Safety protection validity verification system and method for endpoint equipment

By using script files to automatically control remote command control tools on command and control servers to generate and place Trojan samples, the problems of cumbersome and inefficient manual operations in the existing technology are solved, and efficient automated verification of endpoint security equipment is achieved.

CN120017416AInactive Publication Date: 2025-05-16BEIJING ZHIQIAN TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510468772.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-05-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, C2 attack platforms such as CobaltStrike, Sliver, and Metasploit cannot directly automate the server monitoring, Trojan generation, and delivery operations, and need to be completed manually, resulting in cumbersome operations and inefficient verification.

Method used

Through the command and control server, the built-in remote command control tool is used to generate Trojan samples and automatically post them to the target endpoint device, send Trojan samples to execute instructions, and complete the online verification of Trojan samples.

Benefits of technology

It realizes automated operations in key links such as Trojan generation, drop-off, execution and launch, improves the efficiency and accuracy of endpoint security equipment verification work, and reduces labor costs and operational errors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017416A_ABST
    Figure CN120017416A_ABST
Patent Text Reader

Abstract

The invention provides a safety protection validity verification system and method for endpoint equipment, and belongs to the technical field of safety validity verification. A command and control server of the system automatically delivers a Trojan sample to a target endpoint device, sends a Trojan sample execution instruction and completes Trojan sample online verification through a preset script file, an automatic verification logic and implementation are constructed, and the situation that manual verification operation is tedious and low in efficiency in the prior art is changed. Due to the fact that full-automatic operation is achieved, workers do not need to participate in all links in the whole process, and manpower input is reduced. Meanwhile, the operation of the automatic system is relatively stable, and extra cost expenditure caused by manual misoperation is reduced, such as unnecessary equipment adjustment or optimization caused by misjudgment of the protection effect of the endpoint equipment. Compared with the conditions of tedious manual operation and high cost in the prior art, the problem of high operation cost of safety protection verification work is effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security effectiveness verification, and in particular to a security protection effectiveness verification system and method for an endpoint device. Background Art

[0002] In today's network security attack and defense drills, CobaltStrike, Metasploit, and Sliver, as tools widely used for remote command control, occupy an important position. From a broader technical perspective, with the rapid development of network technology, various network attack methods are becoming increasingly complex and diverse, and the confrontation between attack and defense is becoming more intense. In such an environment, endpoint security devices (endpoint security devices include laptops, desktops, smartphones, tablets, etc.) play an increasingly critical role in preventing various types of malware and attack behaviors, and the detection and defense of such mainstream attack tools has become one of the key links in ensuring network security.

[0003] CobaltStrike, Metasploit, and Sliver have become one of the preferred tools for many attack teams in attack and defense drills due to their ability to support the generation of multiple attack payload types. Attackers often use various advanced technologies, such as bypassing static detection and behavioral bypass technology, to enable the Trojans they use to evade conventional security detection mechanisms, which undoubtedly increases the difficulty and complexity of defense. In the actual attack and defense drills, in order to effectively verify whether the endpoint security device can play an effective defensive role in the key links from the Trojan to the disk, execution to the online launch, security researchers need to simulate the execution process of the Trojan as realistically as possible, so as to accurately locate the defense action nodes of the endpoint security device, and then optimize and improve the overall defense strategy.

[0004] From the perspective of endpoint security, defense against Trojan attacks usually relies on static detection and dynamic detection defense. Static detection generally scans and identifies file features when the Trojan program is downloaded to the disk, while dynamic detection defense detects the memory information of the process after the Trojan program is executed.

[0005] To verify the effectiveness of static and dynamic endpoint security defense, it is necessary to complete the entire process of Trojans dropping to disk and going online. However, the technical architecture and operation mode of such remote command control tools themselves pose great challenges to the verification work. For example, CobaltStrike is a graphical attack platform written in the cross-platform Java language, which means that when performing verification operations, it is necessary to first start the server and establish a connection with the client before a series of verification actions can be completed through the graphical interface. This mode of operation is highly dependent on manual operation. Not only is the process cumbersome and complicated, but it is also extremely difficult and costly to achieve automation, which severely limits the efficiency and accuracy of the verification work and cannot meet the urgent needs for efficient and accurate verification in today's endpoint security attack and defense confrontation.

[0006] To sum up, under the current technological background, we need a new, efficient and low-cost simulation technology that can break through the limitations of existing technologies and realize the automation of key links such as Trojan generation, disk verification, execution verification and online verification, thereby improving the efficiency and effectiveness of endpoint security device verification and providing more powerful support and guarantee for network security defense.

