Static identification method and device of software installation package, storage medium and equipment
Through the structure analysis of the executable file and the tag query at the end of the section table, the software installation package can be identified without running a program, which solves the risk of running malicious code and improves the accuracy and security of identification.
Patent Information
- Application Number
- CN202411915112.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-05-06
AI Technical Summary
In the prior art, when judging whether a program is an installation package, it is necessary to run the program, which poses a risk of running malicious code.
By performing structural analysis of the executable file, locate the tail address of the section table, and query whether the preset installation package tail tag is included. If included, it is determined to be the installation package program.
It enables the identification of software installation packages without running executable files, avoiding the security risks caused by running malicious code, and improving the accuracy and reliability of identification.
Smart Images

Figure CN119938133A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of file analysis, and in particular to a method, device, storage medium and computer equipment for statically identifying a software installation package. Background Art
[0002] The traditional method of determining whether a program is an installation package usually relies on monitoring whether the program writes specific key values or data in the registry under the specified path during the installation process. This method is effective in most cases, because many regular installation programs will record key data such as installation information, configuration path, version information, etc. by modifying the registry.
[0003] However, this judgment method has a significant flaw: it requires the program to be running in order to monitor. Running an unknown program itself carries certain risks. If the program contains malicious code, then during the running process, these malicious codes may be executed, which may cause pollution to the user's computer environment. For example, malicious programs may install additional software without the user's knowledge, modify system settings, steal user information, or even carry out more serious network attacks. Summary of the invention
[0004] In view of this, the embodiments of the present application provide a method, apparatus, storage medium and computer device for statically identifying a software installation package, which can realize the identification of the software installation package without running an executable file, thereby avoiding the security risks caused by running malicious code.
[0005] According to one aspect of the present application, a method for statically identifying a software installation package is provided, the method comprising:
[0006] Obtaining an executable file to be analyzed, and determining the number of bits of the executable file;
[0007] Performing structural analysis on the executable file, and locating the tail address of the section table of the executable file based on the structural analysis result and the number of bits;
[0008] Based on the section table tail address, query whether the section table tail of the executable file contains a preset installation package tail mark, wherein the preset installation package tail mark is obtained by counting the section table tail features of the installation package file sample;
[0009] If the end of the section table of the executable file contains a preset installation package end mark, it is determined that the executable file belongs to a software installation package program.
[0010] In an optional implementation manner, before obtaining the executable file to be analyzed, the method further includes:
[0011] Acquire multiple first installation package file samples and multiple second non-installation package file samples, wherein the first installation package file samples include installation package files of different versions corresponding to multiple software, and the second non-installation package file samples include files of multiple types;
[0012] Analyze the tail of the section table corresponding to each first installation package file sample respectively to determine the first high-frequency section table tail mark corresponding to the installation package file, and analyze the tail of the section table corresponding to each second non-installation package file sample respectively to determine the second high-frequency section table tail mark corresponding to the non-installation package file;
[0013] The second high-frequency node table tail mark is removed from the first high-frequency node table tail mark to obtain the preset installation package tail mark.
[0014] In an optional implementation, after querying whether the section table tail of the executable file includes a preset installation package tail mark based on the section table tail address, the method further includes:
[0015] If the section table tail of the executable file does not include a preset installation package tail mark, locating the section table header address of the executable file based on the structure analysis result and the number of bits, and locating the program resource data position of the executable file from the section table header of the executable file according to the section table header address;
[0016] Querying whether the program resource data of the executable file conforms to the preset installation package program resource characteristics based on the program resource data location;
[0017] If the program resource data of the executable file meets the preset installation package program resource characteristics, it is determined that the executable file belongs to the software installation package program.
[0018] In an optional implementation, the preset installation package program resource feature includes that the program resource data capacity is greater than the preset installation package capacity and the program resource data includes a preset installation package program resource mark; before obtaining the executable file to be analyzed, the method further includes:
[0019] Acquire multiple second installation package file samples and multiple second non-installation package file samples, wherein the second installation package file samples include installation package files of different versions corresponding to multiple software, and the second non-installation package file samples include files of multiple types;
[0020] Analyze the program resource data corresponding to each second installation package file sample to determine the first high-frequency program resource tag corresponding to the installation package file, and analyze the tail of the section table corresponding to each non-installation package file sample to determine the second high-frequency program resource tag corresponding to the non-installation package file;
[0021] The second high-frequency program resource mark is removed from the first high-frequency program resource mark to obtain the preset installation package program resource mark.
