A ransomware detection method, system, device and medium

By identifying the loop body based on jump instructions, instruction sequences and data flow directions in ransomware detection, and combining software network behavior and file access behavior detection ransomware, the problem of insufficient detection accuracy in the existing technology is solved, and efficient detection of optimized code is achieved.

CN119416219BActive Publication Date: 2025-05-09SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510018306.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-05-09
Estimated Expiration
2045-01-07

AI Technical Summary

Technical Problem

The prior art cannot fully obtain the loop body in the executable program binary file, and cannot identify all password algorithms in the target software, resulting in insufficient detection accuracy of the ransomware.

Method used

By obtaining the executable program binary file of the software to be detected and its dynamic execution trajectory, the loop body is identified based on the jump instructions, the instruction sequence and data flow direction, and the final loop body collection is obtained. Then, through the input and output data of the identified loop body, the cryptographic algorithm is recognized, and ransomware detection is carried out in combination with the software network behavior and file access behavior.

Benefits of technology

It effectively solves the problem of not being able to fully obtain loop bodies and identify all password algorithms, improves the detection accuracy of ransomware, and can identify loop bodies and password algorithms in the code optimized after loop expansion and compilation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119416219B_ABST
    Figure CN119416219B_ABST
Patent Text Reader

Abstract

The present invention provides a ransomware detection method, system, device and medium, which belongs to the technical field of ransomware detection. The scheme identifies loop bodies based on jump instructions, instruction sequences and data flows respectively, effectively solving the problem that the existing scheme cannot fully obtain loop bodies in executable program binary files; in view of the problem that most of the same jump addresses do not appear repeatedly in the dynamic trajectory generated by the code optimized by loop unrolling and compilation optimization, the scheme adopts a loop detection method based on instruction sequences on the basis of loop body detection based on jump instructions, and obtains loop bodies that cannot be obtained based on jump instructions based on the uniqueness of the timing relationship between instructions; at the same time, in view of the situation that two rounds of loops are highly crossed and do not present independent modules in the trajectory, the comprehensiveness of loop body detection is further improved by adopting a method based on data flow, thereby improving the detection accuracy of ransomware.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of ransomware detection, and in particular relates to a ransomware detection method, system, device and medium. Background Art

[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.

[0003] Ransomware often performs suspicious operations in loops, such as repeatedly trying to connect to malicious servers, continuously performing encryption and decryption operations, or frequently modifying system files. Identifying these abnormal loops helps discover potential malicious activities and effectively detect ransomware.

[0004] When detecting loop bodies, traditional methods mostly only detect jump instructions in the execution trajectory of binary files. This method cannot detect all loop bodies for codes optimized by loop unrolling and compilation optimization, and cannot effectively detect loop bodies for highly optimized instructions. It is impossible to identify all cryptographic algorithms in the target software, which leads to insufficient detection accuracy of ransomware. Summary of the invention

[0005] In order to overcome the deficiencies of the above-mentioned prior art, the present invention provides a ransomware detection method and system to solve the problem that the existing solutions cannot fully obtain the loop body in the executable program binary file and cannot identify all the cryptographic algorithms in the target software, thereby resulting in insufficient ransomware detection accuracy.

[0006] According to a first aspect of an embodiment of the present invention, a ransomware detection method is provided, comprising:

[0007] Obtain the executable program binary file of the software to be detected, as well as the dynamic execution trajectory of the binary file;

[0008] Based on the obtained dynamic execution trajectory, loop bodies are identified based on jump instructions, instruction sequences and data flows respectively; wherein, loop bodies are identified based on jump instructions to obtain a first loop body set; for loop bodies in the first loop body set, loop bodies are identified based on instruction sequences to obtain a second loop body set; for loop bodies in the first loop body set, loop bodies are identified based on data flows to obtain a third loop body set; the union of the first loop body set, the second loop body set and the third loop body set is used as the final identified loop body;

[0009] By obtaining the input and output data of the identified loop body, the cryptographic algorithm is identified based on the mapping relationship between the input and output data;

[0010] Ransomware detection is achieved based on the recognized cryptographic algorithm combined with the software network behavior and file access behavior.

