Method for Tracking Processes Created by Windows Task Scheduler
By injecting dynamic connection libraries into the task planning service process and hooking up the event tracking API, obtaining and building a task context, the problem of inability to accurately track task schedulers and process creation in the existing technology is solved, and the accuracy of malicious code analysis and system security are improved.
Patent Information
- Application Number
- CN202411401374.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-09
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2044-10-09
AI Technical Summary
The prior art is difficult to track and correlate the creation of Windows task schedulers and their operations in real time and accurately, resulting in malware being able to avoid defense systems and poses security risks.
By injecting a dynamic connection library containing a context marshaling module into the task schedule service process, hooking the Windows event tracking API and hooking functions, obtaining and building the thread's task context, the security proxy module operates during process creation.
It realizes accurate capture of the task creation process, improves the accuracy of malicious code behavior analysis, reduces system impact and association analysis consumption, and avoids false alarms when the process of the same name is started concurrently.
Smart Images

Figure CN119416199B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and specifically relates to a method for tracking the creation process of Windows Task Scheduler, an electronic device, and a corresponding storage medium. Background Art
[0002] The Task Scheduler can be executed automatically, so it is often exploited by malware to achieve goals such as resident, execution, and privilege elevation. In addition, according to the above description of the implementation mechanism of the Task Scheduler service, simply analyzing from the process creation relationship, it is impossible to associate the Task Scheduler with the process creation specified by its operation. This feature can also be exploited by malware to achieve defense evasion actions.
[0003] For example: The malicious program A.exe creates 2 task schedules and then closes: Task-1: When the system is idle, start PowerShell.exe, and specify a download script in its command line to download the malicious program B.exe from a certain site. Task-2: When the system starts, run the malicious program B.exe. When the system is idle, Task-1 is executed, and the Task Scheduler service process starts the powershell.exe process (svchost.exe -> powershell.exe) and downloads B.exe. The next time the system logs in, Task-2 is executed, and the Task Scheduler service process starts B.exe. (svchost.exe -> B.exe) In the above process, from the perspective of file creation and process start relationships (the analysis of these two relationships is the most commonly used means in the defense system), neither A.exe nor B.exe is directly associated. Attackers can use this mechanism to disperse a set of malicious behaviors into multiple task schedules for execution, and the execution of each task is not sufficient to trigger an alarm in the defense system, thus achieving the goal of evading defense.
[0004] Even if it is possible to capture the creation operation of the task schedule by some means, only a connection can be established between A.exe and Task-1, Task-2, but the direct association between Task-2 and B.exe is still missing. When svchost.exe starts B.exe, even if the process creation notification is captured at the kernel level and through call stack analysis, it can be determined that B.exe is started by the Task Scheduler service process (when Windows runs, there are multiple svchost.exe processes, each carrying different groups of system services), it is impossible to know which specific task triggered it, posing a huge security risk.
[0005] There are some methods in the prior art that collect events by means of ETW, but they have problems such as post-event analysis, inability to support real-time, incomplete trigger information, and inability to ensure accurate task-process association. Summary of the Invention
[0006] The objective of the embodiments of the present application is to provide a method for tracking the process creation of the Windows Task Scheduler. Through the analysis of schedsvc.dll and ubmp.dll, it can be determined that event tracking-related processing will be performed before and after the task starts a process, so as to solve at least some of the problems in the background technology.
[0007] To achieve the above objective, the present application provides a method for tracking the process creation of the Windows Task Scheduler. The method includes: injecting a dynamic link library containing a context marshaling module into the task scheduler service process, and hooking the event tracking API in Windows Event Tracking with the hook function in the context marshaling module through the dynamic link library; obtaining the parameter information in the event tracking API called by the unified background process manager of the system through the hook function, and constructing the task context of the thread based on the parameter information; when the security proxy module receives a callback for process creation, perform the following operations: determine whether the task context of the thread exists, and when the thread has a task context, operate on the created process according to the task context.
[0008] Optionally, there are multiple event tracking APIs and the hook functions. The event tracking APIs are correspondingly hooked with the hook functions in the context marshaling module.
[0009] Optionally, the event tracking API includes: the API used by the unified background process manager to register a Windows Event Tracking provider, the API used by the unified background process manager to determine whether a specified event needs to be published, and the API used by the unified background process manager to publish an event.
