Static identification method and device of malicious code, storage medium and computer equipment

By statically scanning the code file, identifying and converting continuous mov instructions into plain text strings for comparison, the problem of obfuscated plain text string recognition in malware is solved, and fast and accurate malicious code recognition and system security protection are achieved.

CN120068067APending Publication Date: 2025-05-30CHENGDU MEGAYOU TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411980226.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The prior art is difficult to accurately identify obfuscated plain text strings in malware, resulting in difficulty in identifying malicious codes.

Method used

By statically scanning the code file, identifying continuous mov instructions, converting them into plain text strings for comparison, and determining whether it is a virus signature, thereby determining whether there is malicious code in the code file.

Benefits of technology

Without executing code, it can quickly and accurately identify obscured plaintext strings in the code file, avoid the risk of execution of potential malicious code and improve system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068067A_ABST
    Figure CN120068067A_ABST
Patent Text Reader

Abstract

The invention discloses a static recognition method and device for malicious codes, a storage medium and computer equipment. The method comprises the steps that a to-be-recognized code file is acquired; static scanning is conducted on the code file, continuous mov instructions are recognized from the code file in the scanning process, and a first target object is obtained according to the continuous mov instructions; performing plaintext character string conversion on the first target object to obtain a target plaintext character string, and judging whether the target plaintext character string is a virus feature code or not to obtain a first judgment result; and determining whether malicious codes exist in the code file or not based on the first judgment result. According to the method and the device, malicious code identification can be carried out under the condition that codes are not executed, the execution risk of potential malicious codes is avoided, and the obfuscated plaintext character strings in the code file can be rapidly and accurately identified while the system security is protected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular, to a method and apparatus for statically identifying malicious code, a storage medium, and a computer device. Background Art

[0002] With the rapid progress of computer technology and the wide popularization of the Internet, computer viruses have gradually evolved into complex and ever-changing malicious software. The makers of these malicious softwares constantly modify the virus codes, creating a large number of variants to avoid the detection of traditional virus signature databases, thus posing a significant challenge to accurately identifying the characteristics of malicious software.

[0003] A signature, as a binary string extracted from a virus sample by an anti-virus software and capable of uniquely identifying a virus, may be scattered in different sections of a file. However, current malicious software makers have adopted some more novel obfuscation means, such as obfuscation techniques based on equivalent code replacement and obfuscation methods based on plain text strings, etc. These means make malicious software more difficult to be identified by existing anti-virus softwares. Summary of the Invention

[0004] In view of this, the present application provides a method and apparatus for statically identifying malicious code, a storage medium, and a computer device. By identifying and analyzing consecutive mov instructions in a code file, and performing plain text string conversion on the consecutive mov instructions and comparing with virus signatures, potential malicious code can be detected. This method can identify malicious code without executing the code, avoiding the execution risk of potential malicious code, and can quickly and accurately identify the obfuscated plain text strings in the code file while protecting system security.

[0005] According to one aspect of the present application, there is provided a method for statically identifying malicious code, including:

[0006] Obtain a code file to be identified;

[0007] Perform a static scan on the code file, and identify consecutive mov instructions from the code file during the scan, and obtain a first target object according to the consecutive mov instructions;

[0008] Perform plain text string conversion on the first target object to obtain a target plain text string, and determine whether the target plain text string is a virus signature to obtain a first judgment result;

[0009] Based on the first judgment result, determine whether there is malicious code in the code file.

[0010] According to another aspect of the present application, there is provided a device for statically identifying malicious code, including:

[0011] A code file acquisition module, configured to acquire a code file to be recognized;

[0012] A scanning module, configured to perform static scanning on the code file, and during the scanning process, recognize consecutive mov instructions from the code file, and obtain a first target object according to the consecutive mov instructions;

[0013] A first judgment module, configured to perform plaintext string conversion on the first target object to obtain a target plaintext string, and judge whether the target plaintext string is a virus signature to obtain a first judgment result;

[0014] A result determination module, configured to determine whether there is malicious code in the code file based on the first judgment result.

[0015] According to another aspect of the present application, there is provided a storage medium, on which a computer program is stored, and when the program is executed by a processor, the above-mentioned static recognition method of malicious code is implemented.

