An intelligent software reverse analysis method and system based on large models
By acquiring multi-dimensional dynamic behavior and electrical signal data, and combining the attention mechanism of the big model for asymmetric matching, the problem of detecting hidden malicious code in the existing technology is solved, and the deep correlation analysis of cross-dimensional features is realized, which improves the accuracy and credibility of reverse analysis.
Patent Information
- Application Number
- CN202510607107.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-13
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-05-13
AI Technical Summary
The prior art is difficult to effectively detect hidden malicious code combined with hardware-level side channel attacks, and lacks the ability to deeply explore the correlation between the dynamic behavior of binary code and the underlying electrical signals, resulting in high false positive rates of analysis results and lacks the ability to deeply correlate cross-dimensional features.
By obtaining multi-dimensional dynamic behavior data and underlying electrical signal fluctuation data, combining dynamic instrumentation technology to generate execution trajectory sequences, and using the attention mechanism of the big model for timestamp synchronization, building a fusion data flow, performing asymmetric matching, adjusting the interpretation path weight of potential malicious instructions in binary code, and generating an inverse analysis report.
It realizes synchronous acquisition of software instruction flow and hardware physical behavior, accurately restores binary code execution logic, identify hidden malicious patterns that are difficult to detect by traditional methods, reduces false positive rates, and provides high-reliability reverse analysis results.
Smart Images

Figure CN120124060B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of large model technologies, and in particular, to an intelligent software reverse analysis method and system based on a large model. Background Art
[0002] In scenarios such as advanced persistent threat attacks and zero-day vulnerability exploitation, malicious code often evades traditional detection through means such as dynamic behavior obfuscation and hardware-level side-channel attacks. There is an urgent need for a technical solution that can synchronously analyze software instruction logic and hardware behavior characteristics and achieve automated and high-precision reverse analysis to identify hidden malicious code patterns.
[0003] Current mainstream solutions adopt a hybrid analysis method based on static features and dynamic behavior monitoring. By monitoring behavior data such as system call sequences and memory access patterns generated during the operation of the target program, pattern matching is performed in combination with a predefined malicious behavior rule library. Some solutions introduce hardware performance counter data as an auxiliary feature to improve the ability to identify abnormal behaviors.
[0004] This solution has insufficient capture granularity for hardware-level abnormal signals and is difficult to detect side-channel attack behaviors based on electromagnetic leakage and power consumption mutations; the behavior rule library relies on prior knowledge; the simple superposition of static and dynamic features results in a high false alarm rate in the analysis results and lacks the ability to perform in-depth correlation analysis of cross-dimensional features. Summary of the Invention
[0005] This application provides an intelligent software reverse analysis method and system based on a large model to solve the problem of low detection accuracy in the process of intelligent software reverse analysis in the prior art.
[0006] In a first aspect, this application provides an intelligent software reverse analysis method based on a large model, including:
[0007] During the execution of binary code, obtain multi-dimensional dynamic behavior data and underlying electrical signal fluctuation data, where the multi-dimensional dynamic behavior data includes memory read / write data, register state change data, and system call sequences;
[0008] Based on the multi-dimensional dynamic behavior data, combined with dynamic instrumentation technology, generate an execution trace sequence corresponding to the binary code execution process;
[0009] Perform preprocessing of timestamp synchronization on the underlying electrical signal fluctuation data and the execution trace sequence to generate a fused data stream;
[0010] Combined with the attention mechanism of the large model, perform asymmetric matching between the fused data stream and a preset malicious behavior feature library;
[0011] Adjust the interpretation path weight of potential malicious instructions in the binary code according to the matching result to generate a reverse analysis report.
[0012] Optionally, combining the attention mechanism of the large model, performing an asymmetric match between the fused data stream and a preset malicious behavior feature library, including:
[0013] Convert the fused data stream into a structured data stream according to the instruction execution order recorded in the execution trace sequence;
[0014] Analyze the correlation between the instruction operation codes and the amplitude of the electrical signal fluctuations in the structured data stream through the attention mechanism of the large model;
[0015] Based on the correlation analysis result, construct an instruction operation code sequence that meets the preset fluctuation conditions, and based on the instruction operation code sequence, determine candidate patterns in combination with a sliding window;
[0016] Perform an asymmetric match between the candidate pattern and the preset malicious behavior feature library, generate a matching probability value between the candidate pattern and the malicious behavior pattern, and use the matching probability value as the matching result.
[0017] Optionally, the analyzing the correlation between the instruction operation codes and the amplitude of the electrical signal fluctuations in the structured data stream through the attention mechanism of the large model includes:
[0018] Combine the instruction operation code of each record in the structured data stream with the corresponding electrical signal fluctuation amplitude into a multi-dimensional coding unit, and combine all the multi-dimensional coding units into a multi-dimensional coding unit sequence;
[0019] Perform cross-coding analysis on the multi-dimensional coding unit sequence through the attention mechanism of the large model, and calculate the association strength value between the semantic coding of each instruction operation code and the amplitude coding of the electrical signal fluctuation amplitude;
[0020] According to the association strength value, construct a dynamic mapping relationship between the instruction operation code and the electrical signal fluctuation amplitude, and use the dynamic mapping relationship as the correlation analysis result. Each instruction operation code in the dynamic mapping relationship is associated with at least one fluctuation amplitude interval.
[0021] Optionally, the performing cross-coding analysis on the multi-dimensional coding unit sequence through the attention mechanism of the large model and calculating the association strength value between the semantic coding of each instruction operation code and the amplitude coding of the electrical signal fluctuation amplitude includes:
[0022] Based on the multi-dimensional coding unit sequence, splice the semantic coding and the amplitude coding at the same time series position according to a preset ratio to generate an interactive coding pair, and combine all the interactive coding pairs into an interactive coding pair sequence;
[0023] Perform a bidirectional context scan on the sequence of interaction coding pairs through the attention mechanism of the large model to determine the dynamic interaction weights between each semantic coding and the corresponding amplitude coding within the current time series window;
[0024] Based on the dynamic interaction weights, calculate the feature similarity metric values between each semantic coding and the corresponding amplitude coding, and convert the feature similarity metric values into association strength values.
[0025] Optionally, based on the correlation analysis results, construct an instruction opcode sequence that meets the preset fluctuation conditions, and based on the instruction opcode sequence, combine a sliding window to determine candidate patterns, including:
[0026] According to the correlation analysis results, screen out instruction opcodes that meet the preset fluctuation amplitude threshold from the structured data stream, and all instruction opcodes that meet the preset fluctuation amplitude threshold form an instruction opcode sequence;
[0027] Perform a sliding window analysis on the instruction opcode sequence, and according to the analysis results, count the occurrence frequencies of opcode combinations within each window;
[0028] Mark the opcode combinations with occurrence frequencies exceeding the preset frequency threshold as candidate patterns.
[0029] Optionally, the adjusting the interpretation path weights of potential malicious instructions in the binary code according to the matching results to generate a reverse analysis report includes:
[0030] Based on the matching probability values, screen out potential malicious instruction combinations that exceed the preset risk threshold from the opcode combinations of the candidate patterns;
[0031] Perform cross-verification on the amplitude of the electrical signal fluctuation and the instruction opcode of the potential malicious instruction combination, and adjust the weight of the potential malicious instruction combination according to the verification results and determine the core analysis object;
[0032] Generate a reverse analysis report based on the instruction opcode sequence, the underlying electrical signal fluctuation data, and the matched malicious behavior characteristics in the core analysis object.
[0033] Optionally, the adjusting the weight of the potential malicious instruction combination according to the verification results and determining the core analysis object includes:
[0034] Divide the critical behavior phases according to the timing distribution characteristics of the potential malicious instruction combination;
[0035] Extract the associated fluctuation amplitude intervals corresponding to each instruction opcode in the potential malicious instruction combination from the dynamic mapping relationship;
[0036] When the actual fluctuation amplitude of at least one instruction opcode exceeds the corresponding associated fluctuation amplitude range, the interpretation path weight of the critical behavior stage is adjusted in an equal ratio according to the amplitude;
[0037] According to the adjusted interpretation path weight, re - sort the analysis priorities of each critical behavior stage, and take the critical behavior stage with the adjusted interpretation path weight higher than the preset weight threshold as the core analysis object.