[0011] Furthermore, the loop body is identified based on the jump instruction, which specifically includes the following processing steps:

[0012] Traverse the dynamic execution trajectory;

[0013] Get the jump addresses of all jump instructions and count the number of jump addresses that succeed for each jump;

[0014] Obtain jump addresses whose number of successfully jumped jump addresses is greater than a preset threshold;

[0015] Based on the position of the jump address in the dynamic execution trace, the instruction at the jump address and subsequent instructions are stored in a preset loop body storage structure until the next instruction is a jump instruction, thereby realizing the acquisition of the loop body.

[0016] Furthermore, the judgment of whether the jump address is successfully jumped is specifically as follows: after the jump instruction, if the instruction address is the jump address, the jump is successful.

[0017] Furthermore, the loop body is identified based on the instruction sequence, which specifically includes the following processing procedures: traversing the instructions in each loop body in the first loop body set in turn; comparing the current instruction with the historical instruction sequence that has been traversed in the current loop body, and if the same continuous instructions with a number of instructions greater than 2 are found in the historical instruction sequence, the same continuous instructions are marked as loop bodies.

[0018] Furthermore, in the determination of the same continuous instructions, only the type and size of the register are considered in the determination of the register.

[0019] Furthermore, in the identification of the loop body based on the instruction sequence, the identified loop body is identified by a preset identifier; wherein the same loop body is identified by the same identifier; and based on the identifier corresponding to the loop body, loop reduction processing is performed on the identified loop body.

[0020] Furthermore, the loop body is identified based on the data flow, which specifically includes the following processing steps:

[0021] Generate data flow based on dynamic execution trajectory;

[0022] Based on the data flow, a directed acyclic graph is constructed with the input variables and output variables in each instruction in the dynamic execution trajectory as nodes;

[0023] Determine whether the subgraphs under each source node in the directed acyclic graph are the same. If they are the same, use the current subgraph as a loop body.

[0024] According to a second aspect of an embodiment of the present invention, a ransomware detection system is provided, including:

[0025] A data acquisition unit, which is used to acquire the executable program binary file of the software to be detected, and the dynamic execution trajectory of the binary file;

[0026] A loop body identification unit, which is used to identify loop bodies based on jump instructions, instruction sequences and data flows based on the obtained dynamic execution traces; wherein the loop bodies are identified based on jump instructions to obtain a first loop body set; for loop bodies in the first loop body set, the loop bodies are identified based on instruction sequences to obtain a second loop body set; for loop bodies in the first loop body set, the loop bodies are identified based on data flows to obtain a third loop body set; and the union of the first loop body set, the second loop body set and the third loop body set is used as the loop body finally identified;

[0027] A cryptographic algorithm identification unit, which is used to identify the cryptographic algorithm based on the mapping relationship between the input and output data by acquiring the input and output data of the identified loop body;

[0028] The ransomware detection unit is used to detect ransomware based on the recognized cryptographic algorithm combined with the software network behavior and the access behavior to the file.

[0029] According to a third aspect of an embodiment of the present invention, an electronic device is provided, including a memory and a processor, and computer instructions stored in the memory and executed on the processor, wherein when the computer instructions are executed by the processor, the above-mentioned ransomware detection method is completed.

[0030] According to a fourth aspect of an embodiment of the present invention, a computer-readable storage medium is provided for storing computer instructions. When the computer instructions are executed by a processor, the above-mentioned ransomware detection method is performed.

[0031] One or more of the above technical solutions have the following beneficial effects:

[0032] The scheme of the present invention provides a method, system, device and medium for detecting ransomware. The scheme identifies loop bodies based on jump instructions, instruction sequences and data flow directions respectively, effectively solving the problem that the existing scheme cannot fully obtain loop bodies in executable program binary files, cannot identify all cryptographic algorithms in target software, and thus leads to insufficient detection accuracy of ransomware. The present invention aims at the problem that most of the same jump addresses do not appear repeatedly in the dynamic trajectory generated by the code optimized by loop unrolling and compilation optimization. On the basis of loop body detection based on jump instructions, a loop detection method based on instruction sequences is adopted to obtain loop bodies that cannot be obtained based on jump instructions based on the uniqueness of the timing relationship between instructions. The present invention further improves the comprehensiveness of loop body detection by adopting a method based on data flow direction in the case where two rounds of loops are highly crossed and do not present independent modules in the trajectory, thereby improving the detection accuracy of ransomware. The advantages of the additional aspects of the present invention will be partially given in the following description, and some will become obvious from the following description, or understood through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The accompanying drawings in the specification, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.