[0016] According to still another aspect of the present application, there is provided a computer device, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor. When the processor executes the program, the above-mentioned static recognition method of malicious code is implemented.

[0017] By means of the above technical solution, a static recognition method and device, a storage medium, and a computer device for malicious code provided by the present application first acquire a code file to be recognized. Then, perform static scanning on the code file. During the scanning process, it is necessary to recognize consecutive mov instructions. If consecutive mov instructions are recognized, then these consecutive mov instructions can be used as the first target object. After determining the first target object, further, perform plaintext string conversion on the mov instructions included in the first target object to obtain the target plaintext string corresponding to the first target object. Then, compare the target plaintext string with a known virus signature library to obtain a first judgment result. Finally, make a final judgment according to the first judgment result to determine whether there is malicious code in the code file. The embodiments of the present application detect potential malicious code by recognizing and analyzing consecutive mov instructions in the code file, and performing plaintext string conversion and virus signature comparison on the consecutive mov instructions. This method can identify malicious code without executing the code, avoiding the execution risk of potential malicious code, and can quickly and accurately identify the obfuscated plaintext strings in the code file while protecting system security.

[0018] The above description is only an overview of the technical solution of the present application. In order to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the specific embodiments of the present application are specifically given below. Description of the Drawings

[0019] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0020] Figure 1 A flowchart showing a method for statically identifying malicious code provided by an embodiment of the present application is shown;

[0021] Figure 2 A structural schematic diagram of a device for statically identifying malicious code provided by an embodiment of the present application is shown;

[0022] Figure 3 A structural schematic diagram of a device of a computer device provided by an embodiment of the present application is shown. Detailed Embodiments

[0023] The present application will be described in detail below with reference to the drawings and in conjunction with the embodiments. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.

[0024] In this embodiment, a method for statically identifying malicious code is provided. As Figure 1 shown, the method includes:

[0025] Step 101, obtaining a code file to be identified.

[0026] Step 102, performing a static scan on the code file, and identifying consecutive mov instructions from the code file during the scan, and obtaining a first target object according to the consecutive mov instructions.

[0027] Step 103, performing a plaintext string conversion on the first target object to obtain a target plaintext string, and determining whether the target plaintext string is a virus signature to obtain a first judgment result.

[0028] Step 104, determining whether there is malicious code in the code file based on the first judgment result.

[0029] In the embodiments of the present application, first, code files to be recognized are obtained. These code files can come from various sources, such as user uploads, network downloads, or system internal generation. Then, static scanning is performed on the code files. Static scanning refers to analyzing the code files without executing the code. Specifically, the bytes or text content of the code files can be read and parsed. Through static scanning, a comprehensive analysis of the code files can be carried out without triggering potential malicious behaviors. During the scanning process, consecutive mov instructions need to be identified. This is because for consecutive plain text strings in code files, they are generally easy to be recognized as signature codes, but software may obfuscate such plain text strings, for example, assign and use the plain text strings in the form of multiple mov instructions. The mov instruction is an instruction for data transfer, and its function is to move data from one location to another. Therefore, by identifying consecutive mov instructions, it can be further determined whether there is potential malicious code in the code files. If consecutive mov instructions are identified, then these consecutive mov instructions can be used as the first target objects. It should be noted that each set of consecutive mov instructions can be used as a first target object. If there are multiple sets of consecutive mov instructions in the code file, then multiple first target objects can be correspondingly obtained.

[0030] After determining the first target objects, further, the mov instructions included in the first target objects can be converted into plain text strings, that is, the mov instructions are decoded, decrypted, or simply character-converted to convert binary or encoded data into a readable text form. After obtaining the target plain text strings corresponding to the first target objects, the target plain text strings can be compared with a known virus signature library to obtain a first judgment result to determine whether the target plain text strings contain known virus signatures. Here, a virus signature is a binary string that can be used to uniquely identify virus characteristics, and this binary string can be located in different sections of the code file.

[0031] Finally, a final judgment can be made according to the first judgment result to determine whether there is malicious code in the code file. Specifically, if the target plain text string matches the virus signature, it can be considered that there is malicious code in the code file.