[0038] In a second aspect, the present application provides an intelligent software reverse analysis system based on a large model, including:
[0039] An acquisition module, configured to acquire multi - dimensional dynamic behavior data and underlying electrical signal fluctuation data during the execution of binary code, where the multi - dimensional dynamic behavior data includes memory read - write data, register state change data, and system call sequences;
[0040] A first generation module, configured to generate an execution trace sequence corresponding to the execution process of binary code based on the multi - dimensional dynamic behavior data in combination with dynamic instrumentation technology;
[0041] A second generation module, configured to perform pre - processing of timestamp synchronization on the underlying electrical signal fluctuation data and the execution trace sequence to generate a fused data stream;
[0042] A matching module, configured to perform asymmetric matching of the fused data stream with a preset malicious behavior feature library in combination with the attention mechanism of the large model;
[0043] An adjustment module, configured to adjust the interpretation path weight of potential malicious instructions in the binary code according to the matching result to generate a reverse analysis report.
[0044] In a third aspect, the present application provides a computing device, including a processor and a memory, where a computer program is stored in the memory, and the processor is configured to run the computer program to execute any one of the methods of an intelligent software reverse analysis based on a large model in the first aspect.
[0045] In a fourth aspect, the present application provides a computer storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, they implement any one of the methods of an intelligent software reverse analysis based on a large model in the first aspect.
[0046] In this application, an intelligent software reverse analysis method based on a large model is provided. The method includes: during the execution of binary code, obtaining multi-dimensional dynamic behavior data and underlying electrical signal fluctuation data, where the multi-dimensional dynamic behavior data includes memory read / write data, register state change data, and system call sequences; based on the multi-dimensional dynamic behavior data, combining dynamic instrumentation technology to generate an execution trace sequence corresponding to the binary code execution process; performing preprocessing of timestamp synchronization on the underlying electrical signal fluctuation data and the execution trace sequence to generate a fused data stream; combining the attention mechanism of the large model to perform asymmetric matching between the fused data stream and a preset malicious behavior feature library; and according to the matching result, adjusting the interpretation path weight of potential malicious instructions in the binary code to generate a reverse analysis report.
[0047] The technical solution provided by this application has the following beneficial effects:
[0048] This application realizes the synchronous acquisition of software instruction flow and hardware physical behavior, providing a data basis for cross-dimensional analysis; accurately restores the binary code execution logic through dynamic instrumentation technology, retaining complete runtime context information; eliminates the time deviation between hardware signals and software behavior, constructs a spatio-temporal aligned joint feature expression; mines the deep correlation between instruction opcodes and electrical signal anomalies, identifying hidden malicious patterns that are difficult to detect by traditional methods; dynamically focuses on high-risk code segments, and outputs an interpretable analysis result containing a hardware evidence chain.
[0049] Furthermore, after structuring the fused data stream in the order of instruction execution, this application analyzes the correlation between instruction opcodes and electrical signal amplitudes through a large model, screens abnormal instruction sequences, and statistically counts the high-frequency combinations within a sliding window as candidate patterns, and finally performs probabilistic matching with the malicious feature library.
[0050] Moreover, it locates abnormal behavior segments through cross-domain correlation analysis of instructions and signals, combines sliding window statistics to enhance the ability to discover patterns, and uses probabilistic matching to reduce the false alarm rate, realizing accurate malicious code identification assisted by hardware.
[0051] These aspects or other aspects of this application will be more clearly understood in the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] In order to more clearly illustrate the technical solutions in the embodiments of this application or in the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0053] Figure 1Flowchart of an intelligent software reverse analysis method based on a large model provided by an embodiment of this application;
[0054] Figure 2 Schematic structural diagram of an intelligent software reverse analysis system based on a large model provided by an embodiment of this application;
[0055] Figure 3 Schematic structural diagram of a computing device provided by an embodiment of this application. Detailed implementation manners
[0056] To enable those skilled in the art to better understand the solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application.
[0057] In some processes described in the specification and claims of this application and the above-mentioned drawings, there are multiple operations that appear in a specific order. However, it should be clearly understood that these operations may not be executed in the order in which they appear in this article or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish each different operation, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions such as "first" and "second" in this article are used to distinguish different messages, devices, modules, etc., do not represent the sequence, and do not limit that "first" and "second" are of different types.
[0058] Researchers have found that existing software reverse analysis methods are difficult to effectively detect hidden malicious codes combined with hardware-level side-channel attacks and lack the ability to deeply explore the correlation between the dynamic behavior of binary codes and underlying electrical signals. Based on this, an embodiment of this application provides an intelligent software reverse analysis method based on a large model. This method can synchronously collect software behavior data and hardware electrical signals, construct a spatio-temporally aligned fusion data stream, and use the large model attention mechanism to achieve asymmetric matching of cross-dimensional features, so as to accurately identify potential malicious instructions and generate an interpretable analysis report. The technical solutions of this application can be applied to scenarios such as advanced persistent threat detection, zero-day vulnerability analysis, and hardware-assisted security auditing.
[0059] The technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative efforts shall fall within the protection scope of this application.
[0060] Figure 1The flowchart of an intelligent software reverse analysis method based on a large model provided by an embodiment of this application is as follows Figure 1 As shown, this method includes:
[0061] Step 101: During the execution of binary code, obtain multi-dimensional dynamic behavior data and underlying electrical signal fluctuation data, where the multi-dimensional dynamic behavior data includes memory read / write data, register status change data, and system call sequences.
[0062] In this step, the multi-dimensional dynamic behavior data refers to a set of behavior characteristics such as memory access records, register value change streams, and operating system call records generated during program operation. Memory read / write data refers to the access records of the memory space during the operation of the target program, including the physical address of the read / write operation, access length, operation timestamp, and read / write content, which are used to analyze the memory operation mode of the program and potential data theft behaviors. The register status change data records the historical changes of the values of hardware registers such as general registers and flag registers during program execution, including the register values before and after the change, the change instruction address, and the timestamp, reflecting the underlying execution state transition of the program. The system call sequence is a record of requests initiated by the program through the operating system interface, including the call type (such as file operation, network communication), parameter content, and return result arranged in chronological order, which is used to identify the sensitive behavior chain of the program. The underlying electrical signal fluctuation data represents the physical layer characteristic data such as the processor pin level change and bus signal amplitude collected through hardware probes.
[0063] In the embodiment of this application, a dynamic monitoring tool is used to capture the memory read / write operation addresses and contents, register value change history, and system call types and parameters during the operation of the target program. At the same time, a high-speed data acquisition card is used to record the voltage waveform data of the specified pins of the processor. The two types of data are marked with time stamps through a unified clock source and temporarily stored in the buffer.
[0064] For example, when analyzing a certain encrypted ransomware, it is recorded that it frequently calls the memory allocation function to apply for large chunks of memory (memory read / write data), continuously modifies specific register values (register status data), and periodically triggers file system operations (system call sequence); at the same time, regular amplitude mutations are synchronously collected on the processor power supply pins (electrical signal fluctuation data).
[0065] Step 102: Based on the multi-dimensional dynamic behavior data, combined with dynamic instrumentation technology, generate an execution trace sequence corresponding to the binary code execution process.
[0066] In this step, the dynamic instrumentation technology refers to a technical means of inserting probe code during program operation to record the execution path. The execution trace sequence represents a linear record chain composed of instruction opcodes and their context environments arranged in chronological order.
[0067] In the embodiments of the present application, lightweight monitoring instructions are inserted into the critical code segments of the target program to record in real time the machine instruction operation codes executed at each step and the corresponding memory addresses, reorganize the discrete monitoring point data into a continuous execution flow record in chronological order, and at the same time retain the register snapshot data when each instruction is executed.
