Network attack threat verification method and system
By simulating the server to perform attachment phishing attacks and steganography, triggering malicious programs to execute and analyzing the email content, solving the security threat problem of difficult to verify the phishing email attacks in the existing technology, and achieving efficient threat verification and response.
Patent Information
- Application Number
- CN202510131541.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-06
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2045-02-06
AI Technical Summary
The prior art is difficult to efficiently verify the security threats generated by phishing email attacks based on hidden network transmission, making it difficult to deeply understand and effectively deal with new types of cyber attacks.
The attachment phishing attack is carried out by simulated servers, triggering the target host to download and run malicious programs, obtain host information, and generate emails that embed malicious control commands using steganography, execute commands through malicious programs and send emails that embedded execution results, and determine the threat path based on the sending and receiving status and content of the email.
It has achieved efficient verification of the security threat of phishing email attacks based on hidden network transmission, and can deeply understand and respond to new future cyber attacks, enhancing concealment and long-term nature.
Smart Images

Figure CN119583222B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network attack threat verification method and system. Background Art
[0002] Social engineering attacks exploit human psychological vulnerabilities and trust relationships, with the attacker's goal being to obtain sensitive information or gain control over the target system. Email phishing is one of the most common social engineering attacks. Attackers often disguise themselves as trustworthy organizations or individuals, tricking users into clicking malicious links or downloading attachments. This allows them to steal sensitive information such as login credentials, or even directly infect the target device.
[0003] In recent years, attackers' methods have become increasingly sophisticated, and covert network transmission techniques can improve the success rate and stealth of attacks. Attackers often use steganography, encrypted communication protocols, or disguise legitimate traffic to conceal instructions and data transmissions, thereby circumventing network security equipment's in-depth monitoring of network traffic and anomaly detection. This not only makes the attack difficult to detect but also allows attackers to maintain long-term control.
[0004] In summary, phishing email attacks, transmitted over covert networks, not only circumvent traditional security measures but can also lead to large-scale, long-term, and undetectable privacy leaks and system control, posing a serious and persistent threat to individuals, organizations, and even society. Therefore, in-depth research into the implementation process of such social engineering attacks and evaluating the security performance of devices under such attacks is crucial. Efficiently verifying the security threats posed by phishing email attacks transmitted over covert networks is of great theoretical and practical significance for a deeper understanding of and effective response to future new cyberattack threats. Summary of the Invention
[0005] In view of this, an object of the present invention is to provide a network attack threat verification method and system to efficiently verify the security threats caused by phishing email attacks based on covert network transmission.
[0006] In the first aspect, an embodiment of the present invention provides a network attack threat verification method, including: conducting a phishing email attack on a target host corresponding to a target email address based on an attachment phishing method to trigger the target host to download and run a malicious program; obtaining host information of the target host, and generating a first malicious email embedded with a malicious control command using steganography based on the host information, and then sending the first malicious email to the malicious program to execute the malicious control command through the malicious program; receiving a second malicious email sent by the malicious program; wherein the malicious program is used to generate the second malicious email based on the execution result of the malicious control command, and the second malicious email is embedded with the execution result using steganography; based on the email sending and receiving status and the email content of each email received and sent, determining the threat path of the phishing email attack.
[0007] In the second aspect, an embodiment of the present invention also provides a network attack threat verification system, including a simulation server and a target host corresponding to a target email address; the simulation server is used to perform a phishing email attack on the target host based on an attachment phishing method to trigger the target host to download and run a malicious program; the simulation server is also used to obtain the host information of the target host, and based on the host information, generate a first malicious email embedded with a malicious control command using steganography, and then send the first malicious email to the malicious program; the malicious program is used to execute the malicious control command, and based on the execution result of the malicious control command, generate a second malicious email embedded with the execution result using steganography, and then send the second malicious email to the simulation server; the simulation server is also used to determine the threat path of the phishing email attack based on the email sending and receiving status and the email content of each email received and sent.
[0008] An embodiment of the present invention provides a network attack threat verification method and system. A simulation server conducts a phishing email attack on a target host corresponding to a target email address using an attachment phishing method, triggering the target host to download and run a malicious program. The system then obtains the target host's host information and, based on the host information, sends a first malicious email embedded with a malicious control command using steganography to the malicious program, allowing the malicious program to execute the malicious control command. The system then receives a second malicious email embedded with the execution result of the malicious control command, sent by the malicious program based on the execution result of the malicious control command. Finally, the threat path of the phishing email attack is determined based on the email sending and receiving status and the content of each email sent and received. Using the above technology, a network attack against a target host can be simulated using attachment phishing and steganography. The threat path of the phishing email attack can then be determined based on the email sending and receiving status and email content of the simulated server. This method can efficiently verify the security threats generated by network attacks based on covert network transmission, and has important theoretical and practical significance for in-depth understanding and effective response to future new network attack threats.