[0022] In an optional implementation, after querying whether the program resource data of the executable file meets the preset installation package program resource characteristics based on the program resource data location, the method further includes:
[0023] If the program resource data of the executable file does not conform to the preset program resource characteristics of the installation package, locating the file resource description list data of the executable file based on the program resource data, and querying whether the file resource description list data conforms to the preset file description characteristics of the installation package;
[0024] If the file resource description list data conforms to the preset installation package file description characteristics, it is determined that the executable file belongs to the software installation package program.
[0025] In an optional implementation manner, after querying whether the file resource description list data conforms to a preset installation package file description feature, the method further includes:
[0026] If the file resource description list data does not conform to the preset installation package file description characteristics, it is determined that the executable file does not belong to the software installation package program;
[0027] The preset installation package file description feature includes a plurality of preset installation description tags, and the preset installation description tags at least include installation, install, and setup.
[0028] In an optional implementation manner, obtaining the executable file to be analyzed and determining the bit number of the executable file includes:
[0029] Obtaining a file to be analyzed, and identifying whether the file to be analyzed is an executable file;
[0030] If it is an executable file, determining the number of bits of the executable file, performing an integrity check on the executable file, and continuing to execute subsequent steps when the executable file passes the integrity check, and determining that the file to be analyzed belongs to a program that cannot be run when the executable file fails the integrity check;
[0031] If the file to be analyzed is not an executable file, it is determined that the file to be analyzed does not belong to a software installation package program.
[0032] According to another aspect of the present application, a static identification device for a software installation package is provided, the device comprising:
[0033] A file acquisition module, used to acquire an executable file to be analyzed and determine the number of bits of the executable file;
[0034] A file identification module, used for: performing structural analysis on the executable file, and locating the tail address of the section table of the executable file based on the structural analysis result and the number of bits;
[0035] Based on the section table tail address, query whether the section table tail of the executable file contains a preset installation package tail mark, wherein the preset installation package tail mark is obtained by counting the section table tail features of the installation package file sample;
[0036] If the end of the section table of the executable file contains a preset installation package end mark, it is determined that the executable file belongs to a software installation package program.
[0037] In an optional embodiment, the device further comprises: a sample analysis module, configured to:
[0038] Acquire multiple first installation package file samples and multiple second non-installation package file samples, wherein the first installation package file samples include installation package files of different versions corresponding to multiple software, and the second non-installation package file samples include files of multiple types;
[0039] Analyze the tail of the section table corresponding to each first installation package file sample respectively to determine the first high-frequency section table tail mark corresponding to the installation package file, and analyze the tail of the section table corresponding to each second non-installation package file sample respectively to determine the second high-frequency section table tail mark corresponding to the non-installation package file;
[0040] The second high-frequency node table tail mark is removed from the first high-frequency node table tail mark to obtain the preset installation package tail mark.
[0041] In an optional implementation, the file identification module is further used to:
[0042] If the section table tail of the executable file does not include a preset installation package tail mark, locating the section table header address of the executable file based on the structure analysis result and the number of bits, and locating the program resource data position of the executable file from the section table header of the executable file according to the section table header address;
[0043] Querying whether the program resource data of the executable file conforms to the preset installation package program resource characteristics based on the program resource data location;
[0044] If the program resource data of the executable file meets the preset installation package program resource characteristics, it is determined that the executable file belongs to the software installation package program.
[0045] In an optional implementation, the preset installation package program resource feature includes that the program resource data capacity is greater than the preset installation package capacity and the program resource data includes a preset installation package program resource mark; the sample analysis module is further used to:
[0046] Acquire multiple second installation package file samples and multiple second non-installation package file samples, wherein the second installation package file samples include installation package files of different versions corresponding to multiple software, and the second non-installation package file samples include files of multiple types;
[0047] Analyze the program resource data corresponding to each second installation package file sample to determine the first high-frequency program resource tag corresponding to the installation package file, and analyze the tail of the section table corresponding to each non-installation package file sample to determine the second high-frequency program resource tag corresponding to the non-installation package file;
[0048] The second high-frequency program resource mark is removed from the first high-frequency program resource mark to obtain the preset installation package program resource mark.