[0068] For example, for the aforementioned ransomware, it is found through instrumentation that there are loop calls to memory copy instructions in its execution flow, and the target address is passed through a specific register before each copy. These instruction operation codes and register values are serialized into a timestamped execution trace.
[0069] Step 103: Perform preprocessing on the underlying electrical signal fluctuation data and the execution trace sequence for timestamp synchronization to generate a fused data stream.
[0070] In this step, the fused data stream represents a unified data structure after aligning the hardware signal sampling points and software instruction execution points along the time axis.
[0071] In the embodiments of the present application, the timestamp of the peak and valley feature points of the electrical signal data is extracted and matched with the instruction timestamps in the execution trace through a sliding window. When it is detected that the time difference between the hardware signal event and the software instruction event is less than the set tolerance, the signal amplitude is bound to the corresponding instruction to generate a fused data unit, and finally a time-aligned fused data sequence is formed.
[0072] For example, in the ransomware case, it is found that the execution moment of the memory copy instruction is always accompanied by a spike with an amplitude 1.3 times the standard value at the processor power supply pin (confirmed by comparing the instruction timestamp and the electrical signal mutation timestamp), and this correlation is recorded in the fused data unit.
[0073] Step 104: Combine the attention mechanism of the large model to perform asymmetric matching between the fused data stream and a preset malicious behavior feature library.
[0074] In this step, the large model attention mechanism refers to a technology that dynamically focuses on key feature combinations by calculating the correlation weights between the semantic features of instruction operation codes and electrical signal features. Its core is to establish a cross-domain correlation model between instructions and hardware signals to replace the traditional fixed-rule feature matching method. The malicious behavior feature library stores a standardized feature set of known attack patterns, including typical malicious instruction sequences, corresponding electrical signal fluctuation patterns, and their hazard levels, as the comparison benchmark for asymmetric matching. The feature sources include historical attack sample analysis and expert experience induction. Asymmetric matching represents a feature comparison method that considers different weight ratios of hardware features and software features.
[0075] In the embodiments of the present application, the fused data stream is input into a pre-trained large model. The model first performs semantic encoding on the instruction operation code and at the same time performs feature encoding on the amplitude of the electrical signal. The interaction weight matrix of the two types of encoding is calculated through the multi-head attention mechanism, and the instruction-signal combinations with weights exceeding the threshold are screened out. After calculating the similarity with the patterns in the malicious feature library, the matching probability is output.
[0076] For example, the model identifies a combined pattern of the loop memory copy instruction of ransomware and a power spike, and the matching degree with the feature of "memory filling ransomware" known in the feature library reaches 0.92 (the matching degree calculation formula is the weighted harmonic mean of semantic similarity and signal similarity).
[0077] Step 105: According to the matching result, adjust the interpretation path weight of the potentially malicious instructions in the binary code to generate a reverse analysis report.
[0078] In this step, the potentially malicious instructions refer to instruction segments that simultaneously meet the dual conditions of abnormal software behavior and abnormal hardware signals after cross-dimensional matching. Their typical features include: frequently occurring dangerous system calls, abnormal memory access patterns accompanied by sudden changes in the amplitude of electrical signals, etc. The interpretation path weight represents a quantitative index reflecting the suspicious degree of each code segment in the analysis process. The reverse analysis report includes the location markers (address / opcode) of malicious instructions, the corresponding electrical signal abnormality evidence (amplitude deviation / waveform diagram), the name of the matching malicious pattern, the behavior hazard level, and the confidence score, forming a complete analysis conclusion with mutual verification of software and hardware evidence.
[0079] In the embodiments of the present application, the weight of the suspicious instruction segment is initially assigned according to the matching probability, and the weight value is dynamically adjusted in combination with the abnormal amplitude of the electrical signal in the instruction segment. Finally, the analysis report is generated by sorting in descending order of the weight value. The original machine code of the high-weight instruction segment, the corresponding electrical signal abnormality evidence, and the description of the matching malicious pattern are marked in the report. When generating the reverse analysis report, the features of the new attack mode are injected into the malicious behavior knowledge graph, and the parameters of the large model are updated through incremental learning.
[0080] For example, the memory copy instruction segment of the aforementioned ransomware is given the highest weight of 0.95 due to both high matching probability and electrical signal abnormality, and is marked as "highly suspicious encryption behavior" in the report. At the same time, the system API sequence it calls and the corresponding power fluctuation curve are listed as evidence.
[0081] This method breaks through the limitation of traditional reverse analysis that only focuses on software behavior by synchronously analyzing the dynamic execution characteristics of binary code and underlying hardware signals. It uses a large model to establish a cross-dimensional feature correlation model, improves the recognition ability of malicious code using hardware-level stealth technologies, and the generated reverse analysis report contains double-verification information of both software instruction logic and hardware anomaly evidence, providing a highly credible judgment basis for security analysts.
[0082] To solve the problem that it is difficult to effectively correlate hardware behavior characteristics and software instruction characteristics in binary code reverse analysis, in some embodiments, step 104: Combining the attention mechanism of the large model, asymmetric matching the fused data stream with a preset malicious behavior feature library includes:
[0083] Step 201: Convert the fused data stream into a structured data stream according to the instruction execution order recorded in the execution trace sequence.
[0084] In step 201, the structured data stream refers to a standardized data sequence formed by reorganizing elements such as instruction operation codes and electrical signal fluctuation amplitudes in the fused data stream according to the execution time sequence. Each record of it contains three fields: the operation code type, the corresponding electrical signal amplitude, and the time sequence mark.
[0085] In the embodiments of the present application, the instruction operation codes and their associated electrical signal amplitudes at each time point are extracted from the fused data stream, arranged in the time stamp order of the execution trace sequence, and structured table data containing complete time sequence relationships is generated to ensure that the subsequent analysis can maintain the context relevance of the original execution flow.
[0086] Step 202: Analyze the correlation between the instruction operation codes and the electrical signal fluctuation amplitudes in the structured data stream through the attention mechanism of the large model.
[0087] In step 202, the instruction operation code is the machine instruction encoding extracted during the execution of the binary code, obtained by using dynamic instrumentation technology to capture the original machine code pointed to by the program counter in real time; the electrical signal fluctuation amplitude is the voltage change value measured by a high-speed data acquisition card on the processor power supply pin or a specific bus line. After time stamp synchronization, the two form paired records in the fused data stream. The instruction operation code sequence is a subsequence composed of instruction operation codes that meet the preset fluctuation conditions (such as the electrical signal amplitude exceeding the associated interval), arranged in the original execution order. This sequence retains the context execution environment of the abnormal instructions and is used for subsequent pattern statistical analysis. Its generation process must strictly follow the time sequence relationship of the execution trace sequence. The correlation between the instruction operation code and the electrical signal fluctuation amplitude refers to the quantitative correlation degree between the semantic feature and the physical signal feature established by the large model, reflecting the possibility of hardware signal anomalies caused during the execution of specific instructions.
[0088] In the embodiments of the present application, the large model performs a two-way scan on the structured data stream. First, it performs semantic encoding on the instruction operation code to generate feature vectors, and at the same time, normalizes and encodes the amplitude of the electrical signal. Then, it calculates the attention weight matrix of the two types of feature vectors. The higher the weight value, the stronger the correlation between the instruction and the electrical signal anomaly.
[0089] Step 203: Based on the correlation analysis result, construct an instruction operation code sequence that meets the preset fluctuation conditions. Based on the instruction operation code sequence, determine candidate patterns in combination with a sliding window.
[0090] In step 203, the preset fluctuation conditions refer to the electrical signal anomaly determination criteria obtained by analyzing historical data, including dimensions such as the amplitude mutation amplitude and the duration. The candidate pattern refers to an instruction combination fragment that meets the fluctuation conditions and appears frequently.
[0091] In the embodiments of the present application, filter out the instruction operation codes whose attention weights exceed the threshold, splice them into a candidate sequence in the execution order, scan the sequence with a fixed-length window sliding, count the occurrence frequencies of each instruction combination within the window, mark the combinations whose frequencies exceed the set value as candidate patterns, and record their occurrence positions.