[0009] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or understood by practicing the present invention. The purposes and other advantages of the present invention are realized and obtained by the structures particularly pointed out in the description, claims and drawings.
[0010] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0012] Figure 1 Schematic diagram of a flow chart of a network attack threat verification method according to an embodiment of the present invention;
[0013] Figure 2 This is a system architecture diagram for network attack threat verification in an embodiment of the present invention;
[0014] Figure 3 This is an example diagram of the remote control process in an embodiment of the present invention;
[0015] Figure 4 Schematic diagram of the structure of a network attack threat verification system in an embodiment of the present invention. DETAILED DESCRIPTION
[0016] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0017] To facilitate understanding of this embodiment, a network attack threat verification method disclosed in an embodiment of the present invention is first described in detail. This method can be applied to a simulation server. Figure 1 The flowchart of a network attack threat verification method shown in FIG. 1 may include the following steps:
[0018] Step S102: A phishing email attack is performed on a target host corresponding to a target email address based on an attachment phishing method, so as to trigger the target host to download and run a malicious program.
[0019] Step S104: obtaining host information of the target host, and generating a first malicious email embedded with a malicious control command using steganography based on the host information, and then sending the first malicious email to the malicious program to execute the malicious control command through the malicious program.
[0020] Step S106: receiving a second malicious email sent by the malicious program.
[0021] The malicious program is used to generate a second malicious email based on the execution result of the malicious control command, and the second malicious email is embedded with the execution result using steganography.
[0022] Step S108: determining the threat path of the phishing email attack based on the email sending and receiving status and the email content of each email received and sent.
[0023] An embodiment of the present invention provides a network attack threat verification method. A simulation server conducts a phishing email attack on a target host corresponding to a target email address based on an attachment phishing method, triggering the target host to download and run a malicious program. The server then obtains the host information of the target host and, based on the host information, sends a first malicious email embedded with a malicious control command using steganography to the malicious program, allowing the malicious program to execute the malicious control command. The server then receives a second malicious email embedded with the execution result of the malicious control command, sent by the malicious program based on the execution result of the malicious control command. The method ultimately determines the threat path of the phishing email attack based on the email sending and receiving status and the content of each email sent and received. Using the above technology, a network attack against the target host can be simulated using attachment phishing and steganography. The threat path of the phishing email attack can then be determined based on the email sending and receiving status and email content of the simulated server. This method can efficiently verify the security threats generated by network attacks based on covert network transmission, and has important theoretical and practical significance for in-depth understanding and effective response to future new network attack threats.
[0024] As a possible implementation, step S102 (i.e., launching a phishing email attack on a target host corresponding to a target email address based on an attachment phishing method to trigger the target host to download and run a malicious program) may include:
[0025] Step 1: Generate a phishing email with a phishing attachment based on a preset software vulnerability and a target email address, and send the phishing email to the target email address.
[0026] For example, the preset software vulnerability may be a remote code execution vulnerability; the operation method of the above step 1 may include the following steps 11 to 12:
[0027] Step 11, exploiting a remote code execution vulnerability to construct a malicious Word document embedded with a malicious link and malicious code; wherein, the malicious link is used to trigger the target host to execute the malicious code when the malicious Word document is opened to download and run the malicious program from the download server.
[0028] The embedding methods of malicious links and malicious codes include but are not limited to modifying the internal data structure of Word documents.
[0029] Step 12: Use the Word document as a phishing attachment and the target email address as the recipient to generate a phishing email.
[0030] Step 2: When the phishing attachment is opened, the target host is triggered to download a malicious program from a download server corresponding to the simulated attacker and run the malicious program; wherein the malicious program is stored on the download server.
[0031] As a possible implementation method, the simulation server can adopt the EwoMail mail server; based on this, the steps of establishing the simulation server can include: configuring the mailbox domain name of the EwoMail mail server; turning off SELinux of the EwoMail mail server and configuring the mail sending port of the EwoMail mail server; installing EwoMail and establishing a mapping relationship between the mailbox domain name of the EwoMail mail server and the local IP address, and then creating an email account of the EwoMail mail server.