[0010] Optionally, the event tracking API is the API related to event tracking in the NTDLL.DLL library; the API used to register a Windows Event Tracking provider is EtwEventRegister, the API used to determine whether a specified event needs to be published is EtwEventEnabled, and the API used to publish an event is EtwEventWrite.
[0011] Optionally, obtaining the parameter information in the event tracking API called by the unified background process manager of the system through the hook function includes: when the event tracking API is called by the unified background process manager, enter the hook function corresponding to the event tracking API; obtain the parameter information in the event tracking API through the hook function corresponding to the event tracking API.
[0012] Optionally, parameter information in an event tracking API called by the unified background process manager of the system is obtained through the hook function, and a task context of a thread is constructed based on the parameter information, including: obtaining a globally unique identifier from an API for registering a Windows event tracing provider, and saving a first handle returned by the API for registering the Windows event tracing provider when the globally unique identifier is the specific value; obtaining a second handle and a first event publishing identifier from an API for determining whether a specified event needs to be published, and performing a next step when the second handle is the same as the first handle and the first event publishing identifier is a trigger event; obtaining a third handle, a second event publishing identifier, and event information from an API for publishing an event, and extracting a full path of a task from the event information when the third handle is the same as the first handle and the second event publishing identifier is a trigger event, and constructing the task context from the full path of the task.
[0013] Optionally, after constructing the task context of the thread based on the parameter information, the method further includes: setting the task context to the current thread; wherein setting the task context to the current thread includes: directly setting the task context to a specific field of the current thread structure or setting it through an external thread-to-task context mapping structure to associate the task context with the current thread.
[0014] Optionally, operations in operating on a created process according to the task context include: a blocking operation, a release operation, or sending an audit message determined according to a preset policy.
[0015] Optionally, the method further includes: clearing the constructed context when an API for determining whether a specified event needs to be published is called to publish an action result event of a task.
[0016] In this application, a device for tracking a process created by a Windows Task Scheduler is further provided. The device includes: an injection hook module for injecting a dynamic link library including a context marshaling module into a task scheduler service process, and hooking an event tracking API in Windows event tracing with a hook function in the context marshaling module through the dynamic link library; an obtaining and constructing module for obtaining parameter information in the event tracking API called by the unified background process manager of the system through the hook function, and constructing a task context of a thread based on the parameter information; a judging and executing module for implementing the following operations when a security proxy module receives a callback of process creation: judging whether a task context of a thread exists, and operating on the created process according to the task context when a task context of the thread exists.
[0017] In this application, an electronic device is further provided, including: at least one processor; a memory connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the at least one processor implements the foregoing method for tracking the process creation of the Windows Task Scheduler by executing the instructions stored in the memory.
[0018] In this application, a machine-readable storage medium is further provided. Instructions are stored on the machine-readable storage medium, and when the instructions are executed by a processor, the processor is configured to execute the method for tracking the process creation of the Windows Task Scheduler as described above.
[0019] In this application, a computer program product is further provided, including a computer program which, when executed by a processor, implements the foregoing method for tracking the process creation of the Windows Task Scheduler.
[0020] The above technical solutions have the following beneficial effects:
[0021] By using the task management mechanism inside Windows and injecting into the context marshaling module of the Task Scheduler service process, the precise capture of the action of "task creation process" is realized, thereby improving the accuracy of malicious code behavior analysis.
[0022] Other features and advantages of the embodiments of this application will be described in detail in the subsequent specific implementation part. Description of the Drawings
[0023] The drawings are used to provide a further understanding of the embodiments of this application, and constitute a part of the specification. Together with the following specific implementation, they are used to explain the embodiments of this application, but do not constitute a limitation to the embodiments of this application. In the drawings:
[0024] Figure 1 Schematically shows a schematic diagram of the steps of the method for tracking the process creation of the Windows Task Scheduler according to an embodiment of this application;
[0025] Figure 2 Schematically shows a schematic diagram of the implementation process of the method for tracking the process creation of the Windows Task Scheduler according to an embodiment of this application;
[0026] Figure 3 Schematically shows a schematic diagram of the structure of the device for tracking the process creation of the Windows Task Scheduler according to an embodiment of this application;
[0027] Figure 4 Schematically shows the internal structure diagram of the electronic device according to an embodiment of this application. Detailed Description of the Invention
[0028] The following will describe in detail the specific implementation manners of the embodiments of the present application in conjunction with the accompanying drawings. It should be understood that the specific implementation manners described herein are only used to illustrate and explain the embodiments of the present application, and are not used to limit the embodiments of the present application.
