation of loading the target program. In this way, both the loading of the target program is completed, and the baseline value of the target program is incidentally collected. Compared with the prior art, when monitoring the operation of the target process, this application shortens the monitoring process and improves the monitoring efficiency. Here, it should be noted that after the target program is loaded, the code segment and data segment corresponding to the target program will be stored in the memory of the target process, that is, a continuous memory space allocated by the computer for the target program.
[0041] In addition, since the compilation method of a program can be divided into static compilation and dynamic compilation, static compilation means that in the loading stage of the target program, the code segment and data segment of the target program stored in the storage medium or disk are moved to the computer memory space; while dynamic compilation means that in the loading stage of the target program, not only the code segment and data segment of the target program stored in the storage medium or disk need to be moved to the computer memory space, but also the code segment and data segment need to be moved from an additional dynamic library file through the loader at the application layer to the computer memory space to complete the loading of the dynamic library file.
[0042] In the process of performing the simulated loading of the target program by the prior art, only the code segment and data segment of the target program stored in the storage medium or disk are moved to the computer memory space. Therefore, it can only obtain the code segment and data segment of the target program itself. After the hash calculation, it can only obtain the baseline value of the code segment and data segment of the target program itself, and cannot obtain the baseline value corresponding to the code segment and data segment in the dynamic library file. Therefore, the prior art cannot monitor the code segment and data segment in the dynamic library file.
[0043] Therefore, the reference values obtained in this application include the first reference values of the target program itself and the second reference values corresponding to the target program stored in the dynamic library file. Herein, "first" and "second" do not limit the number of reference values. There can be multiple first reference values for the target program itself, and there can also be multiple second reference values for the target program in the dynamic library file. The first and second here are only used to distinguish the reference values for different objects. In an alternative embodiment, as Figure 3 shown, Figure 3 FIG. 1 shows an alternative method embodiment for collecting reference values provided by an exemplary embodiment of this application. The method embodiment includes the following steps:
[0044] Step S201, when the target process loads the target program, use the dynamic library preloading technology to intercept the key functions of the target program. The key functions are critical functions used to distinguish whether the target program is in the loading stage or the running stage;
[0045] Among them, the operation of the target program is divided into a loading stage and a running stage. The loading stage is the handling and preparation stage, and the running stage is the stage of executing the program from beginning to end in the order of these instructions, commonly known as running the program once. Then, to obtain the reference value, it can only be obtained in the loading stage. Therefore, it is necessary to distinguish whether the target program is in the loading stage or the running stage. This application uses a critical function (referred to as a key function here) to make the distinction, that is, when the critical function is further executed, the target program should enter the running stage. The key function corresponding to each target program is different, and no specific limitation is made here.
[0046] Since it is necessary to collect the reference value in the loading stage of the target program, the target program is not allowed to enter the running stage before the reference value collection is completed. This application uses the dynamic library preloading technology to intercept the key functions of the target program to prevent the target program from entering the running stage before the reference value collection is completed. In this way, the target program can be intercepted just until the loading is completed, so as to obtain the relationship mapping table of all code segments and data segments required to run the target program, and collect the first reference value and the second reference value according to this relationship mapping table.
[0047] Optionally, using the dynamic library preloading technology to intercept the key functions of the target program includes:
[0048] After finding the key function, add a first jump instruction after the key function to jump the target program from the loading stage to the reference value collection stage. Among them, the collection of the reference value can be executed through a collection function.
[0049] Step S202, after successful interception, read the code segment and data segment of the target program itself and the code segment and data segment located in the dynamic library file based on the relationship mapping table. The relationship mapping table is generated after the target program is loaded and includes the start address and end address corresponding to the target program.