[0092] Step 204: Asymmetrically match the candidate pattern with a preset malicious behavior feature library to generate a matching probability value between the candidate pattern and the malicious behavior pattern, and use the matching probability value as the matching result.
[0093] In step 204, the asymmetric match refers to a feature comparison method that considers the difference in the importance of instruction semantics. The matching probability value reflects the similarity between the candidate pattern and the known malicious pattern.
[0094] In the embodiments of the present application, calculate the weighted similarity between the instruction sequence feature vector of the candidate pattern and the template vector in the malicious feature library, where the weight of key instructions (such as system calls) is higher than that of ordinary instructions, and finally output a list of matching probability values for each candidate pattern.
[0095] The following is a specific example:
[0096] In the specific embodiment of analyzing the encrypted ransomware, first, the fusion data stream containing memory copy instructions (such as movsb) and corresponding power spikes of 1.3 times is converted into a structured data stream according to the chronological order of the execution trajectory. Each record contains the instruction opcode, the amplitude of the electrical signal, and a timestamp accurate to the microsecond level. Then, the correlation weight between each movsb instruction and the power spike is calculated through the attention mechanism of the large model. When the amplitude exceeds 1.3 times the standard value (preset fluctuation condition), these instructions are constructed into a sequence to be analyzed in the execution order. The "movsb - movsb - push - call - movsb" combination is found to appear 8 times in every 10 cycles (the frequency threshold is set to 5 times) by using a sliding window of length 5 to count this sequence, and it is marked as a candidate pattern. When comparing this pattern with the feature library, first calculate the similarity of the instruction sequence (0.89 based on the edit distance algorithm) and the similarity of the electrical signal waveform (0.94 based on the dynamic time warping algorithm). Finally, the matching probability value of 0.92 is obtained from the weighted harmonic mean formula of the two (the weight ratio is 6:4).
[0097] In the embodiment of the present application, by establishing a deep correlation model between instructions and electrical signals, combining dynamic sliding window statistics and weighted feature matching, accurate identification of hardware - level covert attacks is achieved. The generated matching results contain both software behavior characteristics and hardware anomaly evidence, providing a multi - dimensional determination basis for reverse analysis.
[0098] In order to further improve the accuracy of the correlation analysis between the instruction opcode and the amplitude fluctuation of the electrical signal, in some embodiments, step 202: The analysis of the correlation between the instruction opcode and the amplitude fluctuation of the electrical signal in the structured data stream through the attention mechanism of the large model includes:
[0099] Step 301: Combine the instruction opcode of each record in the structured data stream with the corresponding amplitude fluctuation of the electrical signal into a multi - dimensional coding unit, and combine all multi - dimensional coding units into a multi - dimensional coding unit sequence.
[0100] In step 301, the multi - dimensional coding unit refers to a composite data structure that encapsulates a single instruction opcode and the amplitude fluctuation of the electrical signal at its corresponding moment, containing information in three dimensions: the opcode type, the amplitude size, and the timestamp. The multi - dimensional coding unit sequence is a time - series data chain formed by arranging the instruction opcode collected at each moment and its corresponding amplitude fluctuation of the electrical signal in the execution time order. Each unit contains three key dimensions: the machine coding of the instruction opcode, the quantified amplitude of the electrical signal fluctuation at this moment, and the timestamp marked accurate to the microsecond level. This structure completely preserves the spatio - temporal correspondence relationship between software instructions and hardware signals.
[0101] In the embodiment of the present application, the instruction operation code and the electrical signal amplitude of each record are extracted from the structured data stream. Each pair of operation code - amplitude data is packed into an independent unit in the order of execution time, and then all the units are combined into an ordered sequence according to the time sequence, maintaining the spatio - temporal relationship of the original execution flow.
[0102] Step 302: Perform cross - coding analysis on the multi - dimensional coding unit sequence through the attention mechanism of the large model, and calculate the correlation strength value between the semantic coding of each instruction operation code and the amplitude coding of the electrical signal fluctuation amplitude.
[0103] In step 302, the correlation strength value is a quantization index calculated by the large model to reflect the matching degree between the instruction semantic features and the electrical signal features. The larger the value, the stronger the correlation between the instruction and the current electrical signal anomaly. The semantic coding is a vectorized representation obtained by the large model after extracting features from the original machine instruction operation code. Its generation process is as follows: First, the operation code is disassembled to obtain the mnemonic and operand types, and then it is converted into a dense vector reflecting the instruction function and semantics through a pre - trained language model. For example, a memory operation instruction will be encoded as a vector emphasizing data movement features, while an arithmetic instruction highlights numerical operation features. The amplitude coding is a digital expression after feature compression of the original electrical signal waveform. Its generation process is: First, the collected analog signal is discretely sampled, and statistical features such as peaks and means within each clock cycle are extracted, and then a low - dimensional feature vector is obtained through auto - encoder dimensionality reduction. This coding especially retains key waveform features such as signal mutations and periodic laws, facilitating cross - modal matching with instruction semantics.
[0104] In the embodiment of the present application, the large model first extracts semantic features from the instruction operation codes in the multi - dimensional coding unit sequence, and at the same time performs feature coding on the electrical signal amplitude, and then calculates the interaction strength of the two types of features through the attention weight matrix, and finally outputs the correlation strength score between each operation code and the corresponding amplitude.
[0105] Step 303: According to the correlation strength value, construct a dynamic mapping relationship between the instruction operation code and the electrical signal fluctuation amplitude, and use the dynamic mapping relationship as the result of the correlation analysis. Each instruction operation code in the dynamic mapping relationship is associated with at least one fluctuation amplitude interval.
[0106] In step 303, the dynamic mapping relationship is a correspondence rule table between instruction operation codes and typical electrical signal fluctuation ranges established based on the correlation strength values, which is used to determine whether abnormal electrical signals will be generated when specific instructions are executed. The specific process of constructing the dynamic mapping relationship is as follows: First, perform clustering analysis on all correlation strength values of the same type of instruction operation codes, use the density clustering algorithm to identify the main distribution range, and take the median of the strength values as the reference value for the correlation between the instruction and the electrical signal; then calculate the standard deviation of each strength value from the reference value, and take the range of plus and minus two standard deviations as the reasonable fluctuation range; finally, establish a triple mapping table of "instruction type - reference strength value - reasonable fluctuation range". For example, the reference strength value of the movsb instruction is set to 0.85, and the reasonable fluctuation range is 0.82 - 0.88. When the correlation strength value of the newly input instruction electrical signal exceeds this range, an abnormal alarm is triggered. This process realizes the adaptive update of the correlation relationship between instructions and electrical signals through dynamic statistical learning, ensuring that abnormal patterns generated by new types of attacks can be captured.
[0107] In the embodiment of the present application, all correlation strength value distributions of the same type of instruction operation codes are statistically analyzed. After clustering analysis, the corresponding reasonable amplitude fluctuation range is determined, and a mapping dictionary of "instruction type - amplitude range" is established. When the newly input instruction electrical signal exceeds this range, an abnormal alarm is triggered.
[0108] The following is a specific example:
[0109] In the embodiment of analyzing the ransomware, first, each record in the structured data stream that contains the movsb instruction and a 1.3 - fold power spike is combined into a multi - dimensional coding unit. The unit contains the instruction machine code, 1.3 - fold amplitude data, and an accurate timestamp, and is composed of a sequence of 200 units in the execution order; when analyzing through a large - model, first convert the movsb instruction into a semantic coding vector [0.7, 0.2, 0.5] that reflects the memory copy feature, and at the same time encode the 1.3 - fold amplitude as a waveform feature vector [0.8, 0.3]. Calculate the cosine similarity between the two to obtain an initial correlation strength value of 0.85; then adjust it through the attention mechanism weighting, and the final correlation strength value is 0.88 (adjustment formula: correlation strength value = initial similarity × instruction weight coefficient, where the weight coefficient of the movsb instruction is set to 1.04); after statistically analyzing the correlation strength values of all movsb instructions, construct the dynamic mapping relationship.
