Malicious Code Recognition Method, Device and Electronic Device Based on Honeypot Technology
Through the malicious code identification method based on honeypot technology, the behaviors containing malicious code are identified and controlled, and the problem of difficult to identify malicious code variants is solved, and effective identification and prevention of malicious code is achieved.
Patent Information
- Application Number
- CN202411244248.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-06
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2044-09-06
AI Technical Summary
There are many forms of variants of malicious code. It hides its own behavior path through disguise, making it difficult to effectively identify it through feature code matching, resulting in the inability to effectively prevent unauthorized operations of malicious code.
The malicious code recognition method based on honeypot technology is adopted to determine the behavior path information corresponding to the real-time access behavior, generate access behavior characteristics, and use pre-trained malicious code recognition model to identify behavior types, and respond to the behavior type containing malicious code for behavior control.
It realizes effective identification of malicious code, improves effective prevention of unauthorized operations corresponding to malicious code, and avoids the harm of malicious code to the computer operating system.
Smart Images

Figure CN119150284B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present application relate to the field of computer technologies, and particularly to a malicious code recognition method, apparatus, and electronic device based on honeypot technology. Background Art
[0002] Malicious code refers to a code segment that can perform unauthorized operations in a computer operating system. It will have an adverse impact on the normal execution of the computer operating system. For example, taking Trojan viruses as an example, they can perform malicious operations on the computer operating system, maliciously tamper with data, etc. Currently, for malicious code, malicious code recognition is usually carried out by means of signature matching.
[0003] However, when using the above method, the following technical problems often exist:
[0004] Malicious code often exists in various forms of variants, which can hide their own behavior paths through disguise. It is difficult to effectively identify variant malicious code by means of signature matching, so that unauthorized operations corresponding to malicious code cannot be effectively prevented. Summary of the Invention
[0005] The content part of the present application is used to introduce concepts in a brief form, and these concepts will be described in detail in the subsequent detailed implementation part. The content part of the present application is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0006] Some embodiments of the present application propose a malicious code recognition method, apparatus, electronic device, and computer-readable storage medium based on honeypot technology to solve one or more of the technical problems mentioned in the above background art part.
[0007] In a first aspect, some embodiments of the present application provide a malicious code recognition method based on honeypot technology. The method includes: determining whether there is first behavior path information corresponding to a real-time access behavior, where the first behavior path information represents the behavior path corresponding to a historical access behavior, and the real-time access behavior and the historical access behavior correspond to the same behavior initiation node and behavior path; in response to the absence, performing the following first processing step: generating an access behavior feature corresponding to the real-time access behavior; generating a behavior type corresponding to the real-time access behavior according to the access behavior feature and a pre-trained first malicious code recognition model, where the behavior type includes: a first behavior type and a second behavior type, the first behavior type represents that the real-time access behavior does not contain malicious code, and the second behavior type represents that the real-time access behavior contains malicious code; in response to the presence, performing the following second processing step: updating the path of the first behavior path information according to the real-time access behavior to generate second behavior path information; generating a behavior type corresponding to the real-time access behavior according to the second behavior path information and a pre-trained second malicious code recognition model; in response to the behavior type being the second behavior type, performing behavior control on the real-time access behavior through a honeypot.
[0008] In a second aspect, some embodiments of the present application provide a malicious code recognition device based on honeypot technology. The device includes: a determination unit configured to determine whether there is first behavior path information corresponding to a real-time access behavior, where the first behavior path information represents the behavior path corresponding to a historical access behavior, and the real-time access behavior and the historical access behavior correspond to the same behavior initiation node and behavior path; a first execution unit configured to, in response to the absence, perform the following first processing step: generating an access behavior feature corresponding to the real-time access behavior; generating a behavior type corresponding to the real-time access behavior according to the access behavior feature and a pre-trained first malicious code recognition model, where the behavior type includes: a first behavior type and a second behavior type, the first behavior type represents that the real-time access behavior does not contain malicious code, and the second behavior type represents that the real-time access behavior contains malicious code; a second execution unit configured to, in response to the presence, perform the following second processing step: updating the path of the first behavior path information according to the real-time access behavior to generate second behavior path information; generating a behavior type corresponding to the real-time access behavior according to the second behavior path information and a pre-trained second malicious code recognition model; a behavior control unit configured to, in response to the behavior type being the second behavior type, perform behavior control on the real-time access behavior through a honeypot.
[0009] In a third aspect, the present application further provides an electronic device, which includes a processor, a memory, and a computer program stored on the memory and executable by the processor. When the computer program is executed by the processor, the method described in any implementation manner of the first aspect is implemented.
[0010] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described in any implementation manner of the first aspect is implemented.