[0007] Since C2 attack platforms such as CobaltStrike, Sliver, and Metasploit cannot directly automate server-side monitoring, Trojan generation, and delivery, they must be completed manually according to command input, and even open a graphical interface to manually compare the detection and interception of endpoint devices. The operation is cumbersome and the verification efficiency is low.

[0008] In order to facilitate understanding of the technical solution of this application, the relevant technical terms are explained as follows: 1. CobaltStrike, Cobalt Strike is a GUI framework penetration testing tool based on Metasploit, which integrates port forwarding, service scanning, automated overflow, multi-mode port monitoring, exe, powershell Trojan generation, etc. Cobalt Strike is divided into client and server, which can be distributed and coordinated. Phishing attacks include: site cloning, target information acquisition, java execution, browser automatic attack, etc.

[0009] Cobalt Strike is mainly used for team operations and can be described as a team penetration tool that allows multiple attackers to connect to a group server at the same time and share attack resources, target information, and sessions.

[0010] As a collaborative APT tool (Advanced Persistent Threat, APT, advanced persistent threat, is a complex and persistent network attack), Cobalt Strike's penetration testing of intranets and its function as an APT control terminal make it the first choice of many APT organizations.

[0011] 2. Metasploit. Metasploit is an open source security vulnerability detection tool. At the same time, Metasploit is a free tool, so security personnel often use Metasploit to detect the security of the system. Metasploi Framework (MSF) was released as an open source in 2003 and is a freely available development framework. It is a powerful open source platform for developing, testing and using malicious code. This environment provides a reliable platform for penetration testing, shelcode writing and vulnerability research.

[0012] This scalable model integrates payload, encoder, no-operation generator (nops) and vulnerabilities, making Metasploit Framework a way to study high-risk vulnerabilities. It integrates common overflow vulnerabilities and popular shellcodes on various platforms and is constantly updated. The current version collects hundreds of practical overflow attack programs and some auxiliary tools, allowing people to complete security vulnerability detection using simple methods.

[0013] 3. Silver: Over the past few years, Cobalt Strike has been abused by various attackers (including ransomware operations), who use it to drop "beacons" on attacked networks and move laterally to high-value systems. However, defenders have mastered methods to detect and block Cobalt Strike attacks, and attackers have turned to other tools that can evade endpoint detection and response (EDR) and antivirus solutions.

[0014] 4. Among the many tactics used by attackers, one of the most insidious is command and control servers (C2). These servers act as the brains of computer hacking operations, coordinating the operations of infected devices and allowing attackers to manipulate them at will. In the field of cybersecurity, a full understanding of how C2 works is essential to effectively defend against increasingly prevalent and sophisticated digital threats.

[0015] Command and Control (C2) servers are a fundamental backbone of hacker and cybercriminal activities. These servers form the nerve center of a vast network of infected devices, allowing attackers to remotely control these systems without raising suspicion. The C2 server concept is based on the command and control model, where the attacker plays the role of commander and the infected devices act as pawns to achieve the attacker's malicious goals. C2 servers act as a bridge between the attacker and the infected devices, facilitating two-way communication between the parties involved and the transfer of instructions and data. These servers are designed to be discreet and hidden in the network, often masquerading as regular servers or legitimate devices to evade detection by network security systems. Access to C2 servers provides attackers with a wide range of capabilities, allowing them to carry out malware distribution and even DDoS attacks with relative ease.

[0016] Command and control server architectures are carefully designed to ensure smooth, secure communication between attackers and infected devices. These servers are usually built in a hierarchical manner with different levels of access and control for malicious operators. At the top of the hierarchy is the master server, which acts as a central hub for managing and coordinating hacker operations. This server is responsible for receiving and processing instructions sent by attackers and sending commands to infected devices.

[0017] Below the primary server, there may be many satellite servers or command nodes, distributed across different geographical locations to increase the resilience and availability of the system. These secondary nodes act as local points of contact for infected devices, reducing latency and making communications more efficient. Each command node can specialize in certain functions or operations, allowing attackers to divide the workload and maintain flexibility in controlling the network.

[0018] C2 servers operate based on secure and encrypted communication protocols, which ensure the confidentiality and integrity of information exchanged between attackers and infected devices. Attackers often use stealth and camouflage techniques to disguise C2 server activities and evade detection by network security systems. This may include using encrypted connections, dynamically changing IP addresses, and rotating domains, making it more difficult for investigators to track the attacker's activities and identify the source of their attacks. Summary of the invention

[0019] The purpose of the present invention is to overcome the above-mentioned technical deficiencies and provide a security protection effectiveness verification system and method for endpoint devices to solve the problems in the related technologies that C2 attack platforms such as CobaltStrike, Sliver, Metasploit, etc. cannot directly and automatically complete server-side monitoring, Trojan generation, delivery and other operations, and need to be completed manually according to command input, and even open a graphical interface to manually compare the detection and interception of endpoint devices, resulting in cumbersome operations and low verification efficiency.