[0110] In the embodiment of the present application, by establishing a dynamic mapping relationship between instruction operation codes and electrical signal characteristics, precise quantitative analysis of hardware - level abnormal behaviors is realized, providing a quantifiable determination basis for identifying malicious codes combined with physical - layer attacks, and at the same time enhancing the interpretability of reverse - analysis results.
[0111] In some embodiments, to further improve the accuracy of calculating the correlation strength between the instruction opcode and the amplitude fluctuation of the electrical signal, step 302: performing cross-coding analysis on the multi-dimensional coding unit sequence through the attention mechanism of the large model, and calculating the correlation strength value between the semantic coding of each instruction opcode and the amplitude coding of the electrical signal amplitude fluctuation, includes:
[0112] Step 401: Based on the multi-dimensional coding unit sequence, splice the semantic coding and the amplitude coding at the same time series position according to a preset ratio to generate an interactive coding pair, and combine all the interactive coding pairs into an interactive coding pair sequence.
[0113] In step 401, the interactive coding pair refers to a composite feature vector formed by splicing the instruction semantic coding vector and the electrical signal amplitude coding vector at the same moment according to a fixed dimension ratio, where the semantic coding occupies the first 60% of the dimensions and the amplitude coding occupies the last 40% of the dimensions. The interactive coding pair sequence refers to an ordered set formed by arranging the composite feature vectors obtained by splicing the instruction semantic coding and the electrical signal amplitude coding corresponding to each execution moment in the original instruction execution order. Each interactive coding pair contains two key parts: the front segment is the feature vector extracted by the semantic understanding model from the instruction opcode (reflecting the instruction function semantics), and the rear segment is the amplitude coding vector obtained by feature compression of the corresponding electrical signal waveform at that moment (characterizing the hardware behavior characteristics). After being spliced according to a preset ratio, both retain their respective modal characteristics and establish cross-domain associations. The entire sequence strictly follows the actual execution timing of the binary code to ensure that subsequent analysis can accurately reflect the instruction-signal spatio-temporal association characteristics during program operation.
[0114] In the embodiments of the present application, the semantic coding and the amplitude coding at each time point are extracted from the multi-dimensional coding unit sequence, spliced head-to-tail according to a dimension ratio of 6:4 to generate an interactive coding pair containing complete cross-modal features, and then all the interactive coding pairs are combined into a new sequence structure according to the original execution timing.
[0115] Step 402: Perform bidirectional context scanning on the interactive coding pair sequence through the attention mechanism of the large model to determine the dynamic interaction weight between each semantic coding and the corresponding amplitude coding within the current time series window.
[0116] In step 402, the timing position represents the absolute execution order position of a single multi-dimensional coding unit in the overall sequence, reflecting the linear execution flow order of binary code instructions. Example: the position where the amplitude encoding of the operation code of the Nth instruction is located. The timing window represents a dynamic range interval centered on the current timing position, used to limit the context range window for relevance analysis. The size of the window is adjusted by the "distribution of instruction operation code types" (e.g., the window is enlarged for function call instructions). The dynamic interaction weight is a coefficient matrix calculated through the attention mechanism, reflecting the degree of association between semantic encoding and amplitude encoding. Each element in the matrix represents the interaction intensity between a specific instruction feature dimension and an electrical signal feature dimension.
[0117] In the embodiment of the present application, the large model performs forward and backward bidirectional scans on the interaction coding pair sequence. First, it calculates the dot product similarity between each semantic coding dimension and the amplitude coding dimensions within multiple front and rear timing windows, and then obtains the weight matrix through normalization, retaining the interaction relationships with weights exceeding the average value.
[0118] Step 403: Based on the dynamic interaction weight, calculate the feature similarity metric value between each semantic coding and the corresponding amplitude coding, and convert the feature similarity metric value into an association strength value.
[0119] In step 403, the feature similarity metric value is the cross-modal feature matching degree weighted by the dynamic weight, and its conversion process includes non-linear activation and normalization processing. The specific process of converting the association strength value: The specific process of converting the feature similarity metric value into an association strength value is as follows: Based on a preset linear mapping rule, project the original range of the feature similarity metric value to the [0,1] interval, where the projection formula is: association strength value = (feature similarity metric value - minimum similarity threshold) / (maximum similarity threshold - minimum similarity threshold). The minimum / maximum similarity threshold is determined by statistically analyzing the similarity distribution of all instruction operation codes and electrical signal amplitudes in the training dataset. When the feature similarity metric value exceeds the maximum threshold, the association strength value is taken as 1, and when it is lower than the minimum threshold, it is taken as 0. Exemplarily, taking the detection of stack overflow attacks as an example: The feature similarity metric value of analyzing the semantic coding of a certain strcpy instruction and the corresponding amplitude coding of the electrical signal is 0.85 (calculation process: calculate the similarity between the semantic coding vector [0.2,0.6] and the amplitude coding vector [0.3,0.5] through cosine similarity, obtaining a value of 0.936, and scaling it to 0.85 through normalization). Given that the minimum similarity threshold in the dataset is 0.2 and the maximum threshold is 0.9, then the association strength value = (0.85 - 0.2) / (0.9 - 0.2) = 0.93, indicating a high association between this instruction and the electrical signal anomaly.
[0120] In the embodiments of the present application, dynamic interaction weights are used to perform weighted fusion on semantic encoding and amplitude encoding, and the inner product of the weighted vectors is calculated as the initial similarity, which is linearly mapped to the standard correlation strength interval after being activated by the sigmoid (Sigmoid Function, sigmoid) function.
[0121] The following is a specific example:
[0122] In the embodiment of analyzing the encrypted ransomware, first, the semantic encoding vector [0.7, 0.2, 0.5] of the movsb instruction is concatenated with the amplitude encoding vector [0.8, 0.3] of 1.3 times the power spike according to the 6:4 dimension ratio to generate an interaction encoding pair in the form of [0.7, 0.2, 0.5, 0.8, 0.3], and the interaction encoding pairs of all 200 time series points are formed into a sequence according to the execution order; when scanning bidirectionally through the large model, calculate the attention weights of the current movsb instruction semantic encoding and the amplitude encoding within the front and back 5 time series windows respectively, and the interaction weight with the abnormal amplitude [0.8, 0.3] reaches 0.92 (the weight calculation formula is the dot product of the semantic encoding and the amplitude encoding after normalization); based on this weight, perform weighted calculation on the feature similarity. First, perform weighted fusion on the semantic encoding [0.7, 0.2, 0.5] and the amplitude encoding [0.8, 0.3] according to the weight of 0.92, then calculate the modulus of the fused vector to obtain the similarity metric value of 0.89, and finally convert it into the standard correlation strength value of 0.87 through the sigmoid function.
[0123] In the embodiments of the present application, through cross-modal feature fusion and dynamic weight calculation of interaction encoding pairs, the accurate quantification of the deep correlation relationship between instructions and electrical signals is realized, providing a reliable technical means for detecting covert attacks using processor microarchitecture defects.
[0124] To further improve the recognition accuracy of abnormal instruction patterns, in some embodiments, step 203: based on the correlation analysis result, construct an instruction opcode sequence that meets the preset fluctuation condition, and based on the instruction opcode sequence, combine a sliding window to determine candidate patterns, including:
[0125] Step 501: According to the correlation analysis result, screen out the instruction opcodes that meet the preset fluctuation amplitude threshold from the structured data stream, and all the instruction opcodes that meet the preset fluctuation amplitude threshold constitute the instruction opcode sequence.
[0126] In step 501, the preset fluctuation amplitude threshold refers to the abnormal determination standard of electrical signals set according to historical data analysis. When the fluctuation amplitude of the electrical signal corresponding to an instruction exceeds this standard, it is considered that the instruction has a suspicion of abnormal behavior.
