Memory horse detection method and device, electronic equipment and storage medium
By using preset class feature library and risk feature library, memory horse risk class identification and weight calculation are performed for loaded classes in Java virtual machines, the problems of low memory horse detection efficiency and high memory consumption in the existing technology are solved, and efficient memory horse detection is achieved.
Patent Information
- Application Number
- CN202311630479.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-29
- Publication Date
- 2025-05-30
AI Technical Summary
When the existing memory horse detection scheme detects the bytecode of the Java virtual machine running, it is inefficient and has too much memory consumption, which affects the normal operation of the system.
Through the preset class feature library of different memory horse types, the memory horse risk class is obtained from the loaded class of the process to be detected, its corresponding class byte code stream is obtained, and the cumulative weight is determined based on the preset risk feature library to determine the memory horse detection result of the process to be detected.
It reduces the memory overhead during memory horse detection, improves the memory horse detection efficiency, and can effectively identify different types of memory horses.
Smart Images

Figure CN120068062A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and particularly to a method, apparatus, electronic device, and storage medium for detecting memory horses. Background Art
[0002] A memory horse is a technical means of fileless attack. In the case of fileless attack, the Trojan file only exists in the server's running memory and there is no corresponding file in the server, thus effectively avoiding detection by traditional detection tools. The fileless attack technology allows an attacker to access the system, thereby enabling subsequent malicious activities. By manipulating vulnerabilities, the attacker can damage the system, elevate privileges, or spread malicious code laterally on the network.
[0003] Taking the Java memory horse as an example, existing memory horse detection solutions usually obtain all class bytecodes in the JVM, analyze and detect the class bytecodes in the running memory, and output the detection results.
[0004] However, the number of classes in the Java virtual machine during operation is very large. For example, the number of classes in a normal Java virtual machine during operation is as high as more than four thousand. For large projects, the number of classes is even more. If all class bytecodes are obtained for analysis, the detection efficiency is very low, and the memory consumption will be too large during detection, affecting the normal operation of the system. Summary of the Invention
[0005] The purpose of the embodiments of this application is to provide a method, apparatus, electronic device, and storage medium for detecting memory horses.
[0006] To solve the above technical problems, the embodiments of this application are implemented through the following aspects.
[0007] According to a first aspect of the embodiments of the present disclosure, a method for processing device versions is provided. The method includes: obtaining memory horse risk classes from the loaded classes of the process to be detected according to a preset class feature library of different memory horse types; obtaining the class bytecode stream corresponding to the memory horse risk classes, where the class bytecode stream includes at least one class bytecode; determining the cumulative weight of the class bytecode stream corresponding to the memory horse risk classes according to a preset risk feature library; and determining the memory horse detection result of the process to be detected according to the cumulative weight.
[0008] According to a second aspect of the embodiments of the present disclosure, there is provided a memory horse detection device, the device including: a class acquisition module configured to acquire memory horse risk classes from the loaded classes of a process to be detected according to a class feature library of different memory horse types preset; a bytecode stream acquisition module configured to acquire a bytecode stream corresponding to the memory horse risk classes, the bytecode stream including at least one bytecode; a weight determination module configured to determine an accumulated weight of the bytecode stream corresponding to the memory horse risk classes according to a preset risk feature library; and a detection module configured to determine a memory horse detection result of the process to be detected according to the accumulated weight.
[0009] According to a third aspect of the embodiments of the present disclosure, there is provided an electronic device, including: a memory, a processor, and computer executable instructions stored on the memory and executable on the processor, the computer executable instructions, when executed by the processor, implementing the steps of: acquiring memory horse risk classes from the loaded classes of a process to be detected according to a class feature library of different memory horse types preset; acquiring a class bytecode stream corresponding to the memory horse risk classes, the class bytecode stream including at least one class bytecode; determining an accumulated weight of the class bytecode stream corresponding to the memory horse risk classes according to a preset risk feature library; and determining a memory horse detection result of the process to be detected according to the accumulated weight.
[0010] According to a fourth aspect of the embodiments of the present disclosure, there is provided a computer-readable storage medium storing computer executable instructions, the computer executable instructions, when executed by a processor, implementing the steps of: acquiring memory horse risk classes from the loaded classes of a process to be detected according to a class feature library of different memory horse types preset; acquiring a class bytecode stream corresponding to the memory horse risk classes, the class bytecode stream including at least one class bytecode; determining an accumulated weight of the class bytecode stream corresponding to the memory horse risk classes according to a preset risk feature library; and determining a memory horse detection result of the process to be detected according to the accumulated weight.
[0011] The technical solution provided by the embodiments of the present disclosure: acquiring memory horse risk classes from the loaded classes of a process to be detected according to a class feature library of different memory horse types preset; acquiring a class bytecode stream corresponding to the memory horse risk classes, the class bytecode stream including at least one class bytecode; determining an accumulated weight of the class bytecode stream corresponding to the memory horse risk classes according to a preset risk feature library; and determining a memory horse detection result of the process to be detected according to the accumulated weight. By adopting the above technical means, classification and judgment are carried out for the characteristics of different memory horse types, and then the class bytecode stream of the memory horse risk classes is acquired specifically, which can reduce the memory overhead during memory horse detection and improve the memory horse detection efficiency.
[0012] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and do not limit the present disclosure.
