Mail risk detection method and device

By receiving and decrypting emails, detecting newly created processes and obtaining their source program attribute values, the problem of attackers bypassing detection through email protocols is solved, and the reliability of email risk detection and network security defense capabilities are improved.

CN120050056APending Publication Date: 2025-05-27INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410801044.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-06-20
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect and defend against attackers through Internet mail protocol communication to bypass the detection and defense of C&C server technology.

Method used

By receiving and decrypting emails, the newly created process is detected and the attribute value of the source program corresponding to each process in the process chain to which it belongs. Then, compare these attribute values ​​with the valid program attribute values ​​in the program release repository. If a suspicious source program is found, use the risk sample library to determine the risk of the email.

Benefits of technology

It improves the reliability of email risk detection, can effectively identify and defend against malicious code transmitted through email protocols, and enhances network security defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050056A_ABST
    Figure CN120050056A_ABST
Patent Text Reader

Abstract

The invention provides a mail risk detection method and device, and relates to the technical field of information security. The method comprises the following steps: receiving a mail and decrypting the mail; if the newly created process is detected, obtaining an attribute value of a source program corresponding to each process in a process chain to which the newly created process belongs; and if at least one suspicious source program is obtained according to the attribute value of the source program corresponding to each process in the process chain to which the newly created process belongs and the attribute value of each effective program in a program release warehouse, determining the risk of the mail according to the at least one suspicious source program and a risk sample library. The device is used for executing the method. According to the mail risk detection method and device provided by the embodiment of the invention, the reliability of risk detection of the mail is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular, to a method and device for detecting email risks. Background Art

[0002] Email (Electronic Mail) is an electronic communication method for transmitting information such as text, pictures, audio, and video over the Internet. It has become an essential communication tool in people's daily life and work, greatly facilitating people's communication and information exchange.

[0003] Currently, in the field of network security offense and defense, Trojan files of malicious C&C (Command and Control) servers have always been one of the main tools used by attackers to invade systems, steal information, or perform malicious operations. Malicious Trojan development technology has been continuously evolving in file encryption and obfuscation, often using file encryption and obfuscation technology to make its code more difficult to be statically analyzed, thereby evading traditional virus detection. And it can communicate using the Internet mail protocol to bypass the detection and defense of C&C server technology. Therefore, how to solve the problem of attackers using the Internet mail protocol to communicate and bypass the detection and defense of C&C server technology urgently needs to be solved. Summary of the Invention

[0004] In view of the problems in the prior art, embodiments of the present invention provide a method and device for detecting email risks, which can at least partially solve the problems existing in the prior art.

[0005] In a first aspect, the present invention proposes a method for detecting email risks, including:

[0006] Receiving an email and decrypting the email;

[0007] If a newly created process is detected, obtaining the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs;

[0008] If at least one suspicious source program is obtained based on the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs and the attribute values of each valid program in the program release repository, determining the risk of the email according to the at least one suspicious source program and the risk sample library.

[0009] In a second aspect, the present invention provides a device for detecting email risks, including:

[0010] A receiving module, configured to receive an email and decrypt the email;

[0011] An obtaining module, configured to obtain the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs if a newly created process is detected;

[0012] A determination module, configured to determine the risk of the email according to the at least one suspicious source program and a risk sample library if at least one suspicious source program is obtained based on the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs and the attribute values of each valid program in the program release repository.

[0013] In a third aspect, the present invention provides a computer device, including a memory, a processor, and a computer program stored on the memory, where the processor executes the program to implement the email risk detection method according to any one of the above embodiments.

[0014] In a fourth aspect, the present invention provides a computer-readable storage medium storing computer programs / instructions, and when the computer programs / instructions are executed by a processor, the email risk detection method according to any one of the above embodiments is implemented.

[0015] In a fifth aspect, the present invention provides a computer program product including computer programs / instructions, and when the computer programs / instructions are executed by a processor, the email risk detection method according to any one of the above embodiments is implemented.

[0016] The email risk detection method and device provided by the embodiments of the present invention receive an email and decrypt the email; if a newly created process is detected, obtain the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs; if at least one suspicious source program is obtained based on the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs and the attribute values of each valid program in the program release repository, determine the risk of the email according to the at least one suspicious source program and a risk sample library. By performing risk detection on the source programs corresponding to each process in the process chain of the newly created process related to the email, the risk of the email is determined, improving the reliability of email risk detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings. In the drawings:

[0018] Figure 1 is a flowchart of the email risk detection method provided by the first embodiment of the present invention.

[0019] Figure 2 is a flowchart of the email risk detection method provided by the second embodiment of the present invention.

[0020] Figure 3 It is a flowchart of a method for detecting email risks provided by the third embodiment of the present invention.

[0021] Figure 4 It is a flowchart of a method for detecting email risks provided by a fourth embodiment of the present invention.

[0022] Figure 5 It is a flowchart of a method for detecting email risks provided by the fifth embodiment of the present invention.

[0023] Figure 6 It is a schematic diagram of the structure of a device for detecting email risks provided by a sixth embodiment of the present invention.

[0024] Figure 7 It is a schematic diagram of the structure of a device for detecting email risks provided by the seventh embodiment of the present invention.