[0127] In the embodiment of the present application, each instruction opcode and its associated electrical signal amplitude are extracted from the structured data stream, the amplitude is compared with the reasonable fluctuation range of this instruction type in the dynamic mapping relationship, and the abnormal instructions with amplitudes exceeding the upper limit of the range are screened out, and a sequence to be analyzed is formed according to the original execution order.
[0128] Step 502: Perform a sliding window analysis on the instruction opcode sequence. According to the analysis results, count the occurrence frequencies of opcode combinations in each window.
[0129] In step 502, the sliding window analysis means that an analysis window with a fixed length slides along the instruction sequence in order, and when the window stops each time, the complete instruction combination form within the window is extracted for statistics. The opcode combination refers to the complete sequence composed of consecutive instruction opcodes covered by the current sliding window. For example, when the window length is 5, the 5 consecutive instruction opcodes in each window (such as "mov-call-push-jmp-ret") are regarded as an independent combination, and it is required that the opcode type and arrangement order are exactly the same during statistics to be counted as the same combination. The occurrence frequency refers to the proportion of the number of times a specific instruction opcode combination is detected in all sliding windows during the sliding window analysis process, reflecting the degree of repeated occurrence of this combination during program execution. The specific calculation method is: count the number of occurrences of the target instruction combination in all valid sliding windows, and divide by the total number of sliding windows to obtain the ratio. For example, when the window length is 5 instructions, if a combination is detected 15 times in 100 window slides, its occurrence frequency is 0.15, and this value is used to judge whether the instruction combination has characteristics in terms of behavior patterns.
[0130] In the embodiment of the present application, the window length is set to 5 adjacent instructions, and it slides one by one along the instruction opcode sequence. Each time, the opcode type and arrangement order of 5 instructions within the window are used as an independent combination, and the occurrence times of each combination in all windows are recorded.
[0131] Step 503: Mark the opcode combinations with occurrence frequencies exceeding the preset frequency threshold as candidate patterns.
[0132] In step 503, the preset frequency threshold is the minimum number of abnormal repetitions set according to the baseline of normal program behavior, and is used to filter out accidental instruction combinations.
[0133] In the embodiment of the present application, count the occurrence frequencies of instruction combinations in all sliding windows, mark the combinations with occurrence times exceeding the set threshold as candidate patterns, and at the same time record the occurrence positions of these patterns in the sequence and the corresponding electrical signal abnormal characteristics.
[0134] The following is a specific example:
[0135] In the embodiment of analyzing the encrypted ransomware, first, 120 movsb instructions with the amplitude of all electrical signals exceeding 1.3 times the standard value are screened out from the structured data stream, and they are arranged in the sequence to be analyzed according to the execution order; a sliding window with a window length of 5 is used to scan this sequence, and a total of 116 valid windows are generated. It is statistically found that the specific combination of "movsb - movsb - push - call - movsb" appears in 58 windows (frequency = 58 / 116 = 0.5), far exceeding the preset frequency threshold of 0.3; the frequency threshold of 0.3 is set by rounding up after analyzing that the maximum occurrence frequency of this combination in 100 normal samples is 0.28, and the current frequency value of 0.5 indicates the abnormality of this combination. Combining the abnormality of the electrical signal amplitude corresponding to it, finally, this mode is marked as a highly suspicious candidate encrypted behavior mode.
[0136] In the embodiment of the present application, by combining the electrical signal anomaly threshold and the sliding window statistical method, malicious instruction patterns with repetitive characteristics are effectively identified, the detection ability against advanced persistent threat attacks is enhanced, and a reliable behavior pattern evidence chain is provided for reverse analysis.
[0137] In order to further improve the accuracy and credibility of the reverse analysis report, in some embodiments, step 105: adjusting the interpretation path weight of potential malicious instructions in the binary code according to the matching result to generate a reverse analysis report, including:
[0138] Step 601: Based on the matching probability value, screen out potential malicious instruction combinations that exceed the preset risk threshold from the opcode combinations of the candidate patterns.
[0139] In step 601, the preset risk threshold is the lowest judgment standard set according to the harm degree of different malicious behavior types, and is used to distinguish general suspicious behaviors and highly suspicious malicious behaviors. A potential malicious instruction combination refers to an instruction sequence that simultaneously meets the following conditions after being screened by the matching probability: composed of multiple consecutive or intermittently appearing suspicious opcodes; the overall matching probability exceeds the preset risk threshold; it shows repetitive or regular characteristics in the program execution flow. This combination reflects possible fragments of malicious behavior patterns, such as typical attack characteristics like encryption loops and code injection.
[0140] In the embodiment of the present application, the matching probability values are extracted from all candidate patterns, compared with the preset hierarchical risk threshold, instruction combinations that exceed the critical value are screened out, and at the same time, the malicious behavior types and probability values they match are recorded as the input data for subsequent in - depth analysis.
[0141] Step 602: Conduct cross-verification on the potential malicious instruction combinations for the amplitude of electrical signal fluctuations and the instruction operation codes. Adjust the weights of the potential malicious instruction combinations according to the verification results and determine the core analysis objects.
[0142] In step 602, cross-verification refers to verifying the credibility of candidate patterns by comparing the dynamic mapping relationship of instruction operation codes with the actual electrical signal fluctuation characteristics. The weight is a numerical index quantifying the malicious possibility of instruction combinations, and its generation process is as follows: The initial weight comes from the matching probability value and is adjusted according to the following rules after cross-verification: For each electrical signal of an operation code exceeding the dynamic mapping interval, the weight increases by 10% of the base value; when multiple consecutive operation codes are abnormal simultaneously, the weight increases exponentially according to the number of abnormal times; when a critical system call instruction is abnormal, the weight is additionally increased by 20%. The final weight value comprehensively reflects the software behavior anomaly degree and the sufficiency of hardware evidence. The core analysis objects are the set of instruction combinations with the highest risks determined through cross-verification, including the following elements: The potential malicious instruction combinations ranked among the top after weight adjustment; the corresponding abnormal electrical signal fluctuation evidence; the matching descriptions of known malicious behavior characteristics. These objects are the main basis for generating the reverse analysis report and represent the most likely real attack behaviors.
[0143] In the embodiment of the present application, for the high-probability instruction combinations screened out, extract the electrical signal fluctuation data corresponding to each operation code included therein, check whether all meet the abnormal conditions defined in the dynamic mapping relationship, and dynamically adjust the final weight value of the instruction combination according to the number and severity of the satisfied abnormal conditions.
[0144] Step 603: Generate a reverse analysis report based on the instruction operation code sequence, underlying electrical signal fluctuation data, and matching malicious behavior characteristics in the core analysis objects.
[0145] In the embodiment of the present application, use the top several instruction combinations with the highest weight values as the core analysis objects, extract their complete instruction sequences, corresponding electrical signal waveform diagrams, descriptions of malicious behavior characteristics matching the objects, and the verification basis during the weight adjustment process, and generate an analysis report containing text descriptions and visual evidence according to the standard template.
[0146] The following is a specific example:
[0147] In the embodiment of analyzing the encrypted ransomware, first, the "movsb-movsb-push-call-movsb" instruction combination with a matching probability of 0.92 is screened out from the candidate patterns as a potential malicious instruction combination (the preset risk threshold is 0.85); when cross-verifying this combination, it is found that the amplitude of the electrical signals corresponding to the 3 movsb instructions all exceed 1.3 times the upper limit of the dynamic mapping interval (the standard interval is 1.1 - 1.2 times). According to the rule of increasing the weight by 0.05 for each abnormal instruction, the initial weight of 0.92 is adjusted to 1.07 (0.92 + 3×0.05); finally, this combination is determined as the core analysis object, and the memory address distribution of this instruction sequence, the 1.3 times power spike waveform diagram, and the comparison result with the features of the "memory filling type ransomware" in the feature library are detailedly marked in the reverse analysis report, forming a complete encrypted behavior determination evidence chain. The calculation process of the weight value of 1.07 is: the basic matching probability of 0.92 plus the 0.05 weight increment for each abnormal movsb instruction (a total of 3), and the final value directly reflects the confidence level of this malicious behavior.