[0050] Among them, by the above method, the execution process of the target program is intercepted just after the loading of the target program is completed, that is, the code segment and data segment stored in the storage medium or disk of the target program are moved to the computer memory space. It is also necessary to move the code segment and data segment from the dynamic library file to the computer memory space through the loader at the application layer. Therefore, all the code segments and data segments supporting the operation of the target program have been stored in the computer memory space, and they also need to be read from the computer memory space during later reading. Therefore, new mapping addresses need to be generated for the code segment and data segment of the target program stored in the storage medium or disk and the code segment and data segment in the dynamic library file, thereby obtaining the relationship mapping table. Therefore, the relationship mapping table records the mapping addresses of the code segment and data segment of the target program stored in the storage medium or disk in the computer memory space, and the mapping addresses of the code segment and data segment in the dynamic library file in the computer memory space.
[0051] Then, the monitoring device can read the code segment and data segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file from the computer memory space according to the start address and end address of each code segment and each data segment recorded in the relationship mapping table.
[0052] Step S203, perform hash calculation on the code segment and data segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file to obtain the first reference value and the second reference value.
[0053] Among them, after reading the code segment and data segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file from the computer memory space according to the above process, perform hash calculation respectively to obtain the first reference value corresponding to the code segment and data segment of the target program itself and the second reference value corresponding to the code segment and data segment of the target program located in the dynamic library file.
[0054] The first reference value and the second reference value are also essentially the hash values corresponding to the code segment and the data segment. A hash value is a unique and extremely compact numerical representation of a piece of data. If a plaintext is hashed and even a single letter of the passage is changed, subsequent hashes will produce different values. It is computationally impossible to find two different inputs that hash to the same value. Therefore, the hash value of the data can be used to verify the integrity of the data. Therefore, using the hash value obtained through hash calculation as the reference value for subsequent comparison can serve as a reliable basis for detecting whether malicious code has been implanted or the original code has been modified by an attacker during the loading and running of the program.
[0055] Step S30, in the loading stage of the target program, obtain the code segment and the data segment corresponding to the target program, and perform hash calculation to obtain the first hash value;
[0056] Among them, since the target program will obtain a relationship mapping table after being loaded, when the monitoring device collects the first reference value and the second reference value through the dynamic library preloading technology, further, the code segment and the data segment corresponding to the target program in the loading stage can be read according to the relationship mapping table, and the corresponding hash calculation is performed to obtain the first hash value.
[0057] It should be noted here that a corresponding hash value will be calculated for a valid code segment or data segment area. Then, for the target program, multiple first hash values can be obtained by performing hash calculation on it. The "first" here is not a limitation on the number of hash values, but only to distinguish the hash values corresponding to the loading stage from those corresponding to the running stage. The following second hash value also does not limit the number of hash values, but only to distinguish from the hash values in the loading stage.
[0058] Based on the above description, since the target program includes the code segment and data segment of the target program itself and also includes the code segment and data segment stored in the dynamic library file, it is necessary to calculate the code segments and data segments from different sources separately. Then, the first hash value includes a first sub-hash value and a second sub-hash value.
[0059] In an optional embodiment, as Figure 4 shown, Figure 4 An optional method embodiment provided by this application for calculating the first sub-hash value and the second sub-hash value includes the following steps:
[0060] Step S301, obtain the code segment and data segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file;
[0061] Among them, after the target program is loaded, a relationship mapping table will be generated. The relationship mapping table records the mapping addresses (including start addresses and end addresses) of the code segments and data segments of the target program stored in the storage medium or disk in the computer memory space, as well as the mapping addresses (including start addresses and end addresses) of the code segments and data segments in the dynamic library file in the computer memory space. According to the start address and end address, the code segments and data segments of the target program itself and the code segments and data segments of the target program in the dynamic library file can be read from the computer memory space during the loading stage of the target program.
[0062] Step S302: Perform hash calculation on the code segments and data segments of the target program itself to obtain a first sub-hash value.
[0063] Step S303: Perform hash calculation on the code segments and data segments of the target program in the dynamic library file to obtain a second sub-hash value.
[0064] Among them, after reading the code segments and data segments of the target program itself and the code segments and data segments of the target program in the dynamic library file, performing hash calculation respectively can obtain the first sub-hash value and the second sub-hash value.