[0034] Figure 1 Schematic diagram of the loop_store structure described in an embodiment of the present invention;

[0035] Figure 2 A schematic diagram of trajectory generation described in an embodiment of the present invention;

[0036] Figure 3 A schematic diagram of the crossover of two blocks of instructions described in an embodiment of the present invention;

[0037] Figure 4 It is a schematic diagram of source node subgraph comparison described in an embodiment of the present invention;

[0038] Figure 5 The present invention is a flowchart of a ransomware detection method according to an embodiment of the present invention. DETAILED DESCRIPTION

[0039] It should be noted that the following detailed descriptions are exemplary and are intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meanings as those commonly understood by those skilled in the art to which the present invention belongs.

[0040] It should be noted that the terms used herein are for describing specific embodiments only and are not intended to be limiting of exemplary embodiments according to the present invention.

[0041] In the absence of conflict, the embodiments of the present invention and the features of the embodiments may be combined with each other.

[0042] Terminology explanation:

[0043] Structural loop: mainly refers to the loop pattern in the control flow graph;

[0044] Sequence loop: refers to the expanded form of the structure loop.

[0045] like Figure 5 As shown, this embodiment provides a ransomware detection method, including the following processing process:

[0046] Step 1: Obtain the executable binary file of the software to be tested and the dynamic execution trajectory of the binary file;

[0047] In a specific implementation, the generation of the dynamic trace is specifically: obtaining the execution trace of the binary file through an existing dynamic binary instrumentation tool, wherein each trace includes an instruction address, an assembly instruction, and register information.

[0048] Specifically, when the binary file starts to execute, the control of the CPU is first in the dynamic binary instrumentation tool. The dynamic binary instrumentation tool takes an execution trajectory from the program branch, and the compiled code is placed in the code cache. After the compilation of such an execution trajectory is completed, the dynamic binary instrumentation tool transfers the control of the CPU to the compiled code, and then the CPU executes this code, repeating the above steps to execute the entire program. Among them, two instruction spaces will appear in the execution trajectory, including: the instruction address space of the program execution organized by the dynamic binary instrumentation tool and the instruction address space of the software program to be detected. In the execution trajectory, the two address spaces will intersect in the form of blocks, but there are great differences in the instruction addresses. The instruction address space of the program execution can be located through the instruction address. The following loop body recognition is based on the trajectory of the program execution part.

[0049] Step 2: Based on the obtained dynamic execution trace, loop bodies are identified based on jump instructions, instruction sequences and data flows respectively; wherein, loop bodies are identified based on jump instructions to obtain a first loop body set; for loop bodies in the first loop body set, loop bodies are identified based on instruction sequences to obtain a second loop body set; for loop bodies in the first loop body set, loop bodies are identified based on data flows to obtain a third loop body set; the union of the first loop body set, the second loop body set and the third loop body set is used as the final identified loop body;

[0050] In a specific implementation, the loop body is identified based on the jump instruction, which specifically includes the following processing steps:

[0051] Traverse the dynamic execution trajectory;

[0052] Obtain the jump addresses of all jump instructions, and count the number of jump addresses of each successful jump; wherein, the judgment of whether the jump is successful is specifically: after the jump instruction, if the instruction address is the jump address, the jump is successful;

[0053] Obtain jump addresses whose number of successfully jumped jump addresses is greater than a preset threshold;

[0054] Based on the position of the jump address in the dynamic execution trace, the instruction at the jump address and subsequent instructions are stored in a preset loop body storage structure until the next instruction is a jump instruction, thereby realizing the acquisition of the loop body.