[0049] In an optional implementation manner, the file identification module is further used to:
[0050] If the program resource data of the executable file does not conform to the preset program resource characteristics of the installation package, locating the file resource description list data of the executable file based on the program resource data, and querying whether the file resource description list data conforms to the preset file description characteristics of the installation package;
[0051] If the file resource description list data conforms to the preset installation package file description characteristics, it is determined that the executable file belongs to the software installation package program.
[0052] In an optional implementation manner, the file identification module is further used to:
[0053] If the file resource description list data does not conform to the preset installation package file description characteristics, it is determined that the executable file does not belong to the software installation package program;
[0054] The preset installation package file description feature includes a plurality of preset installation description tags, and the preset installation description tags at least include installation, install, and setup.
[0055] In an optional implementation manner, the file acquisition module is further used to:
[0056] Obtaining a file to be analyzed, and identifying whether the file to be analyzed is an executable file;
[0057] If it is an executable file, determining the number of bits of the executable file, performing an integrity check on the executable file, and continuing to execute subsequent steps when the executable file passes the integrity check, and determining that the file to be analyzed belongs to a program that cannot be run when the executable file fails the integrity check;
[0058] If the file to be analyzed is not an executable file, it is determined that the file to be analyzed does not belong to a software installation package program.
[0059] According to another aspect of the present application, a storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the static identification method of the software installation package is implemented.
[0060] According to another aspect of the present application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the above-mentioned static identification method of the software installation package when executing the program.
[0061] By means of the above technical scheme, a static identification method, device, storage medium and computer equipment of a software installation package provided in an embodiment of the present application are used to perform structural analysis on an executable file to be analyzed, locate the tail address of the section table based on the structural analysis result and the number of bits of the executable file, and query whether the tail of the section table of the executable file contains a preset installation package tail mark based on the tail address of the section table. If it does, it is determined that the executable file belongs to the software installation package program. The embodiment of the present application can realize the identification of the software installation package without running the executable file, avoiding the security risks caused by running malicious code, and presets the tail mark of the installation package by counting the tail features of the section table of the installation package file sample. By locating the tail of the section table and querying the preset tail mark of the installation package, it is possible to accurately and quickly determine whether the executable file is an installation package. At the same time, since the method is based on structural analysis rather than simple file name or file type judgment, it can reduce false positives and false negatives caused by file name disguise or file type confusion.
[0062] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0064] Figure 1A schematic diagram of a process flow of a static identification method for a software installation package provided in an embodiment of the present application is shown;
[0065] Figure 2 A schematic diagram showing a flow chart of another method for statically identifying a software installation package provided in an embodiment of the present application is shown;
[0066] Figure 3 A schematic diagram of the structure of a static identification device for a software installation package provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0067] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that the embodiments and features in the embodiments of the present application can be combined with each other without conflict.
[0068] In this embodiment, a static identification method for a software installation package is provided, such as Figure 1 As shown, the method includes:
[0069] Step 101: Obtain an executable file to be analyzed and determine the bit number of the executable file.
[0070] Step 102: Perform structural analysis on the executable file, and locate the tail address of the section table of the executable file based on the structural analysis result and the number of bits.
[0071] Step 103: query whether the section table tail of the executable file contains a preset installation package tail mark based on the section table tail address, wherein the preset installation package tail mark is obtained by counting the section table tail features of the installation package file sample.
[0072] Step 104: If the end of the section table of the executable file contains a preset installation package end mark, it is determined that the executable file belongs to a software installation package program.
[0073] The static identification method of the software installation package provided in the embodiment of the present application is intended to determine whether it is a software installation package by analyzing its internal structural features without running the executable file. First, obtain an executable file to be determined (such as an .exe file). At the same time, determine the number of bits (32 bits or 64 bits) of the file for subsequent analysis, because executable files of different bits may differ in structure. In the internal structure of the executable file, the section table (SectionTable) is an important component, which records the properties of each part of the file, such as size, location, permissions, etc. Secondly, the tail address of the section table can be found by structurally analyzing the executable file. This address is the key position for subsequent judgment, because many installation package files will leave specific marks at the end of the section table. The embodiment of the present application presets one or more installation package tail marks based on the section table tail features of the installation package file sample obtained by statistics. By querying the tail of the section table of the file to be analyzed, it is determined whether it contains these preset marks. If it is included, it indicates that the file is likely to be an installation package file. Finally, if the preset installation package tail mark is found at the end of the section table, then the executable file can be considered to be a software installation package program. On the contrary, if the corresponding mark is not found, it is impossible to determine whether it is an installation package by this method alone, and further judgment is required by other methods.
