Process tampering detection method and device and electronic equipment

By monitoring and risk detection of write events of the second process, accurately identifying whether the first process has been tampered with, solving the problem of difficult to identify and defend against process tampering in the prior art, and improving the protection capability of network security.

CN119939583APending Publication Date: 2025-05-06HILLSTONE NETWORKS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510017461.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-06
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The prior art is difficult to accurately identify and defend against process tampering. Attackers bypass the scanning of security software by generating white executable files, resulting in the inability to effectively identify the tampered processes and reduce network security.

Method used

By monitoring whether there is a write event of the second process when the first process is started, risk detection is performed, and based on the write code information, whether the first process has been tampered with, accurate detection of process tampering is achieved.

Benefits of technology

It improves the accuracy of detection of process tampering, avoids attackers from bypassing the scanning of security software by generating white executable files, and enhances network security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939583A_ABST
    Figure CN119939583A_ABST
Patent Text Reader

Abstract

The invention provides a process tampering detection method and device and electronic equipment, and relates to the technical field of information security, the method comprises the following steps: in response to starting of a first process, monitoring whether a write event of a second process exists or not; under the condition that the write event of the second process is monitored, performing risk detection on the second process according to the process information of the second process; and under the condition that the risk detection of the second process does not pass, determining whether the first process is tampered or not according to code information written into the memory of the first process by the second process. According to the process tampering detection method and device and the electronic equipment provided by the invention, in the detection process, the write event of the second process is monitored, so that an attacker can be prevented from bypassing a scanning event of security software by generating a white executable file in a related technology, the process tampering detection accuracy is improved, and the detection efficiency is improved. And the network security protection capability can also be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security, and in particular to a process tampering detection method, device and electronic equipment. Background Art

[0002] Process tampering is an advanced process injection method that uses malicious code to replace process code segments in processes created by legitimate executable files. Through process tampering, attackers can inject malicious code into other processes, which can not only damage users' computers and steal users' personal information, but also cause economic losses to users in serious cases.

[0003] Although in the related technology, there are security software that can scan malicious codes, but when attackers tamper with the process, they can often generate some white executable files. The security software scans the white executable files, but what is actually in the memory is the image section created by the malicious executable file. This will bypass the scanning defense of the security software, resulting in the inability to accurately identify the tampered process tampering, and also reduce network security. Summary of the invention

[0004] In view of this, an object of the present invention is to provide a process tampering detection method, device and electronic device, which can accurately identify the tampered process to improve the protection capability against process tampering, and further improve the protection capability of network security.

[0005] In a first aspect, an embodiment of the present invention provides a method for detecting process tampering, the method comprising: in response to the start of a first process, monitoring whether there is a write event of a second process; the write event is an event generated by the second process writing code into the memory of the first process; in a case where a write event of the second process is monitored, performing a risk detection on the second process based on process information of the second process; in a case where the risk detection of the second process fails, determining whether the first process has been tampered with based on the code information written by the second process into the memory of the first process.

[0006] In combination with the first aspect, an embodiment of the present invention provides a first possible implementation scheme of the first aspect, wherein the step of performing risk detection on the second process based on the process information of the second process includes: judging whether the second process is in a pre-configured whitelist based on the process information; if not, determining that the risk detection of the second process has failed; if yes, determining that the risk detection of the second process has passed.

[0007] In combination with the first aspect, an embodiment of the present invention provides a second possible implementation of the first aspect, wherein, when the risk detection of the second process fails, determining whether the first process has been tampered with is based on the code information written by the second process to the memory of the first process, including: determining the target code segment to which the code information written by the second process to the memory of the first process belongs; comparing the target code segment in the memory of the first process with the target code segment in the executable file of the first process to see whether they are consistent, to obtain a comparison result; and determining whether the first process has been tampered with based on the comparison result.