[0055] Specifically, the identification of the loop body based on the jump instruction specifically includes the following processing steps:

[0056] There are a large number of loops in the generated dynamic execution traces. Most loops use loop structures when implementing the code, and control the loop by satisfying certain conditions. In the dynamic execution traces, conditional control is basically implemented by jump instructions, so the loop body can be detected by detecting jump instructions in the dynamic execution traces.

[0057] Jump instructions usually do not exist alone. They rely on the change of the flag bit in the previous statement to control the implementation of the current jump instruction. Set the first instruction after the jump as the start of the loop and the next jump instruction as the end. Since the same code fragment only occupies the same instruction address in the dynamic trajectory, the fragment that jumps to the same instruction address multiple times through the jump instruction can be determined as a loop structure. The specific steps are as follows:

[0058] Step (1): Traverse the dynamic execution trace, count the jump addresses of the jump instructions and record them as address, and count the number of repeated occurrences of the jump address that successfully jumps and record them as num. As shown in Table 1, after the jump instruction, if the instruction address is the jump address, it means that the jump is successful, and a tuple [address, num] is obtained.

[0059] Step (2): Extract all addresses whose num is greater than or equal to 2 and construct an address set;

[0060] Step (3): Determine the position of address in the dynamic execution trace, extract the instruction at address and add it to the linked list loop_store[i], where loop_store represents a two-level linked list, and its linked list element loop_store[i] is the initial pointer to the i-th linked list, and the initial value of i is set to 0; if the next instruction of address is a jump instruction, jump to step (4), otherwise add the next instruction to the linked list pointed to by loop_store[i].

[0061] Step (4): i=i+1, and based on the next address in the address set, execute the processing of step (3) until all addresses in the address set are traversed.

[0062] It should be noted that each linked list pointed to by loop_store[i] stores a loop body, and the secondary linked list lop_store stores multiple loop bodies.

[0063] Table 1 Jump instruction examples

[0064]

[0065] In a specific implementation, the loop body is identified based on the instruction sequence, which specifically includes the following processing procedures: traversing the instructions in each loop body in the first loop body set in turn; comparing the current instruction with the historical instruction sequence that has been traversed in the current loop body, and if the same continuous instructions with a number of instructions greater than 2 are found in the historical instruction sequence, the same continuous instructions are marked as loop bodies.

[0066] In a specific implementation, in the identification of the loop body based on the instruction sequence, the identified loop body is identified by a preset identifier; wherein the same loop body is identified by the same identifier; and based on the identifier corresponding to the loop body, the identified loop body is subjected to loop reduction processing.

[0067] Specifically, the identification of the loop body based on the instruction sequence includes the following processing steps:

[0068] In the dynamic trace generated by the code optimized by loop unrolling and compilation optimization, most of the same jump addresses do not appear repeatedly. Therefore, the loop detection method based on jump instructions cannot detect all loop bodies. The scheme described in this embodiment uses a loop detection method based on instruction sequences to identify nested loops in the loop body identified in the loop detection method based on jump instructions on the basis of loop detection based on jump instructions. In the dynamic trace, the instructions have a good timing relationship, and the instruction execution order is unique.

[0069] In the scheme described in this embodiment, for nested loops, a loop identification set loop_id is introduced to represent the identified nested inner loop body. Loop identification adopts a layer-by-layer reduction method from the inside to the outside. The specific detection steps are as follows:

[0070] Step (1): Point the T pointer to the first instruction of the current loop body, and extract the instruction Ci pointed to by T. If it is empty, exit and determine whether the historylist structure (i.e., the pre-built first-level linked list) and the loop_store_new structure (i.e., the second-level linked list, each loop_store_new[i] stores the head pointer of a loop body) are empty. If both are empty, go to step (2); if the historylist structure is not empty and the loop_store_new structure is empty, go to step (3); if the loop_store_new structure is not empty, go to step (5);

[0071] Step (2): Add instruction Ci to the historylist structure, move the T pointer backward (i.e. point to the next instruction), and go to step (1);

