Security test method, device and equipment based on killing-free attack file
By using a kill-free attack file with pre-set sleep state in offense and defense testing, and using exception handling functions to update memory attributes, the problem of insufficient concealment of attack files in the existing technology is solved, and high concealment and effective security testing effects are achieved.
Patent Information
- Application Number
- CN202411730503.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-28
- Publication Date
- 2025-05-02
AI Technical Summary
During the offensive and defensive testing process, it is difficult for the prior art to effectively test the security of the defense system because there is a lack of effective methods to ensure the concealment of attack files.
By presetting the sleepless attack file in the system under test, and using exception handling functions to update the memory attributes, the killless attack file dynamically updates its memory attributes in the running and sleep states, thereby improving concealment.
The high concealment of the attack file without killing is achieved, reducing the possibility of being discovered, thereby improving the security testing effect of the system under test.
Smart Images

Figure CN119921972A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a security testing method, device and equipment based on anti-killing attack files. Background Art
[0002] In the field of network security, verifying system security through attack and defense tests between the red and blue parties is a common security testing method. When conducting attack and defense tests between the two parties, the simulated attacker often needs to use various malware or malicious codes to attack the system being tested in order to verify the security issues existing in the system.
[0003] In this process, the simulated attacker needs to improve the concealment of the malware as much as possible to avoid being scanned by the defender's defense system during the attack and defense test, thereby achieving effective attack testing on the system under test.
[0004] In the current prior art, there are relatively few means to ensure the concealment of attack files used for testing in attack and defense tests, which makes them easy to be discovered during the attack and defense testing process, thereby failing to effectively test the security of the defense system. Summary of the invention
[0005] In view of this, the present invention provides a security testing method, device and equipment based on anti-killing attack files to solve the problem that the security of the defense system cannot be effectively tested during the attack and defense test process.
[0006] In a first aspect, the present invention provides a security testing method based on an anti-killing attack file, wherein the initial state of the anti-killing attack file is a dormant state, and the initial attribute of the first memory corresponding to the anti-killing attack file is non-executable. The method comprises:
[0007] After the system under test receives the security test instruction, it initiates a startup attempt by instructing the anti-killing attack file pre-set in the dormant state inside the system under test through the startup instruction;
[0008] When an abnormal reminder triggered by the startup attempt is monitored, updating the attribute of the first memory to executable through a predefined exception handling function;
[0009] Triggering the system under test to run the anti-killing attack file, and using the preset insertion code in the anti-killing attack file to replace the original sleep function in the system under test with the first sleep function;
[0010] When a sleep instruction for the anti-killing attack file is detected, the first sleep function is called to put the anti-killing attack file into a sleep state, and the attribute of the first memory is updated to be non-executable;
[0011] When the safety test on the system under test is completed, the safety protection data of the system under test is read and a safety test report is generated.
[0012] The method provided by the present aspect starts, after starting the security test of the system under test, an anti-killing attack file with a memory attribute pre-set as non-executable in the system under test; after monitoring the exception reminder triggered by the attempted startup, the attribute of the first memory is updated to executable through a pre-defined exception handling function to run the anti-killing attack file, and the sleep function in the system under test is replaced during the running process, so that when the sleep instruction of the anti-killing attack file is subsequently monitored, the attribute of the first memory is updated to non-executable through the replaced sleep function, thereby achieving the update of the attribute of the memory corresponding to the attack file as it runs and sleeps, thereby improving the concealment of the attack file, reducing the possibility of being discovered during the security test, and thus improving the test effect when the security test of the system under test is performed.
[0013] In an optional implementation manner, the start instruction and the sleep instruction are generated as follows:
[0014] Based on the program code inside the anti-killing attack file, generate a startup instruction and a sleep instruction of the attack file;
[0015] Or based on the startup instruction information and sleep instruction information remotely sent by the simulated attacking party of the security test, the startup instruction and sleep instruction of the attack file are generated respectively.
[0016] In this embodiment, instructions for controlling the startup or sleep of the attack file are generated through the program code inside the anti-killing attack file or the instruction information from the simulated attacker during the test, so as to ensure that the attack file can be started at the appropriate time during the operation, thereby ensuring the attack effect of the attack file and improving the effectiveness of the security test.
[0017] In an optional implementation, the abnormal reminder is an access violation reminder, and the access violation reminder is issued when the system under test detects that the anti-killing attack file initiates a startup attempt when the attribute of the first memory is in a non-executable state;
[0018] When an abnormal reminder triggered by the startup attempt is monitored, updating the attribute of the first memory to executable through a predefined exception handling function includes:
[0019] When an access violation reminder issued by the system under test is monitored, the system under test is instructed to call a predefined exception handling function for processing, and based on the exception handling function, the memory protection function of the system under test itself is called to update the attribute of the first memory to executable.
[0020] In this implementation, when the system under test initiates an access violation reminder, the system under test's own exception handling mechanism is used to instruct it to call a predefined exception handling function to update the memory attributes of the anti-killing attack file, so that the anti-killing attack file can be started and run normally. Since the update of memory attributes is implemented based on the mechanism of the system under test itself, the concealment of the anti-killing attack file when it is started can be effectively improved, thereby ensuring the security test effect.