[0032] For example, a simulation server can be built using the EwoMail mail server, which provides complete email services (including sending and receiving emails, email storage, user management, and other functions). The EwoMail mail server itself can be configured with multiple domain names to send and receive emails, but before installing EwoMail, you need to configure an email domain name as the primary domain name of the email address. After investigating the target object (corresponding to the target host), the simulated attacker can set the email domain name related to the target object on the EwoMail mail server. For example, if the target object is an employee of a company, the simulated attacker can set the email domain name to be similar to the company's email domain name; then the simulated attacker can build a simulation server according to the following process:
[0033] Step A1: Check and disable SELinux.
[0034] For example, when setting up a simulation server, you can enter the command "vi / etc / sysconfig / selinux" in the command line window of the EwoMail mail server's operating system and change "SELINUX=enforcing" to "SELINUX=disable" to disable SELinux, thereby avoiding service abnormalities caused by permission issues on the EwoMail mail server.
[0035] Step A2: Test port 25.
[0036] Port 25 is the default SMTP port, used for sending and relaying emails. Since port 25 is required when sending emails to external email accounts created with EwoMail, you need to use Telnet to test whether port 25 is reachable in advance. If port 25 is not reachable, you need to configure port 25 to ensure that it is reachable.
[0037] Step A3, install EwoMail.
[0038] For example, determine the domain name, install EwoMail using git in a CentOS environment, and then perform the following configuration operations:
[0039] Step A31, communication configuration.
[0040] Add the local IP address and mailbox domain name to the hosts file of the EwoMail mail server to map the mailbox domain name to the local IP address, thereby establishing an association between the local IP address and the mailbox domain name.
[0041] Step A32: Create an email account.
[0042] You can configure the mailbox domain name and create a mailbox account through the mailbox management background of EwoMail, then select an mailbox account to access the Web mailbox system to log in and use it, and set the account name of the mailbox account so that the account name can be displayed in the sender's abbreviation in the emails received by the recipient.
[0043] Step A33: design and construct a phishing email.
[0044] The simulated attacker can investigate the relevant information of the target object, and based on the investigated information, carefully write a Word document embedded with malicious links and malicious code to enhance its credibility. The attacker can edit the misleading email content and add it to the phishing email, add the Word document as an attachment to the phishing email, and add the target email address as the recipient to the phishing email. After the phishing email is sent to the target email address, the malicious link in the Word document is opened by the target object, triggering the target host to execute the malicious code to download and run the malicious program.
[0045] As a possible implementation, the host information may include the host ID, operating system information and host detailed information of the target host; based on this, the simulation server may also log in using the created email account before obtaining the host information of the target host; then obtaining the host information of the target host in the above step S104 may include: obtaining a first email containing a first specific subject, and parsing the first email to obtain the host ID and operating system information of the target host from the first email; obtaining a second email containing a second specific subject, and parsing the second email to obtain the host detailed information of the target host from the second email.
[0046] In actual application, in order to achieve remote control of the target host based on email, you can initialize configuration information (including email account information, SMTP server information, etc.) and define a class for interacting with the mailbox. When the class is instantiated, an IMAP4_SSL object is created. For example, the instruction self.c = imaplib.IMAP4_SSL(server) is used to create the IMAP4_SSL object. The IMAP4_SSL object can be used to create an SSL-based IMAP4 connection, and the username and password provided by the created email account can be used to log in through the login method. For example, the instruction "self.c.login(gmail_user, gmail_pwd)" is used to log in to the email account.
[0047] The subject of an email can be used to identify different types of information. For example, the subject 'hereiam:' indicates the existence of a host, while the subject 'hereiam:botid' indicates detailed information about the host. A checkBots method can be defined to check the information of a bot (i.e., a target host) that has been backdoored (i.e., running a malicious program) to determine which specific target host or hosts it is. Specifically, the checkBots method can be used to retrieve emails with a specific subject ('hereiam:') from the mailbox. Parsing the information in the email can obtain the bot's ID and operating system information, and then print out the bot's ID and operating system information, thereby achieving the purpose of stealing the host's ID and operating system information. The getBotInfo method can be used to retrieve emails with a specific subject ('hereiam:botid') from the mailbox. Parsing the information in the email can obtain detailed information about a specific bot, and then print out the detailed information about the specific bot, thereby achieving the purpose of stealing the host's detailed information.
