File security classification checking method, device and equipment based on windows operating system API HOOK, medium and product

By using API HOOK technology in Windows operating system, the confidentiality check of any application when reading and writing files is achieved, solving the problem of high-secret file leakage caused by third-party commercial software not performing confidentiality checks, and ensuring the security and compliance of the files.

CN120145446AActive Publication Date: 2025-06-13XIAN JINGXING RUICHUANG TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510223162.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-06-13
Estimated Expiration
2045-02-26

AI Technical Summary

Technical Problem

Third-party commercial software does not perform a confidential check when opening a confidential file, resulting in the leak of high-density file content to low-density users.

Method used

The file secret checking method based on the Windows operating system API HOOK is adopted. The driver module registers the callback function and the dll injection mechanism, modify the entry address of the target process API, and point it to a custom hook function, so that the secret judgment is made when the file is opened.

Benefits of technology

It realizes the secret check of any application when reading and writing files, prevents high-density files from leaking, and has simple logic, wide-ranging and fast functions, and small resource overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145446A_ABST
    Figure CN120145446A_ABST
Patent Text Reader

Abstract

The invention discloses a file security level checking method, device, equipment, medium and product based on an API HOOK of a windows operating system, and relates to the field of computer software application, the method comprises the steps that a callback function is registered by utilizing a driving module, when the windows operating system creates a process, a created process ID is sent to a service module in a user mode in the callback function, and when the process is created, the service module in the user mode is used for checking the security level of the file; receiving a service completion message of the service module; in the service module, based on a dll injection mechanism, injecting a dll injection program of the API HOOK module into the memory space of the created process; after the dll injection program is injected, an API HOOK module is utilized to modify an entry address of a target process API, and the entry address points to a self-defined hook function; the target process is the created process; and when the application opens the file corresponding to the target process, calling the security level judgment logic of the hook function, and judging whether the user security level can open the file corresponding to the target process, thereby avoiding the problem of high-density file leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer software applications, particularly to file security and confidentiality, and file classification inspection. Background Art

[0002] In many countries and regions, governments and industry organizations have clear laws and regulations regarding the protection of sensitive information. Setting classification levels is an important means to meet these compliance requirements. In certain industries (such as finance, healthcare, national defense, etc.), industry standards and best practices require the classification and protection of sensitive information.

[0003] Setting classification levels can ensure that only personnel with the corresponding classification level can access files of a specific classification level. Users with a lower classification level cannot read or modify files with a higher classification level, thus preventing sensitive information from being obtained by unauthorized personnel. Setting classification levels can limit the scope of information dissemination, ensure that sensitive information is shared only within the necessary scope, and reduce the risk of information leakage. In cross-departmental collaboration, setting classification levels can ensure that only personnel with the corresponding classification level permissions can access and process files of a specific classification level, thereby ensuring the security and integrity of information.

[0004] Through setting classification levels, the security awareness of employees and relevant personnel can be enhanced, enabling them to understand the importance and protection requirements of files with different classification levels. As part of security training and guidance, it helps employees correctly understand and implement information protection measures.

[0005] In summary, in a security and confidentiality system, setting classification levels for files is an important means to ensure information security, compliance, and risk management. Through setting classification levels, the access and dissemination of information can be effectively controlled, unauthorized access and information leakage can be prevented, while meeting the requirements of laws, regulations, and industry standards. In addition, setting classification levels also helps to improve work efficiency and the security awareness of employees, ensuring that information is properly protected throughout its life cycle.

[0006] Currently, the classification mechanisms of common software on the market all conduct file classification inspections on their own developed functions. For example, when downloading a file, it will check whether the user's classification level is higher than that of the file to be downloaded before downloading; when viewing the content of a file, it will also check whether the user's classification level is higher than that of the downloaded file. Its classification inspection ensures the classification security of files at the code level.

[0007] However, software is not an isolated system, and files or data often flow from one software system to another. For example, the self-developed software X has a classification mechanism. User A uses software X to create a file a.txt, sets the classification of the file to confidential, and saves the association relationship between the classification and the file. When user B uses software X to open the a.txt file, software X will check whether the classification of user B is higher than that of the a.txt file. Since X is self-developed software, this checking logic is written in the code of software X. If user B does not use software X to open the a.txt file but uses the Notepad software built into Windows to open it, and Windows Notepad does not have a confidential checking mechanism and can open the file, then the file will be leaked.