[0065] After obtaining the first reference value and the second reference value, the monitoring device jumps the target program from the acquisition stage to the running stage by adding a second jump instruction after the first jump instruction. In this way, the target program starts to enter the running stage.
[0066] Step S40: In the running stage of the target program, obtain the code segments and data segments corresponding to the target program and perform hash calculation to obtain a second hash value.
[0067] Among them, when the target program is loaded, a relationship mapping table is generated, and this relationship mapping table will be stored in the computer memory space until the target program runs to completion. Therefore, during the loading stage of the target program and the running stage of the target program, the monitoring device can read all the code segments and data segments supporting the running of the target program from the computer memory space according to this relationship mapping table.
[0068] Among them, since all the code segments and data segments of the target program include the code segments and data segments of the target program itself and the code segments and data segments of the target program in the dynamic library file. Therefore, it is necessary to calculate the code segments and data segments from different sources separately, and then the second hash value includes a third sub-hash value and a fourth sub-hash value.
[0069] In an optional embodiment, as Figure 5 shown Figure 5An optional method embodiment for calculating a third sub-hash value and a fourth sub-hash value provided by the present application, the method embodiment includes the following steps:
[0070] Step S401, obtain the code segment and data segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file;
[0071] Among them, after the target program is loaded, a relationship mapping table will be generated. The relationship mapping table records the mapping addresses (including start addresses and end addresses) in the computer memory space of the code segment and data segment of the target program stored in the storage medium or disk, and the mapping addresses (including start addresses and end addresses) in the computer memory space of the code segment and data segment in the dynamic library file; according to the start address and end address, the code segment and data segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file can be read from the computer memory space at any time during the running stage of the target program.
[0072] Step S402, perform a hash calculation on the code segment and data segment of the target program itself to obtain a third sub-hash value;
[0073] Step S403, perform a hash calculation on the code segment and data segment of the target program located in the dynamic library file to obtain a fourth sub-hash value.
[0074] Among them, after reading the code segment and data segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file, perform a hash calculation respectively to obtain a third sub-hash value and a fourth sub-hash value.
[0075] Step S50, compare the first hash value with a reference value to obtain a first comparison result;
[0076] Among them, after the present application obtains the first hash value according to the above steps, since the first hash value includes a first sub-hash value and a second sub-hash value, the monitoring device needs to perform the following steps during the loading stage of the target program:
[0077] Compare the first sub-hash value with a first reference value to obtain a first sub-result;
[0078] Compare the second sub-hash value with a second reference value to obtain a second sub-result;
[0079] Use the first sub-result and the second sub-result as the first comparison result.
[0080] Among them, generally, all the code segments and data segments required by the target program are fixed and will not be changed. Therefore, whether in the loading stage or the running stage, the code segments and data segments corresponding to the target program are exactly the same as those in the loading stage and will not change. If there is a change, it can indicate that the code segments and data segments have been tampered with, then there is a risk in the memory of the target process. Based on this monitoring basis, the monitoring device needs to compare the first sub-hash value and the second sub-hash value calculated in the loading stage with the corresponding first reference value and second reference value respectively to obtain the monitoring result of the target process in the loading stage of the target program.
[0081] The first sub-result includes two cases: the first sub-hash value is consistent with the first reference value; the first sub-hash value is inconsistent with the first reference value.
[0082] The second sub-result includes two cases: the second sub-hash value is consistent with the second reference value; the second sub-hash value is inconsistent with the second reference value.
[0083] Step S60: Compare the second hash value with the reference value to obtain the second comparison result;
[0084] Among them, based on the above description, since the second hash value also includes the third sub-hash value and the fourth sub-hash value, the monitoring device needs to perform the following steps during the running stage of the target program:
[0085] Compare the third sub-hash value with the first reference value to obtain the third sub-result;
[0086] Compare the fourth sub-hash value with the second reference value to obtain the fourth sub-result;
[0087] Determine the third sub-result and the fourth sub-result as the second comparison result.
[0088] Similarly: The third sub-result includes two cases: the third sub-hash value is consistent with the first reference value; the third sub-hash value is inconsistent with the first reference value.