[0032] By applying the technical solution of this embodiment, first, obtain the code file to be recognized. Next, perform a static scan on the code file. During the scan, it is necessary to identify consecutive mov instructions. If consecutive mov instructions are identified, then these consecutive mov instructions can be used as the first target object. After determining the first target object, further, perform plaintext string conversion on the mov instructions included in the first target object to obtain the target plaintext string corresponding to the first target object. After that, compare the target plaintext string with the known virus signature database to obtain the first judgment result. Finally, based on the first judgment result, a final judgment can be made to determine whether there is malicious code in the code file. In the embodiment of the present application, by identifying and analyzing consecutive mov instructions in the code file, and performing plaintext string conversion and virus signature comparison on the consecutive mov instructions, potential malicious code is detected. This method can identify malicious code without executing the code, avoiding the execution risk of potential malicious code, and can quickly and accurately identify the obfuscated plaintext strings in the code file while protecting system security.

[0033] In the embodiment of the present application, optionally, the step of "performing plaintext string conversion on the first target object to obtain the target plaintext string" in step 103 includes: for each mov instruction in the first target object, determine the target memory location corresponding to the mov instruction, and determine whether the target memory locations corresponding to the mov instructions are consecutive memories; when the target memory locations corresponding to the mov instructions are consecutive memories, splice the assignments corresponding to the mov instructions in the order of appearance of each mov instruction in the code file to obtain the byte array corresponding to the first target object; convert the byte array into the target plaintext string according to the target encoding method.

[0034] In this embodiment, for each mov instruction in the first target object, first parse the instruction to determine its target memory location. Specifically, the instruction operands can be parsed, especially those parts that specify the destination of data movement. The target memory location can be obtained by register indirect addressing, direct memory address, or address calculation based on a certain base address and offset. Once the target memory location of each mov instruction is determined, then determine whether these target memory locations form a continuous memory block. The continuity check can be specifically implemented by comparing the target memory locations of adjacent mov instructions. If there is a fixed increment between the target memory locations (for example, increasing by 1 byte each time, corresponding to a single-byte assignment), then these addresses can be considered continuous. When it is determined that the target memory locations corresponding to each mov instruction are continuous memory, the values assigned by each mov instruction (i.e., the data being moved) are concatenated in the order in which the mov instructions appear in the code file to form a byte array. Here, the "assignment" refers to the data operated on by the mov instruction. This data can be an immediate number (a value directly given in the instruction) or a value read from another register or memory location. The concatenation process can take the assignment of each mov instruction as an element of the byte array. After obtaining the byte array, it is converted into a plain text string according to the target encoding method. Here, the encoding method specifies how to convert the byte sequence into a readable character sequence. Common encoding methods include ASCII, UTF-8, UTF-16, etc. For example, find the characters corresponding to the byte values in the encoding table and combine these characters into a string, and the final obtained string is the target plain text string. In the embodiment of the present application, by analyzing consecutive mov instructions, when a series of mov instructions with consecutive target memory locations are detected, the assignments of these instructions are concatenated into a byte array and converted into a plain text string according to the target encoding method, which helps to reveal malicious code hidden in the code file.

[0035] In the embodiment of the present application, optionally, when performing the "static scanning of the code file" in step 102, the method further includes: identifying a suspicious code segment from the code file during the scanning process, and using the suspicious code segment as the second target object; obtaining the first register value change data of the target register before and after the execution of the second target object, and calculating the similarity between the first register value change data and the second register value change data of the register before and after the execution of each malicious code sample, and determining whether the second target object is a virus signature according to the similarity to obtain a second judgment result; correspondingly, step 104 includes: determining whether there is malicious code in the code file based on the first judgment result and the second judgment result.

[0036] In this embodiment, during the process of statically scanning a code file, in addition to identifying consecutive mov instructions to determine whether the plaintext strings in the code file are obfuscated, it is also possible to identify whether there is code that has been equivalently replaced. The main principle of equivalent code replacement is to use the assembly instructions of certain instructions with similar functions to replace the original instructions, or to replace them with a combination of several instructions. This will not change the original behavior of the code file, but can hide the malicious code features. Therefore, it is possible to analyze whether the changes to the registers before and after the execution of a piece of assembly code are the same as the changes to the registers before and after the execution of malicious code. If they are the same, it means that the behaviors of the code are consistent, that is, this piece of assembly code is malicious code.