[0021] In an optional implementation, the replacing the original sleep function in the system under test with the first sleep function by using the preset insertion code in the anti-killing attack file includes:
[0022] The preset insertion code is added before the original sleep function of the system under test through a hook mechanism to obtain a first sleep function, and the preset insertion code is used to cancel the executable attribute of the first memory.
[0023] In this implementation, the dormant function is replaced through a hook mechanism, which can hide malicious behavior in the function of the system under test itself, making it difficult for the security detection tool of the system under test itself to identify it, thereby ensuring the concealment of the attack and achieving better security testing results.
[0024] In an optional implementation, calling the first sleep function to put the anti-killing attack file into a sleep state and updating the attribute of the first memory to be non-executable includes:
[0025] Creating a first thread based on a preset insertion code in the first sleep function;
[0026] Executing the original sleep function in the first sleep function to put the anti-killing attack file into a sleep state;
[0027] After the anti-killing attack file enters the dormant state, the first thread is used to update the attribute of the first memory to be non-executable.
[0028] In this embodiment, a thread for updating the attributes of the first memory to be non-executable is created through a first sleep function, thereby realizing the change of memory attributes. Since the sleep function belongs to the function of the system under test itself, its behavior during execution is not easy to be detected, so that the memory update is not easy to be noticed.
[0029] In an optional implementation manner, the reading of the security protection data of the system under test and generating a security test report includes:
[0030] Collecting statistics on attack information and response data collected by the security protection system inside the tested system during the security test;
[0031] A security test report is generated based on the attack information and the response data.
[0032] This implementation method generates a security test report by collecting relevant information about the system under test and its internal security protection system after the security test is completed, so that the security protection personnel of the tested party can analyze the problems of the current security protection system more comprehensively and make corresponding adjustments.
[0033] In an optional implementation, the generating the startup instruction and the sleep instruction of the attack file based on the program code in the anti-killing attack file includes:
[0034] Determining the running cycle and the dormant cycle of the anti-killing attack file according to the program code inside the anti-killing attack file;
[0035] The startup instruction and the sleep instruction of the anti-killing attack file are generated based on the operation cycle.
[0036] In this implementation, instructions for starting or sleeping the anti-killing attack file are regularly generated through the operation cycle determined by the program code inside the anti-killing attack file, so that the starting and sleeping of the anti-killing attack file can be automatically executed to ensure the test effect.
[0037] In a second aspect, the present invention provides a security testing device based on an anti-killing attack file, wherein the initial state of the anti-killing attack file is a dormant state, and the initial attribute of the first memory corresponding to the anti-killing attack file is non-executable, and the device comprises:
[0038] The attack file startup module is used to initiate a startup attempt after the system under test receives the security test instruction and instructs the anti-killing attack file pre-set in the dormant state inside the system under test through the startup instruction;
[0039] A first memory attribute updating module is used to update the attribute of the first memory to executable through a predefined exception handling function when an abnormal reminder triggered by the startup attempt is detected;
[0040] A sleep function replacement module, used to trigger the system under test to run the anti-killing attack file, and replace the original sleep function in the system under test with the first sleep function by using the preset insertion code in the anti-killing attack file;
[0041] A second memory attribute updating module is used to call the first sleep function when a sleep instruction for the anti-killing attack file is detected, so that the anti-killing attack file enters a sleep state, and updates the attribute of the first memory to be non-executable;
[0042] The security test report generating module reads the security protection data of the system under test and generates a security test report after the security test on the system under test is completed.
[0043] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the security testing method based on anti-killing attack files of the above-mentioned first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0044] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the security testing method based on anti-killing attack files of the above-mentioned first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0046] Figure 1 It is a flowchart of a security testing method based on anti-killing attack files according to an embodiment of the present invention;
[0047] Figure 2 is a flow chart of another security testing method based on anti-killing attack files according to an embodiment of the present invention;
[0048] Figure 3 This is an example diagram of a flow chart of memory attribute changes of an anti-killing attack file during a security test according to an embodiment of the present invention;
[0049] Figure 4 is a structural block diagram of a security testing device based on anti-killing attack files according to an embodiment of the present invention;
[0050] Figure 5 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0051] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.
[0052] In the field of network security, verifying system security through attack and defense tests between the red and blue parties is a common security testing method. When conducting attack and defense tests between the two parties, the simulated attacker often needs to use various malware or malicious codes to attack the system being tested in order to verify the security issues existing in the system.
[0053] In this process, the simulated attacker needs to improve the concealment of the malware as much as possible to avoid being scanned by the defender's defense system during the attack and defense test, thereby achieving effective attack testing on the system under test.
[0054] In the current prior art, there are relatively few means to ensure the concealment of attack files used for testing in attack and defense tests, which makes them easy to be discovered during the attack and defense testing process, thereby failing to effectively test the security of the defense system.