[0089] The fourth sub-result includes two cases: the fourth sub-hash value is consistent with the second reference value; the fourth sub-hash value is inconsistent with the second reference value.
[0090] In an optional embodiment, since there are code segments and data segments that can only be read and code segments and data segments that can be both read and written in the code segments and data segments corresponding to the target program, the code segments and data segments that can be both read and written cannot be monitored, so only the data segments and code segments with read permission set to read-only can be monitored. For the read permissions of the code segments and data segments of the target program, they can be set in the relationship mapping table, and the monitoring device can obtain the read permissions of the code segments and data segments by reading the information on the relationship mapping table.
[0091] Therefore, the monitoring device can also determine whether to perform the hash calculation operation on the first hash value and the second hash value according to the following operations:
[0092] After obtaining the code segment and data segment corresponding to the target program, determine whether the code segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file are stored in the valid memory area of the target process according to the read permission of the target program;
[0093] Among them, the code segment and data segment corresponding to the target program include the code segment and data segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file.
[0094] The read permissions of the code segment and data segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file can be obtained by reading the relationship mapping table. The valid memory area of the target process represents the memory area where the code segment and data segment with read-only permissions are stored in the target process.
[0095] When the computer allocates memory, it can store code segments and data segments with different read permissions in different areas. Therefore, the monitoring device can determine whether the code segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file are stored in the valid memory area of the target process through the read permission information in the relationship mapping table.
[0096] If it is determined that the code segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file are stored in the valid memory area of the target process, then perform the hash calculation operations of obtaining the first hash value and obtaining the second hash value;
[0097] Based on the above description, this application can only monitor code segments and data segments with read-only permissions, that is, it can only monitor code segments and data segments stored in the valid memory area. Therefore, when the monitoring device determines that the code segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file are stored in the valid memory area of the target process, it performs the hash calculation operations of obtaining the first hash value and obtaining the second hash value.
[0098] If it is determined that the code segment of the target program itself and the code segment and data segment located in the dynamic library file are not stored in the valid memory area of the target process, then reject the execution of the hash calculation operations of obtaining the first hash value and obtaining the second hash value.
[0099] Among them, it can be understood that since the code segments and data segments that can be both written and read cannot be monitored, when the monitoring device determines that the code segments of the target program itself and the code segments and data segments in the dynamic library file are not stored in the valid memory area of the target process, the hash calculation operations of obtaining the first hash value and obtaining the second hash value are refused to be executed.
[0100] In another optional embodiment, the present application may be to improve the monitoring efficiency and save resources. A corresponding monitoring level may be set for the code segments and data segments of the target program. The monitoring level corresponding to the code segments and data segments of the target process may continue to be obtained through the relationship mapping table. Then, when the monitoring level corresponding to the code segments and data segments of the target program is greater than or equal to the preset monitoring level, the hash calculation operations of obtaining the first hash value and obtaining the second hash value are executed; conversely, when the monitoring level corresponding to the code segments and data segments of the target program is less than the preset monitoring level, the hash calculation operations of obtaining the first hash value and obtaining the second hash value are refused to be executed.
[0101] Step S70, determine the monitoring result of the target process according to the first comparison result and the second comparison result.
[0102] Among them, if there is a comparison inconsistency in the first comparison result and the second comparison result, the monitoring device may determine that the monitoring result of the target process is that there is a risk in the target process memory;
[0103] Conversely, if the first comparison result and the second comparison result are both in agreement, the monitoring device may determine that the monitoring result of the target process is that the target process memory is safe.
[0104] Since the first comparison result includes a first sub-result and a second sub-result, and the second comparison result includes a third sub-result and a fourth sub-result, further, if there is a comparison inconsistency in the first sub-result, the second sub-result, the third sub-result, and the fourth sub-result, the monitoring device may determine that the monitoring result of the target process is that there is a risk in the target process memory.
