A method and system for measuring application behavior based on system calls
Through real-time monitoring and analysis of system call sequences, combined with behavior feature extraction and pattern recognition technology, the limitations of the existing technology in detecting and measuring application behavior are solved, and efficient and accurate abnormal behavior recognition and behavior measurement are achieved, supporting security analysis and risk assessment.
Patent Information
- Application Number
- CN202510116665.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-01-24
AI Technical Summary
The prior art has limitations in detecting and measuring the behavior of target applications, and it is difficult to deal with dynamic changes and malicious code injection. The signature-based detection method is ineffective against new or variant attack methods, and network traffic analysis has limited ability to detect behavior at the application level.
By monitoring and analyzing system call sequences in real time, using behavior feature extraction and pattern recognition technology, the abnormal behavior of the target application is identified, and quantitatively evaluated through defined behavior metrics to generate behavior metric reports.
Real-time detection and measurement of target application behavior is achieved, detection efficiency and accuracy is improved, false positives and missed reports are reduced, and detailed behavioral metrics reports are provided to support security analysis and risk assessment.
Smart Images

Figure CN119557883B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electronic digital data processing, and in particular to a method and system for measuring application behavior based on system calls. Background Art
[0002] In today's digital age, computer applications have become an indispensable part of people's daily lives and work. With the widespread popularity of applications and the continuous expansion of their functions, their security issues have become increasingly prominent; malware, network attacks, data leaks and other security incidents have occurred frequently, posing a huge threat to the information security of individuals, enterprises and countries. Therefore, how to effectively detect and measure the behavior of target applications and timely discover and prevent potential security risks has become an important issue that needs to be solved in the field of computer security.
[0003] Traditional target application behavior detection and measurement methods mainly rely on static code analysis, signature-based detection, and network traffic analysis. However, these methods have many limitations in practical applications. Although static code analysis can discover potential security vulnerabilities in advance, it is difficult to cope with dynamic changes and malicious code injection at runtime. Signature-based detection methods rely on known malicious pattern libraries and are often helpless against new or variant attack methods. Network traffic analysis mainly focuses on network-level behavior and has limited ability to detect application-level behavior.
[0004] As a bridge between the operating system and the target application, the system call is an indispensable part of the target application's execution process. Each system call represents the target application's request or operation on the operating system resources. Therefore, the system call sequence contains rich behavioral information. By analyzing the system call sequence, we can gain a deep understanding of the target application's running status and potential security risks. In recent years, application behavior detection and measurement methods based on system calls have gradually become a research hotspot. However, application behavior detection and measurement based on system calls is not easy. First, there are many types of system calls, and different types of system calls have different semantic and behavioral characteristics. How to accurately extract the key features related to the target application behavior is a difficult problem. Second, the behavior patterns of the target application are complex and changeable, especially when it comes to malware or covert attacks, their behavior patterns are often more difficult to predict and identify. In addition, real-time performance is also an aspect that cannot be ignored in behavior detection and measurement. If abnormal behavior cannot be detected and responded to in a timely manner, it may bring serious security threats to the system. Summary of the invention
[0005] The purpose of the present invention is to provide an application behavior measurement method and system based on system calls to overcome the problems existing in the prior art. The present invention can complete the detection and measurement of the target application behavior in a short time by real-time monitoring and analysis of the system call sequence, thereby improving the detection efficiency; based on the behavior feature extraction and behavior pattern recognition technology, it can accurately identify the abnormal behavior of the target application and reduce the false alarm rate and the missed alarm rate; by defining a complete set of behavior measurement indicators, it can comprehensively reflect the behavior characteristics of the target application, providing strong support for security analysis and risk assessment.