[0011] The above-mentioned various embodiments of the present application have the following beneficial effects: Through the malicious code recognition method based on the honeypot technology in some embodiments of the present application, effective identification of malicious codes is achieved, and effective prevention of unauthorized operations corresponding to malicious codes is improved. Specifically, the reason for the inability to effectively identify malicious codes is that malicious codes often exist in various forms of variants, which can hide their own behavior paths in a disguised form, and it is difficult to effectively identify variant malicious codes by using the signature matching method, thus unable to effectively prevent unauthorized operations corresponding to malicious codes. Based on this, in some embodiments of the present application, the malicious code recognition method based on the honeypot technology first determines whether there is first behavior path information corresponding to the real-time access behavior, where the above-mentioned first behavior path information represents the behavior path corresponding to the historical access behavior, and the above-mentioned real-time access behavior corresponds to the same behavior initiation node and behavior path as the above-mentioned historical access behavior. In practice, for malicious codes, they often disguise themselves to achieve purposes such as tampering with and collecting content in the computer operating system, so they correspond to corresponding behavior execution paths. At the same time, for latent malicious codes, their tampering and collection often have a certain frequency. Therefore, by judging whether there is first behavior path information corresponding to the real-time access behavior, it is possible to determine access behaviors with the same behavior path and the same behavior initiation node. Then, in response to the non-existence, the following first processing steps are executed: First step, generate access behavior characteristics corresponding to the above-mentioned real-time access behavior. Characterize the behavior characteristics of the real-time access behavior from the feature perspective in sequence. Second step, according to the above-mentioned access behavior characteristics and the pre-trained first malicious code recognition model, generate the behavior type corresponding to the above-mentioned real-time access behavior, where the above-mentioned behavior type includes: the first behavior type and the second behavior type, the above-mentioned first behavior type represents that the above-mentioned real-time access behavior does not contain malicious code, and the above-mentioned second behavior type represents that the above-mentioned real-time access behavior contains malicious code. When there is no first behavior path information, it can represent that the real-time access behavior is the first access behavior or a disguised access behavior. Therefore, the first malicious code recognition model and the access behavior characteristics can be combined to identify whether the real-time access behavior contains malicious code. Further, in response to the existence, the following second processing steps are executed: First step, update the path of the above-mentioned first behavior path information according to the above-mentioned real-time access behavior to generate second behavior path information. When there is first behavior path information, it represents that there is a historical access behavior similar to the real-time access behavior. Therefore, the first behavior path information and the real-time access behavior can be combined. Second step, according to the above-mentioned second behavior path information and the pre-trained second malicious code recognition model, generate the behavior type corresponding to the above-mentioned real-time access behavior. In this way, by combining historical access behaviors and current access behaviors, from the perspective of access behaviors at different times, analyze whether the real-time access behavior contains malicious code.Finally, in response to the above behavior type being the above second behavior type, the honeypot performs behavior control on the above real-time access behavior. In practice, when malicious code is included, corresponding behavior control is performed to avoid harm to the computer operating system. In this way, effective identification of malicious code is achieved, and effective prevention of unauthorized operations corresponding to malicious code is improved. Brief Description of the Drawings
[0012] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages, and aspects of the embodiments of the present application will become more obvious. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the elements and elements are not necessarily drawn to scale.
[0013] Figure 1 is a flowchart of some embodiments of a malicious code recognition method based on honeypot technology according to the present application;
[0014] Figure 2 is a schematic structural diagram of some embodiments of a malicious code recognition device based on honeypot technology according to the present application;
[0015] Figure 3 is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present application. Detailed Description of the Embodiments
[0016] The embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present application. It should be understood that the drawings and embodiments of the present application are only for exemplary purposes and are not used to limit the protection scope of the present application.
[0017] In addition, it should be noted that for the sake of convenience of description, only parts related to the relevant invention are shown in the drawings. Without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.
[0018] It should be noted that the concepts such as "first" and "second" mentioned in the present application are only used to distinguish different devices, modules, or units, and are not used to limit the order or interdependence relationship of the functions performed by these devices, modules, or units.
[0019] It should be noted that the modifications of "one" and "multiple" mentioned in the present application are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly stated in the context, it should be understood as "one or more".
[0020] The names of the messages or information exchanged between multiple devices in the embodiments of the present application are for illustrative purposes only and are not used to limit the scope of these messages or information.
[0021] The present application will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.
[0022] Reference Figure 1 , which shows the flow 100 of some embodiments of the malicious code recognition method based on the honeypot technology according to the present application. The malicious code recognition method based on the honeypot technology includes the following steps:
[0023] Step 101, determine whether there is first behavior path information corresponding to the real-time access behavior.
[0024] In some embodiments, the execution subject (for example, a computing device) of the malicious code recognition method based on the honeypot technology can determine whether there is first behavior path information corresponding to the real-time access behavior. Among them, the first behavior path information characterizes the behavior path corresponding to the historical access behavior. In practice, the behavior path represents each specific access behavior of the historical access behavior in chronological order. For example, the historical access behavior may include access behavior A and access behavior B. Specifically, at time T 1 moment, access behavior A can be executed, and at time T 2 moment, access behavior B can be executed. Among them, time T 1 is earlier than time T 2 moment. Among them, access behavior A can be used to obtain the access permission of a file. Access behavior B can be to tamper with the file content after executing the access behavior. The real-time access behavior corresponds to the same behavior initiation node and behavior path as the above historical access behavior. The behavior initiation node can be the terminal that initiates the access behavior. In practice, the historical access behavior and the real-time access behavior correspond to the terminal that initiates the access behavior corresponding to the same IP address. In practice, the above execution subject can read the historical access record to determine whether there is first behavior path information.
[0025] In practice, when in a high network risk, the above execution subject can regard the access behavior corresponding to each real-time access request as the real-time access behavior. When in a low network risk and the network traffic is high, that is, the number of access requests per unit time is high, it is more resource-consuming to judge the behavior type for the real-time access behavior corresponding to each real-time access request. Therefore, the access behavior corresponding to the real-time access requests transmitted through a certain several ports can be regarded as the real-time access behavior.
[0026] It should be noted that the above computing device can be hardware or software. When the computing device is hardware, it can be implemented as a distributed cluster composed of multiple servers or terminal devices, or as a single server or a single terminal device. When the computing device is embodied as software, it can be installed in the above-listed hardware devices. It can be implemented as, for example, multiple software or software modules for providing distributed services, or as a single software or software module. No specific limitation is made here. In practice, the above computing device can be an intermediate server set between the server cluster and the Internet, used to forward requests transmitted via the Internet to the server cluster, and to forward the data stored in the server cluster requested by the requests to the corresponding terminals.