[0013] Other features and advantages of the present disclosure will be described in detail in the following specific implementation section. Brief Description of the Drawings
[0014] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0015] Figure 1 A schematic flowchart showing a method for detecting a memory horse provided by an embodiment of the present application;
[0016] Figure 2 A schematic classification diagram showing a Java memory horse provided by an embodiment of the present application;
[0017] Figure 3 Another schematic flowchart showing a method for detecting a memory horse provided by an embodiment of the present application;
[0018] Figure 4 Another schematic flowchart showing a method for detecting a memory horse provided by an embodiment of the present application;
[0019] Figure 5 Another schematic flowchart showing a method for detecting a memory horse provided by an embodiment of the present application;
[0020] Figure 6 A schematic diagram showing a key business process during the detection of a Java memory horse provided by an embodiment of the present application;
[0021] Figure 7 Another schematic flowchart showing a method for detecting a memory horse provided by an embodiment of the present application;
[0022] Figure 8 A schematic diagram of an application scenario example for detecting a memory horse provided by an embodiment of the present application;
[0023] Figure 9 A block diagram showing a processing device for a device version provided by an embodiment of the present application;
[0024] Figure 10 A block diagram showing another processing device for a device version provided by an embodiment of the present application;
[0025] Figure 11Schematic diagram of the hardware structure of an electronic device for implementing the memory horse detection method provided in the embodiments of the present application. Detailed implementation manners
[0026] In order to enable those skilled in the art to better understand the technical solutions in the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0027] First, introduce the professional terms in the Java memory horse example in the present application.
[0028] WebShell, a Web background management script.
[0029] Java agent, also known as a Java proxy, is a plug-in specification for the Java virtual machine, which can observe and modify Java code without modifying the compiled Java business code.
[0030] JVM, Java virtual machine, a virtual machine that can execute Java bytecode, implemented with a stack-structured machine.
[0031] Class bytecode file, that is, a Class file, a file that runs in the Java virtual machine after being compiled by the Java compiler.
[0032] JSP, Jakarta Server Pages, a dynamic web technology standard. JSP is deployed on a web server and can respond to requests sent by clients, and dynamically generate Web pages in HTML, XML or other formats according to the request content, and then return them to the requester.
[0033] Java PID, Java process ID, the process number corresponding to the running Java program.
[0034] Java memory horse, a memory Trojan for fileless attacks injected into the Java virtual machine process.
[0035] Figure 1 Shows a flowchart of a memory horse detection method provided in an embodiment of the present application, as Figure 1 shown, the method may include the following steps:
[0036] In step S101, according to the class feature library of different memory horse types preset, obtain memory horse risk classes from the loaded classes of the process to be detected.
[0037] According to the different attack principles of memory horses, memory horses can be classified into different types. Taking Java memory horses as an example, they can be divided into memory horses of the dynamic registration component type and memory horses of the dynamic memory modification type. Among them, memory horses of the dynamic memory modification type can include non-evasive memory horses and / or evasive memory horses. The implementation of memory horses of the dynamic registration component type depends on Java specification features and will dynamically add new components or classes in memory. The memoryless feature of memory horses of the dynamic registration component type is obvious. While memory horses of the dynamic memory modification type utilize Java Agent technology to modify the existing class bytecodes in memory to make them into malicious memoryless Web shells without affecting the business functions.
[0038] Figure 2 The following shows a schematic diagram of the classification of a Java memory horse provided by an embodiment of the present application, as Figure 2 shown. Memory horses of the dynamic registration component type are mainly related to containers or frameworks. The essential difference between memory horses of the dynamic memory modification type and memory horses of the dynamic registration component type is that memory horses of the dynamic registration component type will add new malicious component classes, while memory horses of the dynamic memory modification type modify the existing component classes (such as all modifiable component classes involved in the dynamic registration component type) to make them contain malicious code logic. In addition, memory horses of the dynamic memory modification type include a special type of memory horses of the dynamic memory modification type. In order to counter memory horse detection tools, this type of memory horses of the dynamic memory modification type makes memory horse detection means unable to run by destroying key business processes to avoid memory horse detection. This type of memory horse can be called an evasive memory horse, and memory horses of the dynamic memory modification type other than this can be called non-evasive memory horses. Taking Java evasive memory horses as an example, according to the characteristics that Java memory horse detection tools are usually implemented based on Java agent, in the Java agent process, by destroying the key business processes of Java instrumentation (such as the Attach process), the memory horse detection tools cannot work properly (such as unable to Attach).
[0039] It should be noted that although the present application mainly uses Java as an example to illustrate the memory horse detection method, it should not be understood as a limitation to the technical solution. It can be understood that the technical solution of the present application can also be applied to the detection of other types of memory horses, and the present application does not limit this.
[0040] In some embodiments, the class feature library may include a first type of feature library corresponding to memory horses of the dynamic registration component type, where the first type of feature library includes at least one of a first key class, a first key interface, and a first key annotation.
[0041] Exemplarily, taking the dynamic registration of malicious Servlets as an example, the first key class may include javax.servlet.http.HttpServlet, and the first key interface may include javax.servlet.Servlet. Taking the memory horse related to the SpringMVC framework as an example, the first key annotation may include one or more of the following annotations:
[0042] org.springframework.stereotype.Controller,
[0043] org.springframework.web.bind.annotation.RestController and
[0044] org.springframework.web.bind.annotation.RequestMapping.
[0045] It can be understood that those skilled in the art can flexibly set at least one of the corresponding first key class, first key interface, and first key annotation based on the characteristics of the corresponding memory horse.