[0006] In order to achieve the above object, the technical solution adopted by the present invention is as follows:
[0007] In a first aspect, the present invention provides a method for measuring application behavior based on system calls, comprising the following steps:
[0008] Real-time monitoring of the system call sequences generated by the target application during execution;
[0009] Preprocessing the system call sequence, and then using a behavior feature extraction algorithm on the preprocessed system call sequence to extract key behavior features related to the target application behavior;
[0010] Input key behavior features into a pre-trained behavior pattern recognition model, and use the behavior pattern recognition model to identify abnormal behavior patterns of the target application;
[0011] According to the preset behavior measurement indicators, the abnormal behavior patterns identified by the behavior pattern recognition model are quantitatively evaluated to generate a behavior measurement report;
[0012] Furthermore, the real-time monitoring includes at least one of the following:
[0013] Replace the pointer of the system call corresponding to the target application in the system call table, so that the pointer points to the custom monitoring function to achieve real-time monitoring;
[0014] Use system call monitoring tools to achieve real-time monitoring;
[0015] Further, the modifying the operating system kernel includes: replacing the pointer of the system call corresponding to the target application in the system call table so that the pointer points to the custom monitoring function;
[0016] The system call monitoring tool includes: a system tracker and a system probe;
[0017] Further, the preprocessing includes: removing redundant information and normalizing data;
[0018] Furthermore, the behavior feature extraction algorithm includes a frequent pattern mining algorithm and a sequence alignment algorithm;
[0019] Furthermore, the training of the behavior pattern recognition model includes: data preparation and model training;
[0020] Further, the data preparation includes: collecting system call sequences, allowing the behavior pattern recognition model to learn known normal behavior features, and then marking abnormal behavior features in the system call sequences, allowing the behavior pattern recognition model to learn the abnormal behavior features, and obtaining prepared data, the prepared data being normal behavior features and abnormal behavior features;
[0021] The model training includes: dividing the prepared data into a training set and a test set, setting various parameters of the behavior pattern recognition model, using the training set to train the behavior pattern recognition model, and then using the test set to calculate various indicators of the behavior pattern recognition model, evaluating the trained behavior pattern recognition model according to the various indicators, and then according to the evaluation results, tuning the parameters and data volume of the behavior pattern recognition model to obtain a trained behavior pattern recognition model;
[0022] Furthermore, the preset behavior measurement indicators are: system call frequency, system call sequence length, system call response time, resource consumption indicator and abnormal behavior indicator;
[0023] The quantitative evaluation includes: continuously collecting system call exception data of the target application, then analyzing the collected system call exception data according to preset behavior measurement indicators, and then comparing the analyzed data with system call frequency, system call sequence length, system call response time and resource consumption indicators;
[0024] Furthermore, the behavior measurement report includes: a quantitative score of the target application behavior, a specific description of the abnormal behavior pattern, and a risk level description.
[0025] In a second aspect, the present invention provides an application behavior measurement system based on system calls, comprising:
[0026] System call monitoring module: used to monitor the system call sequence generated by the target application during execution in real time;
[0027] Behavior feature extraction module: used to preprocess the system call sequence, and then use the behavior feature extraction algorithm to extract the key behavior features related to the target application behavior.
[0028] Behavior pattern recognition module: used to input key behavior features into a pre-trained behavior pattern recognition model, and identify abnormal behavior patterns of the target application through the behavior pattern recognition model;
[0029] Behavior measurement module: used to quantitatively evaluate the abnormal behavior patterns identified by the behavior pattern recognition model based on preset behavior measurement indicators and generate a behavior measurement report.
[0030] The above technical solution has the following advantages or beneficial effects:
[0031] In the first aspect, the present invention provides an application behavior measurement method based on system calls. By real-time monitoring of the system call sequence generated by the target application during execution, it can timely discover and identify potential security threats or malicious behaviors, which helps to defend against security attacks such as malware, viruses, Trojans, etc., and improve the overall security of the system; using a behavioral feature extraction algorithm and a pre-trained behavioral pattern recognition model, it can more accurately extract and identify abnormal behavior patterns that are inconsistent with the normal behavior of the target application from complex system calls, which helps to reduce false positives and missed positives and improve the efficiency and accuracy of security detection; through the preset behavioral measurement indicators, the identified abnormal behavior patterns are quantitatively evaluated, which can generate The detailed and specific behavior measurement report can not only help users or security management systems understand the specific risk situation of the target application, but also provide strong data support for subsequent security analysis and risk assessment; the method of the present invention makes the behavior of the target application observable, measurable and manageable. Through the real-time monitoring and reporting mechanism, users or security management systems can clearly understand the operating status and potential risks of the target application, so as to take corresponding security measures to enhance the controllability and stability of the system; once an abnormal behavior pattern is found, the system can immediately generate a report and notify the user or security management system, which helps to take timely measures to block potential attacks or damages and reduce the impact and losses of security incidents on the system.