[0027] In some optional implementation manners of some embodiments, determining whether there is first behavior path information corresponding to the real-time access behavior by the above execution subject may include the following steps:
[0028] The first step is to activate the target container.
[0029] Among them, the above target container is an isolation container. In practice, the target container can be a container that replicates the resources stored in the server cluster. By setting the target container, it is possible to avoid damage to the resources in the server cluster caused by real-time network behaviors when the behavior type of the real-time access behavior has not been determined.
[0030] The second step is to, in response to successful activation, execute the above real-time access behavior within the above target container, and record the execution content when the above real-time access behavior is executed as candidate behavior path information.
[0031] Among them, the above candidate behavior path information includes: a candidate behavior path node queue. The candidate behavior nodes in the above candidate behavior path node queue include: behavior commands, behavior execution environments, behavior execution states, and behavior operation contents. In practice, since the target container has the same cluster environment as the server cluster to be accessed by the implementation access behavior, the above real-time access behavior can be executed within the target container to obtain each specific access behavior operation of the above real-time access behavior in chronological order as the candidate behavior path node queue. The behavior command represents the specific behavior command to be executed. For example, the behavior command can be "reg add XX", that is, modify the registry. The behavior execution environment represents the container state of the current target container when the behavior command is executed, specifically, it can represent file status, system status, etc. The behavior execution state represents the execution state of the behavior command, specifically, it can include: in execution, execution failed, execution successful. The behavior operation content represents the operation object corresponding to the behavior command and the execution result after the behavior command is executed. For example, when the behavior command is "reg add XX", the corresponding behavior operation content can be adding "XX" to the registry.
[0032] In the third step, according to the candidate behavior node sequence, perform the following path finding steps:
[0033] Step 1: Determine the target behavior path node as the candidate behavior path node located at the head position in the candidate behavior path node queue.
[0034] In practice, the candidate behavior path nodes can be stored in the form of a queue.
[0035] Step 2: According to the behavior command, behavior execution environment, and behavior execution status included in the target behavior path node, traverse the behavior path graph to determine whether the behavior path graph contains the target behavior path node.
[0036] Among them, the behavior path graph is a directed graph generated according to different access behaviors. The behavior path graph can be a path graph constructed according to each historical operation behavior before the real-time operation behavior. Specifically, since each operation behavior corresponds to at least one path node, and the path nodes are ordered, and there are duplicate and cross path nodes between different operation behaviors, therefore, the above-mentioned behavior path graph can be constructed according to each historical operation behavior. In practice, the above-mentioned execution subject can determine whether there are path nodes in the behavior path graph that are the same as the behavior command, behavior execution environment, and behavior execution status included in the target behavior path node through graph traversal.
[0037] Step 3: In response to the non-existence, generate a determination result indicating the non-existence of the above-mentioned first behavior path information
[0038] Step 4: In response to the existence and the candidate behavior node sequence excluding the target behavior path node being empty, generate a determination result indicating the existence of the above-mentioned first behavior path information.
[0039] In the fourth step, in response to the existence and the candidate behavior node sequence excluding the target behavior path node being non-empty, use the candidate behavior node sequence excluding the target behavior path node as the candidate behavior node sequence, and perform the above path finding steps again.
[0040] Step 102, in response to the non-existence, perform the following first processing step:
[0041] Step 1021, generate the access behavior characteristics corresponding to the real-time access behavior.
[0042] In some embodiments, the above-mentioned execution subject can generate the access behavior characteristics corresponding to the real-time access behavior.
[0043] As an example, first, the above-mentioned execution entity can perform static feature extraction on the access content corresponding to the real-time access behavior to obtain static access behavior features. Then, the above-mentioned execution entity can perform dynamic feature extraction on each specific access behavior corresponding to the real-time access behavior to obtain dynamic access behavior features. Next, the above-mentioned static access behavior features and dynamic access behavior features are combined to obtain the above-mentioned access behavior features.
[0044] In some optional implementation manners of some embodiments, generating the access behavior features corresponding to the above-mentioned real-time access behavior may include the following steps:
[0045] First step, for each candidate behavior path node in the candidate behavior path node queue, perform the following feature processing steps:
[0046] Step 1: Disassemble the behavior commands included in the above-mentioned candidate behavior path node to generate an assembly instruction set.
[0047] In practice, the above-mentioned execution entity can use a dynamic debugging tool and a static debugging tool to disassemble the behavior commands included in the candidate behavior path node to generate an assembly instruction set. In practice, due to the differences in language formats corresponding to different high-level languages, through disassembly processing, the behavior commands included in the above-mentioned candidate behavior path node can be converted into an assembly instruction set with the same expression form.
[0048] Step 2: Extract instruction features from each assembly instruction in the above-mentioned assembly instruction set to generate instruction features and obtain an instruction feature set.
[0049] In practice, the above-mentioned execution entity can use the instruction feature extractor included in the access behavior feature extractor to extract instruction features from the assembly instructions to generate instruction features. Specifically, the instruction feature extractor can be a downsampling network composed of 5 serially connected convolutional layers. Specifically, the streamlined network structure can reduce the amount of feature processing during feature extraction. In addition, the network structure design of the downsampling network can reduce the feature length.
[0050] Step 3: Extract environmental features from the behavior execution environment included in the above-mentioned candidate behavior path node to obtain environmental features.
[0051] In practice, the above-mentioned execution entity can access the environmental feature extractor included in the behavior feature extractor. In practice, the environmental feature extractor can perform index feature extraction on the key execution metrics in the behavior execution environment. Specifically, to ensure the execution of behavior commands, a large number of processes and resources often need to be kept in use, and full-scale feature extraction of the behavior execution environment involves a huge amount of data processing. Therefore, the above-mentioned execution entity and the environmental feature extractor can perform index feature extraction on the key execution metrics in the behavior execution environment to obtain environmental features. In practice, the key metrics can include: read operation permission status, current process list, current hardware resource occupancy status, etc.