[0055] To this end, an embodiment of the present invention provides a security testing method based on an anti-kill attack file. After starting the security test of the system under test, an attempt is made to start the anti-kill attack file whose memory attribute is pre-set as non-executable in the system under test; after monitoring the exception reminder triggered by the attempted startup, the attribute of the first memory is updated to executable through a predefined exception handling function to run the anti-kill attack file, and the sleep function in the system under test is replaced during the running process, so that when the subsequent anti-kill attack file receives the sleep instruction, the attribute of the first memory is updated to non-executable through the replaced sleep function, thereby realizing that the attribute of the memory corresponding to the attack file is updated as it runs and sleeps, thereby improving the concealment of the attack file, reducing the possibility of being discovered during the security testing process, and thereby improving the test effect when the security test of the system under test is performed.
[0056] According to an embodiment of the present invention, an embodiment of a security testing method based on an anti-killing attack file is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0057] In this embodiment, a security testing method based on an anti-killing attack file is provided, which can be applied to a security testing tool when performing security testing on a system under test, wherein the initial state of the anti-killing attack file is: a dormant state, and the initial attribute of the first memory corresponding to the anti-killing attack file is non-executable, wherein the first memory is the memory corresponding to the anti-killing attack file in the system under test.
[0058] Figure 1 FIG. 1 is a flow chart of a security testing method based on anti-killing attack files according to an embodiment of the present invention. Figure 1 As shown, the process includes the following steps:
[0059] Step S101, after the system under test receives the security test instruction, the anti-killing attack file pre-set in the system under test in a dormant state initiates a startup attempt through a startup instruction.
[0060] Security testing can be understood as using security testing tools to perform simulated attack behaviors on the system under test while the security defense system inside the system under test is running. The deficiencies in the security protection measures of the system under test can be understood based on the results of the simulated attack and defense between the defense system and the security testing tool, so that R&D personnel can make corresponding improvements.
[0061] For security testing tools, they can be regarded as software or code that executes simulated attack behaviors, that is, malware corresponding to the anti-kill attack file pre-set in the tested system in this application. The anti-kill attack file is referred to as the attack file in the following text.
[0062] After the security test begins, the system under test will receive a security test instruction to notify the relevant defense tools inside the system under test to start running. At this time, the attack file can start simulating attack behaviors on the system under test. Since the initial state of the attack file is dormant, it needs to initiate a startup attempt after receiving a startup instruction to enter the running state and perform specific malicious behaviors. The startup instruction can be a control instruction sent remotely by the simulated attacker, or it can be a startup instruction set by the attack file itself and triggered based on certain rules. After receiving the startup instruction, the attack file initiates a startup attempt.
[0063] Step S102: when an abnormal reminder triggered by a startup attempt is detected, the attribute of the first memory is updated to executable through a predefined abnormal processing function.
[0064] The system under test for the security test in this method is the Windows system. For this system, it has a special exception handling mechanism, namely the VEH mechanism. The VEH (Vector Exception Handling) exception handling function is an advanced technology in the Windows operating system, which is used to handle the abnormal conditions encountered by the program at runtime. These abnormal conditions may include division by zero errors, memory access violations, system call failures, etc. VEH is a more flexible mechanism than the traditional structured exception handling (SEH). It allows the program to install an exception handling function, which is called by the operating system when an exception occurs.
[0065] Since the initial attribute of the memory corresponding to the anti-killing attack file itself is non-executable, after it initiates a startup attempt, it will conflict with the state of the memory attribute, causing the tested system to detect the exception caused by the startup attempt of the anti-killing attack file and issue a corresponding exception reminder. At the same time, based on Winsows' own exception handling mechanism, that is, the VEH mechanism mentioned above, after the exception occurs, the operating system will call the pre-defined exception handling function in the anti-killing attack file to handle the exception. In the process of handling the exception through the exception handling function, the operating system will change the attribute of the first memory to executable for the purpose of resolving the exception, so that the attack file can complete the startup and run.
[0066] Step S103, triggering the system under test to run the anti-killing attack file, and using the preset insertion code in the anti-killing attack file to replace the original sleep function in the system under test with the first sleep function.
[0067] After the first memory attribute corresponding to the anti-killing attack file is changed to executable, its startup attempt can be realized, that is, it can trigger the system under test to run the anti-killing attack file. After the anti-killing attack file starts running, corresponding malicious behaviors can be performed to verify the security of the system under test.
[0068] The anti-killing attack file contains a pre-written insertion code, namely, a preset insertion code. After the anti-killing attack file starts running, the original sleep function inside the operating system can be modified according to the preset insertion code to obtain a first sleep function, and then the original sleep function is replaced with the first sleep function.
[0069] Step S104, when a sleep instruction for the anti-killing attack file is detected, a first sleep function is called to put the anti-killing attack file into a sleep state, and the attribute of the first memory is updated to be non-executable.
[0070] For anti-kill attack files, during the security test, they are not always in the running state, but can decide whether to run according to the specific startup command or sleep command. When it receives the startup command in the sleep state, it initiates the startup and enters the running state to perform the corresponding malicious behavior. When it receives the sleep command in the running state, it can enter the sleep state and no longer perform the corresponding malicious behavior.
[0071] Therefore, when a sleep instruction for an anti-killing attack file is detected, the operating system's own sleep function can be called to switch the anti-killing attack file to a sleep state. Since the sleep function inside the system has been replaced by the first sleep function, the modified content of the first sleep function can enable it to change the first memory, that is, the attribute corresponding to the anti-killing attack file, to non-executable after completing the function of switching the anti-killing attack file to a sleep state, so as to avoid being detected by the memory scanning tool of the security defense system and ensure the concealment of the attack file.