[0032] Furthermore, by replacing the pointer in the system call table, the system call can directly jump to the custom monitoring function when it is executed, realizing deep monitoring of the system call, and being able to capture the most original and lowest-level system call information to ensure the accuracy and completeness of the monitoring; by utilizing the system call monitoring tool to realize real-time monitoring of the target application behavior, monitoring management becomes more convenient and efficient.
[0033] Furthermore, the system tracer can capture the interaction information between the process and the operating system kernel to achieve real-time monitoring and recording; the system probe can monitor specific system call sequences or target applications to achieve accurate problem location.
[0034] Furthermore, the system call data often contains a large amount of redundant information that has no direct contribution to behavior detection and measurement, such as frequently occurring irrelevant system calls, repeated records, etc. By removing this information through preprocessing, the amount of data for subsequent processing can be significantly reduced, and the speed and efficiency of data processing can be improved; different system calls may have different parameter formats and data types, which will bring difficulties to subsequent data analysis. Through data normalization, the system call data can be converted into a unified and standard format, which can simplify the data processing process and improve processing efficiency.
[0035] Furthermore, the frequent pattern mining algorithm can identify normal behavior patterns that frequently appear in the data set, and then by comparing the actual behavior with these normal behavior patterns, it can quickly identify potential security threats or performance issues when abnormal behavior is discovered; the sequence comparison algorithm compares the system call sequence of the target application with the historical behavior sequence of the user or system to find similarities and differences, thereby accurately identifying abnormal behavior, and has an advantage in detecting complex attack patterns and malware.
[0036] Furthermore, through preliminary data preparation and training the prepared data, the behavior pattern recognition model can learn richer behavior features, thereby improving the accuracy of identifying abnormal behavior features, and helping the behavior pattern recognition model maintain good generalization capabilities when dealing with unseen target applications or new system call sequences.
[0037] Furthermore, by collecting system call sequences, the behavior pattern recognition model can learn known normal behavior features, providing rich learning materials for the behavior pattern recognition model, and marking a part of abnormal behavior features in the system call sequence so that the behavior pattern recognition model can learn abnormal behavior features, improving the behavior pattern recognition model's ability to recognize abnormal behavior features, thereby ensuring the quality and diversity of training data, thereby helping to improve the accuracy of the behavior pattern recognition model; by dividing the prepared data into training sets and test sets, which are used for training and evaluation of the behavior pattern recognition model respectively, the generalization ability of the behavior pattern recognition model on unknown data can be ensured, and by calculating various indicators of the behavior pattern recognition model, the performance of the behavior pattern recognition model can be comprehensively evaluated, providing a basis for subsequent tuning, and by adjusting the parameters of the behavior pattern recognition model, increasing the amount of data and other optimization measures based on the evaluation results of the test set, the performance of the behavior pattern recognition model is continuously improved, and the continuous tuning process can ensure that the behavior pattern recognition model always maintains a high degree of accuracy and reliability.
[0038] Furthermore, by measuring the behavior of the target application through multiple dimensions such as system call frequency, system call sequence length, system call response time, resource consumption indicators and abnormal behavior indicators, it is possible to comprehensively and meticulously reflect the running status of the target application. The multi-dimensional measurement method can more accurately describe the behavioral characteristics of the target application than a single indicator. By continuously collecting the system call sequence abnormal data of the target application, real-time monitoring of the target application behavior is achieved. By comparing the collected system call sequence abnormal data with the system call frequency, system call sequence length, system call response time and resource consumption indicators, the abnormal behavior pattern of the target application can be accurately identified.
[0039] Furthermore, by providing quantitative scores for target application behaviors, the report provides decision makers with an intuitive and comparable evaluation standard; the specific description of abnormal behavior patterns provides decision makers with rich contextual information, enabling them to gain in-depth insights into the nature, scope of impact, and possible consequences of abnormal behavior patterns, helping decision makers to more accurately assess risks and develop appropriate response measures; the division of risk levels enables decision makers to quickly determine the severity of abnormal behavior patterns, thereby prioritizing high-risk issues and ensuring the security and stability of the system.