[0029] Figure 1 Schematically shows a schematic diagram of the steps of a method for tracking the process creation of the Windows Task Scheduler according to an embodiment of the present application. As Figure 1 shown, a method for tracking the process creation of the Windows Task Scheduler includes:
[0030] S01. Inject a dynamic link library (DLL, Dynamic Link Library) containing a context marshaling module into the task scheduler service process, and hook the event tracing API (Application Programming Interface) in Event Tracing for Windows (ETW) with the hook function in the context marshaling module through the dynamic link library;
[0031] S02. Obtain the parameter information in the event tracing API called by the unified background process manager of the system through the hook function, and construct the task context of the thread based on the parameter information;
[0032] S03. When the security proxy module receives a callback for process creation, perform the following operations: determine whether the task context of the thread exists, and when the task context of the thread exists, operate on the created process according to the task context.
[0033] In this embodiment, the task context marshaling module is injected into the service process. Here, the injection refers to loading a dynamic link library (DLL) into the process and executing it. There are various implementation methods, and the present application does not limit the injection method.
[0034] The task context marshaling module is a dynamic link library injected into the task scheduler service process, which mainly hooks the ETW-related APIs. The purpose is to extract task information when the UBPM module publishes a specified event, construct a task context and attach it to the current thread for the security proxy to query the task information when the process is created.
[0035] The security proxy module, preferably running in the kernel layer, queries the task information in the thread context after capturing the process creation notification, and performs filtering and other processing on the action of the task scheduler to start the process.
[0036] The task context refers to the detailed information of the task as the subject, which can be a pointer to a data structure encapsulating the task details or an identification number of the task in an external database.
[0037] This application is implemented based on the Unified Background Process Manager (UBPM) provided by the Windows system. However, due to different Windows versions, the unified background management function of the unified background process manager may be implemented by other functional modules. For example, in the case of early systems such as Windows 7 where the UBPM module is not used to maintain tasks, the same ETW hook processing can be performed on taskeng.exe to achieve the same technical effect, and this application does not make any limitations in this regard.
[0038] Through the above implementation manners, by using the task management mechanism inside Windows and injecting it into the context marshaling module of the task scheduler service process, the precise capture of the "task creation process" action is achieved, thereby improving the accuracy of malicious code behavior analysis.
[0039] The data capture in this implementation manner accompanies the task creation process, and has good real-time performance compared with the ex-post audit system. At the same time, it has little impact on the system and reduces the consumption of correlation analysis. And it is distinguished based on the process management mechanism inside the system, avoiding false alarms when concurrent processes with the same name are started.
[0040] In some implementation manners of this application, there are multiple event tracing APIs, and the event tracing APIs are correspondingly hooked to the hook functions in the context marshaling module. The event tracing APIs include: the event tracing API called by the system's unified background process manager to register events, the event tracing API called by the system's unified background process manager to determine whether to publish a specified event, and the event tracing API used by the system's unified background process manager to publish events. As a standard component of Windows, the task scheduler service has built-in support for ETW (Event Tracing for Windows). In terms of role, it implements both a controller and a provider, and the provider implemented by itself will be automatically enabled when the service is started. For the convenience of understanding and implementation by those skilled in the art, the event tracing APIs involved in this application are described as follows.
[0041] As a provider, the executor of the task scheduling service, including schedsvc.dll and ubpm.dll, calls EventRegister to register an event with the GUID {DE7B24EA-73C8-4A09-985D-5BDADCFA9017}. Before and after performing task operations, ubpm.dll will attempt to publish corresponding events: first call EventEnabled to determine whether there are consumers subscribed to such events, and if the return value is TRUE, then call EventWrite to write the event. Specifically: before task execution, it will attempt to publish a specified event, such as a trigger event. The ID of the event indicates the type of trigger (for example: 0x6b corresponds to a time trigger, 0x77 corresponds to a logon event trigger...). When calling EventEnabled, the description of the event is specified. When calling EventWrite, the full name of the task (such as the aforementioned Task-1) will be specified in the first parameter. Perform the operations specified by the task, that is, start the process specified by the task (such as the aforementioned B.exe). After task execution, it will attempt to publish result events, such as successful action execution (0xC9), execution failure (0xCA).
