Method for detecting malicious file injection behavior of server

By establishing a file access monitoring framework, real-time detection and analysis of the server's file access behavior, and identifying and cleaning abnormal files, it solves the problem of difficult to detect and clear malicious file injection in the existing technology in real time, and achieves efficient protection effects.

CN119961923AActive Publication Date: 2025-05-09JINZHOU ELECTRIC POWER SUPPLY COMPANY OF STATE GRID LIAONING ELECTRIC POWER SUPPLY +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202411974246.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-09
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

The existing technology is difficult to detect and clear attacks based on malicious file injections in real time when an attack occurs, making it difficult for administrators to discover the injected files, and the protection mode is post-event protection and cannot intercept advanced threats.

Method used

By establishing a file access monitoring framework, regularly detecting the system's network service ports, collecting file access event messages from monitored processes, conducting rule learning and analysis, identifying abnormal file access events, and deleting and cleaning abnormal files in real time.

Benefits of technology

Real-time detection and cleaning of malicious file injection behavior of the server is realized, effectively blocking malicious files injection based on unknown vulnerabilities, reducing the risk of system infection, and providing a better protection effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961923A_ABST
    Figure CN119961923A_ABST
Patent Text Reader

Abstract

A method for detecting malicious file injection behaviors of a server comprises the steps that a network service port of a system is detected regularly, an executable file name corresponding to a process for starting the port is searched, a monitoring file name is added into a program management list to form a program management node, and the program management node is started. The system initially sets a rule learning state and a learning time threshold value for the program management node, and performs file access monitoring on the process; establishing a host file access monitoring mechanism, and collecting event messages of monitored process creation files; the method comprises the following steps of: firstly, entering a learning stage for monitoring a new application program, and counting and learning file access records; when the learning time exceeds a threshold value, summarizing monitored behaviors, extracting an access rule of a process to a file directory, entering a monitoring mode, and sequentially judging analysis states of program nodes; and in the monitoring mode, the system performs classification comparison on the file access records of the monitored process in combination with the access rule of the process, and identifies an abnormal file access event.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a method and system for detecting malicious file injection behavior of a server. Background Art

[0002] The current host security protection method collects data by installing lightweight data collection tools or agents on each endpoint device, including login, process running / creation, directory / file access logs, DNS request information, etc., and aggregates the data to the central service node. At the central service node, suspicious activities, unknown or variant threats are identified through technologies such as intelligent detection algorithms, UEBA (User and Entity Behavior Analytics) comprehensive analysis, and event correlation analysis. For advanced threats, attackers use zero-day vulnerabilities to invade the system and inject anti-killing modified malware. EDR is difficult to detect and kill, or when the malware is triggered to run, there is a risk that the system is still infected. In fact, it is difficult for administrators to find the injected files. The current protection mode is post-event protection, and advanced threats cannot be intercepted when they occur. Summary of the invention

[0003] The purpose of the present invention is to solve the problem of malicious file injection attacks based on zero-day vulnerabilities and clear attack files in real time when attacks occur, and to provide a method for detecting malicious file injection behavior on a server.

[0004] The technical solution of the present invention is: a method for detecting malicious file injection behavior of a server, which comprises:

[0005] Step 1: By periodically detecting the network service port of the system, if a new network service port is found, the executable file name corresponding to the process that starts the port is found. If the file name corresponding to the process is within the monitoring range, the file name is added to the program management list to form a program management node. The system initially sets the rule learning state and learning time threshold for the program management node, and performs file access monitoring on the process;

[0006] Step 2: Establish a host file access monitoring mechanism to collect event messages of file creation by the monitored process;

[0007] Step 3: The monitoring of a new application first enters the learning stage. The monitoring system collects and learns the file access records of the process of the program and saves the access records of the process to disk.

[0008] Step 4: When the learning time exceeds the threshold, the monitored behavior is summarized, the access rules of the process to the file directory are extracted, and the monitoring mode is entered. The analysis status of the program node is judged in turn. If the program node is in the learning state but the learning threshold is exceeded, the access record and access rules of the program node are extracted, and the rules are injected into the rule list of the program.