[0048] As a possible implementation, generating a first malicious email embedded with a malicious control command using steganography based on the host information in step S104 may include: generating the malicious control command based on the host information, encoding the malicious control command into a first image using image steganography, and using the first image embedded with the malicious control command as email content to generate the first malicious email. Accordingly, before executing the malicious control command via the malicious program, the malicious program may also decode the first image contained in the first malicious email using image steganography to obtain the malicious control command.
[0049] For example, the steps of encoding and embedding malicious control commands into the first image using image steganography may include: converting the malicious control commands into a first bitstream, dividing the first bitstream into multiple first sub-bitstreams, and traversing the first image pixel by pixel to embed each first bitstream into the two least significant bits of the corresponding pixel in the first image. This encoding method enables the malicious control commands to be embedded into the image without significantly changing the visual appearance of the image, thereby enhancing the stealth and long-term effectiveness of the attack.
[0050] As a possible implementation, the step of generating a second malicious email based on the execution result of the malicious control command may include: using image steganography to encode the execution result and embed it into a second image; and using the second image embedded with the execution result as the email content to generate the second malicious email. Accordingly, after receiving the second malicious email sent by the malicious program, the simulated server may also use image steganography to decode the second image contained in the second malicious email to obtain the execution result.
[0051] For example, the step of using image steganography to encode and embed the execution result into the second image may include: converting the execution result into a second bitstream, dividing the second bitstream into multiple second sub-bitstreams; and traversing the second image pixel by pixel to embed each second bitstream into the two least significant bits of the corresponding pixel in the second image. This encoding method enables the execution result of the malicious control command to be embedded into the image without significantly changing the visual appearance of the image, thereby enhancing the stealth and long-term effectiveness of the attack.
[0052] As a possible implementation, the above-mentioned step S108 (i.e., determining the threat path of the phishing email attack based on the email sending and receiving status and the email content of each email received and sent) may include: if the phishing email is not successfully sent to the target email address or the sending of the first malicious email fails, then the threat path of the phishing email attack is determined as the first path indicating that the target host has not been maliciously controlled; if the first malicious email is successfully sent and the second malicious email is not successfully received, then the threat path of the phishing email attack is determined as the second path indicating that the target host has been maliciously controlled and data has not been stolen; if the second malicious email is successfully received, then the threat path of the phishing email attack is determined as the third path indicating that data has been stolen from the target host.
[0053] For ease of understanding, the implementation of the above-mentioned network attack threat verification method is described below using a specific application as an example:
[0054] See also Figure 2 As shown in the system architecture diagram of network attack threat verification, network attack threat verification is mainly achieved by sending and receiving emails between the simulation server 100 and the target host 200 under test corresponding to the target mailbox.
[0055] See also Figure 2 As shown, the technical implementation of network attack threat verification mainly includes: first, a simulation server 100 is set up, which is responsible for creating an email address with a simulated network attack nature and sending a phishing email with an attachment to the target email address, so as to simulate the behavior of inducing the target object to view the phishing email and download the attachment on the target host; the attachment of the phishing email is a malicious Word document. Once the target host downloads and opens the Word document, it will trigger the target host to download and run the malicious program, thereby simulating that the target host has been implanted with a backdoor by the attacker through a Word vulnerability; thereafter, the simulated attacker can obtain the host information of the target host by parsing the email with a specified subject, and use image steganography technology to encode the instruction used to control the target host in the image, and then send an email containing the image (that is, the first malicious email at this time) to the malicious program implanted on the target host; the malicious program subsequently decodes the instruction from the image in the email and executes it to achieve remote control of the target device, and uses image steganography technology to encode the execution result of the instruction in the image, and then returns an email containing the image (that is, the second malicious email at this time) to the simulated attacker, so that the simulated attacker can decode the execution result from the image in the email.
[0056] Cyber attack threat verification mainly includes four aspects: setting up phishing servers, implanting backdoors by exploiting Word vulnerabilities, C2C remote control based on the email system, and covert information theft based on image steganography.
[0057] 1. Setting up a phishing server
[0058] Using the EwoMail mail server to set up a simulated server, the attacker can investigate the target and set up the email domain associated with the target. The simulated server is then set up according to the following process: Check and disable SELinux to prevent EwoMail server service anomalies due to permission issues; use Telnet to test port 25 to ensure accessibility; determine the domain name, install EwoMail using git in a CentOS environment, and then perform the relevant configuration operations. These operations primarily include configuring communication, creating an email account, and designing and constructing a phishing email.
[0059] The operation method of communication configuration mainly includes: adding the local IP address and mailbox domain name to the hosts file of the EwoMail mail server to map the mailbox domain name to the local IP address.