[0042] Furthermore, the event tracking API is the API related to event tracking in the NTDLL.DLL library; NTDLL.DLL is an important Windows NT kernel-level file that describes the interfaces of the windows native NTAPI. When Windows starts, ntdll.dll resides in a specific write-protected area of memory, preventing other programs from occupying this memory area. In the Windows system, the API for registering Windows event tracking providers is EtwEventRegister, the API for determining whether a specified event needs to be published is EtwEventEnabled, and the API for publishing events is EtwEventWrite.
[0043] In some embodiments of the present application, parameter information in the event tracking API called by the unified background process manager of the system is obtained through the hook function, including: when the event tracking API is called by the unified background process manager, entering the hook function corresponding to the event tracking API; obtaining the parameter information in the event tracking API through the hook function corresponding to the event tracking API. The hook function (Hook Function) hooked to the foregoing event tracking API can be designed as follows. The hook function includes the OnEventRegister function, the OnEventEnabled function, and the OnEventWrite function. The names of the foregoing hook functions are only examples, and the function names are not limited during implementation. Hook EtwEven tRegister to the OnEventRegister function, hook EtwEventEnabled to the OnEventEnable d function, and hook EtwEventWrite to the OnEventWrite function. For example, when EtwEventRegi ster is called, it will enter the hook function OnEventRegister, obtain the parameters in EtwEventRegist er, and execute its own functions.
[0044] In some embodiments of the present application, a globally unique identifier is obtained from an API for registering a Windows Event Tracing provider. When the globally unique identifier is the specific value, the first handle returned by the API for registering the Windows Event Tracing provider is saved; a second handle and a first event publishing identifier are obtained from an API for determining whether a specified event needs to be published. When the second handle is the same as the first handle and the first event publishing identifier is a trigger event, further processing is performed; a third handle, a second event publishing identifier, and event information are obtained from an API for publishing an event. When the third handle is the same as the first handle and the second event publishing identifier is a trigger event, the full path of the task is extracted from the event information, and the task context is constructed from the full path of the task. Exemplarily, when EtwEventRegister is called, the hook function OnEventRegister is entered, and the parameter GUID (globally unique identifier) in EtwEventRegister is obtained. When the globally unique identifier is the specific value, where the specific value is the aforementioned {DE7B24EA-73C8-4A09-985D-5BDADCFA9017}, the handle returned by twEventRegister is retained, denoted as the first handle, as a precondition for determining whether processing is required when subsequently entering the OnEventEnabled and OnEventWrite functions. When EtwEventEnabled is called, the hook function OnEventEnabled is entered, and the event handle and the event publishing identifier in EtwEventEnabled are obtained, that is, the second handle and the event publishing ID. When the second handle is the same as the first handle and the first event publishing identifier is a trigger event (ID == 0x6B, 0x6D, 0x72, 0x76, 0x77...), TURE is forcibly returned; otherwise, no processing is performed. When EtwEventWrite is called, the hook function OnEventWrite is entered. First, it is determined whether the event handle, that is, the third handle, is the same as the first handle. If they are the same, it is then determined whether the event publishing ID, that is, the second event publishing identifier, is a trigger event (ID == 0x6B, 0x6D, 0x72, 0x76, 0x77...). If both conditions are met, the full path of the task can be extracted from the data parameters of the event, and a task context is constructed from the full path of the task.
[0045] In some embodiments of the present application, after constructing the task context of a thread based on the parameter information, the method further includes: setting the task context to the thread. This embodiment mainly provides a method for associating a runtime task with a thread. The task context can be set to the thread in the following ways, for example: directly setting the task context to a specific field of the thread structure, such as the ArbitraryUserPointer of the thread TIB structure; or through an external thread-to-task context mapping structure.
[0046] In some embodiments of the present application, the operations in operating on the created process according to the task context include: blocking operations, allowing operations, or sending audit messages determined according to a preset policy. When UBPM starts a process in a task action, the security proxy module in the kernel layer will receive a callback for process creation. The security proxy module can attempt to extract the task context associated with the current thread. If the task context exists, it indicates that the newly created process is created by a task plan, and operations can be performed according to the preset policy. This operation can be a filtering operation, such as a blocking operation, an allowing operation, or sending an audit message. The method for extracting the task context here depends on the foregoing setting method, for example, from the ArbitraryUserPointer pointer of the current thread TIB structure, or querying the thread-to-task context mapping.