[0008] In summary, when an operator starts an application software to open a classified file, if the application is a third-party commercial software and these software do not consider the scenario of file classification during development, then these software will not perform classification checks when opening the file, resulting in the leakage of the content of high-classified files to low-classified users. Summary of the Invention

[0009] The purpose of this application is to provide a file classification checking method, device, device, medium and product based on the Windows operating system API HOOK to solve the problem that when a third-party commercial software opens a classified file, the content of high-classified files is leaked to low-classified users.

[0010] To achieve the above purpose, this application provides the following solutions:

[0011] In the first aspect, this application provides a file classification checking method based on the Windows operating system API HOOK, including:

[0012] Using a driver module to register a callback function. When the Windows operating system creates a process, the process ID created is sent to the service module in the user state within the callback function, and the service completion message of the service module is received; the driver module runs in the kernel layer of the Windows operating system; the created process is a task directly opened by the user in the Windows operating system;

[0013] Within the service module, based on the dll injection mechanism, the dll of the API HOOK module is injected into the memory space of the created process;

[0014] After the dll injection program is injected, use the API HOOK module to modify the entry address of the target process API and point the entry address to a custom hook function; the target process is the created process;

[0015] When the application opens the file corresponding to the target process, the confidentiality level judgment logic of the hook function is called to determine whether the user confidentiality level can open the file corresponding to the target process.

[0016] In a second aspect, the present application provides a file confidentiality level inspection device based on the windows operating system API HOOK, including:

[0017] A driver module, a service module, and an API HOOK module;

[0018] The driver module is used to register a callback function. When the windows operating system creates a process, the process ID created is sent to the service module in the user state within the callback function, and the service completion message of the service module is received; the driver module runs in the kernel layer of the windows operating system; the created process is a task directly opened by the user in the windows operating system;

[0019] The service module is used to inject the dll of the API HOOK module into the memory space of the created process based on the dll injection mechanism, and when the application opens the file corresponding to the target process, the confidentiality level judgment logic of the hook function is called to determine whether the user confidentiality level can open the file corresponding to the target process;

[0020] The API HOOK module is used to modify the entry address of the target process API and point the entry address to a custom hook function after the dll injection program is injected; the target process is the created process.

[0021] In a third aspect, the present application provides a computer device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the processor executes the computer program to implement the file confidentiality level inspection method based on the windows operating system API HOOK described in any one of the above.

[0022] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the file confidentiality level inspection method based on the windows operating system API HOOK described in any one of the above.

[0023] In a fifth aspect, the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the file confidentiality level inspection method based on the windows operating system API HOOK described in any one of the above.

[0024] According to the specific embodiments provided by the present application, the following technical effects are disclosed in the present application:

[0025] This application hooks the file operation application programming interface (API) of the Windows operating system and injects the target process of the program through dll injection, enabling any process started by the Windows operating system to perform classification checks when reading and writing files. The entire mechanism runs at the Windows operating system level, and the application is unaware. Due to hooking the underlying API of the Windows operating system, it is independent of the file opening method. Even when using third-party commercial software to open files, classification checks are required, thus avoiding the problem of leakage of highly classified files.

[0026] In addition, one hook in this application can take effect on all applications and programs, with simple logic, wide and rapid effects; this application does not need to monitor file read and write events of the entire file system, only needs to hook the system API, and has low system resource overhead; the core code of this application runs in the user mode of the Windows operating system, with less impact on the operating system. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0028] Figure 1 Flowchart of the file classification check method based on Windows operating system API HOOK provided by an embodiment of the present application;

[0029] Figure 2 Schematic diagram of the dll injection mechanism provided by an embodiment of the present application;

[0030] Figure 3 Schematic diagram of the basic principle of API HOOK provided by an embodiment of the present application;

[0031] Figure 4 Flowchart of the API HOOK provided by an embodiment of the present application;

[0032] Figure 5 Schematic diagram of the relationship between the user mode and the kernel mode provided by an embodiment of the present application;

[0033] Figure 6 Information interaction diagram of each module in the file classification check device based on Windows operating system API HOOK provided by an embodiment of the present application. Detailed implementation manners

[0034] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.