[0020] In order to achieve the above technical objectives, the present invention adopts the following technical solutions: According to a first aspect of the present invention, a security protection effectiveness verification system for an endpoint device is provided, comprising: a command and control server, and at least one endpoint device, wherein: The command and control server is used to control the built-in remote command and control tool to generate Trojan samples through a preset script file and deliver them to the target endpoint device; it is also used to send Trojan sample execution instructions to the target endpoint device after determining that the Trojan sample is delivered successfully; The target endpoint device is used to execute the Trojan sample delivered to the local machine according to the Trojan sample execution instruction, and after the Trojan sample is run, it connects back to the command and control server and sends its own device information to the command and control server to complete the Trojan sample online; The command and control server is also used to verify the effectiveness of security protection of the target endpoint device based on the delivery of Trojan samples and the online status of Trojan samples.

[0021] Preferably, the command and control server establishes a communication connection with the target endpoint device through the IP address and port pre-configured by the user, and monitors the device information returned by the target endpoint device.

[0022] Preferably, the remote command control tool at least includes: A combination of one or more of CobaltStrike, Metasploit, and Sliver.

[0023] According to a second aspect of the present invention, a method for verifying the effectiveness of security protection of an endpoint device is provided, comprising: The command and control server uses a preset script file to control the built-in remote command and control tool to generate a Trojan sample and deliver it to the target endpoint device. After determining that the Trojan sample has been delivered successfully, it sends a Trojan sample execution instruction to the target endpoint device. The target endpoint device executes the Trojan sample delivered to the local device according to the Trojan sample execution instruction, and after the Trojan sample runs, it connects back to the command and control server and sends its own device information to the command and control server to complete the Trojan sample going online; The command and control server verifies the effectiveness of the security protection of the target endpoint device based on the delivery and online status of Trojan samples.

[0024] Preferably, the command and control server controls the built-in remote command control tool to generate a Trojan sample through a preset script file and delivers it to the target endpoint device, including: The script file receives the verification parameters and configuration information input by the user; The script file controls the built-in remote command control tool to generate a corresponding Trojan sample according to the verification parameters and configuration information, and writes the Trojan sample into the system disk directory of the target endpoint device to complete the delivery of the Trojan sample; Wherein, the verification parameters include at least: user authority; The configuration information includes at least: the IP address of the target endpoint device, the directory path for delivering the Trojan horse, and the type of the Trojan horse to be delivered.

[0025] Preferably, the method further comprises: After the Trojan sample is delivered, the script file determines whether the Trojan sample is delivered successfully; If yes, compare the hash values ​​before and after the Trojan sample is delivered, and determine whether it is necessary to send a Trojan sample execution instruction to the target endpoint device based on the comparison result; If not, it is determined that the Trojan sample is detected and killed by the target endpoint device, the Trojan sample delivery fails, and the verification ends.

[0026] Preferably, the script file determines whether the Trojan sample is delivered successfully, specifically: Polling is performed at preset intervals to detect whether the Trojan sample file still exists in the system disk directory of the target endpoint device. If so, the Trojan sample is successfully delivered. If not, the Trojan sample fails to be delivered.

[0027] Preferably, judging whether it is necessary to send a Trojan sample execution instruction to the target endpoint device according to the comparison result includes: If the hash values ​​before and after the Trojan sample is delivered are equal, it is determined that the monitoring program can be started to send the Trojan sample execution instruction to the target endpoint device; If the hash values ​​before and after the Trojan sample is delivered are not equal, it is determined that the Trojan sample is intercepted and the verification ends.

[0028] Preferably, after sending the Trojan sample execution instruction to the target endpoint device, the method further includes: The script file continuously receives the return connection information sent by the target endpoint device through the IP address and port pre-configured by the user; If the return connection information sent by the target endpoint device can be continuously received, the return connection information is decrypted; if the decryption is successful, it is determined that the Trojan is online successfully, and a Trojan exit instruction is sent to the target endpoint device, the remote command control tool is closed, and the verification is ended; if the decryption fails, it is determined that the Trojan fails to go online, the remote command control tool is closed, and the verification is ended; If the return connection information sent by the target endpoint device is not received within the preset time, it is determined that the Trojan horse has failed to go online, the remote command control tool is closed, and the verification is ended.