[0047] In some embodiments of the present application, the method further includes: clearing the constructed context when an event tracking API for determining whether a specified event needs to be published is called to publish an action result event of a task. Whether the process creation is successful or not, UBPM will call EtwEventEnabled to attempt to publish an action result event of the task, and thus enter the hook function OnEventEnabled. In OnEventEnabled, first determine whether the event handle is the same as the foregoing first handle. If it is the same, then continue to determine whether the ID of the published event is an action result event (ID == 0xC9, 0xCA, 0xCB...). If both conditions are met, task context clearing processing is performed; otherwise, no processing is done. The method for clearing the task context corresponds to the foregoing setting method. For example, restore the ArbitraryUserPointer pointer of the current thread TIB structure, or delete the thread-to-task context mapping.
[0048] Figure 2 Schematically shows a schematic diagram of the implementation process of a method for tracking the creation of a process by the Windows Task Scheduler according to an embodiment of the present application. As Figure 2 shown, this embodiment is based on a task context marshaling module 101 and a security proxy module 102, and its implementation process includes:
[0049] 1. Injection. When the task scheduler service process starts, the task context marshaling module 101 is injected into the service process. Here, "injection" means loading a dynamic link library (DLL) into the process and executing it. There are multiple implementation methods, and this application does not limit the injection method. When the task context marshaling module 101 initially executes, it hooks several API related to event tracking in the NTDLL.DLL library, mainly including: hooking EtwEventRegister to the OnEventRegister function 201, hooking EtwEventEnabled to the OnEventEnabled function 202, and hooking EtwEventWrite to the OnEventWrite function 203.
[0050] 2. When registering event types, filtering trigger events, and writing trigger events in Ubpm.dll, the corresponding hook functions are performed and executed.
[0051] 3. The OnEventWrite function 203 generates a task context.
[0052] 4. After receiving the process start notification, the security proxy module filters the task-process based on the read task context.
[0053] 5. The OnEventEnabled function 202 clears the set task context after receiving the result event filtering.
[0054] Through the above implementation manners, in the continuous process of publishing a specified event, creating a process, and publishing an action result event in the task scheduler service, corresponding operations such as capturing task information, setting context, and clearing context are completed. Thus, the precise capture of the action of "task creating a process" is achieved, and further, the accuracy of malicious code behavior analysis is improved. At the same time, compared with the post-audit system, it has advantages such as real-time access control, reducing the consumption of correlation analysis, and avoiding false alarms when concurrent startup of processes with the same name occurs.
[0055] Based on the same inventive concept, this application also provides a device for tracking the process creation by the Windows Task Scheduler. Figure 3 Schematically shows the structural schematic diagram of the device for tracking the process creation by the Windows Task Scheduler according to the embodiment of this application. As Figure 3As shown, the device includes: an injection hook module for injecting a dynamic link library containing a context marshaling module into the task scheduler service process, and hooking the event tracing API in Windows Event Tracing with the hook function in the context marshaling module through the dynamic link library; an acquisition and construction module for obtaining parameter information in the event tracing API called by the system's unified background process manager through the hook function, and constructing the task context of a thread based on the parameter information; a judgment and execution module for the security proxy module to perform the following operations when receiving a callback for process creation: judging whether the task context of the thread exists, and operating on the created process according to the task context when the task context of the thread exists.
[0056] In some alternative embodiments of the present application, there are multiple event tracing APIs and the hook functions, and the event tracing APIs are correspondingly hooked with the hook functions in the context marshaling module.
[0057] In some alternative embodiments, the event tracing API includes: an API for the unified background process manager to register a Windows event tracing provider, an API for the unified background process manager to judge whether a specified event needs to be published, and an API for the unified background process manager to publish an event.
[0058] In some alternative embodiments, the event tracing API is the API related to event tracing in the NTDLL.DLL library; the API for registering a Windows event tracing provider is EtwEventRegister, the API for judging whether a specified event needs to be published is EtwEventEnabled, and the API for publishing an event is EtwEventWrite.
[0059] In some alternative embodiments, obtaining parameter information in the event tracing API called by the system's unified background process manager through the hook function includes: when the event tracing API is called by the unified background process manager, entering the hook function corresponding to the event tracing API; and obtaining parameter information in the event tracing API through the hook function corresponding to the event tracing API.