[0025] Figure 8 It is a schematic diagram of the structure of an apparatus for detecting email risks provided in the eighth embodiment of the present invention.

[0026] Figure 9 It is a schematic diagram of the structure of a device for detecting email risks provided by a ninth embodiment of the present invention.

[0027] Figure 10 It is a schematic diagram of the structure of a device for detecting email risks provided by the tenth embodiment of the present invention.

[0028] Figure 11 It is a schematic diagram of the structure of a device for detecting email risks provided by the eleventh embodiment of the present invention.

[0029] Figure 12 It is a schematic diagram of the physical structure of an electronic device provided by the twelfth embodiment of the present invention. DETAILED DESCRIPTION

[0030] In order to make the purpose, technical scheme and advantages of the embodiments of the present invention more clear, the embodiments of the present invention are further described in detail below in conjunction with the accompanying drawings. Here, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention. It should be noted that, in the absence of conflict, the embodiments in this application and the features in the embodiments can be combined with each other arbitrarily.

[0031] The information collected in the technical solution of this application is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data comply with the relevant laws, regulations and standards of relevant countries and regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0032] Taking the client as the execution entity as an example, the specific implementation process of the email risk detection method provided by the embodiments of the present invention will be described. It can be understood that the execution entity of the email risk detection method provided by the embodiments of the present invention is not limited to the client.

[0033] Figure 1 It is a schematic flowchart of the email risk detection method provided by the first embodiment of the present invention. As Figure 1 shown, the email risk detection method provided by the embodiments of the present invention includes:

[0034] S101. Receive an email and decrypt the email;

[0035] Specifically, the client can receive an email and decrypt the email. Among them, the client can directly receive an email from the email server or receive an email forwarded by the gateway server.

[0036] S102. If a newly created process is detected, obtain the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs;

[0037] Specifically, after decrypting the email, if the client detects a newly created process, then obtain each process in the process chain to which the newly created process belongs, and obtain the source program corresponding to each process. Each source program will have attribute values. The attribute values of the source program include digital signature attribute values, publishing author attribute values, publishing version attribute values, etc.

[0038] S103. If at least one suspicious source program is obtained according to the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs and the attribute values of each valid program in the program release repository, determine the risk of the email according to the at least one suspicious source program and the risk sample library.

[0039] Specifically, for each process in the process chain to which the newly created process belongs, the client compares the attribute values of the source program corresponding to the process with the attribute values of each valid program in the program release repository. If the attribute values of the source program corresponding to the process do not match the attribute values of any valid program in the program release repository, then the source program corresponding to the process is a suspicious source program; if the attribute values of the original program corresponding to the process match the attribute values of a valid program in the program release repository, then the source program corresponding to the process is not a suspicious source program. After the attribute values of the source programs corresponding to all processes in the process chain to which the newly created process belongs have been compared, if at least one suspicious program is obtained, then the risk of the email can be determined based on the at least one suspicious source program and the risk sample library. Among them, the program release repository is preset, and each valid program included is a source program that has been detected and has no risk. The risk sample library is preset, and the programs included are programs that have risks, such as malicious programs like Trojan programs. The process chain to which the newly created process belongs refers to a chain structure formed by the parent process of the newly created process, the parent process of the parent process of the newly created process, the parent process of the parent process of the parent process of the newly created process, and so on.

[0040] For example, compare the program name of the suspicious source program with the names of each risk program in the risk sample library. If the names are the same, it means the suspicious source program is a risk program and the email has a risk. If the names are different, it means the suspicious source program is not a risk program and the email has no risk.

[0041] The method for detecting the risk of an email provided by an embodiment of the present invention receives an email and decrypts the email; if a newly created process is detected, it obtains the attribute values of the source program corresponding to each process in the process chain to which the newly created process belongs; if at least one suspicious source program is obtained based on the attribute values of the source program corresponding to each process in the process chain to which the newly created process belongs and the attribute values of each valid program in the program release repository, then the risk of the email is determined based on the at least one suspicious source program and the risk sample library. By performing risk detection on the source program corresponding to each process in the process chain of the newly created process related to the email, the risk of the email is determined, which improves the reliability of the risk detection of the email.

[0042] Figure 2 is a schematic flowchart of the method for detecting the risk of an email provided by the second embodiment of the present invention. As Figure 2 shown, on the basis of the above embodiments, further, the determining the risk of the email based on the at least one suspicious source program and the risk sample library includes:

[0043] S201. Calculate the digest hash value of each suspicious source program in the at least one suspicious source program;

[0044] Specifically, for the at least one suspicious source program, the client can calculate the digest hash value of each suspicious source program.

[0045] S202. If it is determined that the digest hash value of a suspicious source program is the same as the digest hash value of a risk program in the risk sample library, it is determined that the email is at risk.

[0046] Specifically, the risk sample library can store the digest hash value of each risk program. The client compares the digest hash value of each suspicious source program with the digest hash value of each risk program in the risk sample library. If the digest hash value of a suspicious source program is the same as the digest hash value of a certain risk program, it is determined that the email is at risk. If the digest hash value of a suspicious source program is different from the digest hash value of each risk program in the risk sample library, it is determined that the suspicious source program is not a risk program.