[0029] Preferably, the decrypting the back-connection information is specifically: Decrypt the backlink information using the RSA algorithm to obtain device information of the attacked endpoint device, the device information at least including: device host name, IP address, and user name; The sending of the Trojan sample execution instruction to the target endpoint device is specifically: After encrypting the Trojan sample execution instruction using the AES encryption algorithm, the Trojan sample execution instruction is sent to the target endpoint device; The sending of the Trojan exit instruction to the target endpoint device is specifically: After encrypting the Trojan exit instruction using the AES encryption algorithm, the Trojan exit instruction is sent to the target endpoint device.

[0030] The technical solution provided by the embodiments of the present invention may have the following beneficial effects: The command and control server automatically delivers Trojan samples to the target endpoint device through preset script files, sends Trojan sample execution instructions, completes the online verification of Trojan samples, and builds an automated verification logic and implementation, which changes the situation where the existing manual verification operation is cumbersome and inefficient.

[0031] Since fully automated operation is achieved, there is no need for manual participation in all links, which reduces manpower investment. In long-term network security verification work, professionals no longer need to spend a lot of time on repetitive manual operations, which reduces labor costs. At the same time, the operation of the automated system is relatively stable, reducing additional costs caused by human operational errors, such as unnecessary equipment adjustments or optimizations due to misjudgment of the protection effect of endpoint equipment. Compared with the cumbersome and costly manual operations in the existing technology, it effectively solves the problem of high operating costs for security protection verification work, saving a lot of resources and funds for enterprises and institutions. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 is a schematic diagram of a security protection effectiveness verification system for an endpoint device according to an exemplary embodiment; Figure 2 is a flow chart of a method for verifying the effectiveness of security protection of an endpoint device according to an exemplary embodiment; Figure 3 The present invention is a schematic diagram of a security protection effectiveness verification system for an endpoint device according to another exemplary embodiment. DETAILED DESCRIPTION

[0033] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.

[0034] Embodiment 1 Figure 1 The present invention is a schematic diagram of a security protection effectiveness verification system for an endpoint device according to an exemplary embodiment, the system comprising: A command and control server 1, and at least one endpoint device 2, wherein: The command and control server 1 is used to control the built-in remote command control tool to generate a Trojan sample through a preset script file, and deliver it to the target endpoint device 2; it is also used to send a Trojan sample execution instruction to the target endpoint device 2 after determining that the Trojan sample is delivered successfully; The target endpoint device 2 is used to execute the Trojan sample delivered to the local machine according to the Trojan sample execution instruction, and after the Trojan sample is run, it connects back to the command and control server 1 and sends its own device information to the command and control server 1 to complete the Trojan sample going online; The command and control server 1 is also used to verify the effectiveness of the security protection of the target endpoint device 2 based on the delivery of Trojan samples and the online status of Trojan samples.

[0035] It should be noted that the remote command and control tool (also referred to as C2 attack platform, Command and Control) at least includes: A combination of one or more of CobaltStrike, Metasploit, and Sliver.

[0036] The carrier for running the remote command and control tool (C2 attack platform) is the C2 server, which is called the command and control server in Chinese.

[0037] C2 is a network attack architecture that attackers use to remotely control infected computer systems, servers, IoT devices and other targets. After the malware invades the target endpoint device, it will establish a connection with the C2 server, through which the attacker can send instructions to the target endpoint device, obtain data or use it as a springboard for further attacks. For example, after the hacker organization infects the user's computer with botnet malware, it pretends to connect to the C2 server through HTTP, HTTPS, DNS and other protocols, and then launches a DDoS attack to make the target website unable to work, or instructs the collection of user sensitive information and returns it to the C2 server.

[0038] In the C2 attack platform, the Trojan's online process is usually as follows: the attacker first uses social engineering methods or system vulnerabilities to drop malicious files (such as documents bundled with malicious code, executable files, etc.) containing Trojans (such as the Cobaltstrike Trojan) to the target endpoint device. When the target user accidentally executes this file, the Trojan will run silently in the background of the target endpoint device. Then the Trojan will actively try to connect to the C2 server controlled by the attacker according to the pre-configured parameters, and establish a communication channel through network protocols (such as HTTP, HTTPS, etc.). After the connection is successfully established, the target endpoint device will send its own relevant information to the C2 server to complete the online process, thereby enabling the attacker to perform subsequent remote control operations on the target endpoint device.

[0039] It can be understood that the technical solution provided in this embodiment, the command and control server automatically delivers Trojan samples to the target endpoint device through a preset script file, sends Trojan sample execution instructions, completes the online verification of the Trojan samples, and constructs an automated verification logic and implementation, which changes the situation in which the manual verification operation of the prior art is cumbersome and inefficient.