[0037] Specifically, during the process of statically scanning a code file, preset rules or pattern matching techniques are used to identify possible malicious code fragments. These suspicious code fragments are used as the second target objects for further analysis. Among them, the suspicious code fragments can be identified by means of syntax and semantic analysis of the code file.

[0038] For each identified suspicious code fragment (i.e., the second target object), its execution can be simulated in a virtual environment, and the first register value change data of the target register before and after the execution is recorded. Here, the target register refers to the register whose register value is modified when the second target object is executed.

[0039] After obtaining the first register value change data corresponding to each second target object, further, the similarity between the first register value change data of each second target object and the second register value change data of known malicious code samples can be calculated. This can be achieved by comparing the similar features or patterns of the two data sets, such as using algorithms such as hash functions, cosine similarity, and Jaccard similarity. Here, the second register value change data can be obtained in the same way as the first register value change data.

[0040] Subsequently, based on the calculated similarity, it is determined whether the second target object is a virus signature, and then the second judgment result can be obtained. Specifically, a similarity threshold can be set. If the similarity exceeds this similarity threshold, it is considered that the second target object is malicious.

[0041] Finally, comprehensively consider the first judgment result and the second judgment result to determine whether the code file contains malicious code. In the embodiment of the present application, by identifying suspicious code fragments during the static scanning of the code file and analyzing the value changes of the target register before and after its execution, it is further determined whether the suspicious code fragment is a virus signature. This method combines the advantages of static analysis and dynamic simulation, improving the accuracy and efficiency of malicious code detection. At the same time, by comprehensively considering multiple judgment results, it is possible to more accurately determine whether there is malicious code in the code file.

[0042] In the embodiment of the present application, optionally, the "identifying suspicious code fragments from the code file during the scanning process" includes: during the scanning process, based on the known signatures existing in the preset signature library, matching the code in the code file to obtain multiple target matching positions; if there is an unmatched code fragment between any two adjacent target matching positions, then use the code fragment as the suspicious code fragment.

[0043] In this embodiment, during the process of scanning the code file, a preset signature library can be used as a reference to match the code in the code file line by line or block by block. The signature library contains known signatures, which can be signatures of malicious code or signatures of normal code. Specifically, the matching process can be implemented through string matching, regular expression matching, etc. Whenever a position matching a signature in the signature library is found in the code file, this target matching position can be recorded. After obtaining multiple target matching positions, further determine the code fragments that are located between adjacent target matching positions but are not matched by any signature in the signature library, and use these code fragments as suspicious code fragments. These fragments may contain hidden malicious behaviors, such as those obtained after equivalent code replacement, or they may be obfuscated codes deliberately inserted by malicious code authors to bypass signature detection. In the embodiment of the present application, by using a preset signature library for matching during the scanning of the code file and identifying the unmatched code fragments between adjacent target matching positions as suspicious code fragments, the accuracy and efficiency of malicious code detection are improved. This method combines the advantages of signature matching and code structure analysis, helping to discover potential malicious behaviors and take corresponding security measures.

[0044] In an embodiment of the present application, optionally, the step of "obtaining the first register value change data of the target register before and after the execution of the second target object" includes: obtaining the register value of the target register before the execution of the second target object; placing the second target object into a preset virtual processor environment, and executing the second target object based on the virtual processor environment to obtain the register value of the target register after the execution of the second target object; and obtaining the first register value change data based on the register value of the target register before the execution of the second target object and the register value of the target register after the execution.

[0045] In this embodiment, the first register value change data can be obtained in the following manner. First, before placing the second target object into the virtual processor environment for execution, obtain the initial value of the target register before execution. These initial values will serve as a benchmark for subsequent comparison of the register value changes after execution. To simulate the execution environment of the second target object, it can be placed into a preset virtual processor environment. This environment is isolated and will not affect the actual system or hardware. Executing the second target object in the virtual environment allows for safe observation of its behavior without causing damage to the actual system. The virtual processor environment may be a simulator, sandbox, or similar isolated environment. This environment includes key components capable of simulating the instruction set of the processor, register status, memory access, etc. After executing the second target object in the virtual processor, the value of the target register after execution can be correspondingly obtained.