[0072] Through the steps S101-S104 above, it can be achieved that when the anti-killing attack file is in a dormant state, its corresponding memory attribute is non-executable; when it attempts to start under the condition that the memory attribute is non-executable, the memory attribute is changed through the exception handling mechanism of the system under test to enable it to complete the startup. This greatly improves the concealment of the anti-killing attack file and avoids being detected and killed by the internal security defense system of the system under test.
[0073] In the actual test process, multiple startups and sleeps can be performed to implement attack tests on the system under test. For each startup and sleep, the specific execution process is the same as the above-mentioned related steps and will not be repeated here.
[0074] Step S105, when the security test on the system under test is completed, read the security protection data of the system under test and generate a security test report.
[0075] After a period of security testing, you can end the security testing and start to sort out the security protection data during the testing process. For example, you can sort out the attack information monitored by the security defense system in the tested system and the corresponding responses, and then generate a corresponding test report. Through the security test report, the staff can understand the current security protection and what needs to be improved based on the content in the test report, and achieve the security test effect of promoting defense through attack.
[0076] The security testing method based on the anti-kill attack file provided in the present embodiment starts the anti-kill attack file whose memory attribute is pre-set as non-executable in the system under test after starting the security test of the system under test; after monitoring the exception reminder triggered by the attempted startup, the attribute of the first memory is updated to executable through a pre-defined exception handling function to run the anti-kill attack file, and the sleep function in the system under test is replaced during the running process, so that when the subsequent anti-kill attack file receives the sleep instruction, the attribute of the first memory is updated to non-executable through the replaced sleep function, thereby realizing that the attribute of the memory corresponding to the attack file is updated as it runs and sleeps, thereby improving the concealment of the attack file, reducing the possibility of being discovered during the security testing process, and thus improving the test effect when the security test of the system under test is performed.
[0077] According to an embodiment of the present invention, another embodiment of a security testing method based on an anti-killing attack file is provided, which can be applied to a security testing tool when performing security testing on a system under test. Figure 2 FIG. 1 is a flowchart of another security testing method based on anti-killing attack files according to an embodiment of the present invention. Figure 2 As shown, the process includes the following steps:
[0078] Step S201, after the system under test receives the security test instruction, the system under test initiates a startup attempt by instructing the anti-killing attack file pre-set in the dormant state inside the system under test through the startup instruction. Figure 1 Step S101 of the illustrated embodiment will not be described in detail here.
[0079] Step S202: when an abnormal reminder triggered by a startup attempt is detected, the attribute of the first memory is updated to executable through a predefined abnormal processing function.
[0080] Specifically, the abnormal reminder is an access violation reminder, which is issued when the system under test detects that an anti-killing attack file initiates a startup attempt when the attribute of the first memory is in a non-executable state.
[0081] It can be understood that when the anti-killing attack file initiates a startup attempt, an access violation exception will be generated because its own memory attribute is non-executable. At the same time, the above-mentioned tested system detects the occurrence of the exception and issues an access violation reminder.
[0082] Specifically, in the above step S202, when an abnormal reminder triggered by the startup attempt is monitored, the attribute of the first memory is updated to executable through a predefined exception handling function, including:
[0083] When an access violation reminder issued by the tested system is monitored, the tested system is instructed to call a predefined exception handling function for processing, and based on the exception handling function, the tested system's own memory protection function is called to update the attribute of the first memory to executable.
[0084] It can be understood that, as mentioned in the above embodiment, the tested system is a Windows operating system, which has its own special exception handling mechanism, that is, when an exception occurs, it will call the exception handling function provided by the program itself or the program where the exception occurs to handle the exception. In this case, the tested system will call the exception handling function pre-defined in the anti-killing attack file to handle the access violation exception.
[0085] In the process of handling access violations through the pre-defined exception handling function, the operating system will be instructed to call its own memory protection function, namely the VirtualProtect function, to change the properties of the first memory, that is, to change the properties of the first memory to executable to resolve the exception of illegal access. After the properties of the first memory become executable, the anti-killing attack file can run normally and execute the corresponding malicious behavior to achieve security testing of the system under test.
[0086] Step S203, triggering the system under test to run the anti-killing attack file, and using the preset insertion code in the anti-killing attack file to replace the original sleep function in the system under test with the first sleep function.
[0087] Specifically, in the above step S203, the original sleep function in the system under test is replaced with the first sleep function by using the preset insertion code in the anti-killing attack file, including:
[0088] The preset insertion code is added before the original sleep function of the system under test through the hook mechanism to obtain a first sleep function. The preset insertion code is used to cancel the executable attribute of the first memory.
[0089] In computer programming and system management, a "hook" is a mechanism by which system events can be monitored or the way software runs can be changed, allowing custom code to be inserted (hooked) at specific points in the system or application.