[0046] In some embodiments, when the first condition is met, it is determined that the loaded class is a risk class of a dynamically registered component type memory horse.
[0047] Among them, the first condition includes any one of the following conditions:
[0048] On the server of the process to be detected, there is no file corresponding to the loaded class, and the loaded class meets at least one feature in the first type of feature library;
[0049] When there is a file corresponding to the loaded class on the server of the process to be detected, the file corresponding to the loaded class is a preset file type, and the loaded class meets at least one feature in the first type of feature library.
[0050] Among them, the preset file type may be JSP.
[0051] Since the dynamically registered component - type memory horse will dynamically add new components and classes in memory, execute certain malicious code using the middleware process, and there is no corresponding file on the server. In some possible implementation manners, it is possible to scan on the server of the process to be detected to determine whether there is a file corresponding to the loaded class. When the file corresponding to the loaded class is obtained through scanning, it is determined that there is a file corresponding to the loaded class on the server of the process to be detected. When the file corresponding to the loaded class cannot be obtained through scanning within a preset time, it is determined that there is no file corresponding to the loaded class on the server of the process to be detected.
[0052] Exemplarily, when there is no file corresponding to the loaded class on the server of the process to be detected and the loaded class belongs to a key class in the first feature library (such as javax.servlet.http.HttpServlet), it is determined that the loaded class is a risk class of the dynamically registered component - type memory horse.
[0053] In step S102, obtain the class bytecode stream corresponding to the memory - horse risk class, and the class bytecode stream includes at least one class bytecode.
[0054] Taking the Java memory horse as an example, in some possible implementation manners, it is possible to create a bytecode file corresponding to the memory - horse risk class in the working directory path corresponding to the memory - horse risk class, call the add transformer class converter, capture all loaded class information, obtain the bytecode stream corresponding to the current memory - horse risk class, and write the bytecode stream into the created bytecode file.
[0055] When there are multiple memory - horse risk classes, each memory - horse risk class can be traversed in sequence, so as to generate bytecode files corresponding to the bytecode streams of each memory - horse risk class respectively.
[0056] In step S103, determine the cumulative weight of the class bytecode stream corresponding to the memory - horse risk class according to a preset risk feature library.
[0057] Among them, the risk feature library includes at least one risk feature and the risk weight corresponding to each risk feature respectively.
[0058] The risk feature is used to characterize the corresponding features of different memory horses in the bytecode stream.
[0059] Taking the Java memory horse as an example, in some possible implementation manners, the risk feature library may include multiple risk features using hash mapping as shown in Table 1.
[0060] Table 1
[0061]
[0062]
[0063] It should be noted that Table 1 is an example of the risk characteristics in the risk characteristic library and does not enumerate all the risk characteristics in the risk characteristic library. It can be understood that those skilled in the art can supplement the risk characteristics corresponding to various different memory horses or the new risk characteristics of newly emerging memory horses on the basis of Table 1. In addition, the risk characteristics corresponding to the dynamically modified memory type memory horse in Table 1 are relatively long, and not all risk characteristics are shown in Table 1.
[0064] Figure 3 Another process schematic diagram showing the memory horse detection method provided by the embodiments of the present application is shown in Figure 3 As shown, step S103 may include the following steps.
[0065] In step S1031, each target class bytecode and its corresponding target risk weight are sequentially obtained from the class bytecode stream.
[0066] Among them, the target class bytecode satisfies any target risk characteristic in the risk characteristic library, and the target risk weight is the risk weight corresponding to the target risk characteristic.
[0067] In some possible implementation manners, the bytecodes can be obtained line by line from the bytecode file corresponding to the risk class, and the bytecodes are matched with the risk characteristics in the risk characteristic library. When the bytecode satisfies any target risk characteristic in the risk characteristic library, the bytecode is used as the target class bytecode, and its corresponding weight is obtained. For example, in a bytecode file corresponding to a risk class, there are two target bytecodes, which respectively satisfy the "cmd" risk characteristic and the "memshell" risk characteristic in the risk characteristic library, then the risk weights corresponding to the two target bytecodes are both 5.
[0068] In step S1032, the sum value of the target risk weights corresponding to each target class bytecode is used as the cumulative weight.
[0069] In a bytecode file corresponding to a risk class, there are two target bytecodes, which respectively satisfy the "cmd" risk characteristic and the "memshell" risk characteristic in the risk characteristic library, and the risk weights corresponding to the two target bytecodes are both 5. Then the cumulative weight corresponding to this risk class (bytecode file) is the sum value of the target risk weights corresponding to the target class bytecodes, that is, the cumulative weight is 10.
[0070] In step S104, the memory horse detection result of the process to be detected is determined according to the cumulative weight.
[0071] In some embodiments, the memory horse detection result of the process to be detected can be determined according to the correspondence between the preset weight and the memory horse type.
[0072] Taking the Java memory horse as an example, in some possible implementation manners, the memory horse detection result of the process to be detected can be determined according to the corresponding relationship between the weights and the memory horse types shown in Table 2 below.
[0073] Table 2
[0074] Cumulative weight interval Memory horse type [5,30) Memory horse of dynamically registered component type [30,80) GeSiLa memory horse [80,300) YiJian memory horse [300,1000) Memory horse of dynamically registered component type (Spring component) [1000,+∞) Memory horse of dynamically modified memory type
[0075] It can be understood that the corresponding relationship between the above cumulative weights and the memory horse types can be flexibly extended. For example, the features of current mainstream Web shell injection tools such as BingXie, Yijian, and GeShila can be further classified, so as to further output more detailed tool types of memory horse injection, which is convenient for users to trace and troubleshoot in the later stage and maintain and update.