[0047] Figure 3 It is a schematic flowchart of a method for detecting email risk provided by the third embodiment of the present invention. As Figure 3 shown, on the basis of the above embodiments, further, the attribute values include digital signature attribute values, publishing author attribute values, and publishing version attribute values; correspondingly, obtaining the at least one suspicious source program according to the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs and the attribute values of each valid program in the program publishing repository includes:

[0048] S301. Obtain the matching degree of the source program corresponding to each process in the process chain according to the digital signature attribute value, publishing author attribute value, and publishing version attribute value of the source program corresponding to each process and the digital signature attribute value, publishing version attribute value, and publishing version attribute value of each valid program in the program publishing repository.

[0049] Specifically, the client compares the digital signature attribute value, publishing author attribute value, and publishing version attribute value of the source program corresponding to each process with the digital signature attribute value, publishing author attribute value, and publishing version attribute value of each valid program in the program publishing repository, respectively, to obtain the matching degree of the source program corresponding to each process and each valid program, and obtains the maximum matching degree as the matching degree of the source program corresponding to each process.

[0050] For example, if the digital signature attribute value of the source program a corresponding to the process is the same as that of the valid program b, the matching value between the source program a and the valid program b is incremented by 1; if the release author attribute value of the source program a corresponding to the process is the same as that of the valid program b, the matching value between the source program a and the valid program b is incremented by 1; if the release version attribute value of the source program a corresponding to the process is the same as that of the valid program b, the non-matching value between the source program a and the valid program b is incremented by 1. The initial values of both the matching value and the non-matching value are 0. Therefore, the matching value between the source program a and the valid program b is 2, and the non-matching value is 1. The matching degree of the source program a and the valid program b is equal to the matching value divided by the sum of the non-matching value and the matching value, that is, 2 / (1 + 2) = 2 / 3. If the matching degree of the source program a and the valid program b is the maximum among the matching degrees of the source program a and each valid program, then the matching degree of the source program a corresponding to the process is 2 / 3.

[0051] S302. If it is determined that the matching degree of the source program corresponding to the process is less than the threshold, then the source program corresponding to the process is used as a suspicious source program.

[0052] Specifically, the client compares the matching degree of the source program corresponding to the process with the threshold. If the matching degree of the source program corresponding to the process is greater than or equal to the threshold, then the source program corresponding to the process is not a suspicious source program; if the matching degree of the source program corresponding to the process is less than the threshold, then the source program corresponding to the process is a suspicious source program. Among them, the threshold is set according to actual needs, and the embodiments of the present invention do not make limitations.

[0053] Figure 4 It is a schematic flowchart of the method for detecting email risks provided by the fourth embodiment of the present invention. As Figure 4 shown, on the basis of the above embodiments, further, the receiving and decrypting the email includes:

[0054] S401. Receive the email forwarded from the gateway server; wherein, the email is encrypted by the public key negotiated in advance by the gateway server.

[0055] Specifically, the gateway server sends the email to the client, and the client will receive the email. The gateway server will encrypt the email with the public key, and the public key is negotiated in advance by the gateway server and the client. The email sent by the gateway server is received from other clients. After receiving the email from other clients, the gateway server will decrypt the email with the key negotiated with other clients, and then encrypt the email with the public key negotiated with the client.

[0056] It should be noted that the emails sent to the client will be decrypted by the gateway server and then re-encrypted by the gateway server before being sent to the client. Since the gateway server and the client have pre-negotiated the key, the client should be able to decrypt the emails received from the gateway server.

[0057] S402. Decrypt the email with the private key pre-negotiated with the gateway server;

[0058] Specifically, after receiving the email, the client will decrypt the email with the private key, which is the private key corresponding to the public key pre-negotiated by the gateway server and the client and can decrypt the data encrypted with the public key.

[0059] S403. If the decryption of the email fails, determine that the email is a risky email.

[0060] Specifically, if the client fails to decrypt the email, it can determine that the email is a risky email; if the decryption of the email is successful and the email passes the transparent defense detection of email transmission encryption, subsequent processes will be carried out.

[0061] Based on the above embodiments, further, the decryption of the email includes:

[0062] If it is determined that the email is encoded in a specific manner / or encrypted with a specific encryption algorithm, it is determined that the email is risky.

[0063] Specifically, when decrypting the email, if the client finds that the email is encoded in a specific manner, it can determine that the email is risky. The specific encoding method is Base64 encoding.

[0064] When decrypting the email, if the client finds that the email is encrypted with a specific encryption algorithm, it can determine that the email is risky. The specific encryption algorithm includes but is not limited to the PGP encryption algorithm.

[0065] Based on the above embodiments, further, the method for detecting email risks provided by the embodiments of the present invention further includes:

[0066] If the event identifier of the newly created process is the same as the event identifier in the blacklist, it is determined that the email is risky.

[0067] Specifically, when the client creates a new process, an event identifier of the newly created process is generated. The event identifier of the newly created process is compared with each event identifier in the blacklist. If the event identifier of the newly created process is the same as a certain event identifier in the blacklist, it can be determined that the email has a risk. If the event identifier of the newly created process is different from all event identifiers in the blacklist, it can be determined that no risk of the email is detected in this step. Among them, the blacklist is preset and includes event identifiers of various processes with risks.