[0052] Step 4: Perform state mapping on the behavior execution status included in the above-mentioned candidate behavior path nodes to obtain a behavior execution status vector.
[0053] In practice, since the number of behavior execution statuses is limited, the one-hot encoding method can be used to perform state mapping on the behavior execution status included in the candidate behavior path nodes to obtain a behavior execution status vector.
[0054] Step 5: Extract the operation content from the behavior operation content included in the above-mentioned candidate behavior path nodes to generate operation content features.
[0055] In practice, the above-mentioned execution entity can extract the operation content from the behavior operation content included in the candidate behavior path nodes through the operation content extraction model included in the behavior feature extractor to generate operation content features. Among them, the operation content extraction model uses the Word2Vec model to perform word embedding on the behavior operation content included in the candidate behavior path nodes to obtain operation content features.
[0056] Step 6: Perform feature mapping on the above-mentioned instruction feature set, the above-mentioned environmental features, the above-mentioned behavior execution status vector, and the above-mentioned operation content features to obtain the mapped features.
[0057] In practice, the feature dimensions of the above-mentioned instruction feature set, the above-mentioned environmental features, the above-mentioned behavior execution status vector, and the above-mentioned operation content features are all different. For the convenience of subsequent splicing, the above-mentioned execution entity can access the first upsampling network, the second upsampling network, the third upsampling network, and the fourth upsampling network included in the behavior feature extractor. Among them, the first upsampling network is used to perform feature upsampling on the instruction feature set. The second upsampling network is used to perform feature upsampling on the environmental features. The third upsampling network is used to perform feature upsampling on the behavior execution status vector. The fourth upsampling network is used to perform feature upsampling on the operation content features. Among them, the feature dimensions output by the first upsampling network, the second upsampling network, the third upsampling network, and the fourth upsampling network are N×M 1 、N×M2 、N×M 3 、N×M 4 。Then, since the horizontal dimensions of the output feature dimensions are the same, the features output by different upsampling networks can be vertically concatenated as the above-mentioned mapped features.
[0058] Step 2: Concatenate each of the mapped features in the obtained set of mapped features to obtain a mapped feature map for the above real-time access behavior as the above access behavior feature.
[0059] Step 1022: Generate a behavior type corresponding to the real-time access behavior according to the access behavior feature and the pre-trained first malicious code recognition model.
[0060] In some embodiments, the above-mentioned execution entity can generate a behavior type corresponding to the real-time access behavior according to the access behavior feature and the pre-trained first malicious code recognition model. Among them, the above-mentioned behavior types include: a first behavior type and a second behavior type. The first behavior type indicates that the above real-time access behavior does not contain malicious code, and the second behavior type indicates that the above real-time access behavior contains malicious code.
[0061] Optionally, the first malicious code recognition model includes: an access behavior feature extractor and a malicious code classifier. The access behavior feature extractor is used to generate the above access behavior feature according to the above real-time access behavior. Specifically, for the specific manner in which the access behavior feature extractor extracts the access behavior feature, refer to Step 1021, which will not be elaborated here. The malicious code classifier may include K depth feature extractors, a feature stacking layer, and a binary classifier. Among them, the network structures of the K depth feature extractors are the same and are arranged in parallel. The depth feature extractor adopts a ResNet model. The K depth feature extractors are connected to 1 feature stacking layer for implementing an Add operation to stack the features output by the K depth feature extractors. The binary classifier is used to output the behavior type.
[0062] In some optional implementation manners of some embodiments, the above-mentioned execution entity generating a behavior type corresponding to the above real-time access behavior according to the above access behavior feature and the pre-trained first malicious code recognition model may include the following steps:
[0063] Step 1: Perform horizontal feature map segmentation on the above access behavior feature according to the input size of the above malicious code classifier to obtain a candidate sub-access behavior feature set.
[0064] In practice, the input size is the horizontal size included in the input size of the depth feature extractor. The number of candidate sub-access behavior features in the candidate sub-access behavior feature set is K.
[0065] Step 2: According to the above input size, zero-padding is performed on each candidate sub-access behavior feature in the above candidate sub-access behavior feature set to generate sub-access behavior features, thereby obtaining a sub-access behavior feature set.
[0066] Among them, the feature size of the sub-access behavior features in the above sub-access behavior feature set is consistent with the above input size. In practice, the above execution entity may perform zero-padding on the selected sub-access behavior features according to the vertical size included in the input size to generate sub-access behavior features.
[0067] Step 3: According to the above sub-access behavior feature set and the above malicious code classifier, the above behavior type is generated.
[0068] In practice, first, the above execution entity may perform parallel feature extraction on the sub-access behavior features in the sub-access behavior feature set through K depth feature extractors. Then, the features obtained by extraction are feature-superimposed through a feature superposition layer. Finally, the superimposed features are input into the above binary classifier to obtain the behavior type.
[0069] The content of "in some optional implementation manners of some embodiments" in the above step 1021 and step 1022, as an inventive point of this application, realizes the determination of the corresponding behavior type when the real-time access behavior is a first-time access behavior. Specifically, first, for each candidate behavior path node, this application respectively extracts features from the perspectives of behavior commands, behavior execution environments, behavior execution states, and behavior operation contents. Then, considering that the number of behavior path nodes included in different access behaviors is different, resulting in differences in the sizes of the obtained access behavior features, therefore, this application first performs horizontal feature map segmentation on the above access behavior features according to the input size of the above malicious code classifier to obtain a candidate sub-access behavior feature set. Then, parallel feature extraction is performed on the sub-access behavior features in the sub-access behavior feature set through K depth feature extractors arranged in parallel. Then, the obtained features are processed by means of feature superposition. Finally, the determination of the behavior type is realized through a binary classifier. By this means, the determination of the corresponding behavior type is realized when the real-time access behavior is a first-time access behavior.