[0040] In the second aspect, the present invention also provides an application behavior measurement system based on system calls, wherein the system call monitoring module can capture the system call sequence behavior of the target application in real time, ensure comprehensive monitoring of the target application activities, and record key behavior data without omission; the behavior feature extraction module can extract key behavior features from a large amount of system call sequence data, and can accurately reflect the running status and behavior patterns of the target application; the behavior pattern recognition module uses a pre-trained behavior pattern recognition model to quickly identify abnormal behavior patterns of the target application, greatly improving processing efficiency, reducing the need for manual intervention, and also reducing the risk of false alarms and missed alarms due to human factors; the behavior measurement module measures the behavior of the target application from multiple dimensions, and provides rich data support for comprehensively evaluating the performance and security of the target application. By quantitatively evaluating and generating behavior measurement reports, the system can intuitively display the behavioral performance and risk status of the target application, provide decision-making basis for administrators or operation and maintenance personnel, and help users improve the performance and security of the target application. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 The present invention is a flowchart of a method for measuring application behavior based on system calls.
[0042] Figure 2 The present invention is a structural block diagram of an application behavior measurement system based on system calls. DETAILED DESCRIPTION
[0043] The present invention is further described in detail below in conjunction with specific embodiments, which are intended to explain the present invention rather than to limit it.
[0044] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0045] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0046] Embodiment 1:
[0047] like Figure 1 As shown, the present invention provides an application behavior measurement method based on system calls, comprising the following steps:
[0048] System call monitoring: By replacing the pointer of the system call corresponding to the target application in the system call table, the pointer points to the custom monitoring function, that is, modifying the operating system kernel to monitor the system call sequence generated by the target application in real time during execution, so that the system call sequence can directly jump to the custom monitoring function during execution, realizing in-depth monitoring of the system call sequence, and being able to capture the most original and lowest-level system call sequence information to ensure the accuracy and completeness of monitoring;
[0049] System call sequence preprocessing: remove duplicate system call sequences and irrelevant system call sequences, and normalize the data to ensure the accuracy of subsequent analysis;
[0050] Preferably, the preprocessing is specifically to remove redundant information and normalize the data, including deduplication, directly deleting identical records or data items in the data set; data aggregation, merging data with similar characteristics to reduce the size of the data set; feature selection, selecting features that have a substantial impact on the results according to analysis requirements, and deleting other irrelevant features; data format unification, ensuring that the format of all data is consistent, such as timestamp format, data type, etc.; data range adjustment, adjusting the data to a specific range, such as normalizing numerical data to between 0 and 1; data missing processing, filling or deleting missing data to ensure the integrity of the data set;
[0051] Behavioral feature extraction: A behavioral feature extraction algorithm is used on the preprocessed system call sequence to extract key behavioral features related to the target application behavior;
[0052] Preferably, the behavior feature extraction algorithm includes a frequent pattern mining algorithm and a sequence alignment algorithm to discover subsequences that frequently appear in the system call sequence and to discover similarities and differences between them;
[0053] Behavior pattern recognition: The extracted key behavior features are input into the pre-trained behavior pattern recognition model, and the abnormal behavior patterns of the target application are automatically identified through the behavior pattern recognition model;
[0054] Preferably, the training of the behavior pattern recognition model includes: data preparation and model training, which can more accurately extract and identify abnormal behavior patterns that are inconsistent with the normal behavior of the target application from complex system call sequence data, help reduce false positives and false negatives, and improve the efficiency and accuracy of security detection;
[0055] Specifically, data preparation includes: collecting system call sequences, allowing the behavior pattern recognition model to learn known normal behavior features, and then marking abnormal behavior features in the system call sequences, allowing the behavior pattern recognition model to learn abnormal behavior features, and obtaining prepared data, the prepared data being normal behavior features and abnormal behavior features;
[0056] Specifically, the model training includes: dividing the prepared data into a training set and a test set, setting various parameters of the behavior pattern recognition model, using the training set to train the behavior pattern recognition model, and then using the test set to calculate various indicators of the behavior pattern recognition model, evaluating the trained behavior pattern recognition model according to the various indicators, and then according to the evaluation results, tuning the parameters and data volume of the behavior pattern recognition model to obtain a trained behavior pattern recognition model;
[0057] Behavior measurement: Based on the preset behavior measurement indicators, the abnormal behavior patterns identified by the behavior pattern recognition model are quantitatively evaluated and a detailed behavior measurement report is generated, which can not only help users or security management systems understand the specific risk situation of the target application, but also provide strong data support for subsequent security analysis and risk assessment;
[0058] Preferably, the preset behavior measurement indicators are: system call frequency, system call sequence length, system call response time, resource consumption indicator and abnormal behavior indicator;
[0059] Preferably, the quantitative evaluation includes: continuously collecting system call exception data of the target application, then analyzing the collected system call exception data according to preset behavior measurement indicators, and then comparing the analyzed data with system call frequency, system call sequence length, system call response time and resource consumption indicators;
[0060] Preferably, the behavior metric report includes: a quantitative score of the target application behavior, a specific description of the abnormal behavior pattern, and a risk level description.