[0076] In some embodiments, in addition to determining the detection result of the memory horse risk class and the corresponding memory horse type, the process information (such as the process identifier) of the current process and the corresponding server information (such as the server type) can also be further output.
[0077] By adopting the above technical means, classifying and judging the features of different memory horse types, and then specifically obtaining the class bytecode stream of the memory horse risk class, the memory overhead during memory horse detection can be reduced, and the memory horse detection efficiency can be improved.
[0078] In some embodiments, the memory horse types include non-evasion memory horses and / or evasion memory horses, and the class feature library includes a second type of feature library for non-evasion memory horses and / or a third type of feature library corresponding to evasion memory horses.
[0079] Among them, the second type of feature library may include at least one of a first keyword, a second key class, a second key interface, and a second key annotation. The third type of feature library may include a third key class.
[0080] Taking the Java non-evasion memory horse as an example, the first keyword may be
[0081] isModifiableClass. When this first keyword is True, it indicates that the loaded class is allowed to be modified; when this first keyword is False, it indicates that the loaded class is not allowed to be modified.
[0082] The third key class may include one or more of the following key classes:
[0083] org.apache.catalina.core.ApplicationFilterChain;
[0084] org.apache.catalina.core.StandardWrapperValve;
[0085] javax.servlet.http.HttpServlet;
[0086] org.apache.catalina.valves.ValveBase.
[0087] The second key class can be a collection of the first key class and the third key class, that is, the third key class can be a subset of the second key class, the second key interface can be the same as the first key interface, and the second key annotation can be the same as the first key annotation.
[0088] Taking the Java memory horse that resists anti-virus as an example, the Java memory horse detection tools in the related technology usually implement by using the Javaagent technology. And the memory horse that resists anti-virus makes the memory horse detection tool unable to work properly (such as unable to Attach) by destroying the key business processes, for example, by destroying the key business processes of Java instrumentation (such as the Attach process) in the Java agent process, so that the memory horse detection cannot be carried out normally. The common way to deal with the Java memory horse that resists anti-virus in the related technology is to use HSDB (Hotspot Debugger). HSDB is a tool built into the JVM for in-depth analysis of the internal state of the JVM during operation. However, using this method will cause the Java virtual machine to hang, making all services unable to work properly during that period, and it is not applicable to the actual production environment. To solve the above technical problems, this application introduces the anti-injection function of the non-anti-virus memory horse.
[0089] Figure 4 Another process schematic diagram showing the detection method of the memory horse provided by the embodiments of this application is as Figure 4 shown, and the method may further include the following steps.
[0090] In step S105, in response to the user's operation of enabling the anti-injection function of the non-anti-virus memory horse, the key business process is protected to enable the anti-injection function of the non-anti-virus memory horse.
[0091] This key business process can be, for example, the Attach process of establishing a communication connection with the JVM during Java memory horse detection.
[0092] It can be understood that the key business process can be protected in a variety of possible implementation ways. For example, the anti-injection function of the non-anti-virus memory horse can be enabled by any way such as key file protection, key storage structure protection, or key process blocking during this process. This application does not limit this. In some embodiments, protecting the key business process may include at least one of the following:
[0093] Encrypt the key files during the memory horse detection process;
[0094] Hide the key files during the memory horse detection process;
[0095] Restore the key files during the memory horse detection process when the key files during the memory horse detection process are unavailable.
[0096] It can be understood that any encryption, hiding, and restoration technical solutions in the related technologies can be adopted to implement the above security protection, and the present application does not limit the technical solutions for encrypting, hiding, and restoring the key files.
[0097] It should be noted that the present application does not limit the order of step S105 and other steps. Step S105 can also be before step S101, or can also be between any one of steps S101 - S104.
[0098] Figure 5 Another flowchart showing the memory horse detection method provided by the embodiment of the present application is as Figure 5 shown, and the key business processes can be protected securely through the following steps.
[0099] In step 100, receive the operation of enabling or disabling the non-evasion memory horse anti-injection function of the user.
[0100] In step 101, when the user performs an enabling operation on the non-evasion memory horse anti-injection function and it is the first time to enable it, encrypt and / or hide the key files during the memory horse detection process.
[0101] Encrypting and / or hiding the key files during the memory horse detection process can prevent the evasion memory horse from destroying (such as deleting or illegally modifying) the key files, so that the memory horse detection tool cannot be prevented from detecting and killing the evasion memory horse. At the same time, after encrypting and / or hiding the key files during the memory horse detection process, the non-evasion memory horse cannot attach normally either, thus achieving immunity to the non-evasion memory horse.
[0102] In step 102, after encrypting and / or hiding the key files during the memory horse detection process, or when the user performs an enabling operation on the non-evasion memory horse anti-injection function not for the first time, enable the non-evasion memory horse anti-injection function.
[0103] In step 103, when the user performs a disabling operation on the non-evasion memory horse anti-injection function and the key files have been encrypted and / or hidden, the key files can be restored.
[0104] In the case of performing normal hotfix (such as Hotfix) or hot deployment, the anti-injection function of the non-evasion memory horse can be temporarily turned off in response to the user's operation. At this time, the encrypted and / or hidden key files can be restored so that the hotfix or hot deployment can proceed normally. It can be understood that after the above hotfix or hot deployment is successfully completed, the anti-injection function of the non-evasion memory horse can be turned on in a timely manner.