[0070] Step 103: In response to the existence, execute the following second processing step:
[0071] Step 1031: According to the real-time access behavior, update the path of the first behavior path information to generate second behavior path information.
[0072] In some embodiments, the above execution entity may update the path of the first behavior path information according to the real-time access behavior to generate second behavior path information.
[0073] Optionally, the first line of path information includes: the first line is a path node queue, and the first line of path nodes in the first line of path node queue includes: behavior execution status and behavior operation content. In practice, since an operation behavior often consists of multiple specific operation behaviors, the historical operation behavior also corresponds to a corresponding path node queue. Due to the change of time, the data stored in the file corresponding to the behavior operation content may change. Therefore, the operation object corresponding to the behavior command and the execution result after the execution of the behavior command will also change. Thus, it is necessary to update the first line of path information according to the real-time access behavior to generate the second line of path information.
[0074] In some optional implementation manners of some embodiments, the execution subject updates the first line of path information according to the real-time access behavior to generate the second line of path information, which may include the following steps:
[0075] Update the behavior execution status and behavior operation content included in each first line of path node in the first line of path node queue according to the real-time access behavior to generate a second line of path nodes, and obtain a second line of path node queue as the second line of path information.
[0076] In practice, since the real-time access behavior corresponds to the same behavior path as the historical access behavior, there is a one-to-one correspondence between the candidate behavior path nodes in the candidate behavior path node queue and the first line of path nodes in the first line of path node sequence. Thus, for each first line of path node in the first line of path node sequence, the execution subject can update the behavior execution status and behavior operation content included in the first line of path node according to the corresponding candidate behavior path node. In practice, the update method does not adopt an overwriting update, but an append update to record the changes for the same path node at different times.
[0077] Step 1032, generate the behavior type corresponding to the real-time access behavior according to the second line of path information and the pre-trained second malicious code recognition model.
[0078] In some embodiments, the execution subject may generate the behavior type corresponding to the real-time access behavior according to the second line of path information and the pre-trained second malicious code recognition model.
[0079] In some optional implementation manners of some embodiments, the execution subject generates the behavior type corresponding to the real-time access behavior according to the second line of path information and the pre-trained second malicious code recognition model, which may include the following steps:
[0080] First step, for each second-line path node in the above-mentioned second-line path node queue, according to the behavior execution status and behavior operation content included in the second-line path node, generate a sparse signal for the second-line path node, where the potential state in the sparse signal represents the execution status of the behavior operation content. In practice, the sparse signal can adopt a single-polarity signal coding method to represent the behavior execution status of the behavior operation content. During operation and at the end of operation, a high potential can be used. For non-operation, a low potential can be used. Since access behaviors containing malicious code often have sparsity, that is, to ensure secrecy, they often have a low access frequency, and at the same time, the access has directivity. Therefore, the second-line path node is represented in the form of a sparse signal.
[0081] Second step, perform signal compression on each sparse signal in the obtained sparse signal set to generate a compressed sparse signal, and obtain a compressed sparse signal set.
[0082] In practice, due to the high signal sparsity, especially for access behaviors containing malicious code, the above-mentioned execution entity can adopt the 0 compression method to perform signal compression on the sparse signal to generate a compressed sparse signal.
[0083] Third step, generate the above-mentioned behavior type according to the above-mentioned compressed sparse signal set and the above-mentioned second malicious code recognition model.
[0084] Among them, the second malicious code recognition model adopts a spiking neural network model. Among them, the second malicious code recognition model includes 1 input layer, M hidden layers and 1 output layer. The hidden layer contains W neurons. In practice, compared with the traditional neural network model, the calculation speed is faster, and at the same time, for access behaviors with a high zero occupancy ratio, it can better perform feature extraction to judge the corresponding behavior type.
[0085] Step 104, in response to the behavior type being the second behavior type, perform behavior control on the real-time access behavior through a honeypot.
[0086] In some embodiments, the above-mentioned execution entity can, in response to the behavior type being the second behavior type, perform behavior control on the real-time access behavior through a honeypot. In practice, the above-mentioned execution entity can deny access to the real-time access behavior.
[0087] In some optional implementation manners of some embodiments, the above-mentioned execution entity's performing behavior control on the above-mentioned real-time access behavior through a honeypot in response to the above-mentioned behavior type being the above-mentioned second behavior type may include the following steps:
[0088] First step, determine the behavior interaction degree corresponding to the above-mentioned real-time access behavior.
[0089] Among them, the above-mentioned behavior interaction degree is determined by the behavior execution status, behavior operation content, and behavior operation object corresponding to the above-mentioned real-time access behavior.
[0090] In practice, the above-mentioned execution entity can obtain it by performing a weighted sum of the behavior execution status, behavior operation content, and behavior operation object corresponding to the real-time access behavior. In practice, the behavior execution status, behavior operation content, and behavior operation object correspond to different incentive base scores. The above-mentioned execution entity can obtain the behavior interaction degree by performing a weighted sum according to the candidate behavior path nodes in the candidate behavior path node queue corresponding to the real-time access behavior.
[0091] In the second step, in response to the above-mentioned behavior interaction degree being within the first behavior interaction degree interval, redirect the above-mentioned real-time access behavior value to the first interaction honeypot.
[0092] Among them, the first interaction honeypot is a low-interaction honeypot.