[0105] Conversely, if the first sub-result, the second sub-result, the third sub-result, and the fourth sub-result are all in agreement, the monitoring device may determine that the monitoring result of the target process is that the target process memory is safe.
[0106] In another optional embodiment, the present application may also set a corresponding processing strategy for the situation where there is a risk in the target process memory. When the monitoring device determines that the running process of the target process is unsafe according to the above steps, the corresponding processing strategy is obtained for processing, so as to process the unsafe accident in a timely manner and avoid the expansion of the unsafe situation, resulting in greater losses.
[0107] In yet another alternative embodiment, after determining the monitoring result of the target process, the present application records the monitoring process of the target process, thereby facilitating subsequent operations such as viewing and statistics.
[0108] In yet another alternative embodiment, the monitoring of the target process by the present application may also be provided with corresponding trigger conditions. When the set trigger conditions are met, the above-mentioned monitoring process is executed on the target process.
[0109] It should be noted that although the operations of the method of the present invention are described in a specific order in the drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. On the contrary, the steps depicted in the flowchart may be changed in the order of execution. For example,... Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution. For example,...
[0110] Further referring to Figure 6 , which shows an exemplary structural block diagram of a monitoring device 600 for process memory according to an embodiment of the present application. The monitoring device 600 for the process includes an acquisition module 601, an obtaining module 602, a comparison module 603, and a determination module 604.
[0111] The acquisition module 601 is configured to acquire a reference value of the target program when the target process loads the target program.
[0112] The obtaining module 602 is configured to obtain the code segment and data segment corresponding to the target program during the loading phase of the target program, and perform a hash calculation to obtain a first hash value; and during the running phase of the target program, obtain the code segment and data segment corresponding to the target program, and perform a hash calculation to obtain a second hash value.
[0113] The comparison module 603 is configured to compare the first hash value with the reference value to obtain a first comparison result; and compare the second hash value with the reference value to obtain a second comparison result.
[0114] The determination module 604 is configured to determine the monitoring result of the target process memory according to the first comparison result and the second comparison result.
[0115] In an alternative embodiment, the acquisition module 601 is specifically configured to intercept the key functions of the target program by using the dynamic library preloading technology during the execution of the target program loading by the target process. The key functions are critical functions for distinguishing between the loading phase and the running phase of the target program.
[0116] After successful interception, based on the relationship mapping table, read the code segment and data segment of the target program itself, as well as the code segment and data segment of the target program located in the dynamic library file. The relationship mapping table is generated after the target program is loaded and includes the start address and end address corresponding to the target program.
[0117] Perform hash calculation on the code segment and data segment of the target program itself, as well as the code segment and data segment located in the dynamic library file, to obtain the first reference value and the second reference value.
[0118] In an optional embodiment, the acquisition module 601 is further configured to, after finding the key function, add a first jump instruction after the key function to jump the target program from the loading stage to the reference value acquisition stage.
[0119] In an optional embodiment, the acquisition module 601 is further configured to, after obtaining the first reference value and the second reference value, add a second jump instruction after the first jump instruction to jump the target program from the acquisition stage to the running stage.
[0120] In an optional embodiment, the acquisition module 602 is specifically configured to acquire the code segment and data segment of the target program itself, as well as the code segment and data segment of the target program located in the dynamic library file.
[0121] Perform hash calculation on the code segment and data segment of the target program itself to obtain a first sub-hash value.
[0122] Perform hash calculation on the code segment and data segment of the target program located in the dynamic library file to obtain a second sub-hash value.
[0123] In an optional embodiment, the acquisition module 602 is further specifically configured to acquire the code segment and data segment of the target program itself, as well as the code segment and data segment of the target program located in the dynamic library file.
[0124] Perform hash calculation on the code segment and data segment of the target program itself to obtain a third sub-hash value.
[0125] Perform hash calculation on the code segment and data segment of the target program located in the dynamic library file to obtain a fourth sub-hash value.
[0126] In an optional embodiment, the comparison module 603 is specifically configured to compare the first sub-hash value with the first reference value to obtain a first sub-result.