[0074] By applying the technical solution of this embodiment, a structural analysis is performed on the executable file to be analyzed, the tail address of the section table is located based on the structural analysis result and the number of bits of the executable file, and the tail of the section table of the executable file is queried based on the tail address of the section table to see whether it contains a preset installation package tail mark. If it does, it is determined that the executable file belongs to the software installation package program. The embodiment of the present application can realize the identification of the software installation package without running the executable file, avoiding the security risks caused by running malicious code, and presets the installation package tail mark by counting the tail features of the section table of the installation package file sample. By locating the tail of the section table and querying the preset installation package tail mark, it is possible to accurately and quickly determine whether the executable file is an installation package. At the same time, since this method is based on structural analysis rather than simple file name or file type judgment, it can reduce false positives and false negatives caused by file name disguise or file type confusion.
[0075] Further, as a refinement and extension of the specific implementation of the above embodiment, in order to fully illustrate the specific implementation process of this embodiment, another static identification method of the software installation package is provided, such as Figure 2 As shown, the method includes:
[0076] Step 201: Obtain a file to be analyzed, and identify whether the file to be analyzed is an executable file.
[0077] In this embodiment, a file to be analyzed is obtained, and whether the file is executable (such as .exe, .dll, etc.) is determined by checking the file extension, file header information or other identifiers.
[0078] Step 202: If the file to be analyzed is not an executable file, it is determined that the file to be analyzed does not belong to a software installation package program.
[0079] In this embodiment, if the file is not an executable file, then it naturally cannot be a software installation package program, because the installation package usually needs to contain an executable part to install the software.
[0080] Step 203: If it is an executable file, determine the bit number of the executable file, perform integrity check on the executable file, and determine that the file to be analyzed belongs to a program that cannot be run when the executable file fails the integrity check.
[0081] In this embodiment, if the file to be analyzed is an executable file, then the file is checked to see if it is 32-bit or 64-bit for subsequent analysis. And by comparing the hash value, digital signature, etc. of the file, it is verified whether the file has been tampered with or damaged. If the file is incomplete or tampered with, it is considered as a program that cannot be run.
[0082] Step 204: When the executable file passes the integrity check, a structural analysis is performed on the executable file, and the tail address of the section table of the executable file is located based on the structural analysis result and the number of bits.
[0083] In this embodiment, when the executable file passes the integrity check, the internal structure of the executable file, such as the structure of the PE format, is further analyzed. According to the structure and bit information of the file, the tail address of the section table is found.
[0084] Step 205: query whether the section table tail of the executable file contains a preset installation package tail mark based on the section table tail address, wherein the preset installation package tail mark is obtained by counting the section table tail features of the installation package file sample.
[0085] In this embodiment, the preset installation package tail mark is a specific pattern or string obtained by counting the tail features of the section table of the known installation package file samples. Check whether the tail of the section table of the file to be analyzed contains a preset installation package tail mark, such as NSIS mark, 7z header, zip header, etc.
[0086] In an optional embodiment, the method also includes: obtaining multiple first installation package file samples and multiple second non-installation package file samples, wherein the first installation package file samples include different versions of installation package files corresponding to multiple software, and the second non-installation package file samples include multiple types of files; analyzing the tail of the section table corresponding to each first installation package file sample respectively to determine the first high-frequency section table tail mark corresponding to the installation package file, and analyzing the tail of the section table corresponding to each second non-installation package file sample respectively to determine the second high-frequency section table tail mark corresponding to the non-installation package file; removing the second high-frequency section table tail mark from the first high-frequency section table tail mark to obtain the preset installation package tail mark.