[0008] In combination with the second possible implementation of the first aspect, an embodiment of the present invention provides a third possible implementation of the first aspect, wherein the above-mentioned comparing whether the target code segment in the memory of the first process is consistent with the target code segment in the executable file of the first process to obtain the comparison result includes: calculating a first hash value corresponding to the target code segment in the memory of the first process, and a second hash value corresponding to the target code segment in the executable file of the first process; and obtaining the comparison result according to whether the first hash value and the second hash value are consistent.

[0009] In combination with the third possible implementation of the first aspect, an embodiment of the present invention provides a fourth possible implementation of the first aspect, wherein the above-mentioned write event includes the starting address and the ending address of the written code in the target code segment; calculating the first hash value corresponding to the target code segment in the memory of the first process, and the second hash value corresponding to the target code segment in the executable file of the first process, including: determining the target code area of ​​the written code in the target code segment according to the starting position and the ending position of the written code in the target code segment; calculating the first hash value of the target code area in the memory of the first process, and the second hash value of the target code area in the executable file of the first process.

[0010] In combination with the first aspect, an embodiment of the present invention provides a fifth possible implementation of the first aspect, wherein the above-mentioned response to the startup of the first process, monitoring whether there is a write event of the second process, includes: collecting log information generated by the first process during the startup process; based on whether the log information contains the event type of the memory write event, determining whether there is a write event of the second process.

[0011] In combination with the first aspect, an embodiment of the present invention provides a sixth possible implementation of the first aspect, wherein the method further includes: when the first process is tampered with, terminating the first process.

[0012] In a second aspect, an embodiment of the present invention further provides a device for detecting process tampering, the device comprising: a monitoring module, for monitoring whether there is a write event of a second process in response to the start of a first process; the write event is an event generated by the second process writing code into the memory of the first process; a detection module, for performing risk detection on the second process according to process information of the second process when a write event of the second process is detected; and a determination module, for determining whether the first process has been tampered with according to code information written by the second process into the memory of the first process when the risk detection of the second process fails.

[0013] In a third aspect, an embodiment of the present invention further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the process tampering detection method described in the first aspect when executing the computer program.

[0014] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the process tampering detection method described in the first aspect are executed.

[0015] The embodiments of the present invention bring the following beneficial effects:

[0016] The process tampering detection method, device and electronic device provided by the embodiments of the present invention can monitor whether there is a write event of the second process in response to the start of the first process; when the write event of the second process is monitored, risk detection is performed on the second process according to the process information of the second process; when the risk detection of the second process fails, it is determined whether the first process has been tampered with according to the code information written by the second process to the memory of the first process. During the detection process, by monitoring the write event of the second process, it is possible to avoid the attacker in the related technology from bypassing the scanning event of the security software by generating a white executable file, which not only improves the detection accuracy of process tampering, but also ensures the network security protection capability.

[0017] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention are realized and obtained by the structures particularly pointed out in the description, claims and drawings.

[0018] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 A flowchart of a process tampering detection method provided by an embodiment of the present invention;

[0021] Figure 2 A flowchart of another process tampering detection method provided by an embodiment of the present invention;

[0022] Figure 3 A schematic diagram of the structure of a process tampering detection device provided by an embodiment of the present invention;

[0023] Figure 4 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0024] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.

[0025] Typically, the process of starting a process in Windows is as follows:

[0026] (1) Open the handle of the executable file to be started.

[0027] (2) Create an image section for the executable file.

[0028] (3) Create a process using the image section.

[0029] (4) Allocate process parameters and environment variables.

[0030] (5) Create and start a thread.

[0031] Usually, for performance reasons, when scanning executable files, security software will only be triggered when the file is created, interacted with, or closed. The corresponding callback function can be used to receive notifications of the creation of processes and threads. Usually, the callback function is called when the first thread in these processes, that is, the main thread, is created. At this time, no code has been executed, and the main thread also loads the DLL dependency after the main thread is called.

[0032] Process tampering can occur in the process of creating processes and threads. For example, the process hollowing technique can first use a white executable file to create an image section. After the first thread is started and scanned by security software, it is replaced with the image section of a malicious executable file. That is, the section in the memory is tampered.