[0148] In the embodiment of the present application, through a multi-level verification and weight adjustment mechanism, it is ensured that the analysis results are supported by both software behavior logic and hardware physical evidence, greatly improving the detection accuracy of advanced malicious code and the credibility of the analysis results.
[0149] To further improve the accuracy and interpretability of malicious behavior analysis, in some embodiments, step 602: adjusting the weight of the potential malicious instruction combination according to the verification result and determining the core analysis object includes:
[0150] Step 701: Divide the key behavior stages according to the timing distribution characteristics of the potential malicious instruction combination.
[0151] In step 701, the key behavior stage refers to a continuous instruction interval divided according to the density of the potential malicious instruction combination in the execution trace sequence. The number of stages is dynamically determined by the spatio-temporal distribution of the instruction combination (no fixed number). Each stage must contain at least one potential malicious instruction combination and its associated context instructions before and after (usually covering a range of 50 - 200 instructions). The criticality determination criterion is that the stage contains more than 30% of high-risk instruction operation codes (based on the matching probability value of right 6).
[0152] In the embodiment of the present application, analyze the time interval and functional relevance of each instruction in the potential malicious instruction combination, and merge the instructions with a time interval less than the set value and related functions into the same stage to ensure that each stage contains a complete attack sub-process.
[0153] Step 702: Extract the associated fluctuation amplitude intervals corresponding to the instruction operation codes in the potential malicious instruction combination from the dynamic mapping relationship.
[0154] In step 702, the associated fluctuation amplitude interval is extracted from the dynamic mapping relationship and reflects the range of electrical signal fluctuations that should occur during the normal execution of a specific instruction operation code.
[0155] In the embodiment of the present application, the dynamic mapping relationship dictionary is queried according to the instruction operation code type, and the standard amplitude fluctuation upper and lower limits corresponding to the instruction are obtained as the reference values for anomaly determination.
[0156] Step 703: When the actual fluctuation amplitude of at least one instruction operation code exceeds the corresponding associated fluctuation amplitude interval, adjust the interpretation path weight of the critical behavior stage in proportion to the amplitude.
[0157] In step 703, the amplitude proportional adjustment refers to a dynamic adjustment mechanism in which the weight change amount is proportional to the abnormal amplitude of the electrical signal. The amplitude proportionality means that the weight adjustment ratio has a linear relationship with the percentage by which the actual electrical signal fluctuation amplitude exceeds the associated interval. Specifically: weight adjustment coefficient = 1 + (actual amplitude - upper limit of the interval) / upper limit of the interval × sensitivity factor (default 1.5). For example, when the actual amplitude exceeds the upper limit of the interval by 20%, the weight is increased by 30% (20% × 1.5). This proportional relationship is pre-calibrated by statistically analyzing the correlation between the abnormal amplitude of the electrical signal and the harm level in historical malicious code samples. The interpretation path weight is a numerical index that quantifies the suspiciousness of the critical behavior stage. Its generation process is as follows: The initial weight comes from the matching probability value. After being verified by the abnormal electrical signal, it is dynamically adjusted according to the formula "basic weight + ∑(abnormal amplitude × adjustment coefficient)". Among them, the abnormal amplitude is the percentage by which the actual electrical signal amplitude exceeds the upper limit of the dynamic mapping interval, and the adjustment coefficient is preset according to the instruction type. For example, the memory operation instruction is set to 0.01, and the system call instruction is set to 0.015. The final weight value comprehensively reflects the software behavior anomaly degree and the sufficiency of hardware evidence.
[0158] In the embodiment of the present application, calculate the percentage by which the actual electrical signal amplitude exceeds the associated interval, multiply this percentage by the basic adjustment coefficient to obtain the weight increment, and linearly superimpose it on the initial weight of the critical behavior stage.
[0159] Step 704: Re-sort the analysis priorities of each critical behavior stage according to the adjusted interpretation path weight, and use the critical behavior stages with the adjusted interpretation path weight higher than the preset weight threshold as the core analysis objects.
[0160] In step 704, the analysis priority is the processing order of key behavior stages sorted according to the weights of the interpretation paths. The higher the weight of a stage, the greater the likelihood that it contains real malicious behavior, and it will be preferentially displayed in the reverse analysis report along with a more detailed evidence chain. The priority setting follows the dual criteria of "descending weights + harm degree of attack types" to ensure that high-threat behaviors are analyzed with emphasis. The preset weight threshold is the minimum analysis standard set according to the harmfulness of different attack types.
[0161] In the embodiments of the present application, all key behavior stages are sorted in descending order of the adjusted weights, and the stages with weights exceeding the type-related thresholds are screened out to ensure that the core analysis objects have sufficient evidence of behavioral anomalies and bases for matching malicious features.
[0162] The following is a specific example:
[0163] In the embodiment of analyzing the encrypted ransomware, first, the code segment containing the loop movsb instruction is divided into the key encryption stage; the standard electrical signal amplitude range of the movsb instruction is queried from the dynamic mapping relationship to be 1.1 - 1.2 times the reference value, while the actually detected abnormal amplitude is 1.3 times (exceeding the upper limit by 8.3%); according to the adjustment rule of increasing the weight by 0.006 for every 1% exceeding (calculation formula: weight increment = exceeding percentage × 0.006), the weight of this stage is increased from the initial matching probability of 0.92 to 0.97 (0.92 + 8.3 × 0.006); after screening with the preset weight threshold of 0.95, this encryption stage is determined as the core analysis object.
[0164] In the embodiments of the present application, through the combination of spatio-temporal feature partitioning and dynamic weight adjustment, the refined analysis and credibility quantification of complex attack behaviors are realized, making the reverse analysis results have both the integrity of behavioral logic and the support of physical evidence.
[0165] Figure 2 The structural schematic diagram of an intelligent software reverse analysis system based on a large model provided for the embodiments of the present application is as Figure 2 shown. The system includes:
[0166] An acquisition module 21, configured to acquire multi-dimensional dynamic behavior data and underlying electrical signal fluctuation data during the execution of the binary code, where the multi-dimensional dynamic behavior data includes memory read and write data, register state change data, and system call sequences.
[0167] A first generation module 22, configured to generate an execution trace sequence corresponding to the execution process of the binary code based on the multi-dimensional dynamic behavior data in combination with the dynamic instrumentation technology.
[0168] The second generation module 23 is used to perform preprocessing of timestamp synchronization on the underlying electrical signal fluctuation data and the execution trajectory sequence to generate a fused data stream.
[0169] The matching module 24 is used to perform asymmetric matching between the fused data stream and a preset malicious behavior feature library in combination with the attention mechanism of the large model.
[0170] The adjustment module 25 is used to adjust the interpretation path weight of potential malicious instructions in the binary code according to the matching result to generate a reverse analysis report.
[0171] Figure 2 The described intelligent software reverse analysis system based on a large model can execute Figure 1 The described intelligent software reverse analysis method based on a large model in the illustrated embodiment, and its implementation principle and technical effects will not be elaborated further. For the intelligent software reverse analysis system based on a large model in the above embodiment, the specific ways in which each module and unit perform operations have been described in detail in the embodiment related to the method, and will not be elaborated here.
[0172] In a possible design, Figure 2 The intelligent software reverse analysis system based on a large model in the illustrated embodiment can be implemented as a computing device, such as Figure 3 as shown, the computing device may include a storage component 31 and a processing component 32;
[0173] The storage component 31 stores one or more computer instructions, where the one or more computer instructions are called and executed by the processing component 32.
[0174] The processing component 32 performs the above Figure 1 The intelligent software reverse analysis method based on a large model in the illustrated embodiment.
[0175] Among them, the processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above methods. Of course, the processing component may also be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components for executing the above methods.
[0176] The storage component 31 is configured to store various types of data to support the operation of the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read only memory (EEPROM), erasable programmable read only memory (EPROM), programmable read only memory (PROM), read only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0177] Of course, the computing device may also necessarily include other components, such as input / output interfaces, display components, communication components, etc.
[0178] The input / output interface provides an interface between the processing component and the peripheral interface module, and the above peripheral interface module may be an output device, an input device, etc.