[0061] Embodiment 2:
[0062] like Figure 1 As shown, the present invention provides an application behavior measurement method based on system calls, comprising the following steps:
[0063] System call monitoring: By using the system call monitoring tool to monitor the system call sequence generated by the target application in real time during execution, it can timely discover and identify potential security threats or malicious behaviors, help defend against security attacks such as malware, viruses, Trojans, and improve the overall security of the system;
[0064] Preferably, the system call monitoring tool includes a system tracer and a system probe, so that the monitoring system can more flexibly respond to different monitoring requirements;
[0065] System call sequence preprocessing: remove duplicate system call sequences and irrelevant system call sequences, and normalize the data to ensure the accuracy of subsequent analysis;
[0066] Preferably, the preprocessing is specifically to remove redundant information and normalize the data. The system call sequence data often contains a large amount of redundant information that does not directly contribute to behavior detection and measurement, such as frequently occurring irrelevant system call sequences, repeated records, etc. By removing this information through preprocessing, the amount of data to be processed subsequently can be significantly reduced, thereby improving the speed and efficiency of data processing.
[0067] Specifically, removing redundant information and normalizing data include deduplication, directly deleting identical records or data items in the data set; data aggregation, merging data with similar characteristics to reduce the size of the data set; feature selection, selecting features that have a substantial impact on the results based on analysis requirements, and deleting other irrelevant features; data format unification, ensuring that all data formats are consistent, such as timestamp format, data type, etc.; data range adjustment, adjusting data to a specific range, such as normalizing numerical data to between 0 and 1; data missing processing, filling or deleting missing data to ensure the integrity of the data set;
[0068] Behavioral feature extraction: A behavioral feature extraction algorithm is used on the preprocessed system call sequence to extract key behavioral features related to the target application behavior;
[0069] Preferably, the behavior feature extraction algorithm includes a frequent pattern mining algorithm and a sequence alignment algorithm to discover subsequences that frequently appear in the system call sequence and to discover similarities and differences between them;
[0070] Behavior pattern recognition: The extracted key behavior features are input into the pre-trained behavior pattern recognition model, and the abnormal behavior patterns of the target application are automatically identified through the behavior pattern recognition model;
[0071] Preferably, the training of the behavior pattern recognition model includes: data preparation and model training, which can more accurately extract and identify abnormal behavior patterns that are inconsistent with the normal behavior of the target application from complex system call sequence data, help reduce false positives and false negatives, and improve the efficiency and accuracy of security detection;
[0072] Specifically, data preparation includes: collecting system call sequences, allowing the behavior pattern recognition model to learn known normal behavior features, and then marking abnormal behavior features in the system call sequences, allowing the behavior pattern recognition model to learn abnormal behavior features, and obtaining prepared data, the prepared data being normal behavior features and abnormal behavior features;
[0073] Specifically, the model training includes: dividing the prepared data into a training set and a test set, setting various parameters of the behavior pattern recognition model, using the training set to train the behavior pattern recognition model, and then using the test set to calculate various indicators of the behavior pattern recognition model, evaluating the trained behavior pattern recognition model according to the various indicators, and then according to the evaluation results, tuning the parameters and data volume of the behavior pattern recognition model to obtain a trained behavior pattern recognition model;
[0074] Behavior measurement: Based on the preset behavior measurement indicators, the abnormal behavior patterns identified by the behavior pattern recognition model are quantitatively evaluated and a detailed behavior measurement report is generated, which can not only help users or security management systems understand the specific risk situation of the target application, but also provide strong data support for subsequent security analysis and risk assessment;
[0075] Preferably, the preset behavior measurement indicators are: system call frequency, system call sequence length, system call response time, resource consumption indicator and abnormal behavior indicator;
[0076] Preferably, the quantitative evaluation includes: continuously collecting system call exception data of the target application, then analyzing the collected system call exception data according to preset behavior measurement indicators, and then comparing the analyzed data with system call frequency, system call sequence length, system call response time and resource consumption indicators;
[0077] Preferably, the behavior metric report includes: a quantitative score of the target application behavior, a specific description of the abnormal behavior pattern, and a risk level description.