[0105] In step 104, after restoring the key files, or when the user performs a shutdown operation on the anti-injection function of the non-evasion memory horse but the key files have not been encrypted and / or hidden, the anti-injection function of the non-evasion memory horse can be turned off.
[0106] Figure 6 Fig. shows a schematic diagram of a key business process during Java memory horse detection provided by an embodiment of the present application. This key business process can be, for example, the Attach process of establishing a communication connection with the JVM during Java memory horse detection. Since this key business process is a mature process, the present application only describes in detail the improved step 110 in the example. Taking the protection of key files for security protection of the key business process as an example, as Figure 6 shown, when detecting Java memory horses, the JVM-Client first establishes a communication connection with the JVM-Server through the following Attach process.
[0107] In step 105, check whether there is a.java_pidXXX file. For example, the JVM-Client can check whether there is a.java_pidXXX file in the tmp directory, where "XXX" represents the corresponding Java process identifier. For example, if the Java process identifier is 1543, the corresponding file is.java_pid1543.
[0108] In step 106, when there is no.java_pidXXX file, create an attach_pidXXX file.
[0109] In step 107, the JVM-Client sends a SIGQUIT signal to the JVM-Server of the target process.
[0110] In step 108, the JVM-Server of the target process (hereinafter simply referred to as JVM-Server) receives the SIGQUIT signal sent by the JVM-Client. It can be understood that this SIGQUIT signal is only valid when sent for the first time.
[0111] In step 109, the JVM-Server checks whether there is an attach_pidXXX file. For example, it can check whether there is an.attach_pidXXX file in the tmp directory, where "XXX" represents the corresponding Java process identifier. For example, if the Java process identifier is 1543, the corresponding file is.attach_pid1543.
[0112] In step 110, in the case where there is an attach_pidXXX file, a socket file.java_pidXXX file is created. In some embodiments, the.java_pidXXX file generated in step 110 can be used as a key file for subsequent communication with the JVM (Java Virtual Machine). Each Java process generates it only once and cannot be copied. Moreover, moving the location of this key file will also cause the verification to fail. The usual storage location of this file can be, for example, tmp / .java_pidXXX, where XXX represents the corresponding Java process identifier. For example, if the Java process identifier is 1543, the corresponding file is.java_pid1543.
[0113] In some possible implementation manners, the process can be made immune to the injection of non-evasive memory horses by encrypting and / or hiding the.java_pidXXX key file, that is, the non-evasive memory horse cannot communicate with the JVM and thus cannot implement memory horse injection.
[0114] For evasive memory horses, since the.java_pidXXX key file is encrypted and / or hidden, the evasive memory horse cannot damage the.java_pidXXX key file and cannot prevent the memory horse detection tool from detecting and killing it. Even if the evasive memory horse has damaged the.java_pidXXX key file, by protecting the key business processes, the key file in the memory horse detection process can be restored in the case where the key file is unavailable during the memory horse detection process, so that the evasive memory horse can be detected and killed normally.
[0115] In step 111, after successfully creating the.java_pidXXX file, listen for connection requests based on the socket file.java_pidXXX.
[0116] In step 112, after sending the SIGQUIT signal, the JVM-Client can poll to check whether the.java_pidXXX has been created.
[0117] In step 113, check for timeout. In step 114, if the polling time exceeds the preset time threshold (e.g., 5 seconds) and the created.java_pidXXX file has not been polled yet, end the Attach process.
[0118] In step 115, when the.java_pidXXX file has been created and polled, the JVM-Client initiates connection establishment.
[0119] In step 116, after the JVM-Server receives the connection establishment request sent by the JVM-Client, it verifies the information related to the connection request.
[0120] In step 117, determine whether the verification passes.
[0121] In step 118, if the verification passes, send a connection success instruction to complete the connection establishment.
[0122] In step 119, if the attach_pidXXX file does not exist in the check in step 109 or the verification fails in step 117, end the Attach process.
[0123] By adopting the above technical method, it is possible to achieve immunity to the injection of non-evasive memory horses, reduce the occurrence probability of non-evasive memory horses, and at the same time can normally detect evasive memory horses, improve the memory horse detection ability, and further improve the memory horse detection efficiency.
[0124] In some embodiments, when executing step S101, it is also possible to flexibly obtain memory horse risk classes from the loaded classes of the process to be detected according to the class feature libraries of different preset memory horse types according to the enabling situation of the non-evasive memory horse anti-injection function. Figure 7 Another process schematic diagram showing the memory horse detection method provided by the embodiments of the present application is as Figure 7 shown, and step S101 may specifically include any of the following steps.
[0125] In step S1011, when the non-evasive memory horse anti-injection function is turned off or when the memory horse risk classes are obtained for the first time after the non-evasive memory horse anti-injection function is turned on, obtain the memory horse risk classes from the loaded classes of the process to be detected according to the second type of feature library.
[0126] Exemplarily, when the loaded class meets at least one feature in the second type of feature library, determine that the loaded class is a risk class of a non-evasive memory horse.
[0127] In step S1012, when the anti-injection function of the non-evasive memory horse is enabled and it is not the first time to obtain the risk class of the memory horse, the risk class of the memory horse is obtained from the loaded classes of the process to be detected according to the third type of feature library.