[0040] Since fully automated operation is achieved, there is no need for manual participation in all links, which reduces manpower investment. In long-term network security verification work, professionals no longer need to spend a lot of time on repetitive manual operations, which reduces labor costs. At the same time, the operation of the automated system is relatively stable, reducing additional costs caused by human operational errors, such as unnecessary equipment adjustments or optimizations due to misjudgment of the protection effect of the target endpoint equipment. Compared with the cumbersome and costly manual operations in the existing technology, it effectively solves the problem of high operating costs of security protection verification work, saving a lot of resources and funds for enterprises and institutions.

[0041] In specific practice, the command and control server establishes a communication connection with the target endpoint device through the IP address and port pre-configured by the user, and monitors the device information returned by the target endpoint device.

[0042] It is understandable that to simulate Trojan generation and attack, we first need to determine which IP address and port of the C2 server the delivered Trojan sample will connect to after running. Since the process of generating Trojan samples by the three C2 attack platforms CobaltStrike, Metasploit, and Sliver includes source code compilation and construction, the cost of automated integration is relatively high. Therefore, we use the method of generating Trojans in advance to fix the IP address and port of the C2 server. This will not affect the verification effect and can also reduce the simulation cost.

[0043] In practice, this application analyzes the source code of CobaltStrike, Metasploit, and Sliver attack platforms, and uses Python to implement the monitoring mode of three HTTP protocol interactions. Because it is local verification, a fixed 127.0.0.1 address and port number can be determined, such as port 30024. After the fixed IP address and port are determined, it is only necessary to set the IP address and port number of the C2 server to 127.0.0.1 and 30024 respectively in advance during the Trojan generation phase. Then, after the Trojan is executed, it will automatically connect back to 127.0.0.1:30024, which is the simulated C2 service.

[0044] It can be understood that the technical solution provided in this embodiment determines fixed IP addresses and ports for different C2 attack platforms (such as CobaltStrike, Sliver, Metasploit, etc.) to establish a communication connection with the target endpoint device, and then develops an adaptive interface program, and uses an automated scripting language to simulate the process of the Trojan going online, which can automatically complete server-side listening configuration, delivery and execution operations, etc., overcoming the difficulty that the existing technology cannot directly automate these key steps.

[0045] Embodiment 2 Figure 2 The present invention is a flowchart of a method for verifying the effectiveness of security protection of an endpoint device according to an exemplary embodiment. The method includes: Step S11, the command and control server controls the built-in remote command control tool to generate a Trojan sample through a preset script file, and delivers it to the target endpoint device; and after determining that the Trojan sample is delivered successfully, sends a Trojan sample execution instruction to the target endpoint device; Step S12: the target endpoint device executes the Trojan sample delivered to the local device according to the Trojan sample execution instruction, and after the Trojan sample runs, connects back to the command and control server, sends its own device information to the command and control server, and completes the Trojan sample going online; Step S13: The command and control server verifies the effectiveness of the security protection of the target endpoint device based on the delivery of the Trojan sample and the online status of the Trojan sample.

[0046] It should be noted that the remote command and control tool (also referred to as C2 attack platform, Command and Control) at least includes: A combination of one or more of CobaltStrike, Metasploit, and Sliver.

[0047] The carrier for running the remote command and control tool (C2 attack platform) is the C2 server, which is called the command and control server in Chinese.

[0048] It can be understood that the technical solution provided in this embodiment, the command and control server automatically delivers Trojan samples to the target endpoint device through a preset script file, sends Trojan sample execution instructions, completes the online verification of the Trojan samples, and constructs an automated verification logic and implementation, which changes the situation in which the manual verification operation of the prior art is cumbersome and inefficient.

[0049] Since fully automated operation is achieved, there is no need for manual participation in all links, which reduces manpower investment. In long-term network security verification work, professionals no longer need to spend a lot of time on repetitive manual operations, which reduces labor costs. At the same time, the operation of the automated system is relatively stable, reducing additional costs caused by human operational errors, such as unnecessary equipment adjustments or optimizations due to misjudgment of the protection effect of the target endpoint equipment. Compared with the cumbersome and costly manual operations in the existing technology, it effectively solves the problem of high operating costs of security protection verification work, saving a lot of resources and funds for enterprises and institutions.

[0050] In specific practice, in step S11, the command and control server controls the built-in remote command control tool through a preset script file to generate a Trojan sample and drop it on the target endpoint device, including: The script file receives the verification parameters and configuration information input by the user; The script file controls the built-in remote command control tool to generate a corresponding Trojan sample according to the verification parameters and configuration information, and writes the Trojan sample into the system disk directory of the target endpoint device to complete the delivery of the Trojan sample; Wherein, the verification parameters include at least: user authority; The configuration information includes at least: the IP address of the target endpoint device, the directory path for delivering the Trojan horse, and the type of the Trojan horse to be delivered.