[0093] In the third step, in response to the above-mentioned behavior interaction degree being within the second behavior interaction degree interval, redirect the above-mentioned real-time access behavior value to the second interaction honeypot.
[0094] Among them, the second interaction honeypot is a medium-interaction honeypot.
[0095] In the third step, in response to the above-mentioned behavior interaction degree being within the third behavior interaction degree interval, redirect the above-mentioned real-time access behavior value to the third interaction honeypot.
[0096] Among them, the above-mentioned third interaction honeypot is a high-interaction honeypot.
[0097] The above-mentioned various embodiments of the present application have the following beneficial effects: Through the malicious code recognition method based on the honeypot technology in some embodiments of the present application, the effective identification of malicious code is realized, and the effective prevention of unauthorized operations corresponding to malicious code is improved. Specifically, the reason for the inability to effectively identify malicious code is that malicious code often exists in various forms of variants, which can hide its own behavior path in a disguised form, and it is difficult to effectively identify variant malicious code by using the signature matching method, thus unable to effectively prevent unauthorized operations corresponding to malicious code. Based on this, in some embodiments of the present application, the malicious code recognition method based on the honeypot technology first determines whether there is first behavior path information corresponding to the real-time access behavior, where the above-mentioned first behavior path information represents the behavior path corresponding to the historical access behavior, and the above-mentioned real-time access behavior corresponds to the same behavior initiating node and behavior path as the above-mentioned historical access behavior. In practice, for malicious code, it often disguises itself to achieve the purpose of tampering with and collecting content in the computer operating system, so it corresponds to a corresponding behavior execution path. At the same time, for latent malicious code, its tampering and collection often have a certain frequency. Therefore, by judging whether there is first behavior path information corresponding to the real-time access behavior, it is possible to determine the access behavior with the same behavior path and the same behavior initiating node. Then, in response to the non-existence, the following first processing steps are executed: First step, generate an access behavior feature corresponding to the above-mentioned real-time access behavior. Characterize the behavior characteristics of the real-time access behavior from the feature perspective in sequence. Second step, generate a behavior type corresponding to the above-mentioned real-time access behavior according to the above-mentioned access behavior feature and the pre-trained first malicious code recognition model, where the above-mentioned behavior type includes: the first behavior type and the second behavior type, the above-mentioned first behavior type represents that the above-mentioned real-time access behavior does not contain malicious code, and the above-mentioned second behavior type represents that the above-mentioned real-time access behavior contains malicious code. When there is no first behavior path information, it can represent that the real-time access behavior is the first access behavior or a disguised access behavior. Therefore, the first malicious code recognition model and the access behavior feature can be combined to identify whether the real-time access behavior contains malicious code. Further, in response to the existence, the following second processing steps are executed: First step, update the path of the above-mentioned first behavior path information according to the above-mentioned real-time access behavior to generate second behavior path information. When there is first behavior path information, it represents that there is a historical access behavior similar to the real-time access behavior. Therefore, the first behavior path information and the real-time access behavior can be combined. Second step, generate a behavior type corresponding to the above-mentioned real-time access behavior according to the above-mentioned second behavior path information and the pre-trained second malicious code recognition model. In this way, by combining the historical access behavior and the current access behavior, from the perspective of access behaviors at different times, analyze whether the real-time access behavior contains malicious code.Finally, in response to the above behavior type being the above second behavior type, the honeypot is used to perform behavior control on the above real-time access behavior. In practice, when malicious code is included, corresponding behavior control is performed to avoid harm to the computer operating system. In this way, effective identification of malicious code is achieved, and effective prevention of unauthorized operations corresponding to malicious code is improved.
[0098] Further referring to Figure 2 , as an implementation of the methods shown in the above figures, some embodiments of the present application provide a malicious code recognition device based on honeypot technology. These device embodiments correspond to Figure 1 the method embodiments shown, and the malicious code recognition device based on honeypot technology can be specifically applied to various electronic devices.
[0099] As Figure 2 shown, some embodiments of the malicious code recognition device 200 based on honeypot technology include: a determination unit 201, a first execution unit 202, a second execution unit 203, and a behavior control unit 204. Among them, the determination unit 201 is configured to determine whether there is first behavior path information corresponding to the real-time access behavior, where the above first behavior path information represents the behavior path corresponding to the historical access behavior, and the above real-time access behavior corresponds to the same behavior initiation node and behavior path as the above historical access behavior; the first execution unit 202 is configured to, in response to the non-existence, perform the following first processing steps: generate an access behavior feature corresponding to the above real-time access behavior; generate a behavior type corresponding to the above real-time access behavior according to the above access behavior feature and a pre-trained first malicious code recognition model, where the above behavior type includes: a first behavior type and a second behavior type, the above first behavior type represents that the above real-time access behavior does not contain malicious code, and the above second behavior type represents that the above real-time access behavior contains malicious code; the second execution unit 203 is configured to, in response to the existence, perform the following second processing steps: update the path of the above first behavior path information according to the above real-time access behavior to generate second behavior path information; generate a behavior type corresponding to the above real-time access behavior according to the above second behavior path information and a pre-trained second malicious code recognition model; the behavior control unit 204 is configured to, in response to the above behavior type being the above second behavior type, perform behavior control on the above real-time access behavior through the honeypot.
[0100] It can be understood that the various units described in the malicious code recognition device 200 based on honeypot technology correspond to the respective steps in the method described with reference to Figure 1 Therefore, the operations, features, and beneficial effects described above for the method also apply to the malicious code recognition device 200 based on honeypot technology and the units included therein, and will not be repeated here.
[0101] Figure 3 This is a schematic block diagram of the structure of an electronic device provided by an embodiment of the present application. The electronic device may be a terminal.