[0060] In some alternative embodiments, parameter information in an event tracking API called by the unified background process manager of the system is obtained through the hook function, and a task context of a thread is constructed based on the parameter information, including: obtaining a globally unique identifier from an API for registering a Windows event tracing provider, and saving a first handle returned by the API for registering the Windows event tracing provider when the globally unique identifier is the specific value; obtaining a second handle and a first event publishing identifier from an API for determining whether a specified event needs to be published, and performing a next step when the second handle is the same as the first handle and the first event publishing identifier is a trigger event; obtaining a third handle, a second event publishing identifier, and event information from an API for publishing an event, and extracting a full path of a task from the event information when the third handle is the same as the first handle and the second event publishing identifier is a trigger event, and constructing the task context from the full path of the task.
[0061] In some alternative embodiments, after constructing the task context of the thread based on the parameter information, the method further includes: setting the task context to the current thread; wherein setting the task context to the current thread includes directly setting the task context to a specific field of the current thread structure or setting it through an external thread-to-task context mapping structure to associate the task context with the current thread.
[0062] In some alternative embodiments, operations in operating on a created process according to the task context include: a blocking operation, a release operation, or sending an audit message determined according to a preset policy.
[0063] In some alternative embodiments of the present application, the device further includes a clearing module, which is configured to clear the constructed context when an event tracking API for determining whether a specified event needs to be published is called to publish an action result event of a task.
[0064] Specific definitions of the various functional modules in the above device for tracking the creation of a process by the Windows Task Scheduler can be referred to the definitions of the method for tracking the creation of a process by the Windows Task Scheduler in the foregoing, and will not be elaborated herein. Each module in the above system can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in or independent of a processor in an electronic device in a hardware form, or stored in a memory in the electronic device in a software form, so that the processor can call and execute operations corresponding to the above respective modules. It also precisely captures the action of "task creating a process", and at the same time has advantages such as real-time access control, reducing the consumption of correlation analysis, and avoiding false alarms of processes with the same name.
[0065] The implementation modes in this application can solve problems such as broken chains in traceability analysis in existing systems. For example, in some existing systems, there are basic components such as a complete task plan database, a process injection dynamic library in the kernel layer, process callback notification processing, and a kernel layer filtering engine. Before applying the method proposed in this application, the existing system can capture operations such as the creation, deletion, and modification of task plans, and can also track the creation of processes and the real-time risk behavior assessment during process execution. However, it cannot capture the process of creating a task plan, which will cause a broken chain in traceability analysis in some scenarios. After applying the method proposed in this application, the problem is solved. In this product, the implementation method is basically the same as that described in detail. Here, only the selection of related technologies is described:
[0066] Injection method of the task context marshaling module: It is completed by the kernel layer components of the existing system. When it captures that svchost.exe loads schedsvc.dll, the task context marshaling module (schestub.dll) is loaded into the process space, and the ETW function hook processing in the foregoing steps is completed.
[0067] Construction method of the task context: Use the full path of the task to query the integer ID of the task in the database from the task plan database of the existing system.
[0068] Based on the association method between the task context and the thread, use the ArbitraryUserPointer pointer of the thread TIB structure to complete the setting of the task context (database ID).
[0069] In the security proxy module in the kernel layer, when a process creation callback is captured, obtain the task identifier from the ArbitraryUserPointer pointer of the current thread TIB. If it exists, construct an event with the task as the subject and the process as the object, and send it to the filtering engine for processing. The filtering engine processes it according to the filtering policy.
[0070] It can be seen that the system applying the method or device in this application can avoid the broken chain in traceability analysis caused by the inability to capture the process of creating a task plan, thereby improving the security of the system.
[0071] In some implementation modes of this application, an electronic device is also provided, including: at least one processor; a memory connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the at least one processor executes the foregoing method for tracking the creation process of the Windows task scheduler. Its internal structure diagram can be as Figure 4 shown. Figure 4Schematically shown is an internal structural diagram of an electronic device according to an embodiment of the present application. The electronic device includes a processor A01, a network interface A02, a memory (not shown in the figure), and a database (not shown in the figure) connected through a system bus. Among them, the processor A01 of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes an internal memory A03 and a non-volatile storage medium A04. The non-volatile storage medium A04 stores an operating system B01, a computer program B02, and a database (not shown in the figure). The internal memory A03 provides an environment for the operation of the operating system B01 and the computer program B02 in the non-volatile storage medium A04. The network interface A02 of the electronic device is used to communicate with an external terminal through a network connection. When the computer program B02 is executed by the processor A01, it realizes a method for tracking the process of creating a Windows Task Scheduler.