[0060] The operation method of creating an email account mainly includes: configuring the email domain name and creating an email account through the email management background of EwoMail, then selecting an email account to access the web email system for login, and setting the account name to be displayed in the sender's abbreviation in the emails received by the recipient.
[0061] The operation method of designing and constructing phishing emails mainly includes: simulating the attacker to investigate the relevant information of the target object and then carefully write a Word document with malicious links and malicious codes embedded in it, editing the misleading email content, attaching the Word document and setting the target email address as the recipient, and constructing a phishing email so that after the phishing email is sent to the target email address, the Word document will be opened by the target object, triggering the target host to download and run the malicious program.
[0062] (2) Word vulnerability exploitation
[0063] The vulnerability, CVE-2022-30190, also known as the "Follina" vulnerability, was exploited in Microsoft Office's Microsoft Support Diagnostic Tool (MSDT) when creating a Word document embedded with malicious links and malicious code. This vulnerability allows an attacker to achieve remote code execution by carefully crafting a malicious Word document embedded with malicious links and remote code (in this case, malicious code) and exploiting MSDT's improper handling of external links.
[0064] When a user opens such a malicious Word document, the embedded malicious link triggers the MSDT tool, leading to remote code execution without user interaction. Specifically, the attacker embeds a malicious URL and remote script in the Word document, tricking the user into launching MSDT without their knowledge. The malicious URL then triggers remote code execution on the user's host, downloading and running the remote script. These remote scripts can perform unauthorized actions on the victim's computer, including downloading malware, stealing sensitive information, and implanting backdoors.
[0065] To achieve remote control in the subsequent steps, a client program (the malicious program at this point) was designed with integrated client functionality. This client program is capable of communicating with the simulated attacker client, using network protocols to transmit information. First, exploiting the "Follina" vulnerability, a Word document containing a malicious link and remote code was constructed. When the user opened the document, MSDT was triggered, executing a PowerShell command pre-set in the remote code. This PowerShell command first randomly retrieved the username of a non-public user, then downloaded the malicious program from a server controlled by the simulated attacker to the temporary folder of the user's computer, and finally executed it. To achieve remote code execution, the PowerShell command was Base64-encoded, embedded in the Word document's HTML payload, and triggered via the MS-MSDT protocol. The entire process was designed to exploit the user's trust in the Word document and covertly achieve remote control of the target host.
[0066] (3) C2C remote control based on email system
[0067] It primarily uses the email system as a backdoor to transmit commands between clients, enabling C2C remote control. Specifically, it reads new emails from the target mailbox via IMAP and parses the email content. It then sends an email containing commands to the client program via SMTP. The client program then executes the commands and remotely returns an email containing the results to the designated mailbox. Information is then extracted from the returned email via IMAP. The specific implementation process for using IMAP and SMTP together is as follows:
[0068] Step a1, IMAP receiving commands: The client periodically checks the command emails in the designated mailbox and extracts the tasks to be executed by parsing the email contents through IMAP.
[0069] Step a2, executing the task: Based on the email content parsed by IMAP, the corresponding function module is called to execute the corresponding operation required for the task (such as downloading a file, uploading a file, executing a command, etc.).
[0070] Step a3, SMTP returns the task execution result: After the task is completed, the task execution result is sent to the designated mailbox via SMTP in the form of an email.
[0071] The subject of the email is used to identify different types of information, such as 'hereiam:' to indicate the existence of the host, and 'dmp:botid:jobid' to indicate the result of the task execution. The entire workflow of remote control allows communication and control of malicious programs implanted in the target host through email, see Figure 3 As shown, the implementation of remote control mainly includes the following steps:
[0072] 1) Initial configuration and login.
[0073] Set configuration information (including mailbox account information, SMTP server information, etc.), create an SSL-based IMAP4 connection using the IMAP4_SSL object created in advance when instantiating the class used to interact with the mailbox, and log in using the provided mailbox user name and mailbox password through the login method.
[0074] 2) Check the information that has been implanted into the host.
[0075] Define a checkBots method to check the information of the host with the backdoor implanted. The checkBots method will obtain emails with a specific subject ('hereiam:') from the specified mailbox, parse the information in these emails, and print out the ID and operating system information of the bot (that is, the host with the backdoor implanted).
[0076] 3) Get detailed information of a specific bot.
[0077] Use the getBotInfo method to get detailed information about a specific bot. The getBotInfo method retrieves emails with a specific subject ('hereiam:botid') from the specified mailbox, parses the information in these emails, and prints out detailed information about the specific bot.