[0128] Exemplarily, when the loaded class meets at least one feature in the third type of feature library, it is determined that the loaded class is the risk class of the evasive memory horse. The evasive memory horse circumvents memory horse detection by destroying key business processes. For example, the Java evasive memory horse destroys the key business process of Java instrumentation (such as the Attach process) in the Java agent process, making the memory horse detection tool unable to work properly (such as unable to Attach).
[0129] In some possible implementation manners, in step S1011 and step S1012, it can also be determined whether the loaded class is the risk class of the dynamically registered component type memory horse at the same time. For example, in step S1011 and step S1012, it can also be determined that the loaded class is the risk class of the dynamically registered component type memory horse when the first condition is met.
[0130] By adopting the above technical means, since the anti-injection of the non-evasive memory horse can be immunized after the anti-injection function of the non-evasive memory horse is enabled, the risk class of the memory horse can be obtained from the loaded classes of the process to be detected according to the second type of feature library only when the risk class of the memory horse is obtained for the first time, and when the risk class of the memory horse is obtained non-first, the risk class of the memory horse is obtained from the loaded classes of the process to be detected only according to the third type of feature library, reducing the number of risk classes for memory horse detection and further improving the efficiency of memory horse detection.
[0131] Figure 8 An application scenario example diagram for detecting a memory horse provided by an embodiment of the present application is shown, as Figure 8 shown. The online recruitment platform 300 is a Java web online recruitment website, and its functions include user registration, avatar upload, personal information management, resume management, and log recording. Both its avatar upload and log recording functions may be attacked by attackers to inject a Web shell, resulting in data leakage. The attacker discovers that its log recording function uses the log4j2 framework and uses the framework vulnerability to inject a memory horse using a Web shell tool. Assume that the tools used by the attacker at this time are BingXie and YiJian, and they respectively attempt to inject the corresponding memory horses. Among them, the memory horse injected by BingXie is a dynamically modified memory type memory horse (including a non-evasive memory horse or an evasive memory horse), and the memory horse injected by YiJian is a dynamically registered component type memory horse.
[0132] The administrator of the online recruitment platform uses the memory horse detection device 200 provided by the present application to perform memory horse detection, which may specifically include:
[0133] When the anti-injection function of the non-evasive memory horse is enabled, when an attacker attempts to inject a memory horse, due to the anti-injection function of the non-evasive memory horse being enabled, it is immune to the injection of the non-evasive memory horse, so that the non-evasive memory horse cannot be injected successfully, and only the evasive memory horse can be injected. The memory horse detection device 200 can extract the class bytecode of the loaded classes, and according to the third type of feature library, loop to determine whether the loaded classes meet any feature of the third type of feature library to determine the memory horse risk class.
[0134] When the anti-injection function of the non-evasive memory horse is disabled, the memory horse detection device 200 can extract the class bytecode of the loaded classes, and according to the second type of feature library and the third type of feature library, loop to determine whether the loaded classes meet any feature of the second type of feature library or the third type of feature library to determine the memory horse risk class.
[0135] It can also be determined whether the loaded class belongs to the memory horse risk class of the dynamically registered component type memory horse according to the first type of feature library and the first condition.
[0136] After determining the memory horse risk class, loop through the memory horse risk class to extract the class bytecode of each class.
[0137] The cumulative weight corresponding to each loaded class and Table 2 can be determined according to the class bytecode, and one or more memory horse risk classes can be obtained. For example, those with a cumulative weight in the interval [80, 300) can be determined as the AntSword memory horse, and those with a weight value greater than 1000 are the dynamically modified memory type memory horses, and the detection results are output. In some possible implementation manners, the injection tool type of the dynamically modified memory type memory horse can be further determined according to the characteristics of tools such as Behinder or AntSword (for example, the Behinder memory horse includes fixed encrypted bytecode).
[0138] Figure 9 The block diagram of a memory horse detection device provided by an embodiment of the present application is shown, as Figure 9 shown, the memory horse detection device 200 includes:
[0139] A class acquisition module 210, configured to acquire memory horse risk classes from the loaded classes of the process to be detected according to the class feature libraries of different memory horse types preset;
[0140] A code stream acquisition module 220, configured to acquire the bytecode stream corresponding to the memory horse risk class, and the bytecode stream includes at least one bytecode;
[0141] A weight determination module 230, configured to determine the cumulative weight of the bytecode stream corresponding to the memory horse risk class according to the preset risk feature library;
[0142] The detection module 240 is configured to determine the memory horse detection result of the process to be detected according to the cumulative weight.
[0143] Optionally, the memory horse type includes a dynamically registered component type memory horse, the class feature library includes a first type of feature library corresponding to the dynamically registered component type memory horse, and the class acquisition module 210 is further configured to:
[0144] When the first condition is satisfied, determine the risk class of the loaded class as a dynamically registered component type memory horse;
[0145] The first condition includes any one of the following conditions:
[0146] On the server of the process to be detected, there is no file corresponding to the loaded class, and the loaded class satisfies at least one feature in the first type of feature library;
[0147] When there is a file corresponding to the loaded class on the server of the process to be detected, the file corresponding to the loaded class is of a preset file type, and the loaded class satisfies at least one feature in the first type of feature library.