[0090] After the anti-killing attack file is started and begins to run, the pre-written insertion code can be inserted into the original sleep function of the system through the hook mechanism through the specific running program inside it, so as to modify the sleep function and define the modified sleep function as the first sleep function. After the subsequent attack file receives the sleep instruction, it will notify the operating system to call the first sleep function to switch the state of the attack file, so that the attack file enters the sleep state, and the attribute of the first memory is changed to non-executable through the specific modification content in the first sleep function.
[0091] By using the hook mechanism to modify dormant functions, malicious behavior can be hidden in normal system function calls, reducing abnormal indicators and making it more difficult for behavior-based detection tools to identify illegal activities. And by directly manipulating internal system calls, hooking can perform certain operations without requiring additional permissions, and may also bypass certain auditing and logging mechanisms because it imitates legitimate system behavior.
[0092] Step S204: when a sleep instruction for the anti-killing attack file is detected, a first sleep function is called to put the anti-killing attack file into a sleep state, and the attribute of the first memory is updated to be non-executable.
[0093] Specifically, in step S204, the first dormancy function is called to put the anti-killing attack file into a dormant state, and the attribute of the first memory is updated to be non-executable, including:
[0094] Step S204 - 1 , creating a first thread based on a preset insertion code in a first sleep function.
[0095] It can be understood that when the anti-kill attack file receives the sleep instruction, it will instruct the operating system to call the sleep function to put the anti-kill attack file into a sleep state, that is, no longer execute the malicious activities or attack behaviors in its file content. Since the sleep function has been replaced as mentioned above, the sleep function called at this time is the first sleep function that has been inserted with the preset insertion code. Therefore, when executing the first sleep function, the preset insertion code therein will be executed first, and the first thread will be created based on the specific content of the preset insertion code. The first thread is used to cancel the executableness of the first memory after the subsequent anti-kill attack file enters the sleep state, that is, change the attribute of the first memory to non-executable.
[0096] Step S204-2, executing the original sleep function in the first sleep function to put the anti-killing attack file into a sleep state.
[0097] After the preset insertion code is executed, the original sleep function in the first sleep function will be executed. Its function is to put the anti-killing attack file into a sleep state. For details, please refer to the specific implementation mechanism in the relevant technology, which will not be repeated here.
[0098] Step S204-3: after the anti-killing attack file enters the dormant state, the attribute of the first memory is updated to be non-executable by using the first thread.
[0099] After the anti-killing attack file enters the dormant state, the attribute of the first memory is updated to be non-executable through the first thread created above. Specifically, the thread can call the VirtualProtect function of the operating system to implement the change of the memory attribute.
[0100] Specifically, the start-up instruction and the sleep instruction involved in the above steps are generated as follows:
[0101] Generate the startup and sleep instructions of the attack file based on the program code inside the anti-killing attack file;
[0102] Or based on the startup instruction information and sleep instruction information remotely sent by the simulated attacker of the security test, the startup instruction and sleep instruction of the attack file are generated respectively.
[0103] For the anti-killing attack file, the specific instruction generation rules can be determined according to the program code inside it, so as to automatically generate the startup instruction and sleep instruction based on the specific instruction generation rules, so that it can try to start or sleep. For example, specific trigger conditions can be set, such as after the security defense system scans the first memory for a preset time, it generates a startup instruction to instruct the corresponding program in its own file to try to start and run, and generates a sleep instruction after the attack file runs for a period of time.
[0104] Or, the corresponding instructions are generated by receiving instruction information from a remote simulated attacker. For example, when the simulated attacker sends a startup instruction information, a startup instruction is generated for the anti-killing attack file, so that the anti-killing attack file attempts to start related internal programs; when the simulated attacker sends a sleep instruction information, a corresponding startup instruction is generated to call the sleep function.
[0105] Specifically, as mentioned above, based on the program code inside the anti-killing attack file, the startup instructions and sleep instructions of the attack file are generated, including:
[0106] Determine the running cycle and dormant cycle of the anti-killing attack file according to the program code inside the anti-killing attack file;
[0107] The startup instructions and sleep instructions of the anti-killing attack file are generated regularly based on the running cycle and the sleeping cycle.
[0108] It can be understood that the code inside the anti-killing attack file can determine its own operating cycle and sleep cycle. When the corresponding cycle ends, the corresponding startup instruction or sleep instruction is generated. For example, the operating cycle is 10 minutes and the sleep cycle is 5 minutes. Then, after the anti-killing attack file runs for 10 minutes, a sleep instruction is issued, the sleep function is called to switch the state, and the memory attribute is updated to be non-executable; after the anti-killing attack file sleeps for 5 minutes, a startup instruction is issued to instruct the corresponding program inside the file to initiate a startup attempt, and based on the above-mentioned related steps, the memory attribute is updated to executable, and then the running state is entered.
[0109] Step S205, when the security test on the system under test is completed, read the security protection data of the system under test and generate a security test report.
[0110] Specifically, in step S205, the security protection data of the system under test is read, and a security test report is generated, including:
[0111] Step S205-1 counts the attack information and response data collected by the security protection system inside the tested system during the security test.
[0112] After the security test is completed, the test data is collated to count the specific attack information detected by the security protection system inside the tested system and the responses made to the attack information. This information can help R&D personnel understand the actual defense performance of the security defense system.