[0072] Step (3): Compare instruction Ci with the instructions in the historylist structure starting from the first instruction. If no identical instruction is found until the historylist is empty or there is an identical instruction and the number of consecutive identical instructions in the T and historylist structures is less than or equal to 2, add instruction Ci to the historylist structure, move the T pointer backward, and go to step (1); if the same instruction is found, record the current pointer loopstart, move T and the historylist pointer backward and continue to compare until the comparison fails. If the number of consecutive identical instructions in the T and historylist structures is greater than 2, record the current pointer as loopend and go to step (4);

[0073] Step (4): Match a loop body from loopstart to loopend. If it is a new loop body, identify it with loop_id and store it in loop_store_new[i], i=i+1. If it is a loop body that has appeared before, identify it with the same loop_id and do not store it in loop_store_new. Adjust the pointer of T to point to the next instruction. If it is not empty, go to step (1). Otherwise, go to step (6).

[0074] Step (5): Compare instruction Ci with all loop body instructions in loop_store_new starting from the first instruction. If the instructions are the same, and each loop body in loop_store_new is empty, and the subsequent instructions of T and historylist structures are the same, record the current pointer as loopend and go to step (4); otherwise, go to step (3);

[0075] Step (6): Adjust the T pointer to point to the first instruction of the next loop body in the first loop body set, clear the historylist structure, and go to step (1).

[0076] For ease of understanding, a specific example is given below to explain in detail the processing of steps (1) to (6) above:

[0077] For example: the sequence pointed to by the T sequence pointer is: EabcdabcdabcdggedfEabcdabcdabedf, each letter in the sequence represents an instruction, and the sequence contains the first-level loop bodies "abcd" and "edf".

[0078] In the initial process, in step (1), the historylist and loop_store[i] structures are empty, so go to step (2); in step (2), store "E" in the historylist structure, and move the T pointer backward (i.e., point to the next instruction), and go to step (1); in step (1), the historylist is not empty, and the loop_store structure is empty, so go to step (3); in step (3), store instruction "a" until historylist is "Eabcd", at which point the next instruction is "a" which is the same as historylist, until "abcd" are the same, historylist is empty, and go to step (4) to determine the loop body "abcd", mark it as loop_id (e.g.: loop_1) and store it in loop_store_new[1];

[0079] At this time, in step (1), loop_store (which stores "abcd") is not empty, so go to step (5). "abcd" is the same, so go to step (4). In step (4), the loop of "abcd" is the same and is marked as loop_1, so go to step (1).

[0080] In step (1), repeat step (5) and step (4) until the instruction "g" is different, then go to step (3). In step (3), add instruction "g" to historylist. At this time, historylist is "Eabcdg", then go to step (1). In step (1), repeat step (5) and step (3) until historylist is "EabcdggedfE". At this time, go to step (1) and step (5). "abcd" is the same as loop_store_new[1] (i.e. "abcd"). Go to step (4) and repeat the above process again until the unprocessed instruction sequence T is "abed f", in step (5), go to step (3) and add "a" and "b" to historylist respectively. At this time, historylist is "EabcdggedfEab", go to step (1); in step (1), go to step (5) and go to step (3). At this time, "edf" and historylist (i.e. "EabcdggedfEab") have the same instruction set. Go to step (4) to match a loop body. The new loop is marked as loop_2 and stored in loop_store[2] (i.e. "edf"). At this time, T is empty. Go to step (6) to clear the historylist structure and go to step (1). End.

[0081] Among them, in the loop reduction process (i.e., steps (1) to (6) above), for the loop (body) m and (body) n (where body represents the loop body, and m and n represent the number of times the loop body iterates). For example: in the example above (abcd) m and (abcd) n , both have the same loop body "abcd". In order to reduce the outer loop structure, the same loop_id can be used to replace the two loops to change the T sequence (for example, the above example can be expressed as: E (loop_1) gg (loop_2) E (loop_1) (loop_2)), which is convenient for secondary reduction, such as Figure 1 As shown, each letter represents an instruction or a set of multiple instructions.