[0148] Optionally, the memory horse type includes a non-evasion type memory horse and / or an evasion type memory horse, the class feature library includes a second type of feature library corresponding to the non-evasion type memory horse and / or a third type of feature library corresponding to the evasion type memory horse, and the class acquisition module 210 is further configured to:
[0149] When the anti-injection function of the non-evasion type memory horse is turned off or when the memory horse risk class is obtained for the first time after the anti-injection function of the non-evasion type memory horse is turned on, obtain the memory horse risk class from the loaded classes of the process to be detected according to the second type of feature library; or,
[0150] When the anti-injection function of the non-evasion type memory horse is turned on and it is not the first time to obtain the memory horse risk class, obtain the memory horse risk class from the loaded classes of the process to be detected according to the third type of feature library.
[0151] Optionally, the class acquisition module 210 is further configured to:
[0152] When the loaded class satisfies at least one feature in the second type of feature library, determine the risk class of the loaded class as a non-evasion type memory horse, and the second type of feature library includes at least one of a first keyword, a second key class, a second key interface, and a second key annotation.
[0153] Optionally, the class acquisition module 210 is further configured to:
[0154] When the loaded class satisfies at least one feature in the third type of feature library, determine the risk class of the loaded class as an evasion type memory horse, and the evasion type memory horse circumvents memory horse detection by destroying key business processes, and the third type of feature library includes a third key class.
[0155] Optionally, the risk feature library includes at least one risk feature and a risk weight corresponding to each risk feature respectively. The weight determination module 230 is further configured to:
[0156] Successively obtain each target class bytecode and the corresponding target risk weight from the class bytecode stream. The target class bytecode satisfies any target risk feature in the risk feature library, and the target risk weight is the risk weight corresponding to the target risk feature;
[0157] Use the sum value of the target risk weights corresponding to each target class bytecode as the cumulative weight.
[0158] Optionally, the detection module 240 is further configured to:
[0159] Determine the memory horse detection result of the process to be detected according to the preset corresponding relationship between the weight and the memory horse type.
[0160] The device 200 provided by the embodiments of the present application can execute the various methods in the foregoing method embodiments, and implement the functions and beneficial effects of the various methods in the foregoing method embodiments, which will not be elaborated herein.
[0161] Figure 10 The block diagram of another memory horse detection device provided by the embodiments of the present application is shown. As Figure 10 shown, the memory horse detection device 200 further includes:
[0162] An anti-injection module 250, configured to:
[0163] In response to the user's operation of enabling the anti-injection function for non-evasive memory horses, perform security protection on the key business processes to enable the anti-injection function for non-evasive memory horses.
[0164] Optionally, performing security protection on the key business processes includes at least one of the following:
[0165] Encrypt the key files during the memory horse detection process;
[0166] Hide the key files during the memory horse detection process;
[0167] Recover the key files during the memory horse detection process when the key files during the memory horse detection process are unavailable.
[0168] The device 200 provided by the embodiments of the present application can execute the various methods in the foregoing method embodiments, and implement the functions and beneficial effects of the various methods in the foregoing method embodiments, which will not be elaborated herein.
[0169] Figure 11The following shows a schematic diagram of the hardware structure of the electronic device provided in the embodiments of the present application, as Figure 11 shown, at the hardware level, the electronic device includes a processor, and optionally, an internal bus, a network interface, and a memory. Among them, the memory may include a memory, such as a high-speed random access memory (Random-Access Memory, RAM), and may also include a non-volatile memory, such as at least one disk memory, etc. Of course, the electronic device may also include other hardware required for other services.
[0170] The processor, network interface, and memory can be interconnected through an internal bus, and the internal bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity, only a bidirectional arrow is used in this figure to represent it, but it does not mean that there is only one bus or one type of bus.
[0171] The memory stores programs. Specifically, the program may include program code, and the program code includes computer operation instructions. The memory may include a memory and a non-volatile memory, and provide instructions and data to the processor.
[0172] The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming a device for locating the target user at the logical level. The processor executes the program stored in the memory and specifically executes: Figures 1 - 7 the methods disclosed in the illustrated embodiments and implements the functions and beneficial effects of the various methods described in the foregoing method embodiments, which will not be elaborated herein.
[0173] The above is as in the present application Figures 1 - 7The method disclosed in the illustrated embodiment can be applied in or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor or instructions in the form of software. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.
[0174] The electronic device can also execute the various methods described in the foregoing method embodiments and achieve the functions and beneficial effects of the various methods described in the foregoing method embodiments, which will not be elaborated herein.
[0175] Of course, in addition to the software implementation manner, the electronic device of the present application does not exclude other implementation manners, such as a logic device or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, and may also be hardware or a logic device.
[0176] The embodiments of the present application also propose a computer-readable storage medium, where the computer-readable medium stores one or more programs, and when the one or more programs are executed by an electronic device including a plurality of application programs, the electronic device is caused to execute Figures 1 - 7 the method disclosed in the illustrated embodiment and achieve the functions and beneficial effects of the various methods described in the foregoing method embodiments, which will not be elaborated herein.
[0177] Among them, the computer-readable storage medium includes a read-only memory (ROM for short), a random access memory (RAM for short), a magnetic disk, an optical disc, or the like.
[0178] Furthermore, an embodiment of the present application also provides a computer program product. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the following process is implemented: Figures 1 - 7 The method disclosed in the illustrated embodiment realizes the functions and beneficial effects of each method described in the foregoing method embodiments, and will not be elaborated herein.
[0179] In summary, the foregoing are only the preferred embodiments of the present application, and do not limit the protection scope of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
[0180] The systems, devices, modules, or units illustrated in the foregoing embodiments may be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0181] Computer-readable media includes both permanent and non-permanent, removable and non-removable media and can be implemented by any method or technology for storing information. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can store information accessible by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.