[0113] Step S205-2, generating a security test report based on the attack information, response data and damaged information.
[0114] By summarizing the above statistical data, you can get a specific test report for this test.
[0115] Furthermore, the anti-kill attack file may have a behavior log inside, which can record its specific malicious behavior. After the security test is completed, the log information inside the anti-kill attack file can also be summarized in the test report, and then compared with the relevant information detected by the security defense system, so as to further understand the actual performance of the security defense system. This will help security R&D personnel to further update and upgrade the security defense system and improve the security defense effect.
[0116] The security testing method based on the anti-kill attack file provided by the embodiment of the present invention starts the anti-kill attack file whose memory attribute is pre-set as non-executable in the system under test after starting the security test of the system under test; after monitoring the exception reminder triggered by the attempted startup, the attribute of the first memory is updated to executable through a pre-defined exception handling function to run the anti-kill attack file, and the sleep function in the system under test is replaced during the running process, so that when the subsequent anti-kill attack file receives the sleep instruction, the attribute of the first memory is updated to non-executable through the replaced sleep function, thereby realizing that the attribute of the memory corresponding to the attack file is updated as it runs and sleeps, thereby improving the concealment of the attack file, reducing the possibility of being discovered during the security testing process, and thus improving the test effect when the security test of the system under test is performed.
[0117] In order to facilitate the understanding of the above method embodiments, the specific content of the following embodiments can be used to assist in understanding. Before the attack file starts to execute, the attack file Beacon is started by simulating the attacker to remotely read the Beacon.bin file containing shellcode. "Beacon" usually refers to a malware or code deployed by an attacker in the target network. It can periodically send a signal (ie, a "beacon") to the attacker's control server to indicate that it is active and waiting for further commands. It has a "sleep" function and can enter a dormant state according to the configured time interval. In the dormant state, Beacon reduces its network activity, which helps it avoid detection by network security monitoring tools.
[0118] For the attack file, a VEH exception handling function is set inside it to restore the "executable" attribute when an exception is triggered after the "executable" attribute of the memory is cancelled. When the beacon file initiates a startup attempt and executes the code stored in the memory location pointed to by Beacon, the VEH exception handling function is pre-set to capture the access violation exception caused by memory protection (non-executable memory), and then change the memory protection level to allow code execution.
[0119] For example, an exception handling function FirstVectExcepHandler can be predefined, and the system under test will call this function when a registered exception occurs. Get the triggered exception code and the instruction pointer of the thread where the exception occurred. It checks whether the exception code is "0xc0000005", which is the standard error code in Windows, representing "access violation" (here it means executing a piece of memory with the "executable" attribute canceled).
[0120] If the exception code is indeed "0xc0000005", the exception handling function FirstVectExcepHandler will think that this is an exception caused by canceling the "executable" attribute of Beacon's memory. Then, it instructs the system under test to use the VirtualProtect function to try to modify the protection attribute of the memory page, changing the attribute of the memory area where Beacon is located to PAGE_EXECUTE_READWRITE, making the memory area readable, writable, and executable.
[0121] If the memory attributes are successfully changed, the handler returns CONTINUE_EXECUTION, which tells the system that the exception has been handled and the program can now continue executing. If the exception does not match, it returns CONTINUE_SEARCH, telling the system that this exception handler did not handle the exception and the system should continue looking for other registered exception handlers.
[0122] After the beacon file begins executing, the behavior of two Windows system functions, VirtualAlloc and Sleep, can be monitored and manipulated using a technique called "hooking". In this way, the code can intercept calls to key system functions without changing the original program code. The purpose of this step is to monitor and manipulate the memory and processing behavior related to "Beacon".
[0123] Specifically, when using the hooking technique, the NewSleep function is first attached to the original system function through "Hook". This actually changes the function pointer so that any call to Sleep will be redirected to the corresponding new function, namely the NewSleep function. It will replace the call to the original function, allowing the code to perform additional operations while executing the original function.
[0124] The definition of the NewSleep function can be as follows: when the Sleep function is called, the substitute function NewSleep is triggered. Then, before the original Sleep function is executed, a thread is created to cancel the "executable" attribute of the Beacon memory area immediately after the Beacon enters sleep.
[0125] In order to facilitate understanding of the changes in the memory attributes of the anti-killing attack file during the security test process in the above embodiment, according to an embodiment of the present invention, an example diagram of the memory attribute change process of the anti-killing attack file during the security test process is provided, as shown in FIG. Figure 3 shown.
[0126] When the "Beacon" thread or program is ready to go to sleep, the Sleep function is called and the executable attribute of its memory area is canceled. This is done by using the VirtualProtect system call, which is able to change the protection attributes of memory pages. In this case, it sets the memory to PAGE_READWRITE, which means that the memory area can be read and written, but not executed, which can prevent it from being detected by the memory scanning strategy of security software.
[0127] Then when the "Beacon" thread resumes from sleep, it will try to execute the code previously marked as non-executable, triggering a memory access violation exception. At this time, control will be passed to the VEH exception handler, and VEH will restore the executable attribute of the memory area. Once the memory attribute is changed to executable, the "Beacon" thread or program can continue to execute the attack code normally.