[0046] After obtaining the values of the target register before and after the execution of the second target object, further compare these two values to calculate the change in the register value and record it as the first register value change data. Comparing the register values can be simple numerical comparison, bit operation, etc. In the embodiment of the present application, by executing the second target object in a preset virtual processor environment and comparing the value changes of the target register before and after execution, the first register value change data is obtained. This method combines the advantages of virtualization and register status analysis, helps to safely observe and analyze the behavior of suspicious code fragments, and provides important data support for subsequent malicious code detection.

[0047] In an embodiment of the present application, optionally, after the step of "obtaining the second judgment result", the method further includes: when the second judgment result indicates that the second target object is a virus signature, using the second target object as a new malicious code sample.

[0048] In this embodiment, when the second judgment result indicates that the second target object is a virus signature, subsequently, the second target object can be regarded as a new malicious code sample, that is, the second target object is added to the malicious code sample library for future malicious code detection and analysis. By continuously updating and expanding the malicious code sample library in the embodiments of the present application, it helps to improve the accuracy and efficiency of malicious code detection.

[0049] In the embodiments of the present application, optionally, after the second judgment result indicates that the second target object is not a virus signature, the method further includes: parsing the second target object to generate an abstract syntax tree, and identifying function call relationships, loop structures, and judgment conditions included in the abstract syntax tree to obtain multiple identification results corresponding to the abstract syntax tree; constructing sub-semantic feature vectors based on each identification result, and splicing the sub-semantic feature vectors corresponding to different identification results to obtain a semantic feature vector corresponding to the second target object; comparing the semantic feature vector corresponding to the second target object with the semantic feature vector corresponding to the malicious code sample to obtain multiple vector similarities, and determining whether the maximum vector similarity is greater than a preset similarity threshold. When the result is yes, it is determined that the second target object is a virus signature.

[0050] In this embodiment, if the second judgment result indicates that the second target object is not a virus signature, it means that the second target object is not obfuscated by means of equivalent code replacement, but it does not rule out being obfuscated by other means. Therefore, the second target object can be further identified. Specifically, first, parse the second target object to convert it into an intermediate representation form, that is, an abstract syntax tree (AST). The abstract syntax tree is a tree-like structure used to represent the syntax elements in the code and the relationships between them. After generating the abstract syntax tree, identify the key elements in the tree, including function call relationships, loop structures, and judgment conditions, etc. These elements are the key elements of the code logic and are also the objects that need to be focused on in malicious code detection. In one embodiment, the abstract syntax tree can be traversed and specific nodes or subtrees can be extracted. For example, for function call relationships, all function call nodes can be found and the relationships between the callers and the callee can be recorded; for loop structures and judgment conditions, the loop body and conditional judgment statements can be identified and their structures and contents can be recorded.

[0051] After identifying the key elements in the abstract syntax tree, construct sub-semantic feature vectors based on these elements. A sub-semantic feature vector is a vector used to represent the semantic features of a certain key element in a code snippet, and it can be obtained by encoding or quantifying the key element. Specifically, sub-semantic feature vectors can be constructed through steps such as feature extraction and feature encoding. Among them, feature extraction is to extract useful information from the key elements, such as function names, parameter types, loop counts, etc.; feature encoding is to convert this information into vector form for subsequent comparison and analysis. After constructing all sub-semantic feature vectors, further, perform a concatenation process on them to obtain the semantic feature vector corresponding to the second target object. The concatenation process can involve steps such as vector connection and normalization. Connection is to connect all sub-semantic feature vectors in sequence into a long vector; normalization is to eliminate the dimensionality differences between different sub-semantic feature vectors to make them comparable.

[0052] After obtaining the semantic feature vector of the second target object, compare it with the semantic feature vectors of each malicious code sample to calculate the similarity between them. This similarity is used to determine whether the second target object has similar semantic features to the malicious code sample. After calculating the vector similarity between the second target object and each malicious code sample, the one with the largest vector similarity can be found and compared with a preset similarity threshold. If the largest vector similarity is greater than the preset similarity threshold, it is considered that the second target object has similar semantic features to the malicious code sample, and thus it is determined as a virus signature. Among them, the preset similarity threshold can be a threshold determined based on experience or experiments, used to judge whether the similarity between two semantic feature vectors is high enough to consider that they belong to the same type of malicious code. In the embodiment of the present application, by parsing the second target object and generating an abstract syntax tree, identifying the key elements therein and constructing sub-semantic feature vectors, then concatenating the sub-semantic feature vectors to obtain the semantic feature vector corresponding to the second target object, and finally comparing it with the semantic feature vectors of malicious code samples to determine whether the second target object is a virus signature. This method combines the advantages of static analysis and semantic analysis and can more accurately identify malicious code from code files.