[0068] Figure 5 is a schematic flowchart of the method for detecting email risk provided by the fifth embodiment of the present invention. As Figure 5 shown, on the basis of the above embodiments, further, the method for detecting email risk provided by the embodiments of the present invention further includes:

[0069] S501. Obtain event information of the newly created process;

[0070] Specifically, when the client creates a new process, event information of the newly created process is generated. The client can obtain the event information of the newly created process.

[0071] S502. Determine the risk of the email according to the event information of the newly created process and the risk detection rule.

[0072] Specifically, the client can determine whether the email has a risk according to the event information of the newly created process and the risk detection rule. Among them, the risk detection rule is preset and is set according to actual needs, which is not limited in the embodiments of the present invention.

[0073] For example, the risk detection rule includes risk keywords. If the event information of the newly created process includes risk keywords, then the email has a risk. If the event information of the newly created process does not include any risk keywords in the risk rule, then the email has no risk in the detection of this step.

[0074] The method for detecting email risk of the present invention deeply analyzes the application defects of the current bypass technology of the C&C server in the scenario where the mainstream HTTP / HTTPS protocols are heavily monitored from the perspective of attackers, and deeply analyzes this technical chain from the perspective of defenders. Combining the existing technical defects, effective detection and defense technologies are proposed to promote defense by attacking, improve the understanding of threats, and strengthen the network defense ability.

[0075] By deeply analyzing the technical chain involved in the attack technology and analyzing each stage involved, it can be seen that the attack technology combines mainstream Internet mail communication protocols such as SMTP, POP3, and IMAP to implement functions such as command issuance, permission control, and file transfer between the C&C server and the target machine, and transmits the data interaction of the entire process communication of the C&C server in the form of e-mails, which includes functions such as data encoding, obfuscation, and encryption.

[0076] The control end of the C&C server first creates a malicious command issuance task, then obfuscates and encodes the malicious command, then encrypts the malicious command, and finally transmits it to a third-party mail server with high reputation through the mail transmission encryption module. At this time, the controlled end of the C&C server will create a task to execute the malicious command. On the controlled end, first pull the data to the local through the encrypted mail receiving module, then decrypt and decode the malicious command, and finally execute the malicious command on the controlled end machine.

[0077] By analyzing the implementation of the attack chain function, it is found that in the SMTP protocol, protecting the confidentiality of the mail content is usually achieved by using encryption algorithms during the transmission process. The most common way is to encrypt the SMTP connection by using the Secure Sockets Layer (SSL) or its successor, the Transport Layer Security (TLS). This ensures that the mail content transmitted between the client and the server is encrypted during the transmission process, thus preventing man-in-the-middle attacks and eavesdropping.

[0078] By analyzing the implementation of the attack chain function, it is found that the mail transmission encryption part is implemented through the following specific steps:

[0079] The first step is handshake and negotiation. At the beginning of the SMTP session, the client can send the STARTTLS command to instruct the server to start encryption. If the server supports encryption, it will respond and start the SSL / TLS handshake process.

[0080] The second step is the SSL / TLS handshake. Once the server accepts the STARTTLS command, the server and the client start the SSL / TLS handshake process. This process includes steps such as negotiating encryption algorithms and exchanging keys.

[0081] The third step is encrypted communication. Once the handshake is completed, the subsequent communication of the SMTP session will be encrypted through a secure SSL / TLS channel, including authentication information, mail content, and any other information sent through SMTP.

[0082] The fourth step is to use an encryption algorithm. The specific choice of the encryption algorithm depends on the result of the SSL / TLS handshake negotiation. Usually, a symmetric encryption algorithm (such as AES) is used to protect the privacy of data, and a public-key encryption algorithm (such as RSA) is used for key exchange and authentication.

[0083] The fifth step is certificate verification. During the handshake process, the server usually provides a digital certificate to the client to verify the server's identity. The client can verify the validity of the certificate to ensure a secure connection is established with a legitimate SMTP server. Through the use of SSL / TLS encryption, the email content in the SMTP protocol is protected during transmission.

[0084] By analyzing and reviewing the implementation of the attack chain function, it is found that the encrypted email receiving part is implemented through the following specific steps.

[0085] The first step is to establish a connection (TCP connection). The client starts the communication by using TCP to connect to the default port of the POP3 server (usually port 110). The server listens on this port and waits for the client's connection request.

[0086] The second step is the handshake phase. Once the TCP connection is established, the handshake phase begins. The client sends a greeting command to the server, such as CAPA (capability), and the server responds and confirms the connection. This handshake process is used to confirm the POP3 extensions and functions supported by the other party.

[0087] The third step is the authentication phase. The client provides the username by sending the USER command and then provides the password by the PASS command for authentication. The server verifies the client's identity. If the authentication is successful, the client can start accessing the emails.

[0088] The fourth step is to select the email mailbox. The client uses the LIST command to list the email list on the server. The server responds with the size information of each email. The client can choose to download specific emails or use the RETR command to download all emails.

[0089] The fifth step is to download the emails. The client uses the RETR command to download specific emails. The server sends the content of the email to the client. If the client only wants to delete the email without downloading it, the DELE command can be used.