[0087] In the above embodiment, the preset installation package tail mark can be determined by comparing and analyzing a large number of installation package file samples and non-installation package file samples. First, the first installation package file sample and the first non-installation package file sample are collected. The first installation package file sample includes different versions of installation package files corresponding to multiple software. The purpose of collecting these samples is to cover a wide range of software and versions, thereby ensuring the universality and accuracy of the analysis results. The second non-installation package file sample includes various types of files, such as documents, pictures, audio, video, etc. These samples are collected to establish a "background" data set for non-installation packages, so that the characteristics of installation packages and non-installation packages can be distinguished in subsequent analysis. The tail of the section table of each first installation package file sample is analyzed to extract the section table tail mark unique to the installation package file, such as a specific string, digital pattern or other identifiable features. Similarly, the tail of the section table of each second non-installation package file sample is analyzed to extract the section table tail mark common to non-installation package files. In the installation package file sample, the frequency of occurrence of each section table tail mark is counted to determine the first high-frequency section table tail mark corresponding to the installation package file, such as the section table tail mark with a frequency greater than a specific value. These high-frequency marks are likely to be common features of the installation package file. In the non-installation package file sample, the frequency of occurrence of each section table tail mark is also counted to determine the second high-frequency section table tail mark corresponding to the non-installation package file, such as the section table tail mark with a frequency greater than a specific value. These marks may represent the common characteristics of non-installation package files. Further, in the first high-frequency section table tail mark, those parts that also appear in the second high-frequency section table tail mark are removed, and those common marks that may appear in both the installation package file and the non-installation package file are excluded, so as to obtain more accurate and specific installation package tail marks. The marks finally obtained are the required preset installation package tail marks, which will be used in the subsequent executable file analysis to determine whether it is a software installation package program. The above method can set the preset installation package tail mark more scientifically and accurately. This method not only takes into account the diversity of installation package files, but also eliminates possible interference factors by comparing and analyzing non-installation package file samples, thereby improving the accuracy and reliability of identifying software installation package programs.
[0088] Step 206: If the end of the section table of the executable file contains a preset installation package end mark, it is determined that the executable file belongs to a software installation package program.
[0089] In this embodiment, if the end of the section table contains a preset installation package end mark, then it can be considered that the file belongs to the software installation package program. By gradually checking the executable, integrity, structural characteristics and specific end marks of the file, it is possible to identify whether a file belongs to the software installation package program. This method combines multiple technical means to improve the accuracy and reliability of identification.
[0090] Step 207: If the end of the section table of the executable file does not contain a preset installation package end mark, locate the section table header address of the executable file based on the structure analysis result and the bit number, and locate the program resource data position of the executable file from the section table header of the executable file according to the section table header address; based on the program resource data position, query whether the program resource data of the executable file meets the preset installation package program resource characteristics.
[0091] Step 208: If the program resource data of the executable file meets the preset installation package program resource characteristics, it is determined that the executable file belongs to the software installation package program.
[0092] In this embodiment, if the section table tail does not contain the preset installation package tail mark, then based on this information and the structural analysis results, the section table header address of the executable file is located. The section table header contains a detailed description of each section in the executable file, including their location, size, and attributes. Through this information, the location of the program resource data can be further located. The program resource data usually contains resources such as images, strings, and dialog templates required by the application. After locating the program resource data, continue to check whether these data meet the preset installation package program resource characteristics. These characteristics are derived based on the statistical results of known installation package samples, for example, the resource data size is greater than 10M and has one of the following characteristics: 7z header, zip header, cab header, etc. Finally, if the program resource data of the executable file matches the preset installation package program resource characteristics, then it can be considered that this file is a software installation package program. In the embodiment of the present application, when the section table tail does not contain the preset installation package tail mark, the accuracy and reliability of identifying the software installation package program can be further improved by deeply analyzing the section table header and program resource data of the executable file.
[0093] In an optional embodiment, the preset installation package program resource characteristics include that the program resource data capacity is greater than the preset installation package capacity and that the program resource data contains a preset installation package program resource mark; the method also includes: obtaining multiple second installation package file samples and multiple second non-installation package file samples, wherein the second installation package file samples include different versions of installation package files corresponding to multiple software, and the second non-installation package file samples include multiple types of files; analyzing the program resource data corresponding to each second installation package file sample respectively to determine the first high-frequency program resource mark corresponding to the installation package file, and analyzing the tail of the section table corresponding to each non-installation package file sample respectively to determine the second high-frequency program resource mark corresponding to the non-installation package file; removing the second high-frequency program resource mark from the first high-frequency program resource mark to obtain the preset installation package program resource mark.