[0053] Further, as Figure 1 a specific implementation of the method, the embodiment of the present application provides a static recognition device for malicious code, as Figure 2 shown, the device includes:

[0054] A code file acquisition module, configured to acquire a code file to be recognized;

[0055] A scanning module for statically scanning the code file, identifying consecutive mov instructions from the code file during the scanning process, and obtaining a first target object based on the consecutive mov instructions;

[0056] A first judgment module for converting the first target object into a target plaintext string, determining whether the target plaintext string is a virus signature, and obtaining a first judgment result;

[0057] A result determination module for determining whether there is malicious code in the code file based on the first judgment result.

[0058] Optionally, the first judgment module is used for:

[0059] For each mov instruction in the first target object, determining the target memory location corresponding to the mov instruction, and judging whether the target memory locations corresponding to the mov instructions are consecutive memories;

[0060] When the target memory locations corresponding to the mov instructions are consecutive memories, splicing the assignments corresponding to the mov instructions in the order of appearance of each mov instruction in the code file to obtain a byte array corresponding to the first target object;

[0061] Converting the byte array into a target plaintext string according to the target encoding method.

[0062] Optionally, the device further includes a second judgment module; the second judgment module is used for:

[0063] When statically scanning the code file, identifying a suspicious code segment from the code file during the scanning process, and using the suspicious code segment as a second target object;

[0064] Obtaining the first register value change data of the target register before and after the execution of the second target object, calculating the similarity between the first register value change data and the second register value change data of the register before and after the execution of each malicious code sample, and judging whether the second target object is a virus signature according to the similarity, and obtaining a second judgment result;

[0065] Correspondingly, the result determination module is used for:

[0066] Based on the first judgment result and the second judgment result, determining whether there is malicious code in the code file.

[0067] Optionally, the second judgment module is further used for:

[0068] During the scanning process, based on the known feature codes existing in the preset feature code library, match the codes in the code file to obtain multiple target matching positions;

[0069] If there is an unmatched code segment among any two adjacent target matching positions, then use the code segment as the suspicious code segment.

[0070] Optionally, the second judgment module is further configured to:

[0071] Obtain the register value of the target register before the execution of the second target object;

[0072] Put the second target object into a preset virtual processor environment, and execute the second target object based on the virtual processor environment to obtain the register value of the target register after the execution of the second target object;

[0073] Based on the register value of the target register before the execution of the second target object and the register value of the target register after the execution, obtain the first register value change data.

[0074] Optionally, the device further includes a sample adding module; the sample adding module is used for:

[0075] After obtaining the second judgment result, when the second judgment result indicates that the second target object is a virus feature code, use the second target object as a new malicious code sample.

[0076] Optionally, the second judgment module is further configured to:

[0077] After the second judgment result indicates that the second target object is not a virus feature code, parse the second target object to generate an abstract syntax tree, and identify the function call relationships, loop structures, and judgment conditions included in the abstract syntax tree to obtain multiple recognition results corresponding to the abstract syntax tree;

[0078] Based on each recognition result, construct a sub-semantic feature vector, and splice the sub-semantic feature vectors corresponding to different recognition results to obtain the semantic feature vector corresponding to the second target object;

[0079] Compare the semantic feature vector corresponding to the second target object with the semantic feature vector corresponding to the malicious code sample to obtain multiple vector similarities, and determine whether the maximum vector similarity is greater than a preset similarity threshold. When the result is yes, determine that the second target object is a virus feature code.

[0080] It should be noted that for other corresponding descriptions of the functional units involved in the static malware recognition device provided in the embodiments of the present application, reference can be made to Figure 1 the corresponding descriptions in the method, which will not be elaborated here.

[0081] The embodiments of the present application also provide a computer device, which can specifically be a personal computer, a server, a network device, etc. As Figure 3 shown, the computer device includes a bus, a processor, a memory, and a communication interface, and may also include an input / output interface and a display device. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store location information. The network interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements the steps in the method embodiments.