[0051] It is understandable that the technical solution provided by this embodiment, the adaptive interface program developed for different C2 attack platforms, can accurately generate and execute the online process of different Trojans according to preset parameters, avoiding the problems of parameter setting errors and irregular operations that may occur in manual operations. It effectively solves the problem of inaccurate and unreliable verification results caused by the uncertainty and limitations of manual operations in the prior art, and provides a more scientific and reliable basis for network security decision-making.

[0052] In specific practice, the method further includes: After the Trojan sample is delivered, the script file determines whether the Trojan sample is delivered successfully; If yes, compare the hash values ​​before and after the Trojan sample is delivered, and determine whether it is necessary to send a Trojan sample execution instruction to the target endpoint device based on the comparison result; If not, it is determined that the Trojan sample is detected and killed by the target endpoint device, the Trojan sample delivery fails, and the verification ends.

[0053] In actual practice, the script file determines whether the Trojan sample is successfully delivered, specifically: Polling is performed at preset intervals to detect whether the Trojan sample file still exists in the system disk directory of the target endpoint device. If so, the Trojan sample is successfully delivered. If not, the Trojan sample fails to be delivered.

[0054] It should be noted that the preset duration is set according to user needs, or according to historical experience values, or according to experimental data, for example, it is set to 10 seconds.

[0055] Write the Trojan sample file to the system disk directory of the target endpoint device, and then start to detect whether the Trojan sample file has been detected and killed: (1) Continue polling for 10 seconds to detect whether the Trojan sample file exists. If the Trojan sample file does not exist, it is determined to have been intercepted. The target endpoint device can effectively intercept the Trojan sample and the verification ends. If the Trojan sample file exists, continue to the next step of hash value judgment equality action.

[0056] (2) If the Trojan sample file exists, the hash values ​​before and after delivery are calculated and compared to see if they are equal. If the sample hash values ​​are not equal, it is determined to have been intercepted, and the target endpoint device can effectively intercept the Trojan sample, and the verification ends. If the hash values ​​are equal, proceed to the next step of verification.

[0057] In specific practice, judging whether it is necessary to send a Trojan sample execution instruction to the target endpoint device based on the comparison result includes: If the hash values ​​before and after the Trojan sample is delivered are equal, it is determined that the monitoring program can be started to send the Trojan sample execution instruction to the target endpoint device; If the hash values ​​before and after the Trojan sample is delivered are not equal, it is determined that the Trojan sample is intercepted and the verification ends.

[0058] In specific practice, after sending the Trojan sample execution instruction to the target endpoint device, it also includes: The script file continuously receives the return connection information sent by the target endpoint device through the IP address and port pre-configured by the user; If the return connection information sent by the target endpoint device can be continuously received, the return connection information is decrypted; if the decryption is successful, it is determined that the Trojan is online successfully, and a Trojan exit instruction is sent to the target endpoint device, the remote command control tool is closed, and the verification is ended; if the decryption fails, it is determined that the Trojan fails to go online, the remote command control tool is closed, and the verification is ended; If the return connection information sent by the target endpoint device is not received within the preset time, it is determined that the Trojan horse has failed to go online, the remote command control tool is closed, and the verification is ended.

[0059] It should be noted that the preset duration is set according to user needs, or according to historical experience values, or according to experimental data, for example, it is set to 10 seconds.

[0060] It is understandable that the C2 server continuously listens to the request from the target endpoint device. If no request is received from the target endpoint device for more than 10 seconds, it indicates that the Trojan sample is intercepted, the C2 server is closed, and the verification process is exited.

[0061] If the C2 server receives a request from the target endpoint device, it decrypts the request content and obtains the host name, IP address, and user name of the target endpoint device, indicating that the online process has not been intercepted. It then closes the C2 server and exits the verification process.

[0062] It is understandable that to simulate Trojan generation and attack, we first need to determine which IP address and port of the C2 server the delivered Trojan sample will connect to after running. Since the process of generating Trojan samples by the three C2 attack platforms CobaltStrike, Metasploit, and Sliver includes source code compilation and construction, the cost of automated integration is relatively high. Therefore, we use the method of generating Trojans in advance to fix the IP address and port of the C2 server. This will not affect the verification effect and can also reduce the simulation cost.