[0127] Compare the second sub-hash value with the second reference value to obtain a second sub-result.
[0128] Use the first sub-result and the second sub-result as the first comparison result.
[0129] In an optional embodiment, the comparison module 603 is further specifically configured to compare the third sub-hash value with the first reference value to obtain a third sub-result;
[0130] Compare the fourth sub-hash value with the second reference value to obtain a fourth sub-result;
[0131] Determine the third sub-result and the fourth sub-result as the second comparison result.
[0132] In an optional embodiment, the determination module 604 is further configured to, after obtaining the code segment and data segment corresponding to the target program, determine whether the code segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file are stored in the valid memory area of the target process according to the read permission of the target program;
[0133] If it is determined that the code segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file are stored in the valid memory area of the target process, perform the hash calculation operations of obtaining the first hash value and obtaining the second hash value;
[0134] If it is determined that the code segment of the target program itself and the code segments and data segments located in the dynamic library file are not stored in the valid memory area of the target process, reject the execution of the hash calculation operations of obtaining the first hash value and obtaining the second hash value.
[0135] In an optional embodiment, the determination module 604 is further configured to, after obtaining the code segment and data segment corresponding to the target program, determine the monitoring level corresponding to the code segment and data segment corresponding to the target program;
[0136] If the monitoring level corresponding to the code segment and data segment corresponding to the target program is greater than or equal to a preset monitoring level, perform the hash calculation operations of obtaining the first hash value and obtaining the second hash value;
[0137] If the monitoring level corresponding to the code segment and data segment corresponding to the target program is less than the preset monitoring level, reject the execution of the hash calculation operations of obtaining the first hash value and obtaining the second hash value.
[0138] In an optional embodiment, the determination module 604 is specifically configured to, if there is a situation of inconsistent comparison in the first comparison result and the second comparison result, determine that the monitoring result of the target process is that there is a risk in the target process memory;
[0139] If both the first comparison result and the second comparison result are consistent, determine that the monitoring result of the target process is that the memory of the target process is secure.
[0140] In an alternative embodiment, a processing module is further included.
[0141] The processing module is configured to, when it is determined that the monitoring result of the memory of the process corresponding to the target program is that there is a risk in the memory of the target process, obtain a corresponding processing policy for processing.
[0142] In an alternative embodiment, a recording module is further included.
[0143] The recording module is configured to, after determining the monitoring result of the target process, record a log of the monitoring process of the memory of the target process.
[0144] It should be understood that the various units or modules described in the monitoring device 600 correspond to the respective steps in the method described with reference to Figure 2 Accordingly, the operations and features described above for the method are equally applicable to the device 600 and the units included therein, and will not be repeated here. The device 600 may be pre-implemented in a browser or other security application of an electronic device, or may be loaded into the browser or its security application of the electronic device by means of downloading or the like. The corresponding units in the device 600 may cooperate with the units in the electronic device to implement the solution of the embodiments of the present application.
[0145] Next, with reference to Figure 7 , a schematic structural diagram of a computer system 700 of a service device suitable for implementing the embodiments of the present application is shown.
[0146] As Figure 7 shown, the computer system 700 includes a central processing unit (CPU) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage section 708 into a random access memory (RAM) 703. In the RAM 703, various programs and data required for the operation of the system 700 are also stored. The CPU 701, the ROM 702, and the RAM 703 are connected to each other through a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0147] The following components are connected to the I / O interface 705: an input section 706 including a keyboard, a mouse, etc.; an output section 707 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 708 including a hard disk, etc.; and a communication section 709 including a network interface card such as a LAN card, a modem, etc. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the I / O interface 705 as needed. A removable medium 711, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 710 as needed so that a computer program read therefrom can be installed into the storage section 708 as needed.
[0148] Specifically, according to an embodiment of the present disclosure, the processes described above with reference to Figure 2-5 can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program tangibly embodied on a machine-readable medium, the computer program including program code for performing Figure 2-5 the method. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 709, and / or installed from the removable medium 711.