[0102] As Figure 3 shown, the electronic device includes a processor, a memory, and a network interface connected through a system bus. Among them, the memory may include a non-volatile storage medium and an internal memory.
[0103] The non-volatile storage medium can store an operating system and a computer program. The computer program includes program instructions, and when the program instructions are executed, the processor can be made to execute any malicious code recognition method based on the honeypot technology.
[0104] The processor is used to provide computing and control capabilities to support the operation of the entire electronic device.
[0105] The internal memory provides an environment for the operation of the computer program in the non-volatile storage medium. When the computer program is executed by the processor, the processor can be made to execute any malicious code recognition method based on the honeypot technology.
[0106] The network interface is used for network communication, such as sending assigned tasks, etc. Those skilled in the art can understand that Figure 3 the structure shown in
[0107] It should be understood that the processor may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0108] Among them, in one embodiment, the above-mentioned processor is used to run a computer program stored in a memory to implement the following steps: determining whether there is first behavior path information corresponding to a real-time access behavior, where the first behavior path information characterizes a behavior path corresponding to a historical access behavior, and the real-time access behavior and the historical access behavior correspond to the same behavior initiation node and behavior path; in response to the non-existence, performing the following first processing steps: generating an access behavior feature corresponding to the real-time access behavior; generating a behavior type corresponding to the real-time access behavior according to the access behavior feature and a pre-trained first malicious code recognition model, where the behavior type includes: a first behavior type and a second behavior type, the first behavior type indicates that the real-time access behavior does not contain malicious code, and the second behavior type indicates that the real-time access behavior contains malicious code; in response to the existence, performing the following second processing steps: updating the path of the first behavior path information according to the real-time access behavior to generate second behavior path information; generating a behavior type corresponding to the real-time access behavior according to the second behavior path information and a pre-trained second malicious code recognition model; in response to the behavior type being the second behavior type, performing behavior control on the real-time access behavior through a honeypot.
[0109] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and the computer program includes program instructions, and the method implemented when the program instructions are executed can refer to various embodiments of the malicious code recognition method based on the honeypot technology of the present application.
[0110] Among them, the computer-readable storage medium may be an internal storage unit of the electronic device in the foregoing embodiment, such as a hard disk or memory of the electronic device. The computer-readable storage medium may also be an external storage device of the electronic device, such as a plug-in hard disk equipped on the electronic device, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc.
[0111] It should be noted that in this article, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or system. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or system including that element.
[0112] The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages or disadvantages of the embodiments. The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A malicious code identification method based on honeypot technology, comprising: Determine whether there is first behavior path information corresponding to the real-time access behavior, wherein the first behavior path information represents the behavior path corresponding to the historical access behavior, the real-time access behavior and the historical access behavior correspond to the same behavior initiation node and behavior path, and the behavior path represents each specific access behavior of the historical access behavior in time sequence; In response to not being present, the following first processing steps are performed: Generating access behavior features corresponding to the real-time access behavior; According to the access behavior characteristics and the pre-trained first malicious code recognition model, a behavior type corresponding to the real-time access behavior is generated, wherein the behavior type includes: a first behavior type and a second behavior type, the first behavior type characterizes that the real-time access behavior does not contain malicious code, and the second behavior type characterizes that the real-time access behavior contains malicious code, wherein the first malicious code recognition model includes: an access behavior feature extractor and a malicious code classifier, the malicious code classifier includes K deep feature extractors, a feature stacking layer and a binary classifier, wherein the network structures of the K deep feature extractors are the same and are arranged in parallel, and the K deep feature extractors are connected with 1 feature stacking layer for implementing A dd operation, to perform feature superposition on the features output by the K deep feature extractors, a binary classifier is used to output the behavior type, and the access behavior feature extractor includes: an instruction feature extractor for extracting instruction features from assembly instructions, an environment feature extractor for extracting indicator features from key execution indicators in the behavior execution environment, an operation content extraction model for extracting operation content from the behavior operation content, a first upsampling network for upsampling the instruction feature set, a second upsampling network for upsampling the environment feature, a third upsampling network for upsampling the behavior execution state vector, and a fourth upsampling network for upsampling the operation content feature; In response to existence, the following second processing step is performed: According to the real-time access behavior, updating the first behavior path information to generate second behavior path information; generating a behavior type corresponding to the real-time access behavior according to the second behavior path information and a pre-trained second malicious code recognition model; In response to the behavior type being the second behavior type, the real-time access behavior is controlled through a honeypot, wherein: The generating, according to the second behavior path information and a pre-trained second malicious code recognition model, a behavior type corresponding to the real-time access behavior includes: For each second behavior path node in the second behavior path node queue, a sparse signal for the second behavior path node is generated according to the behavior execution state and behavior operation content included in the second behavior path node, wherein the potential state in the sparse signal represents the execution state for the behavior operation content, and the sparse signal adopts a unipolar signal encoding method to represent the behavior execution state for the behavior operation content; a high potential is used when the operation is in progress and the operation is completed; and a low potential is used when the operation is not in progress; Performing signal compression on each sparse signal in the obtained sparse signal set to generate a compressed sparse signal, thereby obtaining a compressed sparse signal set; The behavior type is generated according to the compressed sparse signal set and the second malicious code recognition model.