[0090] The sixth step is to delete the emails. The client uses the DELE command to mark the emails to be deleted. This step is optional, and the emails can be chosen to be deleted only when exiting the session.

[0091] The seventh step is to exit the session. The client uses the QUIT command to notify the server that the session is about to end. The server sends a response code to indicate acceptance of the exit request and closes the connection.

[0092] By analyzing the implementation of the review attack chain function, it is found that in the multi-device scenario (synchronous), the encrypted email receiving part is implemented through the following specific steps.

[0093] The first step is to establish a connection (TCP connection). The client starts the communication by using TCP to connect to the default port of the IMAP server (usually port 43, or port 993 for an encrypted connection). The server listens on this port and waits for the client's connection request.

[0094] The second step is the handshake phase. Once the TCP connection is established, the handshake phase begins. The client sends a greeting command to the server, usually CAPABILITY. The server responds and confirms the connection. This handshake process is used to confirm the IMAP extensions and functions supported by the other party.

[0095] The third step is the authentication phase. The client authenticates by sending the LOGIN command to provide the username and password. The server verifies the client's identity. If the authentication is successful, the client can start accessing the emails.

[0096] The fourth step is to select the email mailbox. The client uses the SELECT command to select the email mailbox to access (such as the inbox). The server returns the status information of the mailbox, including the total number of emails, the number of unread emails, etc.

[0097] The fifth step is email operation. The client can use the FETCH command to obtain the detailed information of the email, including the email header, the body, etc. The client can use the UID (unique identifier) to identify the email to ensure the synchronization of the email status on multiple devices.

[0098] The sixth step is marking and synchronization. The client can use the STORE command to mark the email, for example, mark it as read or deleted. The client uses the EXPUNGE command to delete the emails marked as deleted. IMAP ensures the synchronization of the email status on multiple devices through mechanisms such as marking and sequence numbers.

[0099] The seventh step is to upload emails. The client can use the APPEND command to upload new emails to the server to ensure the synchronization of emails on multiple devices.

[0100] The eighth step is to exit the session. The client uses the LOGOUT command to notify the server that the session is about to end. The server sends a response code to indicate acceptance of the exit request and closes the connection.

[0101] By analyzing the implementation of the review attack chain function, it is found that in the implementation process of email content obfuscation and encoding, the controlled-end machine will Base64-encode the malicious command execution results. Base64 is a common encoding method used to convert binary data into ASCII characters. In emails, Base64 encoding is usually used to encode email attachments or embedded images. Although Base64 encoding is not true encryption, it can prevent the email content from being directly read by simple observers during transmission.

[0102] By analyzing the implementation of the review attack chain function, it is now found that in the implementation process of email content encryption, the Base64-encoded string is further encrypted using Pretty Good Privacy (PGP). PGP is a standard for communication encryption and digital signatures. It provides a set of tools for protecting emails, files, and entire communications. PGP uses a hybrid encryption model that combines symmetric encryption and asymmetric encryption.

[0103] Thus, by combining the technical problems and defects discovered through the in-depth analysis of the attack techniques above and focusing on the four stages of the attack, the detection and defense solutions are mined and formulated, including the obfuscation stage, decryption stage, email transmission encryption stage, and command execution stage.

[0104] For the obfuscation stage, the Base64 encoding method is used in both the obfuscation operations of commands and command execution results. The plaintext content can be easily decoded through the Base64 Decode method, and the confidentiality of its content cannot be ensured. A major drawback of Base64 encoding is that it is not an encryption algorithm but an encoding method used to convert binary data into text form. It does not hide the structure or content of the data but only converts it into a readable form. Therefore, it does not provide true security but only performs a simple conversion of the data. In addition, Base64 encoding causes data expansion because it converts the original binary data into text form, usually increasing the size by about 1 / 3. This may occupy more space when storing and transmitting data.

[0105] For the detection of the obfuscation stage, the PGP-encrypted data content before obfuscation can be easily obtained by decoding the commands and command execution results using the Base64 Decode method. Therefore, if the email content can be decoded by the Base64Decode method, then the email is at risk.

[0106] For the decryption phase: The encryption and decryption operations of commands and command execution results both use the PGP encryption algorithm, which usually adopts algorithms such as CAST5 and AES in the symmetric encryption part. The security of these algorithms may be affected by the development of algorithms and the improvement of computing power over time. In the asymmetric encryption part, it is mainly based on the RSA algorithm, which is a powerful asymmetric encryption algorithm, but its security may be threatened by large-scale quantum computers. In addition, PGP uses digital signatures to verify the integrity of data and the identity of the sender. However, the RSA-based digital signature is secure on traditional computers but is also threatened in the context of quantum computers. The key management part in the PGP algorithm will largely determine its overall security. When the key management strategy is formulated improperly or executed imperfectly, it may lead to the leakage of private keys. After the defender obtains its private key, the data will be decrypted to obtain the plaintext information.

[0107] For the detection of the decryption phase, the content of the email can be decrypted through a specific decryption algorithm, such as the PGP decryption algorithm. If the decryption is successful, it indicates that the email is encrypted using a specific encryption algorithm and the email poses a risk. To achieve decryption, high-performance computing resource facilities can be introduced to improve the efficiency of cracking the key; the open-source code repositories on the Internet and the internal code repositories of enterprises can be monitored to capture the leaked private key information in a timely manner and improve the success rate of cracking the ciphertext.