[0149] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a portion of code that includes one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur in a different order than that noted in the drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or by a combination of dedicated hardware and computer instructions.
[0150] The units or modules involved in the embodiments described in this application can be implemented in software or in hardware. The described units or modules can also be provided in a processor. For example, it can be described as: a processor includes an XX unit, a YY unit, and a ZZ unit. Among them, the names of these units or modules do not constitute a limitation to the unit or module itself in some cases. For example, the XX unit can also be described as "a unit for XX".
[0151] As another aspect, the present application also provides a computer-readable storage medium, which may be the computer-readable storage medium included in the device described in the above embodiments; or it may exist separately and be a computer-readable storage medium not assembled into the device. The computer-readable storage medium stores one or more programs, and the one or more programs are used by one or more processors to execute the formula input method described in the present application.
[0152] The above description is only the preferred embodiment of the present application and the explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solution formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the inventive concept. For example, the technical solution formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present application.
Claims
1. A method for monitoring process memory, characterized in that, The method includes: When the target process loads the target program, collecting a reference value of the target program; the reference value includes a first reference value of the target program itself and a second reference value of the target program stored in a dynamic library file; In the loading stage of the target program, obtaining the code segment and data segment corresponding to the target program, and performing a hash calculation to obtain a first hash value; In the running stage of the target program, obtaining the code segment and data segment corresponding to the target program, and performing a hash calculation to obtain a second hash value; the code segment and data segment include the code segment and data segment of the target program itself, and the code segment and data segment in the dynamic library file; Comparing the first hash value with the reference value to obtain a first comparison result; Comparing the second hash value with the reference value to obtain a second comparison result; Determining a monitoring result of the target process memory according to the first comparison result and the second comparison result; The collecting the reference value of the target program includes: When the target process loads the target program, using the dynamic library preloading technology to intercept a key function of the target program, the key function being a critical function for distinguishing between the loading stage and the running stage of the target program; After successful interception, reading the code segment and data segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file based on a relationship mapping table, the relationship mapping table being generated after the target program is loaded and including the start address and end address corresponding to the target program; Performing a hash calculation on the code segment and data segment of the target program itself and the code segment and data segment in the dynamic library file to obtain the first reference value and the second reference value.
2. The monitoring method according to claim 1, characterized in that The using the dynamic library preloading technology to intercept the key function of the target program includes: After finding the key function, adding a first jump instruction after the key function to jump the target program from the loading stage to the reference value collection stage.
3. The monitoring method according to claim 2, characterized in that, The method further includes: After obtaining the first reference value and the second reference value, adding a second jump instruction after the first jump instruction to jump the target program from the collection stage to the running stage.
4. The monitoring method according to any one of claims 2-3, characterized in that, The first hash value includes a first sub-hash value and a second sub-hash value. The obtaining the code segment and data segment corresponding to the target program, and performing a hash calculation to obtain a first hash value includes: Obtaining the code segment and data segment of the target program itself and the code segment and data segment of the target program located in the dynamic library file; Performing a hash calculation on the code segment and data segment of the target program itself to obtain a first sub-hash value; Performing a hash calculation on the code segment and data segment of the target program located in the dynamic library file to obtain a second sub-hash value.
5. The monitoring method according to claim 4, characterized in that The comparing the first hash value with the first reference value to obtain a first comparison result includes: Comparing the first sub-hash value with the first reference value to obtain a first sub-result; Compare the second sub-hash value with the second reference value to obtain a second sub-result; Use the first sub-result and the second sub-result as the first comparison result.
6. The monitoring method according to any one of claims 2-3, characterized in that, The second hash value includes a third sub-hash value and a fourth sub-hash value. The step of obtaining the code segment and data segment corresponding to the target program and performing hash calculation to obtain the second hash value includes: Obtain the code segment and data segment of the target program itself and the code segment and data segment of the target program in the dynamic library file; Perform hash calculation on the code segment and data segment of the target program itself to obtain a third sub-hash value; Perform hash calculation on the code segment and data segment of the target program in the dynamic library file to obtain a fourth sub-hash value.