[0033] In addition, common process tampering also includes process Herpaderping, that is, using a malicious executable file to create a section, and using a white file to replace the actual executable file before starting the first thread, tampering with the executable file. The purpose of these two process tampering methods is to let security software scan the white executable file, while the actual memory is the section created by the malicious executable file, so that the security software can be bypassed.

[0034] The above-mentioned method of using white executable files to bypass security software scanning threatens network security to a great extent and often brings unnecessary losses to users.

[0035] Based on this, the embodiments of the present invention provide a process tampering detection method, device and electronic device, which can effectively identify tampered processes to improve the protection capability against process tampering, thereby improving the protection capability of network security.

[0036] To facilitate understanding of this embodiment, a process tampering detection method disclosed in an embodiment of the present invention is first introduced in detail.

[0037] In a possible implementation, the embodiment of the present invention provides a method for detecting process tampering, such as Figure 1 The flowchart of a process tampering detection method shown includes the following steps:

[0038] Step S102, in response to the first process being started, monitoring whether there is a write event of the second process; the write event is an event generated by the second process writing code into the memory of the first process;

[0039] Step S104, when a write event of the second process is detected, performing risk detection on the second process according to the process information of the second process;

[0040] Step S106, when the risk detection of the second process fails, determining whether the first process has been tampered with according to the code information written by the second process into the memory of the first process.

[0041] Here, the second process is different from the first process, and the first process may be any process that needs to be detected in the host.

[0042] In actual use, the executable file of the process, for example, a PE (Portable Executable) file, common PE file formats include EXE (executable), DLL (Dynamic Link Library), OCX (Object Control Extension), SYS (system), COM (command), etc.

[0043] When the host starts a process, such as the first process in the embodiment of the present invention, it can start the corresponding PE file and map the PE file to the host's memory for execution. At the same time, the host can allocate a portion of the memory for use by the PE file. The above-mentioned write event in the embodiment of the present invention refers to an event generated when the second process writes code to the portion of the memory. For example, after the PE file is mapped to the host's memory, code is written to the code area of ​​the PE file in the memory.

[0044] Generally, for a normally started process, the normal process startup process is as follows:

[0045] (1) Process start;

[0046] (2) The main thread of the process starts;

[0047] (3) The main thread of the process loads the DLL dependency.

[0048] Taking the target process as the first process for illustration, the process tampering mentioned above, such as the ProcessHollowing process tampering technology, tampering with the section of the target process, usually occurs in the first thread started in the target process section (i.e., the main thread), and then to the time period when the actual malicious section is executed; and the ProcessHerpaderping process tampering technology tampering with the executable file, usually occurs before the malicious process starts the first thread (main thread). Moreover, the above two process tampering technologies will have an operation in which an external process writes to the memory of the target process, that is, the process of tampering with the target process (for example, the second process in the embodiment of the present application) using the above process tampering technology is equivalent to an external process, and the external process writes the corresponding code to the startup memory of the target process, and only then does the main thread of the target process start to load the DLL dependency. That is, when process tampering occurs, the startup process of the entire process is as follows:

[0049] (1) The target process is started;

[0050] (2) The main thread of the target process is started;

[0051] (3) The external process writes memory code to the target process;

[0052] (4) The main thread of the target process loads the DLL dependency.

[0053] Among them, the above-mentioned external process can be regarded as the second process in the embodiment of the present invention, and the target process is called a normal process or a white process when it has not been tampered with. In the embodiment of the present invention, in the above-mentioned steps S102 and S104, after responding to the start of the first process or the target process, what is actually monitored is the write event of the above-mentioned external process, rather than monitoring the occurrence timing of a certain process tampering process, that is, as long as there is a write event of the external process, it can be monitored in the embodiment of the present invention, and then the subsequent steps are further executed.