[0108] Email transmission encryption phase: The encryption operation of the entire email transmission process is encrypted using the SSL / TLS method. This encryption method has the technical threat of MITM (Man in The Middle). A third party will try to insert itself between the two communicating parties to decrypt or tamper with the data encrypted by SSL / TLS; it usually realizes the exploitation of this threat through steps such as establishing a disguised connection, forging an SSL / TLS handshake, the third party establishing a connection with the server, and decrypting and tampering with the data.

[0109] For the detection of the email transmission encryption stage, an audit policy can be deployed at the exit of the organizational department's email gateway. After adding the organization's trusted root certificate, when the client initiates an SSL / TLS protocol request, it will first be sent to the organization's gateway server. The gateway server will initiate an SSL / TLS protocol request to the target server on behalf of the client. After receiving the request, the target server will generate a public key (target server) and a private key (target server), and return the public key (target server) to the gateway server. At this time, the gateway server will also generate a pair of public and private keys (gateway). The gateway will return the public key (gateway) to the client. The client will generate a key (client) and use the public key (gateway) to encrypt the email and then send it to the gateway server. The gateway server will use the private key (gateway) to decrypt and obtain the key (client). At this time, the gateway server will create a new key (gateway) and use the public key (target server) to encrypt it and then send it to the target server. The target server will use the private key (target server) to decrypt and obtain the key (gateway) and use it to encrypt the email content and then send it to the gateway server. The gateway server can use the key (gateway) to decrypt the email content to obtain the plaintext data. At this time, based on the theoretical basis of MITM technology, the decryption and detection of malicious email communication traffic have been completed. Finally, the gateway server will use the key (client) to encrypt the email content and then send it to the client. The client will use the key (client) to decrypt and obtain the email plaintext content, completing the transparent defense detection of email transmission encryption.

[0110] Command execution stage: When the command is executed on the target machine, the command execution is achieved by calling the system CMD program, which is a relatively conventional command execution method. By monitoring the creation of the cmd.exe process, the running operations of malicious Trojan programs, file creation programs, keylogger programs, browser and system password stealing programs, etc. can be detected in real time, and their processes can be blocked and terminated in a timely manner.

[0111] For the detection of the command execution stage, it relies on the Windows platform and monitors the process call when cmd.exe executes commands. Specifically, it can be achieved through the following three methods.

[0112] First, use security information and audit policies. For example, enable the Windows security audit policy and configure it to monitor process creation events; use the Windows Event Viewer to check the security event log, especially the events containing process creation information. Sort out all relevant event IDs such as 4688 (creation of a new process), etc. to form a blacklist. During the entire life cycle of the host process, determine whether the email has risks by matching the event ID of the newly created process related to the email with the event IDs in the blacklist.

[0113] Second, in combination with the Sysmon security mechanism and in cooperation with Microsoft's system monitoring technology, it is possible to capture more detailed process creation event information. By deploying Sysmon and configuring appropriate risk detection rules, detailed logs including event information generated when detecting email-related process creation are used to determine whether there is a risk in the email.

[0114] Third, by writing a PowerShell script cluster, the core code of the main calling process is: Select * from win32_ProcessStartTrace where processname = 'cmd.exe', which is used to periodically check the running processes and record or report newly created cmd.exe processes. By analyzing and extracting the digital signature attribute values, publishing author attribute values, and publishing version attribute values in the source programs of all processes in the parent process chain of newly created processes related to the entire email, and combining them into a triple format, and then verifying and matching them with the legal and valid program verification forms in the program publishing repository, suspicious source programs are screened out. Then, by comparing the digest hash value of the suspicious source program with the digest hash value of the risk program in the risk sample library, the risk of the email is determined.

[0115] The email risk detection method provided by the embodiment of the present invention conducts technical defect mining and analysis for each stage of the attack technology. By using the algorithm defects such as Base64 Decode and PGP encryption, the technical threat of SSL / TLS communication protocol MITM (Man in The Middle), and features such as command execution CMD process call existing during its operation, targeted detection methods are proposed, effectively improving the detection and troubleshooting efficiency for dealing with such attack technologies and strengthening the overall network defense ability.

[0116] Figure 6 It is a schematic structural diagram of the email risk detection device provided by the sixth embodiment of the present invention, as Figure 6 shown, the email risk detection device provided by the embodiment of the present invention includes a receiving module 601, an obtaining module 602, and a determining module 603, where:

[0117] The receiving module 601 is used to receive the email and decrypt the email; the obtaining module 602 is used to obtain the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs if a newly created process is detected; the determining module 603 is used to determine the risk of the email according to the at least one suspicious source program and the risk sample library if at least one suspicious source program is obtained according to the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs and the attribute values of each valid program in the program publishing repository.

[0118] Specifically, the receiving module 601 can receive emails and decrypt the emails. Among them, the client can directly receive emails from the mail server or receive emails forwarded by the gateway server.

[0119] After decrypting the email described in the resume, if the acquisition module 602 detects a newly created process, it acquires each process in the process chain to which the newly created process belongs, and acquires the source program corresponding to each process. Each source program will have an attribute value. The attribute values of the source program include the digital signature attribute value, the publishing author attribute value, the publishing version attribute value, etc. Among them, the newly created process is related to the email.