7. The monitoring method according to claim 6, characterized in that, The step of comparing the second hash value with the first reference value to obtain a second comparison result includes: Compare the third sub-hash value with the first reference value to obtain a third sub-result; Compare the fourth sub-hash value with the second reference value to obtain a fourth sub-result; Determine the third sub-result and the fourth sub-result as the second comparison result.
8. The monitoring method according to claim 1, characterized in that The relationship mapping table further includes the read permission of the target program. The method further includes: After obtaining the code segment and data segment corresponding to the target program, determine whether the code segment of the target program itself and the code segment and data segment of the target program in the dynamic library file are stored in the valid memory area of the target process according to the read permission of the target program; If it is determined that the code segment of the target program itself and the code segment and data segment of the target program in the dynamic library file are stored in the valid memory area of the target process, perform the hash calculation operations of obtaining the first hash value and obtaining the second hash value; If it is determined that the code segment of the target program itself and the code segment and data segment in the dynamic library file are not stored in the valid memory area of the target process, reject the hash calculation operations of obtaining the first hash value and obtaining the second hash value.
9. The monitoring method according to claim 1, characterized in that The method further includes: After obtaining the code segment and data segment corresponding to the target program, determine the monitoring level corresponding to the code segment and data segment of the target program; If the monitoring level corresponding to the code segment and data segment of the target program is greater than or equal to the preset monitoring level, perform the hash calculation operations of obtaining the first hash value and obtaining the second hash value; If the monitoring level corresponding to the code segment and data segment of the target program is less than the preset monitoring level, reject the hash calculation operations of obtaining the first hash value and obtaining the second hash value.
10. The monitoring method according to claim 1, characterized in that, The step of determining the monitoring result of the target process according to the first comparison result and the second comparison result includes: If there is a situation where the first comparison result and the second comparison result are inconsistent in comparison, determine that the monitoring result of the target process is that there is a risk in the target process memory; If both the first comparison result and the second comparison result are consistent, determine that the monitoring result of the target process is that the memory of the target process is secure.
11. The monitoring method according to claim 10, characterized in that, The method further includes: When it is determined that the monitoring result of the memory of the process corresponding to the target program is that there is a risk in the memory of the target process, obtain a corresponding processing strategy for processing.
12. The monitoring method according to claim 1, wherein The method further includes: After determining the monitoring result of the target process, record the log of the monitoring process of the memory of the target process.
13. A monitoring device for process memory, characterized in that, The device includes: A collection module, configured to collect a reference value of the target program when the target process loads the target program; the reference value includes a first reference value of the target program itself and a second reference value of the target program stored in a dynamic library file; An acquisition module, configured to obtain a code segment and a data segment corresponding to the target program during the loading stage of the target program, and perform a hash calculation to obtain a first hash value; and during the running stage of the target program, obtain a code segment and a data segment corresponding to the target program, and perform a hash calculation to obtain a second hash value; the code segment and the data segment include the code segment and the data segment of the target program itself, and the code segment and the data segment in the dynamic library file; A comparison module, configured to compare the first hash value with the reference value to obtain a first comparison result; and compare the second hash value with the reference value to obtain a second comparison result; A determination module, configured to determine the monitoring result of the memory of the target process according to the first comparison result and the second comparison result; Specifically, the collection module is configured to, when the target process loads the target program, use the dynamic library preloading technology to intercept the key function of the target program, where the key function is a critical function used to distinguish whether the target program is in the loading stage or the running stage; after successful interception, read the code segment and the data segment of the target program itself and the code segment and the data segment of the target program located in the dynamic library file based on the relationship mapping table, where the relationship mapping table is generated after the target program is loaded and includes the start address and the end address corresponding to the target program; perform a hash calculation on the code segment and the data segment of the target program itself and the code segment and the data segment in the dynamic library file to obtain the first reference value and the second reference value.
14. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 12.
Citation Information
Patent Citations
Trusted dynamic measurement method, device and equipment
CN117492865A