Multi-stage process operation and sample behavior confrontation system
Through multi-stage process operation and sample behavior confrontation system, combined with system identification mechanism and resource pool technology, and introducing information entropy sharding mechanism, the problems of obvious operation characteristics and unnatural execution timing in the existing technology are solved, and high concealment and natural execution characteristics are achieved.
Patent Information
- Application Number
- CN202510168960.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-06-10
AI Technical Summary
The existing process operation technology has loopholes in feature extraction, behavioral analysis and feature confrontation, resulting in obvious operational characteristics, unnatural execution timing, unbalanced resource use, and lack of behavioral camouflage mechanisms, making it difficult to avoid behavioral detection.
A multi-stage process operation and sample behavior confrontation system is adopted, combined with system identification mechanism and resource pool technology, to realize hidden data transmission and flexible execution, and a sharding mechanism based on information entropy is introduced to improve the concealment of the transmission process.
It significantly improves concealment, reuses the legal interface of the system, reduces detection risks; realizes natural execution characteristics, balances resource use, avoids centralized operation characteristics, and improves concealment and reliability of the transmission process.
Smart Images

Figure CN120124048A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security technology, and particularly relates to a multi-stage process operation and sample behavior confrontation system. Background Art
[0002] In the field of network security, process operation technology, as a key technology for system behavior analysis, its development process reflects the continuous escalation of technology confrontation. According to technical statistics, among the advanced samples discovered during the period from 2017 to 2021, the usage ratio of process operation technology has increased from 31% to 47%, and shows a trend of evolving from simple operations to complex and covert operations. The mainstream protection solutions are mainly based on technologies such as static feature recognition, dynamic behavior monitoring, and heuristic analysis, but there are still vulnerabilities in feature extraction, behavior analysis, and feature confrontation.
[0003] The existing process operation technologies mainly include the following categories:
[0004] (1) Data transmission technology based on system interfaces. Its main defects are that the system call features are obvious and easy to be monitored and discovered; the process behavior is abnormal and easy to trigger alarms; and a relatively high process access permission is required.
[0005] (2) Direct memory mapping technology. The existing problems include complex memory management, high implementation difficulty; limited system compatibility and limited applicable scenarios; and obvious memory access mode features.
[0006] (3) Customized loading technology. The main limitations are high implementation complexity, difficult development and maintenance; poor running stability and easy to cause the target process to crash; and at the same time, lack of an effective error handling mechanism.
[0007] (4) Pure memory operation technology. The challenges it faces are high technical requirements and high implementation thresholds; prominent system compatibility problems; and complex memory operations and easy to be detected.
[0008] These traditional technologies generally have the following problems:
[0009] (1) Obvious operation features: A large number of sensitive system interfaces are used, and the memory writing behavior features are obvious, which are easy to be discovered by the behavior monitoring of security products.
[0010] (2) Unnatural execution timing: The operation process shows sudden intensive operations, which are tightly coupled with the execution link timing and are significantly different from the execution mode of normal programs.
[0011] (3) Unbalanced resource usage: Memory allocation and interface calls are concentrated within a short period of time, and the system resource usage pattern is significantly abnormal.
[0012] (4) Lack of behavior camouflage mechanism: The existing technologies mainly focus on function implementation and rarely consider how to simulate the behavior characteristics of normal programs.
[0013] In view of this, there is an urgent need for a new type of countermeasure system that can effectively avoid behavior detection and has natural execution characteristics. In particular, it is necessary to solve key technical problems such as how to achieve covert data transmission, how to control the execution timing, and how to improve the concealment of the transmission process. Summary of the Invention
[0014] In order to overcome the deficiencies of the existing technologies, the purpose of the present invention is to provide a multi-stage process operation and sample behavior countermeasure system. By innovatively combining the system identification mechanism and the resource pool technology, the covert transmission and flexible execution of data are realized, and at the same time, a sharding mechanism based on information entropy is introduced to enhance the concealment of the transmission process.
[0015] To achieve the above purpose, the present invention adopts the following technical solutions:
[0016] A multi-stage process operation and sample behavior countermeasure system, characterized in that it includes an identification transmission module, a task scheduling engine module, and an information sharding optimization module;
[0017] Among them, the identification transmission module is used to achieve the covert transmission of data. Through the system identification information mechanism, such as embedding identification fields or dynamic identification allocation, a data transmission channel is established; the task scheduling engine module is used to dynamically distribute operation tasks and simulate natural execution behaviors; the information sharding optimization module intelligently shards information based on the frequency distribution, position weight, and size limit characteristics of the data, and optimizes the concealment and security through sharding strategies to ensure the efficiency and stability of the transmission process.