[0063] In practice, this application analyzes the source code of CobaltStrike, Metasploit, and Sliver attack platforms, and uses Python to implement the monitoring mode of three HTTP protocol interactions. Because it is local verification, a fixed 127.0.0.1 address and port number can be determined, such as port 30024. After the fixed IP address and port are determined, it is only necessary to set the IP address and port number of the C2 server to 127.0.0.1 and 30024 respectively in advance during the Trojan generation phase. Then, after the Trojan is executed, it will automatically connect back to 127.0.0.1:30024, which is the simulated C2 service.

[0064] It can be understood that the technical solution provided in this embodiment determines fixed IP addresses and ports for different C2 attack platforms (such as CobaltStrike, Sliver, Metasploit, etc.) to establish a communication connection with the target endpoint device, and then develops an adaptive interface program, and uses an automated scripting language to simulate the process of the Trojan going online, which can automatically complete server-side listening configuration, delivery and execution operations, etc., overcoming the difficulty that the existing technology cannot directly automate these key steps.

[0065] Further, the decrypting the back-connection information is specifically: Decrypt the backlink information using the RSA algorithm to obtain device information of the attacked endpoint device, the device information at least including: device host name, IP address, and user name; The sending of the Trojan sample execution instruction to the target endpoint device is specifically: After encrypting the Trojan sample execution instruction using the AES encryption algorithm, the Trojan sample execution instruction is sent to the target endpoint device; The sending of the Trojan exit instruction to the target endpoint device is specifically: After encrypting the Trojan exit instruction using the AES encryption algorithm, the Trojan exit instruction is sent to the target endpoint device.

[0066] By default, C2 attack platforms such as CobaltStrike, Metasploit, and Sliver use the HTTP protocol as the communication protocol between the target endpoint device and the C2 server, and decrypt and respond to the request content of the target endpoint device in the request processing part.

[0067] Of course, according to user needs, the C2 attack platform can use HTTPS, DNS and other protocols as the communication protocol between the target endpoint device and the C2 server.

[0068] See also Figure 3For example, the CobaltStrike attack platform encrypts the communication between the target endpoint device and the C2 server through RSA+AES, uses Python to decrypt the request content of the controlled end and encrypt the response, and at the same time, the metadata information (metadata) sent back by the target endpoint device contains the detailed device information of the target endpoint device (for example, the host name, IP address, user name, etc. of the target endpoint device).

[0069] After the Trojan program of the target endpoint device is started, it waits for a preset time (10 seconds by default). The C2 server receives the online information sent by the Trojan program and uses the RSA algorithm to decrypt the request information to obtain the host name, IP address, user name, etc. of the target endpoint device. After the decryption is successful, the C2 server uses the AES encryption algorithm to encrypt the Trojan exit instruction and send it to the target endpoint device, causing the Trojan process to exit and finally shut down the C2 server.

[0070] Among them, it should be noted that: The principle of the RSA encryption algorithm is based on the difficulty of factoring large numbers. In the RSA algorithm, two large prime numbers P and Q are used to generate a public key and a private key. The public key can be made public, while the private key cannot be made public. The encryption process uses the public key to encrypt the plaintext and generate the ciphertext; the decryption process uses the private key to decrypt the ciphertext and restore the original plaintext.

[0071] The AES encryption algorithm, or Advanced Encryption Standard, is a block encryption standard. The AES algorithm was designed by Belgian cryptographers Joan Daemen and Vincent Rijmen as an alternative to DES and was selected as the AES standard in 2000.

[0072] Metadata, also known as intermediary data or relay data, is data about data. It is mainly information describing data properties, used to support functions such as indicating storage location, historical data, resource search, and file records. Metadata is a kind of electronic catalog. In order to achieve the purpose of cataloging, it is necessary to describe and collect the content or characteristics of the data, thereby achieving the purpose of assisting data retrieval.

[0073] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0074] If the integrated units in the above embodiments are implemented in the form of software functional units and sold or used as independent products, they can be stored in the above computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling one or more computer devices (which may be personal computers, servers or network devices, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application.

[0075] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0076] In the several embodiments provided in the present application, it should be understood that the disclosed client can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. The mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0077] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0078] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0079] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A security protection effectiveness verification system for an endpoint device, characterized in that: include: A command and control server, and at least one endpoint device, where: The command and control server is used to control the built-in remote command and control tool to generate Trojan samples through a preset script file and deliver them to the target endpoint device; it is also used to send Trojan sample execution instructions to the target endpoint device after determining that the Trojan sample is delivered successfully; The target endpoint device is used to execute the Trojan sample delivered to the local machine according to the Trojan sample execution instruction, and after the Trojan sample is run, it connects back to the command and control server and sends its own device information to the command and control server to complete the Trojan sample going online; The command and control server is also used to verify the effectiveness of the security protection of the target endpoint device based on the delivery of Trojan samples and the online status of Trojan samples.