[0009] Step 5: In monitoring mode, the system classifies and compares the file access records of the monitored process in combination with the access rules of the process, identifies abnormal file access events and handles them.

[0010] Furthermore, in step 1, by establishing a timing processing flow, the network port opened by the local service is queried to find the service process file name of the port; if the file name belongs to the monitored object, the file access monitoring is performed on the process PID.

[0011] Furthermore, in step 2, file access monitoring uses the Linux system file access monitoring framework fanotify to listen to event messages of process opening and creation, extract file paths and file names, collect directory access records of the process, parse the process ID, file name and path of the accessed file for each event, and form a message with the parsed results.

[0012] Furthermore, in step 3, the message is first written into the database, and the analysis status of the program is obtained according to the process Pid. If the process file access monitoring is in a learning state, the message is placed in the cache; if the program has completed rule learning, the access record is matched according to the rules to determine whether the access is a suspicious access. If the access rules are not met, the access behavior is recorded in the access record table of the abnormal file, and the abnormal files in the monitoring process are isolated and cleared.

[0013] Furthermore, in step 4, the access rule is a directory list of created files learned by the monitoring process.

[0014] Furthermore, in step 5, when abnormal files are processed, for new messages of creating files, it is checked whether the created file is in the directory list. If the created file is not in the directory list, the monitoring program issues an alarm, and deletes and backs up the file.

[0015] The beneficial effects of the present invention are as follows: by establishing a file access monitoring framework, counting and analyzing the file access behavior of network service programs, forming access rules through self-learning and pre-configuration, and forming a security policy for program file creation behavior. In subsequent normal business operations, the file creation behavior can be monitored, abnormal file writing behavior can be detected, and abnormal files can be deleted and cleaned up in real time. Through file rule filtering, the solution can effectively discover and clean up malicious files injected based on unknown vulnerabilities in real time, and block advanced attack threats such as zero-day vulnerabilities. The method is simple and easy to use, suitable for server scenarios based on fixed server business models, and has a good protection effect. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a flow chart of the present invention. DETAILED DESCRIPTION

[0017] The detection method of the present invention, such as Figure 1 As shown, including:

[0018] Step 1: By periodically detecting the network service port of the system, if a new network service port is found, the executable file name corresponding to the process that starts the port is found. If the file name corresponding to the process is within the monitoring range, the file name is added to the program management list to form a program management node. The system initially sets the rule learning state and learning time threshold for the program management node, and performs file access monitoring on the process;

[0019] Step 2: Establish a host file access monitoring mechanism to collect event messages of file creation by the monitored process;

[0020] Step 3: The monitoring of a new application first enters the learning stage. The monitoring system collects and learns the file access records of the process of the program and saves the access records of the process to disk.

[0021] Step 4: When the learning time exceeds the threshold, the monitored behavior is summarized, the access rules of the process to the file directory are extracted, and the monitoring mode is entered. The analysis status of the program node is judged in turn. If the program node is in the learning state but the learning threshold is exceeded, the access record and access rules of the program node are extracted, and the rules are injected into the rule list of the program.

[0022] Step 5: In monitoring mode, the system classifies and compares the file access records of the monitored process in combination with the access rules of the process, identifies abnormal file access events and handles them.

[0023] Furthermore, in step 1, by establishing a timing processing flow, the network port opened by the local service is queried to find the service process file name of the port; if the file name belongs to the monitored object, the file access monitoring is performed on the process PID.

[0024] Furthermore, in step 2, file access monitoring uses the Linux system file access monitoring framework fanotify to listen to event messages of process opening and creation, extract file paths and file names, collect directory access records of the process, parse the process ID, file name and path of the accessed file for each event, and form a message with the parsed results.

[0025] Furthermore, in step 3, the message is first written into the database, and the analysis status of the program is obtained according to the process Pid. If the process file access monitoring is in a learning state, the message is placed in the cache; if the program has completed rule learning, the access record is matched according to the rules to determine whether the access is a suspicious access. If the access rules are not met, the access behavior is recorded in the access record table of the abnormal file, and the abnormal files in the monitoring process are isolated and cleared.

[0026] Further, in step 4, the access rule is a directory list of created files learned by the monitoring process.