[0018] Further, the identification transmission module includes an external data input unit and an internal data recombination unit, which are respectively deployed at the sending end and the receiving end;
[0019] Among them, the external data input unit embeds the sharded data into the target object identification space through the identification field mechanism; the internal data recombination unit restores the data shards by parsing the target object identification field and temporarily stores the data using the reserved fields.
[0020] The working process of the information sharding optimization module includes the following steps:
[0021] (1) Preprocess the input data, count its feature distribution, generate a feature table and calculate the information amount to provide a basis for subsequent sharding;
[0022] (2) Initially shard the data according to a preset strategy, adjust the feature distribution by introducing a position weight factor, and the position weight factor is calculated according to the relative position ratio of the data segment in the whole, for example where \(i\) is the current fragment index and \(N\) is the total number of fragments, to increase the weight of the fragments in the covert priority positions, thereby optimizing the covertness of the fragmentation;
[0023] (3) Evaluate the fragmented data based on a set feature threshold, and determine the fragmentation boundary when the fragment meets the set conditions; otherwise, adjust the fragmentation range to meet the set requirements;
[0024] (4) Limit the size of a single piece of data to meet the transmission capacity of the target system, and set an appropriate overlapping area for fragmentation to improve the reliability of data restoration;
[0025] (5) Generate a unique identifier and check information for each data fragment, construct a transmission unit containing the fragmented data and the check information, and allocate it to an available transmission channel.
[0026] The working process of the identification transmission module includes the following steps:
[0027] (1) Enumerate the identification space of the target object, filter out the identification items with stable status, and establish access permissions;
[0028] (2) Operate according to the principle of least privilege to reduce the risk of abnormal operations, and complete data embedding by accessing the identification fields;
[0029] (3) Encode the fragmented data according to a specific format, and process special characters to meet the requirements, improving the stability of transmission;
[0030] (4) Disperse and store the encoded data in multiple identification items, and restore the data fragments through parsing operations;
[0031] (5) Reserve a storage structure in the target system, which includes a dynamically allocated memory pool, an identification mapping table, and a temporary data buffer. By managing access permissions and using a two-way verification mechanism, ensure the security of data transmission and the reliability of management.
[0032] The working process of the task scheduling engine module includes the following steps:
[0033] (1) Allocate a task control structure in the operation space of the target object, and set the key parameters of the structure, including the callback mechanism, execution period, and time window;
[0034] (2) Obtain the global resource pool object of the target through the system scheduling mechanism, and associate it with the task control structure to achieve resource reuse;
[0035] (3) Configure the task trigger time and the repeated execution interval, and disperse the execution timing by adjusting the time window to avoid the feature of intensive operations;
[0036] (4) Adjust the resource pool management structure and add the task control unit to the system scheduling queue;
[0037] (5) Activate the task control unit and complete the asynchronous execution of tasks through the system resource pool mechanism. The resource pool simulates normal system behavior by dynamically allocating thread resources, balancing task loads, and using the time window mechanism, avoiding characteristics of concentrated operations, thereby ensuring the concealment and naturalness of the execution process.
[0038] The present invention includes three core modules: an identification transmission module, a task scheduling engine module, and an information fragmentation optimization module. Among them, the identification transmission module is used to achieve cross-process transmission of data and establish a concealed transmission channel through the system identification mechanism; the task scheduling engine module is used to control the execution timing of the code and achieve asynchronous scheduling by using the system's native resource pool mechanism; the information fragmentation optimization module is used to perform fragmentation processing on the data to ensure the concealment and security of the transmission process.
[0039] The present invention has the following beneficial effects:
[0040] (1) Significantly improved concealment: Reusing legitimate system interfaces to reduce detection risks; minimizing permission requirements to reduce suspicious characteristics; achieving decentralized data transmission to avoid characteristics of concentrated operations.
[0041] (2) Naturalization of execution characteristics: Achieving asynchronous scheduling by using the resource pool mechanism; simulating normal behavior through flexible timing control; balanced resource usage to reduce abnormal characteristics.