[0128] When the program finds that the Sleep function has been called through the "Hook" mechanism, it prepares to enter the sleep state. At this point in the Sleep function, the whole process will be repeated: the memory attribute will be set to non-executable again, the thread will go to sleep, and then the exception will be triggered again when the thread wakes up, and the VEH handler will restore the executable attribute of the memory.
[0129] The present invention achieves its purpose by utilizing the normal functions of the operating system (such as exception handling), rather than using system calls or known vulnerabilities that are easily marked as malicious in previous solutions. This strategy that relies on normal system behavior is more difficult to be accurately identified and distinguished by the security system, ensuring the effectiveness of attacks during offensive and defensive testing and improving the test results. The present invention dynamically changes the memory protection level and restores the "executable" state only when the code needs to be executed. This method shows strong adaptability and persistence. It can remain hidden even in the face of continuous, real-time memory scanning and monitoring. In addition, by using hooking, malicious behavior is hidden in normal system function calls, reducing abnormal indicators and making it more difficult for behavior-based detection tools to identify illegal activities.
[0130] Bypassing permissions and audit restrictions: By directly manipulating internal system calls, hooking can perform certain operations without requiring additional permissions, while also potentially bypassing certain auditing and logging mechanisms because it mimics legitimate system behavior.
[0131] In this embodiment, a security testing device based on an anti-killing attack file is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware for a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.
[0132] This embodiment provides a security testing device based on an anti-killing attack file. The initial state of the anti-killing attack file is: dormant state. The initial attribute of the first memory corresponding to the anti-killing attack file is: non-executable. Figure 4 As shown, including:
[0133] The attack file startup module 401 is used to initiate a startup attempt by instructing the anti-killing attack file pre-set in the system under test in a dormant state through the startup instruction after the system under test receives the security test instruction.
[0134] The first memory attribute updating module 402 is used to update the attribute of the first memory to executable through a predefined exception handling function when an abnormal reminder triggered by a startup attempt is monitored.
[0135] The sleep function replacement module 403 is used to trigger the system under test to run the anti-killing attack file, and use the preset insertion code in the anti-killing attack file to replace the original sleep function in the system under test with the first sleep function.
[0136] The second memory attribute updating module 404 is used to call the first sleep function when a sleep instruction for the anti-killing attack file is detected, so as to put the anti-killing attack file into a sleep state, and update the attribute of the first memory to be non-executable.
[0137] The security test report generating module 405 reads the security protection data of the system under test and generates a security test report after the security test on the system under test is completed.
[0138] In some optional implementations, the start instruction and the sleep instruction are generated as follows:
[0139] Generate the startup and sleep instructions of the attack file based on the program code inside the anti-killing attack file;
[0140] Or based on the startup instruction information and sleep instruction information remotely sent by the simulated attacker of the security test, the startup instruction and sleep instruction of the attack file are generated respectively.
[0141] In some optional implementations, the abnormal reminder is an access violation reminder, and the access violation reminder is issued when the system under test detects that the anti-killing attack file initiates a startup attempt in a state where the attribute of the first memory is not executable;
[0142] The first memory attribute updating module 402, when detecting an abnormal reminder triggered by a startup attempt, updates the attribute of the first memory to executable through a predefined abnormal processing function, includes:
[0143] When an access violation reminder issued by the tested system is monitored, the tested system is instructed to call a predefined exception handling function for processing, and based on the exception handling function, the tested system's own memory protection function is called to update the attribute of the first memory to executable.
[0144] In some optional implementations, the sleep function replacement module 403, when replacing the original sleep function in the system under test with the first sleep function using the preset insertion code in the anti-killing attack file, includes:
[0145] The preset insertion code is added before the original sleep function of the system under test through the hook mechanism to obtain a first sleep function. The preset insertion code is used to cancel the executable attribute of the first memory.
[0146] In some optional implementations, the second memory attribute updating module 404, when calling the first sleep function to put the anti-killing attack file into a sleep state and updating the attribute of the first memory to be non-executable, includes:
[0147] Creating a first thread based on a preset insertion code in the first sleep function;
[0148] Execute the original sleep function in the first sleep function to put the anti-killing attack file into a sleep state;
[0149] After the anti-killing attack file enters the dormant state, the first thread is used to update the attribute of the first memory to be non-executable.
[0150] In some optional implementations, the security test report generation module 405, when reading the security protection data of the system under test and generating the security test report, includes:
[0151] Collect statistics on attack information and response data collected by the security protection system inside the tested system during security testing;
[0152] Generate security test reports based on attack information and response data.
[0153] In some optional implementations, based on the program code inside the anti-killing attack file, the startup instruction and the sleep instruction of the attack file are generated, including:
[0154] Determine the running cycle and dormant cycle of the anti-killing attack file according to the program code inside the anti-killing attack file;
[0155] The startup instructions and sleep instructions of the anti-killing attack file are generated regularly based on the running cycle and the sleeping cycle.
[0156] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0157] The security testing device based on the anti-killing attack file in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0158] The embodiment of the present invention also provides a computer device having the above Figure 4 The security testing device based on the anti-killing attack file is shown.
[0159] See also Figure 5 , Figure 5 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Figure 5 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 5 A processor 10 is taken as an example.