[0054] The risk detection process of step S104 is actually a risk detection of the second process, which can exclude the false positive caused by the external process being security software. If the risk detection of step S104 fails, the second process is equivalent to a suspicious process at this time. Therefore, in step S106, the risk of the suspicious process is further located to the code information to determine whether the first process has been tampered with, thereby avoiding further execution of malicious code.

[0055] Therefore, the process tampering detection method provided by the embodiment of the present invention can monitor whether there is a write event of the second process in response to the start of the first process; when the write event of the second process is monitored, risk detection is performed on the second process according to the process information of the second process; when the risk detection of the second process fails, it is determined whether the first process has been tampered with according to the code information written by the second process to the memory of the first process. During the detection process, by monitoring the write event of the second process, it is possible to avoid the attacker in the related technology from bypassing the scanning event of the security software by generating a white executable file, which not only improves the detection accuracy of process tampering, but also ensures the network security protection capability.

[0056] In actual use, the process of monitoring the startup event of the first process in the above step S102 is usually monitored through the log information generated by the first process during the startup process. Specifically, the information when the first process starts running can be collected and recorded, including performance data, operation logs, diagnostic information, etc., to monitor the startup event of the first process.

[0057] In some examples, the first process is started on a host, which may be a physical machine or a virtual machine, depending on actual usage, and is not limited in this regard in the embodiments of the present invention.

[0058] The host can run a matching operating system, such as Windows, Linux, etc. These operating systems are usually configured with an event tracking log system, which can be used to track the startup process.

[0059] For example, under the Windows operating system, the Windows operating system can provide an efficient kernel-level tracing mechanism, such as the ETW (Event Tracing for Windows) tracing mechanism, etc. The tracing mechanism can implement the function of an event tracing log system. Generally, the tracing mechanism can be configured to be started together with the host or with the first process, depending on the actual usage, and the embodiment of the present invention does not limit this.

[0060] At this time, in the above step S102, in response to the startup of the first process, the event tracking log system can be started; the log information generated by the first process during the startup process is collected through the event tracking log system; based on whether the log information contains the event type of the memory write event, it is determined whether there is a write event of the second process.

[0061] In actual use, in an embodiment of the present invention, the event types of startup events monitored by the above-mentioned event tracking log system include at least: process write events, process start events, and thread start events; and, in an embodiment of the present invention, when tracking the above-mentioned startup events, it is necessary to configure the log source of the event tracking log system as the startup event, so that the event tracking log system collects the log information generated by the first process during the startup process.

[0062] Taking the ETW tracking mechanism as an example, the log sources that need to be subscribed to the ETW tracking mechanism are Microsoft-Windows-Kernel-Process and Microsoft-Windows-Threat-Intelligence, and the event types are process start (ProcessStart), thread start (ThreadStart), and write event (KERNEL_THREATINT_TASK_WRITEVM), so that the event tracking log system can collect log information during the startup process of the first process.

[0063] In addition, the startup process of the above-mentioned first process and the startup process of the main thread can also be implemented through a callback function, that is, when monitoring the startup event of the first process, a pre-configured callback function can be called; the process startup event and / or thread startup event can be monitored through the callback function; and the write event of the external process can be monitored through the event tracking log system.

[0064] The second process is usually an external process to the first process, and the write event of the second process can be monitored.

[0065] For example, the PsSetCreateProcessNotifyRoutineEx callback function can be pre-configured. After receiving the process start (such as main thread start) notification of the PsSetCreateProcessNotifyRoutineEx callback function and before the main thread loads the DLL dependency, if an external process writes code to the startup memory of the first process, the first process can also be considered to be a suspicious tampered process.

[0066] The specific monitoring process of the startup event of the first process can be set according to actual usage conditions, and the embodiment of the present invention does not limit this.

[0067] In some examples, in order to perform risk detection on the second process, in an embodiment of the present invention, a process whitelist mechanism is introduced to determine whether the second process is suspicious.