[0042] (3) Innovation in technical implementation: The fragmentation strategy based on entropy improves transmission concealment; adopting a multi-level verification mechanism to ensure transmission reliability; modular design supports flexible expansion. Description of the Drawings
[0043] Figure 1 is a schematic structural diagram of the present invention.
[0044] Figure 2 is a structural diagram of the identification transmission module in the present invention.
[0045] Figure 3 is a structural diagram of the task scheduling engine module in the present invention.
[0046] Figure 4 is a flow chart of the information fragmentation optimization in the present invention. Detailed Embodiments
[0047] The technical solution of the present invention will be further described below in conjunction with the drawings. It should be noted that the following embodiments are only used to illustrate the present invention and are not used to limit the scope of the present invention.
[0048] A multi-stage process operation and sample behavior confrontation systemFigure 1 This is the structural schematic diagram of the present invention. When implemented, a modular design concept is adopted, mainly including three core functional modules: an identification transmission module, a task scheduling engine module, and an information sharding optimization module. Among them, the identification transmission module is responsible for the covert transmission of data, the task scheduling engine module realizes the control of the execution process, and the information sharding optimization module ensures the security of the transmission process. The following elaborates on the specific implementation methods of each module in detail.
[0049] As Figure 2 shown, the identification transmission module of the present invention includes two main parts: an external data input unit and an internal data recombination unit. The external data input unit is deployed at the sending end, and the internal data recombination unit is deployed at the receiving end. The two units realize the covert transmission of data through the system identification.
[0050] In a specific embodiment, the external data input unit first realizes the traversal and screening of the target object identification space through the identification space enumeration function. This unit screens out stable identification items through the identification query interface provided by the system and establishes an available identification resource pool. During the identification selection process, characteristics such as the stability and access frequency of the identification items are focused on to ensure that the selected identification items have high availability.
[0051] After the identification space enumeration is completed, the external data input unit enters the access permission control stage. This stage adopts the principle of minimum privilege, only applying for necessary access permissions to reduce the risk of abnormal operations. The permission control mechanism includes functions such as permission level division, temporary permission allocation, and dynamic permission adjustment to ensure the security of the data transmission process.
[0052] In the data encoding conversion stage, the external data input unit encodes the data to be transmitted in a specific format. The encoding process takes into account the system compatibility requirements, processes special characters, and performs necessary escape processing to improve the transmission stability. The encoding strategy can be dynamically adjusted according to the characteristics of the target system, supporting flexible switching between multiple encoding methods.
[0053] After the encoding is completed, the external data input unit performs the identification field embedding operation. This operation embeds the encoded data into the identification space of the target object according to the preset rules through the identification field mechanism provided by the system. The embedding process adopts a distributed storage strategy, dispersing the data in multiple identification items to reduce the data load of a single identification item.
[0054] Corresponding to the external data input unit, the internal data recombination unit first performs the identification parsing and restoration operation. This operation extracts the embedded data fragments by parsing the identification fields of the target object. The parsing process includes steps such as identification item positioning, data extraction, and format restoration to ensure the complete acquisition of the data.
[0055] After obtaining the data, the internal data reorganization unit stores the data in a temporary storage structure. This structure can include a dynamically allocated memory pool, an identity mapping table, and a temporary data buffer. A hierarchical caching strategy is adopted during the storage process to improve data access efficiency through a reasonable memory management mechanism.
[0056] In the data integrity verification stage, the internal data reorganization unit performs reliability verification on the reorganized data. The verification mechanism includes multiple dimensions such as data integrity check, format consistency verification, and version compatibility check to ensure the accuracy of data reorganization. When data anomalies are found, the system will trigger a retransmission mechanism to request the retransmission of damaged data segments.
[0057] Finally, the internal data reorganization unit uniformly manages the storage structures reserved by the system through the reserved structure management function. The management content includes structure allocation, space recycling, and access control, etc. This function adopts a two-way verification mechanism to improve the utilization efficiency of storage resources while ensuring data security.
[0058] Through the above design, the identity transmission module realizes the secure and covert transmission of data. This module effectively avoids the risk of feature recognition in traditional transmission methods through dispersed data storage, minimum privilege control, and multiple verification mechanisms, and improves the concealment and reliability of the transmission process.
[0059] As Figure 3 shown, the task scheduling engine module of the present invention adopts a hierarchical architecture design, mainly including four core components: a task distribution controller, a time window manager, a scheduling policy engine, and a resource pool manager, as well as a unified execution queue. This module realizes the asynchronous distribution and execution control of tasks through the system's native resource scheduling mechanism.