[0082] In the detection loop process, in the existing instruction sequence detection, successful instruction comparison often means that the instructions are exactly the same, but in the actual loop body, the same loop is often implemented using different registers. Therefore, the difference in registers during the matching process should be ignored. In this embodiment, successful comparison means that each register type involved in the operation is

[0083] The types are the same size, such as mov eax [xxx] and mov ebx [xxx], where eax and ebx are two registers with different names, mov is the operation code, [xxx] is the operand, and the two instructions read data from the same address space and put them into registers of the same size, so they can be regarded as the same instruction, that is, the comparison is successful.

[0084] In the specific implementation, the loop body is identified based on the data flow, which specifically includes the following processing procedures:

[0085] Generate data flow based on dynamic execution trajectory;

[0086] Based on the data flow, a directed acyclic graph is constructed with the input variables and output variables in each instruction in the dynamic execution trajectory as nodes;

[0087] Determine whether the subgraphs under each source node in the directed acyclic graph are the same. If they are the same, use the current subgraph as a loop body.

[0088] Specifically, the identification of the loop body based on the data flow direction specifically includes the following processing steps:

[0089] Step (1): Data flow generation

[0090] Each statement in the dynamic execution trace is an assembly instruction. Each operation of the assembly instruction has a fixed input and output position. In addition, the number of operands of the assembly instruction in the trace generated by Intel Pin is 1 or 2. It can be determined which operand is the input or output. The dynamic execution trace corresponding to the loop body obtained in the above-mentioned loop body recognition method based on jump instructions is analyzed from the beginning until the loop ends. Data flow.

[0091] In the scheme described in this embodiment, each statement in the dynamic execution trace is taken as a component, and all instruction operations in the dynamic execution trace are counted, and the instruction operations and components are numbered. A topological structure is constructed based on the numbered instruction operations and components, and the topological structure is stored in XML. The specific topological structure construction process is as follows:

[0092] 1): Count the operations in the loop body and store them in the Functions in the XML structure;

[0093] 2): Treat each statement as a component and express it with an equation, which is stored in the Components in the XML structure;

[0094] 3): For Components, determine the input and output locations based on the assembly instruction operation, with the input node as the parent node, the output as the child node, and the next variable to be processed as the next node.

[0095] For example, some assembly instructions are as follows:

[0096] mov eax,[rbp-0x130];

[0097] add eax,0x1;

[0098] mov edx,[rbp+rax 4-0xa0];

[0099] mov eax,[rbp-0x130];

[0100] add eax,0x2;

[0101] xor edx,eax;

[0102] The data generated by it flows as follows Figure 2 As shown, the solution described in this embodiment stores the data flow in an XML structure.

[0103] Step (2): Loop body identification method based on data flow

[0104] In the dynamic trajectory generation, if highly optimized instructions appear, for example, two loops are highly interleaved and do not present independent modules in the trajectory, such loop bodies cannot be detected by the above two detection methods. The scheme described in this embodiment proposes a loop body detection method based on data flow. Figure 3 As shown, in the figure, two blocks of instructions are interleaved. In the example in the figure, the different execution order of the instructions does not affect the final result.

[0105] In the XML structure, each node includes a number, a variable name, the number of child nodes, the number of child nodes, and the component number corresponding to the child node. In the XML structure, a node is represented as node, the number of child nodes is represented as childcnt, and the child node is represented as childnode. Each node node has childcnt childnode nodes. A directed acyclic graph structure can be formed through child node retrieval. Compare whether the subgraphs under each source node are the same (recursive method can be used), which specifically includes the following processing procedures:

[0106] Search each node in the XML structure by childnode. If the number of childnodes childcnt is greater than 2, loop through each child node to compare whether the component numbers of nodes at the same level are the same, and whether they are the same registers or memory addresses. If the comparison is the same, continue to compare the next child node until the child node is empty, then it is determined to be a loop body.