[0179] The communication component is configured to facilitate communication between the computing device and other devices in a wired or wireless manner, etc.
[0180] Among them, the computing device may be a physical device or an elastic computing host provided by a cloud computing platform, etc. At this time, the computing device may refer to a cloud server, and the above processing component, storage component, etc. may be basic server resources leased or purchased from a cloud computing platform.
[0181] The embodiments of the present application also provide a computer storage medium storing a computer program, and when the computer program is executed by a computer, it can implement the above-mentioned Figure 1 intelligent software reverse analysis method based on a large model shown in the embodiments.
[0182] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again.
[0183] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative effort.
[0184] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0185] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. An intelligent software reverse analysis method based on a large model, characterized in that, Including: During the execution of binary code, obtain multi-dimensional dynamic behavior data and underlying electrical signal fluctuation data, where the multi-dimensional dynamic behavior data includes memory read / write data, register state change data, and system call sequences; Based on the multi-dimensional dynamic behavior data, combined with dynamic instrumentation technology, generate an execution trace sequence corresponding to the binary code execution process; Perform preprocessing of timestamp synchronization on the underlying electrical signal fluctuation data and the execution trace sequence to generate a fused data stream; Combined with the attention mechanism of the large model, perform asymmetric matching between the fused data stream and a preset malicious behavior feature library; According to the matching result, adjust the interpretation path weight of potential malicious instructions in the binary code to generate a reverse analysis report; The combination of the attention mechanism of the large model to perform asymmetric matching between the fused data stream and a preset malicious behavior feature library includes: Convert the fused data stream into a structured data stream according to the instruction execution order recorded in the execution trace sequence; Combine the instruction opcode of each record in the structured data stream with the corresponding electrical signal fluctuation amplitude to form a multi-dimensional coding unit, and combine all multi-dimensional coding units into a multi-dimensional coding unit sequence; Perform cross-coding analysis on the multi-dimensional coding unit sequence through the attention mechanism of the large model to calculate the correlation strength value between the semantic coding of each instruction opcode and the amplitude coding of the electrical signal fluctuation amplitude; According to the correlation strength value, construct a dynamic mapping relationship between the instruction opcode and the electrical signal fluctuation amplitude, and use the dynamic mapping relationship as the correlation analysis result. Each instruction opcode in the dynamic mapping relationship is associated with at least one fluctuation amplitude interval; According to the correlation analysis result, screen out the instruction opcodes that do not meet the preset fluctuation amplitude threshold from the structured data stream. All instruction opcodes that do not meet the preset fluctuation amplitude threshold form an instruction opcode sequence; Perform a sliding window analysis on the instruction opcode sequence. According to the analysis result, count the occurrence frequency of opcode combinations within each window; Mark the opcode combinations with an occurrence frequency exceeding the preset frequency threshold as candidate patterns; Perform asymmetric matching between the candidate patterns and a preset malicious behavior feature library to generate a matching probability value between the candidate patterns and malicious behavior patterns, and use the matching probability value as the matching result.
2. The method according to claim 1, characterized in that The cross-coding analysis of the multi-dimensional coding unit sequence through the attention mechanism of the large model to calculate the correlation strength value between the semantic coding of each instruction opcode and the amplitude coding of the electrical signal fluctuation amplitude includes: Based on the multi-dimensional coding unit sequence, splice the semantic coding and amplitude coding at the same time series position according to a preset ratio to generate an interactive coding pair, and combine all interactive coding pairs into an interactive coding pair sequence; Perform bidirectional context scanning on the interactive coding pair sequence through the attention mechanism of the large model to determine the dynamic interaction weight between each semantic coding and the corresponding amplitude coding within the current time series window; Based on the dynamic interaction weights, calculate the feature similarity metric values between each semantic encoding and the corresponding amplitude encoding, and convert the feature similarity metric values into association strength values.
3. The method according to claim 1, wherein Adjust the interpretation path weights of the potential malicious instructions in the binary code according to the matching results to generate a reverse analysis report, including: Based on the matching probability values, filter out the potential malicious instruction combinations that exceed the preset risk threshold from the opcode combinations of the candidate patterns; Perform cross-verification on the amplitude of the electrical signal fluctuations and the instruction opcodes of the potential malicious instruction combinations, adjust the weights of the potential malicious instruction combinations according to the verification results, and determine the core analysis object; Generate a reverse analysis report based on the instruction opcode sequence, underlying electrical signal fluctuation data, and matching malicious behavior characteristics in the core analysis object.
4. The method according to claim 3, wherein Adjust the weights of the potential malicious instruction combinations according to the verification results and determine the core analysis object, including: Divide the critical behavior phases according to the timing distribution characteristics of the potential malicious instruction combinations; Extract the associated fluctuation amplitude intervals corresponding to each instruction opcode in the potential malicious instruction combinations from the dynamic mapping relationship; When the actual fluctuation amplitude of at least one instruction opcode exceeds the corresponding associated fluctuation amplitude interval, adjust the interpretation path weights of the critical behavior phases in proportion to the amplitude; Re-sort the analysis priorities of each critical behavior phase according to the adjusted interpretation path weights, and use the critical behavior phases with the adjusted interpretation path weights higher than the preset weight threshold as the core analysis object.
5. An intelligent software reverse analysis system based on a large model, characterized in that, Including: An acquisition module for acquiring multi-dimensional dynamic behavior data and underlying electrical signal fluctuation data during the execution of the binary code, where the multi-dimensional dynamic behavior data includes memory read / write data, register state change data, and system call sequences; A first generation module for generating an execution trace sequence corresponding to the execution process of the binary code based on the multi-dimensional dynamic behavior data in combination with dynamic instrumentation technology; A second generation module for preprocessing the underlying electrical signal fluctuation data and the execution trace sequence for timestamp synchronization to generate a fused data stream; A matching module for asymmetrically matching the fused data stream with a preset malicious behavior feature library by combining the attention mechanism of a large model; An adjustment module for adjusting the interpretation path weights of the potential malicious instructions in the binary code according to the matching results to generate a reverse analysis report; Asymmetrically matching the fused data stream with a preset malicious behavior feature library by combining the attention mechanism of a large model, including: Convert the fused data stream into a structured data stream according to the instruction execution order recorded in the execution trace sequence; Combine the instruction opcode and the corresponding electrical signal fluctuation amplitude of each record in the structured data stream into a multi-dimensional coding unit, and combine all the multi-dimensional coding units into a multi-dimensional coding unit sequence; Perform cross-coding analysis on the multi-dimensional coding unit sequence through the attention mechanism of a large model, and calculate the association strength value between the semantic encoding of each instruction opcode and the amplitude encoding of the electrical signal fluctuation amplitude; Construct a dynamic mapping relationship between the instruction opcode and the amplitude fluctuation of the electrical signal according to the correlation strength value, and use the dynamic mapping relationship as the correlation analysis result. Each instruction opcode in the dynamic mapping relationship is associated with at least one amplitude fluctuation range; According to the correlation analysis result, filter out the instruction opcodes that do not meet the preset amplitude fluctuation threshold from the structured data stream. All the instruction opcodes that do not meet the preset amplitude fluctuation threshold form an instruction opcode sequence; Perform a sliding window analysis on the instruction opcode sequence, and according to the analysis result, count the occurrence frequencies of opcode combinations in each window; Mark the opcode combinations with occurrence frequencies exceeding the preset frequency threshold as candidate patterns; Perform an asymmetric match between the candidate patterns and a preset malicious behavior feature library to generate a matching probability value between the candidate patterns and the malicious behavior patterns, and use the matching probability value as the matching result.
6. A computing device, characterized in that, It includes a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement an intelligent software reverse analysis method based on a large model as described in any one of claims 1 to 4.
7. A computer storage medium, characterized in that, A computer program is stored, and when the computer program is executed by a computer, it implements an intelligent software reverse analysis method based on a large model as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Intelligent vulnerability mining platform construction method and system based on large model
CN119760730A