[0060] In the initialization stage of the task scheduling engine, the system first obtains the basic information of the target process through the system information query interface and locates its global resource pool object. The location of the resource management structure is determined by analyzing the memory structure layout of the process, and its status flag is verified to ensure it is in a normal working state, preparing for subsequent timing operations.
[0061] In the execution control structure construction stage, the system allocates a task control structure in the target process space and configures its key fields: the execution time is represented by relative time and can be set to a negative value (e.g., -10000000 represents a 1-second delay); the period parameter sets the repeat execution interval as needed, supporting values ranging from 0 (single execution) to 0x7FFFFFFF; the time window is used to control the maximum execution time of the task; the resource pointer points to the process global resource pool object; and the callback function points to the operation entry to be executed.
[0062] During the queue management phase, the system realizes the scheduling and management of tasks by maintaining two key queues, StartWindow and EndWindow, which adopt a doubly linked list structure. The time window manager is responsible for controlling the timing of task execution, and realizes the decentralization and naturalization of operations by dynamically adjusting the execution interval and window size. The scheduling policy engine allocates resources based on a multi-factor scoring mechanism, using the following scoring formula:
[0063] Score = α * LoadWeight + β * HistoryWeight + γ * PriorityWeight
[0064] Among them, α, β, and γ are weight coefficients, and the default values are 0.4, 0.3, and 0.3 respectively; LoadWeight reflects the current load situation, HistoryWeight represents the historical allocation record, and PriorityWeight represents the influence of priority. This algorithm comprehensively considers multiple factors such as the current state, historical records, priority, and system resource utilization rate, and realizes a more balanced and natural scheduling process.
[0065] As Figure 4 shown, the information sharding optimization module of the present invention realizes an entropy-based intelligent sharding mechanism. This mechanism realizes the optimized sharding of data by analyzing data characteristics, calculating position weights and entropy values, and improves the concealment and security of the transmission process. The specific implementation process of this module is elaborated in detail below.
[0066] In the data preprocessing phase, the system first conducts an initial analysis of the input data, establishes a frequency statistical table, and prepares for the subsequent entropy value calculation. This phase also initializes key data structures such as the entropy value table and the sharding array, providing basic support for the entire sharding process.
[0067] In the position weight calculation phase, the system introduces an innovative position weight factor. This factor uses the following calculation formula:
[0068]
[0069] Among them, W is the position weight factor, i represents the position index of the current data in the sequence, N represents the total length of the data sequence, and 0.15 is the preset weight coefficient. This position-based weight calculation method effectively improves the balance of data distribution.
[0070] Entropy value calculation is the core link of this module. The system uses an improved entropy calculation formula:
[0071] H(i) = -log 2 (P(xi)) + W
[0072] Among them, H(i) represents the weighted entropy value at position i, P(xi) represents the occurrence probability of byte xi, and W is the aforementioned position weight factor. This improved entropy calculation method comprehensively considers the frequency characteristics and position characteristics of the data, providing a more reliable theoretical basis for the fragmentation strategy.
[0073] In the fragmentation generation stage, the system establishes a strict fragmentation condition control mechanism: First, it requires that the average entropy value of the fragmentation be greater than the minimum threshold (default 0.3) to ensure that the fragmentation has sufficient concealment; second, it limits the size of a single fragmentation not to exceed the system limit (0x10000 bytes); finally, by dynamically adjusting the fragmentation boundary, it optimizes the size distribution of the fragmentation on the basis of meeting the above conditions.
[0074] To ensure the reliability of data transmission, during the verification information generation stage, the system generates a unique identifier and verification information for each data fragmentation. The identifier is generated using the SHA-256 algorithm to ensure the uniqueness of the fragmentation; the checksum is calculated using the CRC32 algorithm and is used to verify the integrity of the data. These information and the fragmented data together constitute the complete transmission packet structure.
[0075] In the transmission channel allocation stage, the system implements a weighted round-robin algorithm based on multiple factors. This algorithm realizes a more balanced and natural resource allocation by comprehensively considering factors such as the current load status of the channel, historical allocation records, and priorities. This intelligent channel allocation strategy effectively avoids the problem of unbalanced resource use that may be caused by traditional allocation methods.
[0076] Through the above design, the information fragmentation optimization module not only realizes the efficient fragmentation of data, but more importantly, through entropy analysis and intelligent allocation strategies, it significantly improves the concealment and reliability of data transmission. The implementation of this module provides important technical support for subsequent identity transmission and task scheduling.