[0120] For each process in the process chain to which the newly created process belongs, the determination module 603 compares the attribute value of the source program corresponding to the process with the attribute value of each valid program in the program release repository. If the attribute value of the source program corresponding to the process does not match the attribute value of any valid program in the program release repository, then the source program corresponding to the process is a suspicious source program; if the attribute value of the source program corresponding to the process matches the attribute value of a valid program in the program release repository, then the source program corresponding to the process is not a suspicious source program. After the attribute values of the source programs corresponding to all processes in the process chain to which the newly created process belongs have been compared and at least one suspicious program is obtained, the risk of the email can be determined according to the at least one suspicious source program and the risk sample library. Among them, the program release repository is preset, and each valid program included is a source program that has been detected and has no risk. The risk sample library is preset, and the programs included are programs that have risks, such as malicious programs like Trojan programs. The process chain to which the newly created process belongs refers to a chain structure formed by the parent process of the newly created process, the parent process of the parent process of the newly created process, the parent process of the parent process of the parent process of the newly created process, and so on.

[0121] The email risk detection device provided by the embodiment of the present invention receives an email and decrypts the email; if a newly created process is detected, it acquires the attribute value of the source program corresponding to each process in the process chain to which the newly created process belongs; if at least one suspicious source program is obtained according to the attribute value of the source program corresponding to each process in the process chain to which the newly created process belongs and the attribute value of each valid program in the program release repository, then the risk of the email is determined according to the at least one suspicious source program and the risk sample library. By performing risk detection on the source program corresponding to each process in the process chain of the newly created process related to the email, the risk of the email is determined, which improves the reliability of the email risk detection.

[0122] Figure 7It is a schematic structural diagram of a mail risk detection device provided by the seventh embodiment of the present invention. As Figure 7 shown, on the basis of the above embodiments, further, the determination module 603 includes a calculation unit 6031 and a first judgment unit 6032, where:

[0123] The calculation unit 6031 is used to calculate the digest hash value of each suspicious source program in the at least one suspicious source program; the first judgment unit 6032 is used to determine that the mail is at risk if it is judged that the digest hash value of a suspicious source program is the same as the digest hash value of the risk program in the risk sample library.

[0124] Figure 8 It is a schematic structural diagram of a mail risk detection device provided by the eighth embodiment of the present invention. As Figure 8 shown, on the basis of the above embodiments, further, the attribute value includes a digital signature attribute value, a publishing author attribute value, and a publishing version attribute value; correspondingly, the determination module 603 includes an obtaining unit 6033 and a second judgment unit 6034, where:

[0125] The obtaining unit 6033 is used to obtain the matching degree of the source program corresponding to each process in the process chain according to the digital signature attribute value, the publishing author attribute value, and the publishing version attribute value of the source program corresponding to each process and the digital signature attribute value, the publishing author attribute value, and the publishing version attribute value of each valid program in the program publishing repository; the second judgment unit 6034 is used to use the source program corresponding to the process as a suspicious source program if it is judged that the matching degree of the source program corresponding to the process is less than the threshold.

[0126] Figure 9 It is a schematic structural diagram of a mail risk detection device provided by the ninth embodiment of the present invention. As Figure 9 shown, on the basis of the above embodiments, further, the receiving module 601 includes a receiving unit 6011, a decrypting unit 6012, and a determining unit 6013, where:

[0127] The receiving unit 6011 is used to receive the mail forwarded from the gateway server; wherein, the mail is encrypted by the public key negotiated in advance by the gateway server; the decrypting unit 6012 is used to decrypt the mail by the private key negotiated in advance with the gateway server; the determining unit 6013 is used to determine that the mail is a risk mail if the decryption of the mail fails.

[0128] On the basis of the above embodiments, further, the receiving module 601 is specifically used for:

[0129] If it is judged that the mail is encoded by a specific method / or encrypted by a specific encryption algorithm, it is determined that the mail is at risk.

[0130] Figure 10 is a schematic structural diagram of a mail risk detection device provided by the tenth embodiment of the present invention. As Figure 10 shown, on the basis of the above embodiments, further, the mail risk detection device provided by the embodiments of the present invention further includes a judgment module 604, where:

[0131] The judgment module 604 is used to determine that the mail has a risk if the event identifier of the newly created process is the same as the event identifier in the blacklist.

[0132] Figure 11 is a schematic structural diagram of a mail risk detection device provided by the eleventh embodiment of the present invention. As Figure 11 shown, on the basis of the above embodiments, further, the mail risk detection device provided by the embodiments of the present invention further includes an event information acquisition module 605 and a detection module 606, where:

[0133] The event information acquisition module 605 is used to acquire the event information of the newly created process; the detection module 606 is used to determine the risk of the mail according to the event information of the newly created process and the risk detection rule.

[0134] The embodiments of the device provided by the embodiments of the present invention can specifically be used to execute the processing procedures of the above method embodiments, and its functions will not be elaborated here. Reference can be made to the detailed descriptions of the above method embodiments.