[0182] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements not only includes those elements but also other elements not expressly listed, or elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising said element.
[0183] Each embodiment in this specification is described in a progressive manner. For the identical and similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and reference can be made to the relevant parts of the method embodiment for the related content.
Claims
1. A method for detecting memory horses, characterized in that, the method includes: Obtaining memory horse risk classes from the loaded classes of the process to be detected according to a class feature library of different memory horse types preset; Obtaining the class bytecode stream corresponding to the memory horse risk class, where the class bytecode stream includes at least one class bytecode; Determining the cumulative weight of the class bytecode stream corresponding to the memory horse risk class according to a preset risk feature library; Determining the memory horse detection result of the process to be detected according to the cumulative weight.
2. The method according to claim 1, characterized in that, the memory horse type includes a dynamically registered component type memory horse, and the class feature library includes a first class feature library corresponding to the dynamically registered component type memory horse; the obtaining memory horse risk classes from the loaded classes of the process to be detected according to a class feature library of different memory horse types includes: When a first condition is satisfied, determining that the loaded class is a risk class of the dynamically registered component type memory horse; The first condition includes any one of the following conditions: On the server of the process to be detected, there is no file corresponding to the loaded class, and the loaded class satisfies at least one feature in the first class feature library; When there is a file corresponding to the loaded class on the server of the process to be detected, the file corresponding to the loaded class is a preset file type, and the loaded class satisfies at least one feature in the first class feature library.
3. The method according to claim 2, characterized in that, the preset file type is JSP, and the first class feature library includes at least one of a first key class, a first key interface, and a first key annotation.
4. The method according to claim 1, characterized in that, the memory horse type includes a non-evasion type memory horse and / or an evasion type memory horse, and the class feature library includes a second class feature library corresponding to the non-evasion type memory horse and / or a third class feature library corresponding to the evasion type memory horse; the obtaining memory horse risk classes from the loaded classes of the process to be detected according to a class feature library of different memory horse types includes: When the anti-injection function of the non-evasion type memory horse is turned off or when the memory horse risk classes are obtained for the first time after the anti-injection function of the non-evasion type memory horse is turned on, obtaining memory horse risk classes from the loaded classes of the process to be detected according to the second class feature library; or, When the anti-injection function of the non-evasion type memory horse is turned on and the memory horse risk classes are obtained non-first time, obtaining memory horse risk classes from the loaded classes of the process to be detected according to the third class feature library.
5. The method according to claim 4, characterized in that, the obtaining memory horse risk classes from the loaded classes of the process to be detected according to the second class feature library includes: When the loaded class satisfies at least one feature in the second class feature library, determining that the loaded class is a risk class of the non-evasion type memory horse, and the second class feature library includes at least one of a first keyword, a second key class, a second key interface, and a second key annotation.
6. The method according to claim 4, characterized in that, Obtaining memory horse risk classes from the loaded classes of the process to be detected according to the third type of feature library includes: When at least one feature in the third type of feature library is satisfied by the loaded class, determining the loaded class as a risk class of the evasion-type memory horse, where the evasion-type memory horse circumvents memory horse detection by disrupting critical business processes, and the third type of feature library includes third critical classes.
7. The method according to claim 1, wherein, the risk feature library includes at least one risk feature and a risk weight corresponding to each risk feature respectively, and determining the cumulative weight of the class bytecode stream corresponding to the memory horse risk class according to the preset risk feature library includes: Sequentially obtaining each target class bytecode and the corresponding target risk weight from the class bytecode stream, where the target class bytecode satisfies any target risk feature in the risk feature library, and the target risk weight is the risk weight corresponding to the target risk feature; Taking the sum value of the target risk weights corresponding to each of the target class bytecodes as the cumulative weight.
8. The method according to claim 1, wherein, determining the memory horse detection result of the process to be detected according to the cumulative weight includes: Determining the memory horse detection result of the process to be detected according to the corresponding relationship between the preset weight and the memory horse type.
9. The method according to any one of claims 1 to 8, wherein, the method further includes: In response to the user's operation of enabling the anti-injection function for non-evasion-type memory horses, performing security protection on the critical business process to enable the anti-injection function for non-evasion-type memory horses.
10. The method according to claim 9, wherein, performing security protection on the critical business process includes at least one of the following: Encrypting the critical files during the memory horse detection process; Hiding the critical files during the memory horse detection process; Restoring the critical files during the memory horse detection process when the critical files during the memory horse detection process are unavailable.
11. A detection device for memory horses, wherein, the device includes: A class acquisition module configured to obtain memory horse risk classes from the loaded classes of the process to be detected according to the class feature library of different memory horse types preset; A bytecode stream acquisition module configured to obtain the bytecode stream corresponding to the memory horse risk class, where the bytecode stream includes at least one bytecode; A weight determination module configured to determine the cumulative weight of the bytecode stream corresponding to the memory horse risk class according to the preset risk feature library; A detection module configured to determine the memory horse detection result of the process to be detected according to the cumulative weight.
12. An electronic device, including: A processor; and A memory arranged to store computer-executable instructions, and when the executable instructions are executed, the processor is used to execute the steps of the memory horse detection method according to any one of claims 1-10.
13. A computer-readable storage medium stores one or more programs, and when the one or more programs are executed by an electronic device including a plurality of application programs, the electronic device is caused to execute the steps of the detection method of the memory horse according to any one of claims 1-10.