2. The safety protection effectiveness verification system according to claim 1 is characterized in that: The command and control server establishes a communication connection with the target endpoint device through the IP address and port pre-configured by the user, and monitors the device information returned by the target endpoint device.

3. The safety protection effectiveness verification system according to claim 1 is characterized in that: The remote command control tool at least includes: A combination of one or more of CobaltStrike, Metasploit, and Sliver.

4. A method for verifying the effectiveness of security protection of an endpoint device, characterized in that: include: The command and control server uses a preset script file to control the built-in remote command and control tool to generate Trojan samples and drop them on the target endpoint device. After determining that the Trojan sample has been delivered successfully, the Trojan sample execution instruction is sent to the target endpoint device; The target endpoint device executes the Trojan sample delivered to the local device according to the Trojan sample execution instruction, and after the Trojan sample runs, it connects back to the command and control server and sends its own device information to the command and control server to complete the Trojan sample going online; The command and control server verifies the effectiveness of the security protection of the target endpoint device based on the delivery and online status of Trojan samples.

5. The method according to claim 4, characterized in that The command and control server uses a preset script file to control the built-in remote command and control tool to generate Trojan samples and drop them on the target endpoint device, including: The script file receives the verification parameters and configuration information input by the user; The script file controls the built-in remote command control tool to generate a corresponding Trojan sample according to the verification parameters and configuration information, and writes the Trojan sample into the system disk directory of the target endpoint device to complete the delivery of the Trojan sample; Wherein, the verification parameters include at least: user authority; The configuration information includes at least: the IP address of the target endpoint device, the directory path for delivering the Trojan horse, and the type of the Trojan horse to be delivered.

6. The method according to claim 5, characterized in that Also includes: After the Trojan sample is delivered, the script file determines whether the Trojan sample is delivered successfully; If yes, compare the hash values ​​before and after the Trojan sample is delivered, and determine whether it is necessary to send a Trojan sample execution instruction to the target endpoint device based on the comparison result; If not, it is determined that the Trojan sample is detected and killed by the target endpoint device, the Trojan sample delivery fails, and the verification ends.

7. The method according to claim 6, characterized in that The script file determines whether the Trojan sample is delivered successfully, specifically: Polling is performed at preset intervals to detect whether the Trojan sample file still exists in the system disk directory of the target endpoint device. If so, the Trojan sample delivery is determined to be successful. If not, the Trojan sample delivery fails.

8. The method according to claim 6, characterized in that The step of determining whether it is necessary to send a Trojan sample execution instruction to the target endpoint device according to the comparison result includes: If the hash values ​​before and after the Trojan sample is delivered are equal, it is determined that the monitoring program can be started to send the Trojan sample execution instruction to the target endpoint device; If the hash values ​​before and after the Trojan sample is delivered are not equal, it is determined that the Trojan sample is intercepted and the verification ends.

9. The method according to claim 8, characterized in that After sending the Trojan sample execution instruction to the target endpoint device, the method further includes: The script file continuously receives the return connection information sent by the target endpoint device through the IP address and port pre-configured by the user; If the return connection information sent by the target endpoint device can be continuously received, the return connection information is decrypted; if the decryption is successful, it is determined that the Trojan is online successfully, and a Trojan exit instruction is sent to the target endpoint device, the remote command control tool is closed, and the verification is ended; if the decryption fails, it is determined that the Trojan fails to go online, the remote command control tool is closed, and the verification is ended; If the return connection information sent by the target endpoint device is not received within the preset time, it is determined that the Trojan horse has failed to go online, the remote command control tool is closed, and the verification is ended.

10. The method according to claim 9, characterized in that The decrypting of the back-connection information is specifically as follows: Decrypt the backlink information using the RSA algorithm to obtain device information of the attacked endpoint device, the device information at least including: device host name, IP address, and user name; The sending of the Trojan sample execution instruction to the target endpoint device is specifically: After encrypting the Trojan sample execution instruction using the AES encryption algorithm, the Trojan sample execution instruction is sent to the target endpoint device; The sending of the Trojan exit instruction to the target endpoint device is specifically: After encrypting the Trojan exit instruction using the AES encryption algorithm, the Trojan exit instruction is sent to the target endpoint device.

Citation Information

Patent Citations

  • Function verification method and device of security component

    CN114928564A

  • Trojan horse server detection method and device, electronic equipment and readable storage medium

    CN117201064A

  • File-free attack investigation method and system based on memory forensics

    CN117478373A

  • Safe and reliable detection method and system for actively verifying and preventing virus delivery

    CN117609996A

  • Validation of security monitoring through automated attack testing

    US20180239902A1