[0078] Embodiment 3:
[0079] The present invention also provides a method for measuring application behavior based on system calls in a trusted computing environment, comprising the following steps:
[0080] System call monitoring: Monitor the system call sequence generated by the target application during execution in real time through the Trusted Platform Module (TPM);
[0081] Preferably, in a trusted computing environment, system call monitoring can be combined with a trusted platform, and the security measurement function of the trusted platform can be used to verify the integrity and authenticity of the system call sequence. The trusted platform can record key steps in the system startup process, including the loaded operating system and target application. Through hardware security modules such as the trusted platform, system call monitoring can be performed at the hardware level, improving the accuracy and reliability of monitoring, and preventing malware from bypassing monitoring by tampering with the operating system or target application.
[0082] Behavioral feature extraction: pre-process the monitored system call sequence, and then use the behavioral feature extraction algorithm on the pre-processed target application to extract the key behavioral features related to the target application behavior;
[0083] Preferably, preprocessing includes: removing redundant information and normalizing data, including deduplication, directly deleting identical records or data items in the data set; data aggregation, merging data with similar characteristics to reduce the size of the data set; feature selection, selecting features that have a substantial impact on the results according to analysis requirements, and deleting other irrelevant features; data format unification, ensuring that the format of all data is consistent, such as timestamp format, data type, etc.; data range adjustment, adjusting the data to a specific range, such as normalizing numerical data to between 0 and 1; data missing processing, filling or deleting missing data to ensure the integrity of the data set;
[0084] Preferably, the behavior feature extraction algorithm includes a frequent pattern mining algorithm and a sequence alignment algorithm to discover subsequences that frequently appear in the system call sequence and to discover similarities and differences between them;
[0085] Behavior pattern recognition: The extracted key behavior features are input into the pre-trained behavior pattern recognition model, and the abnormal behavior patterns of the target application are automatically identified through the behavior pattern recognition model;
[0086] Preferably, the training of the behavior pattern recognition model includes: data preparation and model training, which can more accurately extract and identify abnormal behavior patterns that are inconsistent with the normal behavior of the target application from complex system call sequence data, help reduce false positives and false negatives, and improve the efficiency and accuracy of security detection;
[0087] Specifically, data preparation includes: collecting system call sequences, allowing the behavior pattern recognition model to learn behavior features known to be normal behaviors, and then marking the behavior features of abnormal behaviors in the system call sequences, allowing the behavior pattern recognition model to learn the abnormal behavior features, and obtaining prepared data, the prepared data being normal behavior features and abnormal behavior features;
[0088] Specifically, the model training includes: dividing the prepared data into a training set and a test set, setting various parameters of the behavior pattern recognition model, using the training set to train the behavior pattern recognition model, and then using the test set to calculate various indicators of the behavior pattern recognition model, evaluating the trained behavior pattern recognition model according to the various indicators, and then according to the evaluation results, tuning the parameters and data volume of the behavior pattern recognition model to obtain a trained behavior pattern recognition model;
[0089] Preferably, when training the behavior pattern recognition model, trusted computing technology can be used to ensure the integrity and authenticity of the training data. The training data can be encrypted and signed by hardware security modules such as trusted platforms to prevent the data from being tampered with during transmission and storage.
[0090] Behavior measurement: Based on the preset behavior measurement indicators and the acquired abnormal behavior patterns, the abnormal behavior patterns identified by the behavior pattern recognition model are quantitatively evaluated and a detailed behavior measurement report is generated, which can not only help users or security management systems understand the specific risk situation of the target application, but also provide strong data support for subsequent security analysis and risk assessment;
[0091] Preferably, the preset behavior measurement indicators are: system call frequency, system call sequence length, system call response time, resource consumption indicator and abnormal behavior indicator;
[0092] Preferably, the quantitative evaluation includes: continuously collecting system call exception data of the target application, then analyzing the collected system call exception data according to preset behavior measurement indicators, and then comparing the analyzed data with system call frequency, system call sequence length, system call response time and resource consumption indicators;
[0093] Preferably, the behavior metric report includes: a quantitative score of the target application behavior, a specific description of the abnormal behavior pattern, and a risk level description.
[0094] Preferably, the generated behavior measurement report can be stored in an area protected by the trusted platform to ensure the security and integrity of the report. At the same time, the report itself can also be signed and verified so that the user or security management system can verify the authenticity of the report.