[0094] In the above embodiment, the method for setting the preset installation package program resource features includes: collecting a second installation package file sample and a second non-installation package file sample. The second installation package file sample also includes different versions of installation package files corresponding to multiple software, but can be an independent or overlapping set with the first installation package file sample mentioned above. The purpose of collecting these samples is to analyze the program resource data features of the installation package file. The second non-installation package file sample includes various types of non-installation package files, such as documents, pictures, audio, video, etc., which can be an independent or overlapping set with the previous second non-installation package file sample. These samples are collected for comparison to help identify the program resource data features unique to the installation package file. The program resource data of each second installation package file sample is analyzed to extract the program resource tags unique to the installation package file, such as a specific resource type, resource size, resource quantity, a specific pattern of resource content, etc. At the same time, the program resource data of each second non-installation package file sample (if any) is analyzed to extract the common program resource tags of the non-installation package file. These tags may represent the universal resource features of the non-installation package file. In the sample of the installation package file, the frequency of occurrence of each program resource mark is counted to determine the first high-frequency program resource mark corresponding to the installation package file. These high-frequency marks are likely to be resource features common to the installation package file. Although the program resource data of the non-installation package file sample may be less, if there are enough samples, it is also possible to try to count the frequency of occurrence of each program resource mark to determine the second high-frequency program resource mark corresponding to the non-installation package file. However, this step may not be necessary because the program resource data of the non-installation package file often does not have significant commonality. In the first high-frequency program resource mark, those marks that may also appear in the non-installation package file are removed (if the second high-frequency program resource mark can be determined in the second step). This step is to ensure that the obtained preset installation package program resource mark is unique to the installation package file. In addition, a threshold value of the program resource data capacity can also be set as the preset installation package capacity, for example 10M. Only when the program resource data capacity is greater than this threshold value, it is considered that the file may contain resource data unique to the installation package. The marks and capacity thresholds finally obtained are the required preset installation package program resource features, which improve the accuracy and reliability of identifying the software installation package program.
[0095] Step 209: If the program resource data of the executable file does not conform to the preset installation package program resource characteristics, locate the file resource description list data of the executable file based on the program resource data, and query whether the file resource description list data conforms to the preset installation package file description characteristics.
[0096] Step 210: If the file resource description list data conforms to the preset installation package file description characteristics, it is determined that the executable file belongs to a software installation package program.
[0097] Step 211: If the file resource description list data does not conform to the preset installation package file description characteristics, it is determined that the executable file does not belong to the software installation package program; wherein the preset installation package file description characteristics include multiple preset installation description tags, and the preset installation description tags include at least installation, install, and setup.
[0098] In the above embodiment, if the program resource data of the executable file does not match the preset installation package program resource features, then based on the location of the program resource data, the file resource description list data is further located to check whether the file resource description list data contains the preset installation package file description features. These features are derived based on the analysis of known installation package files and are used to identify possible installation package files. If the file resource description list data matches the preset installation package file description features, for example, it contains clear installation description tags such as "install", "install", "setup", etc., if they match, it will be finally determined that the executable file belongs to the software installation package program. If the file resource description list data does not contain the preset installation package file description features, especially the lack of clear installation description tags, then it can be considered that this file does not belong to the software installation package program. Thereby, without the need to run the program, it is predicted in advance whether the program has installation behavior, which improves the efficiency of pre-judgment of the installation of malicious software and the accuracy of the judgment, and greatly improves the real-time performance and accuracy.
[0099] Further, as Figure 1 The specific implementation of the method, the embodiment of the present application provides a static recognition device for a software installation package, such as Figure 3 As shown, the device comprises:
[0100] A file acquisition module, used to acquire an executable file to be analyzed and determine the number of bits of the executable file;
[0101] A file identification module, used for: performing structural analysis on the executable file, and locating the tail address of the section table of the executable file based on the structural analysis result and the number of bits;
[0102] Based on the section table tail address, query whether the section table tail of the executable file contains a preset installation package tail mark, wherein the preset installation package tail mark is obtained by counting the section table tail features of the installation package file sample;
[0103] If the end of the section table of the executable file contains a preset installation package end mark, it is determined that the executable file belongs to a software installation package program.