[0068] For ease of understanding, Figure 1 On the basis of Figure 2 A flowchart of another process tampering detection method is also shown, and the process of performing risk detection on the second process and the process of determining whether the first process has been tampered with are further explained. Figure 2 As shown, the following steps are included:

[0069] Step S202, in response to the first process being started, monitoring whether there is a write event of the second process;

[0070] The write event is an event generated when the second process writes code into the memory of the first process;

[0071] Step S204, when a write event of the second process is detected, obtaining process information of the second process;

[0072] Step S206, determining whether the second process is in a pre-configured whitelist based on the process information;

[0073] If not, execute step S208, that is, determine that the risk detection of the second process has not passed; if yes, determine that the risk detection of the second process has passed, and then return to step S202 to continue monitoring the write events of other second processes until the entire first process is started.

[0074] Step S208, determining the target code segment to which the code information written by the second process into the memory of the first process belongs;

[0075] That is, when the risk detection of the second process fails, the target code segment of the write event is located;

[0076] In actual use, in order to reduce the performance loss of matching detection in subsequent code segment areas and avoid false alarms that may be caused by certain security software, in an embodiment of the present invention, a process whitelist mechanism is introduced, that is, the process information of the security software or security process is added to the whitelist in advance. Specifically, the above process information may include path information of the security software or security process, and the path information can be added to a pre-configured whitelist. After a write event of the second process is monitored, the process information of the second process, such as path information, can be extracted, and it can be determined whether it is in the pre-configured whitelist. If it is, it means that the second process at this time is a risk-free process and the write event can be allowed to proceed. If the process information of the second process is not in the whitelist, it means that the second process at this time is a suspicious process, and the above step S208 is continued to be executed to locate the target code segment written by the write event, and then further determine whether the first process has been tampered with.

[0077] Step S210, comparing the target code segment in the memory of the first process with the target code segment in the executable file of the first process to see if they are consistent, and obtaining a comparison result;

[0078] Step S212: Determine whether the first process has been tampered with based on the comparison result.

[0079] In actual use, the comparison process in the above step S210 is implemented through hash values. Specifically, the first hash value corresponding to the target code segment in the memory of the above first process and the second hash value corresponding to the target code segment in the executable file of the first process can be calculated; and the comparison result is obtained based on whether the first hash value and the second hash value are consistent.

[0080] Specifically, if the comparison result is consistent, it means that the target code segment in the memory of the first process is consistent with the target code segment in the executable file of the first process, that is, the first process has not been tampered with; if they are inconsistent, it means that the first process has been tampered with.

[0081] Furthermore, the above-mentioned write event includes the starting address and the ending address of the written code in the target code segment of the first process memory; when calculating the hash value, the target code area of ​​the written code in the target code segment can be determined according to the starting position and the ending position of the written code in the target code segment, and the target code segment area of ​​the executable file corresponding to it can be calculated according to the section header information of the executable file; then, a first hash value of the target code area in the memory of the first process and a second hash value of the target code area in the executable file of the first process are calculated.

[0082] The executable file here can be the above-mentioned PE file. The PE file is a standard file format for executable files, DLL files, core drivers, etc. in the Windows operating system. Its main structure includes:

[0083] (1) DOS Header: This is the first part of the PE file. It contains a header for an MS-DOS (Microsoft Disk Operating System) compatible executable program. The main purpose of this header is to display an error message when trying to run the PE file in a DOS environment. The last field of the DOS header is a pointer to the PE header.

[0084] (2) PE Header: This is the main part of the PE file, which contains most of the information of the PE file. The PE header consists of the following parts:

[0085] COFF Header: This part contains basic information of the PE file, such as target machine type, number of sections, timestamp, etc.

[0086] Optional Header: This part contains important information of the PE file, such as entry point address, image base address, image size, operating system version, section alignment, file alignment, stack size, data directory, etc.

[0087] Data Directories: This part is part of the optional header, which contains pointers to important data structures in the PE file, such as import table, export table, resource table, exception handling table, relocation table, etc.