[0095] Embodiment 4:
[0096] like Figure 2 As shown, the present invention also provides an application behavior measurement system based on system calls, comprising:
[0097] System call monitoring module: used to monitor the system call sequence generated by the target application during execution in real time;
[0098] Behavior feature extraction module: used to preprocess the system call sequence, and then use the behavior feature extraction algorithm to extract the key behavior features related to the target application behavior.
[0099] Behavior pattern recognition module: used to input key behavior features into a pre-trained behavior pattern recognition model, and identify abnormal behavior patterns of the target application through the behavior pattern recognition model;
[0100] Behavior measurement module: used to quantitatively evaluate the abnormal behavior patterns identified by the behavior pattern recognition model based on preset behavior measurement indicators and generate a behavior measurement report.
[0101] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for measuring application behavior based on system calls, characterized in that: The following steps are involved: Real-time monitoring of the system call sequences generated by the target application during execution; Preprocessing the system call sequence, and then using a behavior feature extraction algorithm on the preprocessed system call sequence to extract key behavior features related to the target application behavior; the behavior feature extraction algorithm includes a frequent pattern mining algorithm and a sequence alignment algorithm; Input key behavior features into a pre-trained behavior pattern recognition model, and use the behavior pattern recognition model to identify abnormal behavior patterns of the target application; The training of the behavior pattern recognition model includes: data preparation and model training; the data preparation includes: collecting system call sequences, so that the behavior pattern recognition model learns known normal behavior features, and then marking abnormal behavior features in the system call sequences, so that the behavior pattern recognition model learns abnormal behavior features, and obtains prepared data, and the prepared data is normal behavior features and abnormal behavior features; the model training includes: dividing the prepared data into a training set and a test set, setting various parameters of the behavior pattern recognition model, using the training set to train the behavior pattern recognition model, and then using the test set to calculate various indicators of the behavior pattern recognition model, evaluating the trained behavior pattern recognition model according to the various indicators, and then according to the evaluation results, tuning the parameters and data volume of the behavior pattern recognition model to obtain a trained behavior pattern recognition model; According to preset behavior measurement indicators, the abnormal behavior patterns identified by the behavior pattern recognition model are quantitatively evaluated to generate a behavior measurement report; the preset behavior measurement indicators are: system call frequency, system call sequence length, system call response time, and resource consumption indicators; the quantitative evaluation includes: continuously collecting system call exception data of the target application, and then analyzing the collected system call exception data according to the preset behavior measurement indicators, and then comparing the analyzed data with the system call frequency, system call sequence length, system call response time and resource consumption indicators.
2. The method for measuring application behavior based on system calls according to claim 1, characterized in that: The real-time monitoring includes at least one of the following: Replace the pointer of the system call corresponding to the target application in the system call table, so that the pointer points to the custom monitoring function to achieve real-time monitoring; Use system call monitoring tools to achieve real-time monitoring.
3. The method for measuring application behavior based on system calls according to claim 2, characterized in that: The system call monitoring tool includes: a system tracer and a system probe.
4. The method for measuring application behavior based on system calls according to claim 1, characterized in that: The preprocessing includes: removing redundant information and normalizing data.
5. The method for measuring application behavior based on system calls according to claim 1, characterized in that: The behavior measurement report includes: a quantitative score of the target application behavior, a specific description of the abnormal behavior pattern, and a risk level description.
6. A system for measuring application behavior based on system calls, based on the method for measuring application behavior based on system calls according to any one of claims 1 to 5, characterized in that: include: System call monitoring module: used to monitor the system call sequence generated by the target application during execution in real time; Behavior feature extraction module: used to preprocess the system call sequence, and then use the behavior feature extraction algorithm to extract the key behavior features related to the target application behavior. Behavior pattern recognition module: used to input key behavior features into a pre-trained behavior pattern recognition model, and identify abnormal behavior patterns of the target application through the behavior pattern recognition model; Behavior measurement module: used to quantitatively evaluate the abnormal behavior patterns identified by the behavior pattern recognition model based on preset behavior measurement indicators and generate a behavior measurement report.
Citation Information
Patent Citations
An FP-growth algorithm-based abnormal behavior detection method and a model applying the method
CN112800101A
Apparatus and method for detecting malware code by generating and analyzing behavior pattern
US20170270299A1