[0104] In an optional embodiment, the device further comprises: a sample analysis module, configured to:
[0105] Acquire multiple first installation package file samples and multiple second non-installation package file samples, wherein the first installation package file samples include installation package files of different versions corresponding to multiple software, and the second non-installation package file samples include files of multiple types;
[0106] Analyze the tail of the section table corresponding to each first installation package file sample respectively to determine the first high-frequency section table tail mark corresponding to the installation package file, and analyze the tail of the section table corresponding to each second non-installation package file sample respectively to determine the second high-frequency section table tail mark corresponding to the non-installation package file;
[0107] The second high-frequency node table tail mark is removed from the first high-frequency node table tail mark to obtain the preset installation package tail mark.
[0108] In an optional implementation manner, the file identification module is further used to:
[0109] If the section table tail of the executable file does not include a preset installation package tail mark, locating the section table header address of the executable file based on the structure analysis result and the number of bits, and locating the program resource data position of the executable file from the section table header of the executable file according to the section table header address;
[0110] Querying whether the program resource data of the executable file conforms to the preset installation package program resource characteristics based on the program resource data location;
[0111] If the program resource data of the executable file meets the preset installation package program resource characteristics, it is determined that the executable file belongs to the software installation package program.
[0112] In an optional implementation, the preset installation package program resource feature includes that the program resource data capacity is greater than the preset installation package capacity and the program resource data includes a preset installation package program resource mark; the sample analysis module is further used to:
[0113] Acquire multiple second installation package file samples and multiple second non-installation package file samples, wherein the second installation package file samples include installation package files of different versions corresponding to multiple software, and the second non-installation package file samples include files of multiple types;
[0114] Analyze the program resource data corresponding to each second installation package file sample to determine the first high-frequency program resource tag corresponding to the installation package file, and analyze the tail of the section table corresponding to each non-installation package file sample to determine the second high-frequency program resource tag corresponding to the non-installation package file;
[0115] The second high-frequency program resource mark is removed from the first high-frequency program resource mark to obtain the preset installation package program resource mark.
[0116] In an optional implementation manner, the file identification module is further used to:
[0117] If the program resource data of the executable file does not conform to the preset program resource characteristics of the installation package, locating the file resource description list data of the executable file based on the program resource data, and querying whether the file resource description list data conforms to the preset file description characteristics of the installation package;
[0118] If the file resource description list data conforms to the preset installation package file description characteristics, it is determined that the executable file belongs to the software installation package program.
[0119] In an optional implementation manner, the file identification module is further used to:
[0120] If the file resource description list data does not conform to the preset installation package file description characteristics, it is determined that the executable file does not belong to the software installation package program;
[0121] The preset installation package file description feature includes a plurality of preset installation description tags, and the preset installation description tags at least include installation, install, and setup.
[0122] In an optional implementation manner, the file acquisition module is further used to:
[0123] Obtaining a file to be analyzed, and identifying whether the file to be analyzed is an executable file;
[0124] If it is an executable file, determining the number of bits of the executable file, performing an integrity check on the executable file, and continuing to execute subsequent steps when the executable file passes the integrity check, and determining that the file to be analyzed belongs to a program that cannot be run when the executable file fails the integrity check;
[0125] If the file to be analyzed is not an executable file, it is determined that the file to be analyzed does not belong to a software installation package program.
[0126] It should be noted that for other corresponding descriptions of the functional units involved in the static identification device for a software installation package provided in the embodiment of the present application, reference can be made to Figure 1 to Figure 2 The corresponding description in the method will not be repeated here.
[0127] The embodiment of the present application also provides a computer device, which can be a personal computer, a server, a network device, etc. The computer device includes a bus, a processor, a memory and a communication interface, and can also include an input and output interface and a display device. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store location information. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the steps in each method embodiment are implemented.
[0128] Those skilled in the art will appreciate that the structure of the above-mentioned computer device is only a partial structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components, or combine certain components, or have a different arrangement of components.
[0129] In one embodiment, a computer-readable storage medium is provided. The computer-readable storage medium may be non-volatile or volatile, and stores a computer program thereon. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0130] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0131] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0132] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.
[0133] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0134] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A static identification method for a software installation package, characterized in that: The method comprises: Obtaining an executable file to be analyzed, and determining the number of bits of the executable file; Performing structural analysis on the executable file, and locating the tail address of the section table of the executable file based on the structural analysis result and the number of bits; Based on the section table tail address, query whether the section table tail of the executable file contains a preset installation package tail mark, wherein the preset installation package tail mark is obtained by counting the section table tail features of the installation package file sample; If the end of the section table of the executable file contains a preset installation package end mark, it is determined that the executable file belongs to a software installation package program.