[0088] (3) Section Headers: This part follows the PE header and contains the section information of the PE file. Each section header describes the name, virtual memory size, virtual address, original data size, original data pointer, section attributes, etc. of a section. Based on the above information, the mapping relationship from the PE file offset address to the process virtual memory address can be obtained.

[0089] (4) Sections: This is the main part of the PE file, which contains the actual code and data of the PE file. When the PE file is executed, the data or code in the section will be mapped to the virtual memory of the process based on the information in the section header. Among them, a PE file usually contains the following sections:

[0090] Text section: This section contains the executable code of the PE file, also known as the code segment or code area. It is usually the largest section in a PE file because it contains the main logic of the program. This section is usually marked as readable and executable, but not writable, to prevent the program from modifying its own code at runtime.

[0091] Data section: This section contains the initialized global variables of the PE file. These variables are assigned initial values ​​when the program starts executing. This section is usually marked as readable and writable, but not executable.

[0092] rdata section: This section contains read-only data of the PE file, such as strings and constants. This section is usually marked as readable, but not writable and not executable.

[0093] idata section: This section contains the import table of the PE file. The import table is a list that contains the functions that the program needs to import from other DLL files. This section is usually marked as readable and writable, but not executable.

[0094] edata section: This section contains the export table of the PE file. The export table is a list that contains the functions that the program provides to other programs for use. This section is usually marked as readable and writable, but not executable.

[0095] reloc section: This section contains the relocation table of the PE file. The relocation table is a list of addresses that need to be fixed when the program is loaded into an unexpected address. This section is usually marked as readable and writable, but not executable.

[0096] In Windows operating system, in PE file, code segment (also called .text segment or code area) is the area for storing program code, which contains all the machine code of the program, that is, the binary instructions directly executed by the CPU. The code segment is usually contained in the above-mentioned text section, and in the embodiment of the present invention, the process of process tampering detection actually monitors whether the code of the code segment or the text section has been tampered. That is, in the above-mentioned step S208, the target code segment located is actually a section of the code segment in the above-mentioned text section, or a section or multiple sections of code in the section.

[0097] Under normal circumstances, when the first process is started, it includes the process of mapping the PE file to the memory, that is, when the first process is started normally, the code of the code segment in the memory is consistent with the code of the code segment in the PE file, that is, the hash value is also consistent. If an external process, such as the second process mentioned above, tampers with the code of the code segment in the memory of the first process, that is, the above-mentioned write event is detected, it will cause the hash value corresponding to the target code segment in the memory of the first process to be inconsistent with the hash value of the code of the corresponding code segment in the PE file, that is, the situation in which the first hash value and the second hash value mentioned above in the embodiment of the present invention are inconsistent can be used as a basis for judgment to indicate that the first process has been tampered with.

[0098] Moreover, after determining that the first process has been tampered with, an alarm can be further generated, and, if the first process has been tampered with, the first process can be terminated to prevent the malicious code written by the second process during tampering from being further executed; at the same time, the generated alarm information includes the write event of the second process, such as the start address and end address of the written code in the target code segment specifically included in the write event, so as to warn of the tampering event of the second process at this time.

[0099] In summary, the process tampering detection method provided in the embodiment of the present invention is suitable for the detection of process tampering and process injection technology by the threat detection engine. Specifically, in the embodiment of the present invention, by collecting and analyzing the host log, the suspicious process is preliminarily judged, and the hash value of the code segment in the process memory and the code segment of the PE file are compared to accurately identify and terminate the tampered process to prevent the execution of malicious code and generate a threat alarm prompt.

[0100] Moreover, in the embodiments of the present invention, suspicious processes can be screened through predefined process behavior analysis and process whitelist mechanisms, thereby avoiding blind and frequent calculation of code segment hash values, accurately identifying and terminating tampered processes, and effectively detecting process tampering techniques that are often used by attackers to evade security software scanning, such as Process Hollowing, Process Herpaderping, Process Doppelganging, etc., thereby improving the ability to identify and protect against process tampering.