[0160] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.
[0161] The memory 20 stores instructions executable by at least one processor 10, so that at least one processor 10 executes the method shown in the above embodiment.
[0162] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0163] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.
[0164] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 may be connected via a bus or other means. Figure 5 The example of connecting through bus is taken in the following.
[0165] The input device 30 can receive input digital or character information, and generate key signal input related to the user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a track pad, a touch pad, an indicator bar, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 may include a display device, an auxiliary lighting device (e.g., an LED) and a tactile feedback device (e.g., a vibration motor), etc. The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display and a plasma display. In some optional embodiments, the display device can be a touch screen.
[0166] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.
[0167] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A security testing method based on anti-killing attack files, characterized in that: The initial state of the anti-killing attack file is: dormant state, the initial attribute of the first memory corresponding to the anti-killing attack file is: non-executable, and the method includes: After the system under test receives the security test instruction, it initiates a startup attempt by instructing the anti-killing attack file pre-set in the dormant state inside the system under test through the startup instruction; When an abnormal reminder triggered by the startup attempt is monitored, updating the attribute of the first memory to executable through a predefined exception handling function; Triggering the system under test to run the anti-killing attack file, and using the preset insertion code in the anti-killing attack file to replace the original sleep function in the system under test with the first sleep function; When a sleep instruction for the anti-killing attack file is detected, the first sleep function is called to put the anti-killing attack file into a sleep state, and the attribute of the first memory is updated to be non-executable; When the safety test on the system under test is completed, the safety protection data of the system under test is read and a safety test report is generated.
2. The method according to claim 1, characterized in that The generation method of the startup instruction and the sleep instruction is: Based on the program code inside the anti-killing attack file, generate a startup instruction and a sleep instruction of the attack file; Or based on the startup instruction information and sleep instruction information remotely sent by the simulated attacking party of the security test, the startup instruction and sleep instruction of the attack file are generated respectively.
3. The method according to claim 1, characterized in that The abnormal reminder is an access violation reminder, and the access violation reminder is issued when the system under test detects that the anti-killing attack file initiates a startup attempt in a state where the attribute of the first memory is not executable; When an abnormal reminder triggered by the startup attempt is monitored, updating the attribute of the first memory to executable through a predefined exception handling function includes: When an access violation reminder issued by the system under test is monitored, the system under test is instructed to call a predefined exception handling function for processing, and based on the exception handling function, the memory protection function of the system under test itself is called to update the attribute of the first memory to executable.
4. The method according to claim 1, characterized in that The method of replacing the original sleep function in the system under test with the first sleep function by using the preset insertion code in the anti-kill attack file includes: The preset insertion code is added before the original sleep function of the system under test through a hook mechanism to obtain a first sleep function, and the preset insertion code is used to cancel the executable attribute of the first memory.
5. The method according to claim 4, characterized in that The calling of the first dormancy function to put the anti-killing attack file into a dormant state and updating the attribute of the first memory to be non-executable includes: Creating a first thread based on a preset insertion code in the first sleep function; Executing the original sleep function in the first sleep function to put the anti-killing attack file into a sleep state; After the anti-killing attack file enters the dormant state, the first thread is used to update the attribute of the first memory to be non-executable.
6. The method according to claim 1, characterized in that The reading of the security protection data of the system under test and generating a security test report includes: Collecting statistics on attack information and response data collected by the security protection system inside the tested system during the security test; A security test report is generated based on the attack information and the response data.
7. The method according to claim 2, characterized in that The step of generating a startup instruction and a sleep instruction of the attack file based on the program code inside the anti-killing attack file includes: Determining the running cycle and the dormant cycle of the anti-killing attack file according to the program code inside the anti-killing attack file; The startup instruction and the sleep instruction of the anti-killing attack file are generated regularly based on the running cycle and the sleep cycle.
8. A security testing device based on anti-kill attack files, characterized in that: The initial state of the anti-killing attack file is: dormant state, the initial attribute of the first memory corresponding to the anti-killing attack file is: non-executable, and the device includes: The attack file startup module is used to initiate a startup attempt after the system under test receives the security test instruction and instructs the anti-killing attack file pre-set in the dormant state inside the system under test through the startup instruction; A first memory attribute updating module is used to update the attribute of the first memory to executable through a predefined exception handling function when an abnormal reminder triggered by the startup attempt is detected; A sleep function replacement module, used to trigger the system under test to run the anti-killing attack file, and replace the original sleep function in the system under test with the first sleep function by using the preset insertion code in the anti-killing attack file; A second memory attribute updating module is used to call the first sleep function when a sleep instruction for the anti-killing attack file is detected, so that the anti-killing attack file enters a sleep state, and updates the attribute of the first memory to be non-executable; The security test report generating module reads the security protection data of the system under test and generates a security test report after the security test on the system under test is completed.
9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the security testing method based on the anti-killing attack file according to any one of claims 1 to 7 by executing the computer instructions.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the security testing method based on the anti-killing attack file according to any one of claims 1 to 7.
Citation Information
Patent Citations
5G communication security test method and system
CN113014589A
Method and device for detecting attack program through antivirus software
CN117828595A