[0107] For example, the eax and ebx registers are essentially different only in their names, and their sizes are exactly the same, so mov eax 0x10 and mov ebx 0x10 can be considered the same instruction, where the component numbers are the same, which means the mov operations are the same;

[0108] If two nodes point to the same node with the same id at the same time during the comparison of child nodes, then skip this source node (i.e. the node at the same level as the current node) and perform the comparison with other source nodes. For ease of understanding, the following example is given: Figure 4 As shown in , in the comparison of parts 1 and 2, the first-level child node eax of the node [rbp-0x130] is the same, and the second-level child nodes are different, but they all point to the same node, so skip part 2 and compare parts 1 and 3, and so on.

[0109] Step 3: By obtaining the input and output data of the identified loop body, the cryptographic algorithm is identified based on the mapping relationship between the input and output data;

[0110] Step 4: Based on the identified cryptographic algorithm, the ransomware is detected in combination with the software network behavior and the file access behavior.

[0111] Specifically, the core of ransomware is to encrypt files through encryption algorithms. After identifying the encryption algorithm, the software network behavior and file access behavior can be comprehensively detected to identify the ransomware.

[0112] In one or more implementations, corresponding to the above method, this embodiment provides a ransomware detection system, including:

[0113] A data acquisition unit, which is used to acquire the executable program binary file of the software to be detected, and the dynamic execution trajectory of the binary file;

[0114] A loop body identification unit, which is used to identify loop bodies based on jump instructions, instruction sequences and data flows based on the obtained dynamic execution traces; wherein the loop bodies are identified based on jump instructions to obtain a first loop body set; for loop bodies in the first loop body set, the loop bodies are identified based on instruction sequences to obtain a second loop body set; for loop bodies in the first loop body set, the loop bodies are identified based on data flows to obtain a third loop body set; and the union of the first loop body set, the second loop body set and the third loop body set is used as the loop body finally identified;

[0115] A cryptographic algorithm identification unit, which is used to identify the cryptographic algorithm based on the mapping relationship between the input and output data by acquiring the input and output data of the identified loop body;

[0116] The ransomware detection unit is used to detect ransomware based on the recognized cryptographic algorithm combined with the software network behavior and the access behavior to the file.

[0117] It should be noted that the system described in this embodiment corresponds to the above method, and its technical details are described in detail in the above method embodiment, so they will not be repeated here.

[0118] In further embodiments, there is also provided:

[0119] An electronic device includes a memory and a processor, and computer instructions stored in the memory and executed on the processor. When the computer instructions are executed by the processor, the above-mentioned ransomware detection method is completed.

[0120] A computer-readable storage medium is used to store computer instructions. When the computer instructions are executed by a processor, the above-mentioned ransomware detection method is completed.

[0121] It can be understood that the relevant technical details of the system described in this embodiment have been described in detail in Example 1, so they will not be repeated here.

[0122] The above description is only a preferred embodiment of the present disclosure and is not intended to limit the present disclosure. For those skilled in the art, the present disclosure may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present disclosure shall be included in the protection scope of the present disclosure.

Claims

1. A ransomware detection method, characterized in that: include: Obtain the executable program binary file of the software to be detected, as well as the dynamic execution trajectory of the binary file; Based on the obtained dynamic execution trajectory, loop bodies are identified based on jump instructions, instruction sequences and data flows respectively; wherein, loop bodies are identified based on jump instructions to obtain a first loop body set; for loop bodies in the first loop body set, loop bodies are identified based on instruction sequences to obtain a second loop body set; for loop bodies in the first loop body set, loop bodies are identified based on data flows to obtain a third loop body set; the union of the first loop body set, the second loop body set and the third loop body set is used as the final identified loop body; By obtaining the input and output data of the identified loop body, the cryptographic algorithm is identified based on the mapping relationship between the input and output data; Based on the recognized cryptographic algorithm, the ransomware detection is realized by combining the software network behavior and the access behavior to the files; The loop body is identified based on the jump instruction, which specifically includes the following processing steps: Traverse the dynamic execution trajectory; Get the jump addresses of all jump instructions and count the number of jump addresses that succeed for each jump; Obtain jump addresses whose number of successfully jumped jump addresses is greater than a preset threshold; Based on the position of the jump address in the dynamic execution trace, the instruction at the jump address and subsequent instructions are stored in a preset loop body storage structure until the next instruction is a jump instruction, thereby obtaining the loop body; The loop body is identified based on the instruction sequence, specifically including the following processing process: sequentially traversing the instructions in each loop body in the first loop body set; comparing the current instruction with the historical instruction sequence that has been traversed in the current loop body, and if the same continuous instructions with the number of instructions greater than 2 are found in the historical instruction sequence, the same continuous instructions are marked as loop bodies; The loop body is identified based on the data flow, which specifically includes the following processing steps: Generate data flow based on dynamic execution trajectory; Based on the data flow, a directed acyclic graph is constructed with the input variables and output variables in each instruction in the dynamic execution trajectory as nodes; Determine whether the subgraphs under each source node in the directed acyclic graph are the same. If they are the same, use the current subgraph as a loop body.