[0101] In some embodiments, the present invention also provides a process tampering detection device, such as Figure 3 A schematic diagram of the structure of a process tampering detection device is shown, the device comprising:

[0102] The monitoring module 30 is used to monitor whether there is a write event of the second process in response to the start of the first process; the write event is an event generated by the second process writing code into the memory of the first process;

[0103] A detection module 32, configured to perform risk detection on the second process according to the process information of the second process when a write event of the second process is detected;

[0104] The determination module 34 is used to determine whether the first process has been tampered with according to the code information written by the second process into the memory of the first process when the risk detection of the second process fails.

[0105] In some embodiments, the detection module 32 is further used to:

[0106] Based on the process information, it is determined whether the second process is in a pre-configured whitelist; if not, it is determined that the risk detection of the second process has failed; if yes, it is determined that the risk detection of the second process has passed.

[0107] In some embodiments, the determination module 34 is further configured to:

[0108] Determine the target code segment to which the code information written by the second process into the memory of the first process belongs; compare whether the target code segment in the memory of the first process is consistent with the target code segment in the executable file of the first process to obtain a comparison result; and determine whether the first process has been tampered with based on the comparison result.

[0109] The above-mentioned determination module 34 is also used for:

[0110] Calculate a first hash value corresponding to the target code segment in the memory of the first process and a second hash value corresponding to the target code segment in the executable file of the first process; and obtain the comparison result according to whether the first hash value and the second hash value are consistent.

[0111] The write event includes the start address and the end address of the written code in the target code segment;

[0112] The determination module 34 is further used for:

[0113] Determine a target code region in the target code segment where the code is written according to a starting position and an ending position of the written code in the target code segment; calculate a first hash value of the target code region in the memory of the first process, and a second hash value of the target code region in the executable file of the first process.

[0114] In some embodiments, the monitoring module 30 is further used to:

[0115] Collect log information generated by the first process during startup; and determine whether there is a write event of the second process based on whether the log information contains an event type of a memory write event.

[0116] In some embodiments, the above apparatus further comprises:

[0117] The ending module is used to end the first process when the first process is tampered with.

[0118] The process tampering detection device provided in the embodiment of the present invention has the same technical features as the process tampering detection method provided in the above embodiment, so it can also solve the same technical problems and achieve the same technical effects.

[0119] Furthermore, an embodiment of the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the computer program.

[0120] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method are executed.

[0121] Furthermore, an embodiment of the present invention also provides a schematic diagram of the structure of an electronic device, such as Figure 4 As shown, it is a schematic diagram of the structure of the electronic device, wherein the electronic device includes a processor 41 and a memory 40, the memory 40 stores computer executable instructions that can be executed by the processor 41, and the processor 41 executes the computer executable instructions to implement the above method.

[0122] exist Figure 4 In the illustrated embodiment, the electronic device further includes a bus 42 and a communication interface 43 , wherein the processor 41 , the communication interface 43 and the memory 40 are connected via the bus 42 .

[0123] Among them, the memory 40 may include a high-speed random access memory (RAM), and may also include a non-volatile memory (non-volatile memory), such as at least one disk storage. The communication connection between the system network element and at least one other network element is realized through at least one communication interface 43 (which can be wired or wireless), and the Internet, wide area network, local area network, metropolitan area network, etc. can be used. The bus 42 can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus 42 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0124] The processor 41 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit in the processor 41 or the instruction in the form of software. The above processor 41 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in the embodiment of the present invention can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor 41 reads the information in the memory and completes the above method in combination with its hardware.

[0125] The process tampering detection method, device and computer program product of the electronic device provided in the embodiments of the present invention include a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the method described in the previous method embodiments. The specific implementation can be found in the method embodiments, which will not be repeated here.