2. The method according to claim 1, wherein: The determining whether there is first behavior path information corresponding to the real-time access behavior includes: activating a target container, wherein the target container is an isolation container; In response to successful activation, the real-time access behavior is executed in the target container, and the execution content of the real-time access behavior is recorded as candidate behavior path information, wherein the candidate behavior path information includes: a candidate behavior path node queue, wherein the candidate behavior nodes in the candidate behavior path node queue include: a behavior command, a behavior execution environment, a behavior execution state, and a behavior operation content; Based on the candidate behavior node sequence, the following path finding steps are performed: Determine the candidate behavior path node at the head of the candidate behavior path node queue as the target behavior path node; According to the behavior command, behavior execution environment and behavior execution state included in the target behavior path node, traverse the behavior path graph to determine whether the target behavior path node is included in the behavior path graph, wherein the behavior path graph is a directed graph generated according to different access behaviors; In response to the absence of the first behavior path information, generating a determination result indicating that the first behavior path information does not exist; In response to the candidate behavior node sequence existing and excluding the target behavior path node being empty, generating a determination result indicating the existence of the first behavior path information; In response to the candidate behavior node sequence excluding the target behavior path node existing and not empty, the candidate behavior node sequence excluding the target behavior path node is used as the candidate behavior node sequence, and the path search step is performed again.
3. The method according to claim 2, wherein: The generating of the access behavior feature corresponding to the real-time access behavior includes: For each candidate behavior path node in the candidate behavior path node queue, perform the following feature processing steps: Disassembling the behavior commands included in the candidate behavior path node to generate an assembly instruction set; Extracting instruction features from each assembly instruction in the assembly instruction set to generate instruction features and obtain an instruction feature set; Extracting environmental features of the behavior execution environment included in the candidate behavior path node to obtain environmental features; Performing state mapping on the behavior execution state included in the candidate behavior path node to obtain a behavior execution state vector; Extracting operation contents of the behavior operation contents included in the candidate behavior path nodes to generate operation content features; Performing feature mapping on the instruction feature set, the environment feature, the behavior execution state vector, and the operation content feature to obtain mapped features; The mapped features in the obtained mapped feature set are concatenated to obtain a mapped feature graph for the real-time access behavior as the access behavior feature.
4. The method according to claim 3, wherein: The generating, according to the access behavior feature and the pre-trained first malicious code recognition model, a behavior type corresponding to the real-time access behavior comprises: According to the input size of the malicious code classifier, the access behavior feature is segmented into a horizontal feature graph to obtain a candidate sub-access behavior feature set; According to the input size, performing zero-filling on each candidate sub-access behavior feature in the candidate sub-access behavior feature set to generate a sub-access behavior feature, thereby obtaining a sub-access behavior feature set, wherein the feature size of the sub-access behavior features in the sub-access behavior feature set is consistent with the input size; The behavior type is generated according to the sub-access behavior feature set and the malicious code classifier.
5. A malicious code identification device based on honeypot technology, comprising: a determining unit configured to determine whether there is first behavior path information corresponding to the real-time access behavior, wherein the first behavior path information represents a behavior path corresponding to the historical access behavior, the real-time access behavior and the historical access behavior correspond to the same behavior initiation node and behavior path, and the behavior path represents each specific access behavior of the historical access behavior in a time sequence; The first execution unit is configured to, in response to the absence, perform the following first processing step: generate an access behavior feature corresponding to the real-time access behavior; generate a behavior type corresponding to the real-time access behavior based on the access behavior feature and a pre-trained first malicious code recognition model, wherein the behavior type includes: a first behavior type and a second behavior type, the first behavior type characterizing that the real-time access behavior does not contain malicious code, and the second behavior type characterizing that the real-time access behavior contains malicious code, wherein the first malicious code recognition model includes: an access behavior feature extractor and a malicious code classifier, the malicious code classifier includes K deep feature extractors, a feature overlay layer and a binary classifier, wherein the network structures of the K deep feature extractors are the same and are set in parallel , K deep feature extractors are connected with a feature stacking layer for implementing Add operation to stack the features output by the K deep feature extractors, a binary classifier is used to output the behavior type, and the access behavior feature extractor includes: an instruction feature extractor for extracting instruction features from assembly instructions, an environment feature extractor for extracting indicator features from key execution indicators in the behavior execution environment, an operation content extraction model for extracting operation content from the behavior operation content, a first upsampling network for upsampling the instruction feature set, a second upsampling network for upsampling the environment feature, a third upsampling network for upsampling the behavior execution state vector, and a fourth upsampling network for upsampling the operation content feature; The second execution unit is configured to, in response to the existence, perform the following second processing steps: according to the real-time access behavior, update the first behavior path information to generate second behavior path information; according to the second behavior path information and a pre-trained second malicious code recognition model, generate a behavior type corresponding to the real-time access behavior; A behavior control unit is configured to perform behavior control on the real-time access behavior through a honeypot in response to the behavior type being the second behavior type, wherein: The generating, according to the second behavior path information and a pre-trained second malicious code recognition model, a behavior type corresponding to the real-time access behavior includes: For each second behavior path node in the second behavior path node queue, a sparse signal for the second behavior path node is generated according to the behavior execution state and behavior operation content included in the second behavior path node, wherein the potential state in the sparse signal represents the execution state for the behavior operation content, and the sparse signal adopts a unipolar signal encoding method to represent the behavior execution state for the behavior operation content; a high potential is used when the operation is in progress and the operation is completed; and a low potential is used when the operation is not in progress; Performing signal compression on each sparse signal in the obtained sparse signal set to generate a compressed sparse signal, thereby obtaining a compressed sparse signal set; The behavior type is generated according to the compressed sparse signal set and the second malicious code recognition model.
6. An electronic device, wherein: The electronic device comprises a processor, a memory, and a computer program stored in the memory and executable by the processor, wherein when the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 4 are implemented.
7. A computer-readable storage medium, wherein: The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
Identification method and device of application access request and computer equipment
CN115913707A
Honeynet-based abnormal traffic processing method and device, computer equipment and storage medium
CN117978474A