2. The method according to claim 1, characterized in that Before obtaining the executable file to be analyzed, the method further includes: Acquire multiple first installation package file samples and multiple second non-installation package file samples, wherein the first installation package file samples include installation package files of different versions corresponding to multiple software, and the second non-installation package file samples include files of multiple types; Analyze the tail of the section table corresponding to each first installation package file sample respectively to determine the first high-frequency section table tail mark corresponding to the installation package file, and analyze the tail of the section table corresponding to each second non-installation package file sample respectively to determine the second high-frequency section table tail mark corresponding to the non-installation package file; The second high-frequency node table tail mark is removed from the first high-frequency node table tail mark to obtain the preset installation package tail mark.
3. The method according to claim 1, characterized in that: After querying whether the tail of the section table of the executable file contains a preset installation package tail mark based on the tail address of the section table, the method further includes: If the section table tail of the executable file does not include a preset installation package tail mark, locating the section table header address of the executable file based on the structure analysis result and the number of bits, and locating the program resource data position of the executable file from the section table header of the executable file according to the section table header address; Querying whether the program resource data of the executable file conforms to the preset installation package program resource characteristics based on the program resource data location; If the program resource data of the executable file meets the preset installation package program resource characteristics, it is determined that the executable file belongs to the software installation package program.
4. The method according to claim 3, characterized in that The preset installation package program resource characteristics include that the program resource data capacity is greater than the preset installation package capacity and the program resource data includes a preset installation package program resource mark; Before obtaining the executable file to be analyzed, the method further includes: Acquire multiple second installation package file samples and multiple second non-installation package file samples, wherein the second installation package file samples include installation package files of different versions corresponding to multiple software, and the second non-installation package file samples include files of multiple types; Analyze the program resource data corresponding to each second installation package file sample to determine the first high-frequency program resource tag corresponding to the installation package file, and analyze the tail of the section table corresponding to each non-installation package file sample to determine the second high-frequency program resource tag corresponding to the non-installation package file; The second high-frequency program resource mark is removed from the first high-frequency program resource mark to obtain the preset installation package program resource mark.
5. The method according to claim 3, characterized in that: After querying whether the program resource data of the executable file meets the preset installation package program resource characteristics based on the program resource data location, the method further includes: If the program resource data of the executable file does not conform to the preset program resource characteristics of the installation package, locating the file resource description list data of the executable file based on the program resource data, and querying whether the file resource description list data conforms to the preset file description characteristics of the installation package; If the file resource description list data conforms to the preset installation package file description characteristics, it is determined that the executable file belongs to the software installation package program.
6. The method according to claim 5, characterized in that After querying whether the file resource description list data conforms to the preset installation package file description characteristics, the method further includes: If the file resource description list data does not conform to the preset installation package file description characteristics, it is determined that the executable file does not belong to the software installation package program; The preset installation package file description feature includes a plurality of preset installation description tags, and the preset installation description tags at least include installation, install, and setup.
7. The method according to any one of claims 1 to 6, characterized in that The obtaining of the executable file to be analyzed and determining the number of bits of the executable file includes: Obtaining a file to be analyzed, and identifying whether the file to be analyzed is an executable file; If it is an executable file, determining the number of bits of the executable file, performing an integrity check on the executable file, and continuing to execute subsequent steps when the executable file passes the integrity check, and determining that the file to be analyzed belongs to a program that cannot be run when the executable file fails the integrity check; If the file to be analyzed is not an executable file, it is determined that the file to be analyzed does not belong to a software installation package program.
8. A static recognition device for a software installation package, characterized in that: The device comprises: A file acquisition module, used to acquire an executable file to be analyzed and determine the number of bits of the executable file; A file identification module, used for: performing structural analysis on the executable file, and locating the tail address of the section table of the executable file based on the structural analysis result and the number of bits; Based on the section table tail address, query whether the section table tail of the executable file contains a preset installation package tail mark, wherein the preset installation package tail mark is obtained by counting the section table tail features of the installation package file sample; If the end of the section table of the executable file contains a preset installation package end mark, it is determined that the executable file belongs to a software installation package program.
9. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
10. A computer device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.