[0126] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0127] In addition, the embodiments or examples of the present disclosure are not exhaustive, but are only illustrative of some embodiments or examples, and are not intended to be specific limitations on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment or example can be implemented as an independent example, and the steps can be combined arbitrarily. For example, the scheme after removing some steps in a certain embodiment or example can also be implemented as an independent example, and the order of the steps in a certain embodiment or example can be arbitrarily exchanged. In addition, the optional methods or optional examples in a certain embodiment or example can be combined arbitrarily; in addition, the various embodiments or examples can be combined arbitrarily, for example, some or all steps of different embodiments or examples can be combined arbitrarily, and a certain embodiment or example can be combined arbitrarily with the optional methods or optional examples of other embodiments or examples.

[0128] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc., which can store program codes.

[0129] In the description of the present invention, it should be noted that the terms “first”, “second” and “third” are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.

[0130] Finally, it should be noted that the above embodiments are only specific implementations of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit them. The protection scope of the present invention is not limited thereto. Although the present invention is described in detail with reference to the above embodiments, those skilled in the art should understand that any person skilled in the art can still modify the technical solutions recorded in the above embodiments within the technical scope disclosed by the present invention, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be based on the protection scope of the claims.

Claims

1. A method for detecting process tampering, characterized in that: The method comprises: In response to the first process being started, monitoring whether there is a write event of the second process; the write event is an event generated by the second process writing code into the memory of the first process; When a write event of the second process is detected, performing risk detection on the second process according to the process information of the second process; When the risk detection of the second process fails, it is determined whether the first process has been tampered with according to the code information written by the second process into the memory of the first process.

2. The method according to claim 1, characterized in that The step of performing risk detection on the second process according to the process information of the second process includes: Determining whether the second process is in a pre-configured whitelist based on the process information; If not, determining that the risk detection of the second process fails; If yes, it is determined that the risk detection of the second process passes.

3. The method according to claim 1, characterized in that: In a case where the risk detection of the second process fails, determining whether the first process has been tampered with according to code information written by the second process to the memory of the first process includes: Determine a target code segment to which the code information written by the second process into the memory of the first process belongs; Comparing the target code segment in the memory of the first process with the target code segment in the executable file of the first process to see whether they are consistent, and obtaining a comparison result; According to the comparison result, it is determined whether the first process has been tampered with.

4. The method according to claim 3, characterized in that Comparing the target code segment in the memory of the first process with the target code segment in the executable file of the first process to see whether they are consistent, and obtaining a comparison result, including: Calculate a first hash value corresponding to the target code segment in the memory of the first process, and a second hash value corresponding to the target code segment in the executable file of the first process; The comparison result is obtained according to whether the first Hash value is consistent with the second Hash value.

5. The method according to claim 4, characterized in that The write event includes the starting address and the ending address of the written code in the target code segment; Calculating a first hash value corresponding to the target code segment in the memory of the first process and a second hash value corresponding to the target code segment in the executable file of the first process, including: Determine a target code region in the target code segment where the code is written according to a starting position and an ending position of the written code in the target code segment; A first hash value of the target code region in the memory of the first process and a second hash value of the target code region in the executable file of the first process are calculated.

6. The method according to claim 1, characterized in that In response to the first process being started, monitoring whether there is a write event of the second process, including: Collecting log information generated by the first process during startup; Based on whether the log information includes an event type of a memory write event, it is determined whether there is a write event of the second process.

7. The method according to claim 1, characterized in that The method further comprises: In the case where the first process is tampered with, the first process is terminated.

8. A process tampering detection device, characterized in that: The device comprises: A monitoring module, configured to monitor whether there is a write event of the second process in response to the start of the first process; the write event is an event generated by the second process writing code into the memory of the first process; a detection module, configured to, when a write event of the second process is detected, perform risk detection on the second process according to the process information of the second process; The determination module is used to determine whether the first process has been tampered with according to the code information written by the second process to the memory of the first process when the risk detection of the second process fails.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method for detecting process tampering described in any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the process tampering detection method described in any one of claims 1 to 7 are executed.