[0077] Through the organic combination of the above three embodiments, the present invention realizes a highly concealed and highly adversarial process operation framework. It not only avoids the feature detection of traditional technologies, but also realizes a more natural execution mode, providing a new technical idea for sample behavior analysis. It should be noted that the above embodiments are only the preferred technical solutions of the present invention and are not used to limit the protection scope of the present invention. Those skilled in the art can also make various deformations and improvements without departing from the technical solutions of the present invention, and these deformations and improvements should also be regarded as the protection scope of the present invention.
Claims
1. A multi-stage process operation and sample behavior confrontation system, characterized in that: It includes an identification transmission module, a task scheduling engine module and an information fragmentation optimization module; Among them, the identification transmission module is used to realize the covert transmission of data and establish a data transmission channel through the system identification information mechanism; the task scheduling engine module is used to dynamically distribute operation tasks and simulate natural execution behaviors; the information sharding optimization module intelligently segments information based on the frequency distribution, position weight and size limit characteristics of the data, optimizes concealment and security through sharding strategies, and ensures the efficiency and stability of the transmission process.
2. A multi-stage process operation and sample behavior confrontation system according to claim 1, characterized in that: The identification transmission module includes an external data input unit and an internal data reorganization unit, which are respectively deployed at the sending end and the receiving end; Among them, the external data input unit embeds the fragmented data into the target object identification space through the identification field mechanism; the internal data reorganization unit restores the data fragments by parsing the target object identification field and uses the reserved field to temporarily store the data.
3. A multi-stage process operation and sample behavior confrontation system according to claim 1, characterized in that: The working process of the information fragmentation optimization module includes the following steps: (1) Preprocess the input data, count its feature distribution, generate a feature table and calculate the amount of information to provide a basis for subsequent sharding; (2) Perform preliminary sharding of the data according to the preset strategy, and adjust the feature distribution by introducing a position weight factor. The position weight factor is calculated based on the relative position ratio of the data fragment in the whole, and the weight of the fragment in the hidden priority position is increased, thereby optimizing the concealment of the sharding; (3) Evaluate the fragments based on the set feature thresholds and determine the fragment boundaries when the fragments meet the set conditions; otherwise, adjust the fragment range to meet the set requirements; (4) Limit the size of single-slice data to meet the transmission capacity of the target system and set appropriate slicing overlap areas to improve data restoration reliability; (5) Generate a unique identifier and verification information for each data shard, construct a transmission unit containing the shard data and verification information, and allocate it to the available transmission channel.
4. A multi-stage process operation and sample behavior confrontation system according to claim 1, characterized in that: The working process of the identification transmission module includes the following steps: (1) Enumerate the target object's identification space, filter out stable identification items, and establish access rights; (2) Operate using the principle of least privilege to reduce the risk of abnormal operations and complete data embedding by accessing identification fields; (3) Encode the data in a specific format and process special characters to meet the requirements to improve the stability of transmission; (4) The encoded data is stored in multiple identification items in a dispersed manner, and the data fragments are restored through parsing operations; (5) A storage structure is reserved in the target system, which includes a dynamically allocated memory pool, an identification mapping table, and a temporary data buffer. The security of data transmission and the reliability of management are ensured by managing access rights and using a two-way verification mechanism.
5. A multi-stage process operation and sample behavior confrontation system according to claim 1, characterized in that: The task scheduling engine module adopts a layered architecture design, including a task distribution controller, a time window manager, a scheduling strategy engine and a resource pool manager. The working process includes the following steps: (1) Allocate a task control structure in the target object’s operation space and set the key parameters of the structure, including the callback mechanism, execution cycle, and time window; (2) Obtain the target’s global resource pool object through the system scheduling mechanism and associate it with the task control structure to achieve resource reuse; (3) Configure the task trigger time and repeated execution interval, and adjust the time window to disperse the execution sequence and avoid operation-intensive features; (4) Adjust the resource pool management structure and add the task control unit to the system scheduling queue; (5) Activate the task control unit and complete the asynchronous execution of tasks through the system resource pool mechanism. The resource pool simulates normal system behavior by dynamically allocating thread resources, balancing task loads, and utilizing the time window mechanism to avoid centralized operation characteristics, thereby ensuring the concealment and naturalness of the execution process.