[0072] Those skilled in the art can understand that Figure 4 the structure shown in is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the electronic device to which the solution of the present application is applied. The specific electronic device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0073] In an embodiment provided by the present application, a machine-readable storage medium is provided. Instructions are stored on the machine-readable storage medium, and when the instructions are executed by a processor, the processor is configured to execute the aforementioned method for tracking the process of creating a Windows Task Scheduler.
[0074] In an embodiment provided by the present application, a computer program product is provided, including a computer program that realizes the aforementioned method for tracking the process of creating a Windows Task Scheduler when executed by a processor.
[0075] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0076] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and combinations of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing device generate means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0077] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means that implement the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0078] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0079] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0080] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory. The memory is an example of computer-readable media.
[0081] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0082] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0083] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.
Claims
1. A method for tracking processes created by the Windows Task Scheduler, characterized in that, The method includes: Injecting a dynamic link library containing a context marshaling module into the task scheduler service process, and hooking the event tracing API in Windows Event Tracing with the hook function in the context marshaling module through the dynamic link library. The event tracing API includes: an API for the unified background process manager to register a Windows event tracing provider, an API for the unified background process manager to determine whether a specified event needs to be published, and an API for the unified background process manager to publish an event; Obtaining parameter information in the event tracing API called by the system's unified background process manager through the hook function, and constructing a task context of a thread based on the parameter information, including: obtaining a globally unique identifier from the API for registering a Windows event tracing provider, and saving the first handle returned by the API for registering a Windows event tracing provider when the globally unique identifier is a specific value; obtaining a second handle and a first event publishing flag from the API for determining whether a specified event needs to be published, and performing the next step when the second handle is the same as the first handle and the first event publishing flag is a trigger event; obtaining a third handle, a second event publishing flag, and event information from the API for publishing an event, and extracting the full path of the task from the event information when the third handle is the same as the first handle and the second event publishing flag is a trigger event, and constructing the task context from the full path of the task; When the security proxy module receives a callback for process creation, it performs the following operations: determining whether a task context of the thread exists, and operating on the created process according to the task context when the thread has a task context.
2. The method according to claim 1, wherein There are multiple event tracing APIs and the hook functions, and the event tracing APIs are correspondingly hooked with the hook functions in the context marshaling module.
3. The method according to claim 1, characterized in that The event tracing API is the API related to event tracing in the NTDLL.DLL library; The API for registering a Windows event tracing provider is EtwEventRegister, the API for determining whether a specified event needs to be published is EtwEventEnabled, and the API for publishing an event is EtwEventWrite.
4. The method according to claim 1, wherein Obtaining parameter information in the event tracing API called by the system's unified background process manager through the hook function, including: When the event tracing API is called by the unified background process manager, entering the hook function corresponding to the event tracing API; Obtaining parameter information in the event tracing API through the hook function corresponding to the event tracing API.
5. The method according to claim 1, characterized in that, After constructing the task context of the thread based on the parameter information, the method further includes: setting the task context to the current thread; Among them, setting the task context to the current thread includes: directly setting the task context to a specific field of the current thread structure or setting it through an external thread-to-task context mapping structure to associate the task context with the current thread.
6. The method according to claim 1, wherein The operations in operating on the created process according to the task context include: Blocking operations, releasing operations or sending audit messages determined according to a preset policy.
7. The method according to claim 3, characterized in that, The method further includes: clearing the constructed context when an API for determining whether a specified event needs to be published is called to publish an action result event of a task.
8. An electronic device, characterized in that, Including: At least one processor; A memory connected to the at least one processor; Among them, the memory stores instructions executable by the at least one processor, and the at least one processor realizes the steps of the method for tracking the creation of a process by the Windows Task Scheduler according to any one of claims 1 to 7 by executing the instructions stored in the memory.
9. A computer-readable storage medium having computer programs / instructions stored thereon, characterized in that, When the computer program / instructions are executed by a processor, the steps of the method for tracking the creation of a process by the Windows Task Scheduler according to any one of claims 1 to 7 are realized.
10. A computer program product, a computer program product, comprising computer programs / instructions, characterized in that, When the computer program / instructions are executed by a processor, the steps of the method for tracking the creation of a process by the Windows Task Scheduler according to any one of claims 1 to 7 are realized.
Citation Information
Patent Citations
Method and device for filtering remote procedure calls
CN111367684A
Hidden process detection method and device based on eBPF, equipment and medium
CN117473501A