[0135] It should be noted that the mail risk detection method and device provided by the embodiments of the present invention can be used in the financial field, and can also be used in any technical field other than the financial field. The embodiments of the present invention do not limit the application fields of the mail risk detection method and device.

[0136] Figure 12 is a schematic physical structure diagram of an electronic device provided by the twelfth embodiment of the present invention. As Figure 12As shown in the figure, the electronic device may include: a processor 1201, a communications interface 1202, a memory 1203, and a communication bus 1204. Among them, the processor 1201, the communications interface 1202, and the memory 1203 communicate with each other through the communication bus 1204. The processor 1201 can call the logical instructions in the memory 1203 to execute the following method: receive an email and decrypt the email; if a newly created process is detected, obtain the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs; if at least one suspicious source program is obtained based on the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs and the attribute values of each valid program in the program release repository, determine the risk of the email based on the at least one suspicious source program and the risk sample library.

[0137] In addition, when the logical instructions in the above-mentioned memory 1203 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0138] This embodiment discloses a computer program product. The computer program product includes a computer program stored on a computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the methods provided in the above method embodiments, for example, including: receiving an email and decrypting the email; if a newly created process is detected, obtaining the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs; if at least one suspicious source program is obtained based on the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs and the attribute values of each valid program in the program release repository, determining the risk of the email based on the at least one suspicious source program and the risk sample library.

[0139] This embodiment provides a computer-readable storage medium that stores a computer program, and the computer program causes the computer to execute the methods provided in the above method embodiments. For example, it includes: receiving an email and decrypting the email; if a newly created process is detected, obtaining the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs; if at least one suspicious source program is obtained based on the attribute values of the source programs corresponding to each process in the process chain to which the newly created process belongs and the attribute values of each valid program in the program release repository, determining the risk of the email according to the at least one suspicious source program and the risk sample library.

[0140] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0141] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0142] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0143] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Therefore, the instructions executed on the computer or other programmable device provide means for implementing the functions specified in Figure 1One process or multiple processes and / or boxes Figure 1 Steps of functions specified in one box or multiple boxes.

[0144] In the description of this specification, the description with reference to terms such as "one embodiment", "one specific embodiment", "some embodiments", "for example", "example", "specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0145] The above-described specific embodiments have further elaborated on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for detecting email risks, characterized in that: include: receiving mail and decrypting said mail; If a newly created process is detected, obtaining the attribute value of the source program corresponding to each process in the process chain to which the newly created process belongs; If at least one suspicious source program is obtained based on the attribute values ​​of the source program corresponding to each process in the process chain to which the newly created process belongs and the attribute values ​​of each valid program in the program release warehouse, the risk of the email is determined based on the at least one suspicious source program and the risk sample library.

2. The method according to claim 1, characterized in that The determining the risk of the email according to the at least one suspicious source program and the risk sample library includes: Calculating a digest hash value of each suspicious source program in the at least one suspicious source program; If it is determined that there is a suspicious source program whose digest hash value is the same as the digest hash value of the risky program in the risk sample library, it is determined that the email has a risk.

3. The method according to claim 1, characterized in that The attribute values ​​include a digital signature attribute value, a publishing author attribute value, and a publishing version attribute value; accordingly, obtaining the at least one suspicious source program according to the attribute values ​​of the source program corresponding to each process in the process chain to which the newly created process belongs and the attribute values ​​of each valid program in the program publishing warehouse includes: Obtaining the matching degree of the source program corresponding to each process in the process chain according to the digital signature attribute value, the publishing author attribute value and the publishing version attribute value of the source program corresponding to each process and the digital signature attribute value, the publishing author attribute value and the publishing version attribute value of each valid program in the program publishing warehouse; If it is determined that the matching degree of the source program corresponding to the process is less than a threshold, the source program corresponding to the process is regarded as a suspicious source program.

4. The method according to claim 1, characterized in that: The receiving of the email and decrypting the email comprises: Receiving the email forwarded from the gateway server; wherein the email is encrypted by the gateway server using a pre-negotiated public key; Decrypting the email using a private key pre-negotiated with the gateway server; If the email decryption fails, the email is determined to be a risky email.

5. The method according to claim 1, characterized in that Decrypting the email includes: If it is determined that the email is encoded in a specific way / or encrypted by a specific encryption algorithm, it is determined that the email is risky.

6. The method according to claim 1, characterized in that Also includes: If the event identifier of the newly created process is the same as the event identifier in the blacklist, it is determined that the email has a risk.

7. The method according to any one of claims 1 to 6, characterized in that: Also includes: Obtaining event information of the newly created process; The risk of the email is determined according to the event information of the newly created process and the risk detection rule.

8. A device for detecting mail risks, characterized in that: include: A receiving module, used for receiving and decrypting emails; An acquisition module, configured to acquire, if a newly created process is detected, an attribute value of a source program corresponding to each process in a process chain to which the newly created process belongs; A determination module is used to determine the risk of the email based on the at least one suspicious source program and a risk sample library if at least one suspicious source program is obtained based on the attribute values ​​of the source program corresponding to each process in the process chain to which the newly created process belongs and the attribute values ​​of each valid program in the program release warehouse.

9. A computer device comprising a memory, a processor and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program / instruction, which implements the steps of the method according to any one of claims 1 to 7 when executed by a processor.

11. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.