[0027] Furthermore, in step 5, when abnormal files are processed, for new messages of creating files, it is checked whether the created file is in the directory list. If the created file is not in the directory list, the monitoring program issues an alarm, and deletes and backs up the file.

[0028] Application examples (or simulation experiments)

[0029] In the host, establish access monitoring for the Java program under Tomcat and nginx. After self-learning time, Tomcat and nginx form the following file access record list. The access record includes the process name, file access path, file

[0030] Type. Create an access record table:

[0031]

[0032] The program analysis module counts the access records of a program, summarizes the file access path and the access file type, and forms a list of file access rules for the program. The rule list is a directory tree composed of the directories in the access path. The content of the access rule includes the program process name, access file path, type of created file, and operation behavior. File access compliance judgment: After a program access rule is established, the subsequent record of file creation is matched by rules to judge the legality of the file write of the record. In a typical file injection vulnerability, hackers remotely inject .class or jar files into the / opt / tomcat / bin directory through the vulnerability. According to the system's judgment, the program does not have the rules for writing class and jar files. The monitoring system can issue an alarm in real time and clean up.

[0033] The above are only specific embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for detecting malicious file injection behavior on a server, characterized in that: include: Step 1: By periodically detecting the network service port of the system, if a new network service port is found, the executable file name corresponding to the process that starts the port is found. If the file name corresponding to the process is within the monitoring range, the file name is added to the program management list to form a program management node. The system initially sets the rule learning state and learning time threshold for the program management node, and performs file access monitoring on the process; Step 2: Establish a host file access monitoring mechanism to collect event messages of file creation by the monitored process; Step 3: The monitoring of a new application first enters the learning stage. The monitoring system collects statistics and learns the file access records of the process of the program, and saves the access records of the process to disk; Step 4: When the learning time exceeds the threshold, the monitored behavior is summarized, the access rules of the process to the file directory are extracted, and the monitoring mode is entered. The analysis status of the program node is judged in turn. If the program node is in the learning state but the learning threshold is exceeded, the access record and access rules of the program node are extracted, and the rules are injected into the rule list of the program. Step 5: In monitoring mode, the system classifies and compares the file access records of the monitored process in combination with the access rules of the process, identifies abnormal file access events and handles them.

2. A method for detecting malicious file injection behavior on a server according to claim 1, characterized in that: In step 1), by establishing a timing processing flow, the network port opened by the local service is queried to find the service process file name of the port; if the file name belongs to the monitored object, the file access monitoring is performed on the process PID.

3. A method for detecting malicious file injection behavior on a server according to claim 1, characterized in that: In step 2), file access monitoring uses the Linux system file access monitoring framework fanotify to listen to the event messages of process opening and creation, extract the file path and file name, collect the directory access records of the process, parse the process ID, file name and path of the accessed file for each event, and form the parsed results into a message.

4. A method for detecting malicious file injection behavior on a server according to claim 1, characterized in that: In step 3), the message is first written into the database, and the analysis status of the program is obtained according to the process Pid. If the process file access monitoring is in the learning state, the message is put into the cache; If the program has completed rule learning, it will match the access record according to the rules to determine whether the access is suspicious. If the access rules are not met, the access behavior will be recorded in the access record table of the abnormal file, and the files with abnormal monitoring processes will be isolated and cleared.

5. A method for detecting malicious file injection behavior on a server according to claim 1, characterized in that: In step 4), the access rule is a directory list of created files learned by the monitoring process.

6. A method for detecting malicious file injection behavior on a server according to claim 1, characterized in that: In step 5), when abnormal files are processed, for new messages of creating files, check whether the created files are in the directory list. If the created files are not in the directory list, the monitoring program issues an alarm, deletes and backs up the files.

Citation Information

Patent Citations

  • Method for detecting malicious software

    CN113449302A

  • Network intrusion detection method and device

    CN115442128A

  • Process analysis and control method for injection vulnerability suppression

    CN118606947A

  • System and method of detecting anomaly malicious code by using process behavior prediction technique

    US20080127346A1

  • White list creation in behavior monitoring system

    US8161552B1