2. A ransomware detection method according to claim 1, characterized in that: The judgment of whether the jump address jumps successfully is specifically as follows: after the jump instruction, if the instruction address is the jump address, the jump is successful.

3. A ransomware detection method according to claim 1, characterized in that: In the determination of the same continuous instructions, the determination of the register only considers the type and size of the register.

4. A ransomware detection method according to claim 1, characterized in that: In the identification of the loop body based on the instruction sequence, the identified loop body is identified by a preset identifier; wherein the same loop body is identified by the same identifier; and based on the identifier corresponding to the loop body, the identified loop body is subjected to loop reduction processing.

5. A ransomware detection system, characterized in that: include: A data acquisition unit, which is used to acquire the executable program binary file of the software to be detected, and the dynamic execution trajectory of the binary file; A loop body identification unit, which is used to identify loop bodies based on jump instructions, instruction sequences and data flows based on the obtained dynamic execution traces; wherein the loop bodies are identified based on jump instructions to obtain a first loop body set; for loop bodies in the first loop body set, the loop bodies are identified based on instruction sequences to obtain a second loop body set; for loop bodies in the first loop body set, the loop bodies are identified based on data flows to obtain a third loop body set; and the union of the first loop body set, the second loop body set and the third loop body set is used as the loop body finally identified; A cryptographic algorithm identification unit, which is used to identify the cryptographic algorithm based on the mapping relationship between the input and output data by acquiring the input and output data of the identified loop body; A ransomware detection unit, which is used to detect ransomware based on the recognized cryptographic algorithm, combined with the software network behavior and the access behavior to the file; The loop body is identified based on the jump instruction, which specifically includes the following processing steps: Traverse the dynamic execution trajectory; Get the jump addresses of all jump instructions and count the number of jump addresses that succeed for each jump; Obtain jump addresses whose number of successfully jumped jump addresses is greater than a preset threshold; Based on the position of the jump address in the dynamic execution trace, the instruction at the jump address and subsequent instructions are stored in a preset loop body storage structure until the next instruction is a jump instruction, thereby obtaining the loop body; The loop body is identified based on the instruction sequence, specifically including the following processing process: sequentially traversing the instructions in each loop body in the first loop body set; comparing the current instruction with the historical instruction sequence that has been traversed in the current loop body, and if the same continuous instructions with the number of instructions greater than 2 are found in the historical instruction sequence, the same continuous instructions are marked as loop bodies; The loop body is identified based on the data flow, which specifically includes the following processing steps: Generate data flow based on dynamic execution trajectory; Based on the data flow, a directed acyclic graph is constructed with the input variables and output variables in each instruction in the dynamic execution trajectory as nodes; Determine whether the subgraphs under each source node in the directed acyclic graph are the same. If they are the same, use the current subgraph as a loop body.

6. An electronic device, characterized in that: The invention comprises a memory and a processor, and computer instructions stored in the memory and executed on the processor, wherein when the computer instructions are executed by the processor, a ransomware detection method according to any one of claims 1 to 4 is completed.

7. A computer-readable storage medium for storing computer instructions, characterized in that: When the computer instruction is executed by the processor, a ransomware detection method as described in any one of claims 1 to 4 is completed.

Citation Information

Patent Citations

  • Botnet command and control protocol acquisition method and device

    CN103905391A

  • Ransomware detection method and device, equipment and storage medium

    CN117332417A