[0082] Those skilled in the art can understand that Figure 3 the structure shown in

[0083] is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0084] In one embodiment, a computer-readable storage medium is provided. The computer-readable storage medium can be non-volatile or volatile, and stores a computer program. When the computer program is executed by the processor, it implements the steps in the above method embodiments.

[0085] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data that have been authorized by the user or fully authorized by all parties.

[0086] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0087] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0088] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A static identification method for malicious code, characterized in that: include: Get the code file to be identified; Static scanning is performed on the code file, and during the scanning process, continuous mov instructions are identified from the code file, and a first target object is obtained according to the continuous mov instructions; Performing plaintext string conversion on the first target object to obtain a target plaintext string, and determining whether the target plaintext string is a virus signature code to obtain a first determination result; Based on the first judgment result, it is determined whether there is malicious code in the code file.

2. The method according to claim 1, characterized in that The performing plaintext character string conversion on the first target object to obtain a target plaintext character string includes: For each mov instruction in the first target object, determine the target memory location corresponding to the mov instruction, and judge whether the target memory location corresponding to each mov instruction is a continuous memory; When the target memory location corresponding to each mov instruction is a continuous memory, the values ​​corresponding to each mov instruction are concatenated according to the order in which each mov instruction appears in the code file to obtain a byte array corresponding to the first target object; Convert the byte array into a target plaintext string according to the target encoding method.

3. The method according to claim 1, characterized in that When the code file is statically scanned, the method further includes: identifying suspicious code segments from the code file during the scanning process, and using the suspicious code segments as second target objects; Obtaining first register value change data of a target register before and after the execution of the second target object, and calculating similarity between the first register value change data and second register value change data of a register before and after the execution of each malicious code sample, and determining whether the second target object is a virus signature code according to the similarity to obtain a second determination result; Accordingly, determining whether there is malicious code in the code file based on the first judgment result includes: Based on the first judgment result and the second judgment result, it is determined whether there is malicious code in the code file.

4. The method according to claim 3, characterized in that The step of identifying suspicious code fragments from the code file during the scanning process includes: During the scanning process, the code in the code file is matched based on the known feature codes in the preset feature code library to obtain multiple target matching positions; If there is an unmatched code fragment between any two adjacent target matching positions, the code fragment is taken as the suspicious code fragment.

5. The method according to claim 3, characterized in that: The obtaining first register value change data of the target register before and after the execution of the second target object includes: Obtaining a register value of a target register before execution of the second target object; placing the second target object into a preset virtual processor environment, executing the second target object based on the virtual processor environment, and obtaining a register value of the target register after the execution of the second target object; The first register value change data is obtained based on the register value of the target register before the execution of the second target object and the register value of the target register after the execution.

6. The method according to any one of claims 3 to 5, characterized in that After obtaining the second judgment result, the method further includes: When the second judgment result indicates that the second target object is a virus signature code, the second target object is used as a new malicious code sample.

7. The method according to any one of claims 3 to 5, characterized in that When the second judgment result indicates that the second target object is not a virus signature, the method further includes: Parsing the second target object to generate an abstract syntax tree, and identifying function call relationships, loop structures, and judgment conditions contained in the abstract syntax tree to obtain multiple recognition results corresponding to the abstract syntax tree; Based on each of the recognition results, construct a sub-semantic feature vector, and concatenate the sub-semantic feature vectors corresponding to different recognition results to obtain a semantic feature vector corresponding to the second target object; The semantic feature vector corresponding to the second target object is compared with the semantic feature vector corresponding to the malicious code sample to obtain multiple vector similarities, and it is determined whether the maximum vector similarity is greater than a preset similarity threshold. When the result is yes, it is determined that the second target object is a virus signature code.

8. A static identification device for malicious code, characterized in that: include: A code file acquisition module is used to acquire the code file to be identified; A scanning module, used for statically scanning the code file, identifying continuous mov instructions from the code file during the scanning process, and obtaining a first target object according to the continuous mov instructions; A first judgment module is used to convert the first target object into a plaintext string to obtain a target plaintext string, and judge whether the target plaintext string is a virus signature code to obtain a first judgment result; A result determination module is used to determine whether there is malicious code in the code file based on the first judgment result.

9. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

10. A computer device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Generative artificial intelligence-based malicious code detection method and system

    CN121009547A