[0078] 4) Send commands to the client program implanted in the target host.
[0079] Use the sendEmail method to send commands to the client program implanted on the target host. The sendEmail method's parameters include botid (client ID, also known as the target host's host ID), jobid (task ID), cmd (the command to be executed by the client program), arg (command parameters), and attachments (a list of attachments). The commands executed by the client program can include executing system commands, taking screenshots, popping up message boxes, locking the client screen, uploading files to the client, and shutting down or restarting the computer, with no restrictions.
[0080] 5) Get the execution result information of a specific task.
[0081] Use the getJobResults method to retrieve the execution results for a specific bot (i.e., a specific host) and job (i.e., a task). This method retrieves emails with the specified subject ('dmp:botid:jobid') from the specified mailbox, parses the information contained in these emails, and prints the execution results of the task in an easy-to-read format. If the email retrieved by this method contains attachments, it will also save the attachments to the specified directory.
[0082] It can also be determined whether to continue sending commands; if it is necessary to continue sending commands, the operation process of 4) and 5) is performed; if it is not necessary to continue sending commands, the remote control process is terminated.
[0083] (4) Covert information theft based on image steganography
[0084] To enhance the stealth and longevity of the attack, image steganography was incorporated, hiding both the command itself and the command execution results within an image file and transmitting them to a remote server. Image steganography, as the name suggests, is a technique that hides secret information (specifically, the command itself or the command execution results in this article) within an image file. Unlike encryption, steganography does not render secret information unreadable; rather, it renders it difficult to detect by hiding it within an image. Specifically, steganography embeds data (such as commands, instructions, or malicious code snippets) within the pixel data of an image without significantly altering its visual appearance.
[0085] Specifically, a least-significant-bit (LSB) steganography method based on PNG images can be used. After converting the payload data to be hidden into a bitstream, the bitstream is segmented into multiple 2-bit data segments. Each data segment is then embedded pixel by pixel into the two least significant bits (i.e., two significant bits) of the color component of a pixel at a specific location in the PNG image (e.g., the first few pixels starting from the upper left corner of the image, arranged from left to right). During the encoding phase, the client program scans the PNG image pixel by pixel, modifying the two least significant bits of the RGB channels of the corresponding pixel to carry the payload data. To ensure the integrity and quality of the embedded data and the image quality, the image capacity (i.e., the number of pixels) is checked before encoding to prevent the payload data size from exceeding the image's capacity. This LSB steganography method exploits the human eye's insensitivity to subtle pixel variations, maintaining the image visually nearly unchanged while concealing information. Furthermore, to improve efficiency, the code can be written to iterate over pixels on demand (i.e., skipping pixels where no data segments need to be embedded) and processing data byte by byte, thereby increasing data processing speed. In summary, the encoding process realizes the function of embedding secret information into PNG images through the LSB steganography method.
[0086] The corresponding decoding process reverses the encoding operation and can specifically include the following: First, the program extracts the payload length information from pixels at specific locations in the PNG image. The payload length information is composed of the two lowest-significant bits of the color components of the pixels at specific locations in the PNG image and is used to indicate the length of the payload data to be subsequently decoded. Then, the program iterates through the pixels of the PNG image, skipping the pixels parsed when extracting the payload length information, extracting the bit stream from the least-significant bits of the subsequent pixel color components, and reconstructing the bit stream into bytes. By looping and concatenating the two lowest-significant bits of the pixels, the program ultimately converts the bytes into characters, thereby recovering the payload data. To ensure decoding accuracy and efficiency, the program can control the data extraction process based on the pre-embedded payload length information to avoid extracting invalid data. In summary, this decoding process effectively extracts the payload data hidden in the PNG image by reversing the encoding operation and combining it with the length information.
[0087] In the aforementioned application scenario, the target host's response to the attack can be used to verify and assess the threat path of the attack. Specifically, the threat path of the target host can be determined based on whether the target host has emails and the content of the emails received by the target host (indicating whether certain operations have been blocked).
[0088] The threat paths of the target host can be divided into three types according to the order of threat scope from small to large:
[0089] The first type of threat path indicates that the target host can resist attacks (i.e., the target host is not maliciously controlled): The first type of threat path indicates that the system or user can effectively defend against attacks when they occur, preventing malicious code execution or backdoor implantation, thereby avoiding the attacker's initial control of the target host.
[0090] The second type of threat path indicates that the target host can detect network transmission anomalies (that is, the target host has been maliciously controlled and no data has been stolen): The second type of threat path indicates that the system or user can identify and alarm abnormal network behavior (including covert data transmission, abnormal traffic patterns, or communication activities using unknown protocols, etc.), thereby preventing attackers from stealing data from the target host.
[0091] The third type of threat path indicates that the target host can perceive the stolen data (that is, the target host has had data stolen): The third type of threat path indicates that the system or user can recognize the behavior of data leakage (such as traces of sensitive information being extracted or transmitted), and can promptly identify data outflows by analyzing files, data packets or communication content and take corresponding measures to curb losses.
[0092] The above network attack threat verification method has the following advantages over existing technologies:
[0093] By combining image steganography, covert communication of mailbox C&C, Word vulnerabilities and phishing email attacks, we simulated the attacker's covert remote control of the target host, and then verified and evaluated the threat path of the attack based on the target host's response to the attack, thereby efficiently verifying the threat scope of network attacks based on covert network transmission, so that relevant personnel can deeply understand and effectively respond to the security threats brought by network attacks.
[0094] Based on the above network attack threat verification method, the embodiment of the present invention also provides a network attack threat verification system, see Figure 4 As shown, the system may include a simulation server 100 and a target host 200 corresponding to a target email address;
[0095] The simulation server 100 can be used to launch a phishing email attack on the target host 200 based on an attachment phishing method, so as to trigger the target host 200 to download and run a malicious program 300;
[0096] The simulation server 100 may also be used to obtain host information of the target host 200, and generate a first malicious email embedded with a malicious control command using steganography based on the host information, and then send the first malicious email to the malicious program 300;
[0097] The malicious program 300 may be used to execute the malicious control command, and based on the execution result of the malicious control command, generate a second malicious email embedded with the execution result using steganography, and then send the second malicious email to the simulation server 100;
[0098] The simulation server 100 may also be used to determine the threat path of the phishing email attack based on the email sending and receiving status and the email content of each email received and sent.
[0099] By using the above-mentioned network attack threat verification system, we can use attachment phishing and steganography to simulate network attacks against the target host, and then determine the threat path of the phishing email attack based on the email sending and receiving status and email content of the simulated server. It can efficiently verify the security threats caused by network attacks based on covert network transmission, and has important theoretical and practical significance for in-depth understanding and effective response to new network attack threats in the future.
[0100] The network attack threat verification system provided in the embodiment of the present invention has the same implementation principle and technical effects as those in the aforementioned network attack threat verification method embodiment. For the sake of brief description, for matters not mentioned in the embodiment of the network attack threat verification system, reference may be made to the corresponding content in the aforementioned network attack threat verification method embodiment.
[0101] Unless otherwise specifically stated, the relative steps, numerical expressions and values of the components and steps set forth in these embodiments do not limit the scope of the present invention.
[0102] If the functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage media include various media capable of storing program code, such as USB flash drives, mobile hard drives, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks.
[0103] In the description of the present invention, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicating orientations or positional relationships, are based on the orientations or positional relationships shown in the accompanying drawings and are intended solely to facilitate and simplify the description of the present invention. They are not intended to indicate or imply that the devices or components referred to must have, be constructed, or operate in a specific orientation, and therefore should not be construed as limitations on the present invention. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.
[0104] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit them. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the above-described embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily conceive of changes to the technical solutions described in the above-described embodiments within the technical scope disclosed by the present invention, or replace some of the technical features therein with equivalents. Such modifications, changes, or replacements do not deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.
Claims
1. A network attack threat verification method, characterized in that: Applicable to simulation servers, including: A phishing email with a phishing attachment is generated based on a preset software vulnerability and a target email address, and the phishing email is sent to the target email address; when the phishing attachment is opened, the target host corresponding to the target email address is triggered to download a malicious program from a download server corresponding to the simulated attacker and run the malicious program; wherein the preset software vulnerability is a remote code execution vulnerability, the simulated server is an EwoMail email server, and the malicious program is stored on the download server; Obtaining host information of the target host, and generating a first malicious email embedded with a malicious control command using steganography based on the host information, and then sending the first malicious email to the malicious program, so that the malicious program decodes the image contained in the first malicious email using image steganography to obtain the malicious control command and execute the malicious control command; wherein the host information includes the host ID, operating system information, and host detailed information of the target host; receiving a second malicious email sent by the malicious program, and decoding an image contained in the second malicious email using image steganography to obtain an execution result; wherein the malicious program is used to generate the second malicious email based on the execution result of the malicious control command, and the second malicious email is embedded with the execution result using steganography; If the phishing email is not successfully sent to the target email address or the sending of the first malicious email fails, the threat path of the phishing email attack is determined to be the first path indicating that the target host has not been maliciously controlled; if the first malicious email is successfully sent and the second malicious email is not successfully received, the threat path of the phishing email attack is determined to be the second path indicating that the target host has been maliciously controlled and data has not been stolen; if the second malicious email is successfully received, the threat path of the phishing email attack is determined to be the third path indicating that data has been stolen from the target host; The generation of the first malicious email and the second malicious email respectively includes: converting the current data to be embedded into a bit stream, and then dividing the bit stream into multiple first sub-bit streams; wherein, the current data to be embedded for the first malicious email is the malicious control command generated by the malicious program based on the host information, and the current data to be embedded for the second malicious email is the execution result; traversing the image required to be included in the corresponding malicious email pixel by pixel to embed each sub-bit stream encoding into the two least significant bits of the corresponding pixel of the image; using the image embedded with multiple sub-bit streams as the email content to generate the corresponding malicious email; wherein, each sub-bit stream is a 2-bit data segment.
2. The network attack threat verification method according to claim 1, characterized in that: Generate phishing emails with phishing attachments based on pre-set software vulnerabilities and target email addresses, including: Exploiting the remote code execution vulnerability, a malicious Word document embedded with a malicious link and malicious code is constructed; wherein the malicious link is used to trigger the target host to execute the malicious code when the malicious Word document is opened, so as to download the malicious program from the download server and run the malicious program; The Word document is used as a phishing attachment, and the target email address is used as the recipient to generate the phishing email.
3. The network attack threat verification method according to claim 1, characterized in that: The establishment of the simulation server includes: Configure the mailbox domain name of the EwoMail mail server; Disable SELinux of the EwoMail mail server and configure the mail sending port of the EwoMail mail server; Install EwoMail, and establish a mapping relationship between the mailbox domain name of the EwoMail mail server and the local IP address, and then create a mailbox account of the EwoMail mail server.
4. The network attack threat verification method according to claim 3, characterized in that: Before obtaining the host information of the target host, the method further includes: logging in using the created email account.
5. A network attack threat verification system, characterized in that: Including the simulation server and the target host corresponding to the target email address; The simulation server is used to: generate a phishing email with a phishing attachment based on a preset software vulnerability and a target email address, and send the phishing email to the target email address; when the phishing attachment is opened, trigger the target host to download a malicious program from a download server corresponding to the simulated attacker and run the malicious program; wherein the preset software vulnerability is a remote code execution vulnerability, the simulation server uses an EwoMail email server, and the malicious program is stored on the download server; The simulation server is further configured to obtain host information of the target host, and generate a first malicious email embedded with a malicious control command using steganography based on the host information, and then send the first malicious email to the malicious program; The malicious program is configured to: decode the image contained in the first malicious email using image steganography to obtain the malicious control command and execute the malicious control command; wherein the host information includes the host ID, operating system information, and host detailed information of the target host; generate a second malicious email embedded with the execution result using steganography based on the execution result of the malicious control command, and send the second malicious email to the simulation server; The simulation server is further configured to: receive a second malicious email sent by the malicious program, and decode the image contained in the second malicious email using image steganography to obtain the execution result; if the phishing email is not successfully sent to the target email address or the sending of the first malicious email fails, determine the threat path of the phishing email attack as a first path indicating that the target host has not been maliciously controlled; if the first malicious email is successfully sent and the second malicious email is not successfully received, determine the threat path of the phishing email attack as a second path indicating that the target host has been maliciously controlled and data has not been stolen; if the second malicious email is successfully received, determine the threat path of the phishing email attack as a third path indicating that data has been stolen from the target host; The generation of the first malicious email and the second malicious email respectively includes: converting the current data to be embedded into a bit stream, and then dividing the bit stream into multiple first sub-bit streams; wherein, the current data to be embedded for the first malicious email is the malicious control command generated by the malicious program based on the host information, and the current data to be embedded for the second malicious email is the execution result; traversing the image required to be included in the corresponding malicious email pixel by pixel to embed each first sub-bit stream encoding into the two least significant bits of the corresponding pixel of the image; using the image embedded with multiple sub-bit streams as the email content to generate the corresponding malicious email; wherein, each sub-bit stream is a 2-bit data segment.
Citation Information
Patent Citations
Attack simulation method and device, electronic equipment and storage medium
CN117318973A
Detection method and system for staged steganographic malicious codes
CN117439768A