[0035] To make the above objects, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below with reference to the accompanying drawings and specific implementation manners.

[0036] The embodiment of the present application provides a file classification check method based on the windows operating system API HOOK. This method is executed by a computer device, which can be specifically executed by a computer device such as a terminal or a server alone, or jointly executed by a terminal and a server. In the embodiment of the present application, as Figure 1 shown, this method includes the following steps.

[0037] S1: Use the driver module to register a callback function. When the windows operating system creates a process, the process ID created is sent to the service module in the user state within the callback function, and the service completion message of the service module is received; the driver module runs in the kernel layer of the windows operating system; the created process is a task directly opened by the user in the windows operating system.

[0038] S2: In the service module, based on the dll injection mechanism, inject the dll of the API HOOK module into the memory space of the created process.

[0039] S3: After the dll injection program is injected, use the API HOOK module to modify the entry address of the target process API and point the entry address to a custom hook function; the target process is the created process.

[0040] S4: When the application opens the file corresponding to the target process, call the classification judgment logic of the hook function to judge whether the user classification can open the file corresponding to the target process.

[0041] In an exemplary embodiment, S1 can be replaced by the following steps.

[0042] S11: Inside the said driver module, register a custom callback function through PsSetCreateProcessNotifyRoutineEx to monitor the CreateProcess API calls of the Windows operating system;

[0043] S12: When the Windows operating system creates a process, trigger the said callback function. Inside the callback function, send the created process ID to the service module in the user mode. Meanwhile, the created process is suspended until the callback function receives the service completion message from the service module, and then the process state is restored to continue running the process.

[0044] In practical applications, the Windows operating system kernel provides a series of event notification (Notify) mechanisms and callback (Callback) mechanisms. Among them, the callback mechanism provides a general method for the driver to send and receive certain types of notifications. These notifications can be notifications generated by a change in the state of a certain component of the system, or notifications generated by a certain condition defined by the developer when the condition is met.

[0045] PsSetCreateProcessNotifyRoutineEx is an API in the Windows kernel used to register or remove a callback function to receive notifications when a process is created or destroyed in the kernel. The parameter NotifyRoutine of this function contains a pointer to the callback function, and when a process is created or destroyed, the kernel will call this function.

[0046] The operating mechanism of this driver module is as follows:

[0047] Step 1: This driver module runs in the kernel layer of the Windows operating system. Register a custom callback function through PsSetCreateProcessNotifyRoutineEx to monitor the system's CreateProcess API calls.

[0048] Step 2: When the Windows operating system creates a process, the callback function registered in Step 1 is triggered. Inside the callback function, send the created process ID to the service module in the user mode. Here, the created process is the task directly opened by the user in the Windows operating system, such as opening a Word document.

[0049] At this time, the created process is in the early initialization state, suspended by the operating system. Only a part of the process resources are initialized, and the execution of the user space code has not started yet. It waits for the callback function to return. Among them, the user space refers to the independent memory area allocated by the operating system for each process, which is used to store information such as the code, data, and stack of the process. In this application, this information is the code and data of the created process.

[0050] Step 3: The callback function receives the service completion message from the service module and then exits. The Windows operating system resumes the state of the newly created process, and the process continues to run.

[0051] In an exemplary embodiment, before S2, it further includes: taking the dll injection program as a Windows service and starting it as the system administrator; the dll injection program has the highest privilege.

[0052] In an exemplary embodiment, after S2, it further includes:

[0053] Create a remote thread in the target process and make the target process call LoadLibrary to trigger the dllmain function of the dll injection program.

[0054] HOOK the target process API based on the dllmain function.

[0055] After the HOOK is completed, send a service completion message to the driver module; the service completion message is HOOK success or HOOK failure.

[0056] In practical applications, in step 2 of the driver module, after the service module receives the created process ID sent by the driver module, based on the dll injection operation mechanism, it injects the dll program for API HOOK into the newly created process.

[0057] Since the dll program to be injected into all processes must have higher privileges, the injection program is made into a Windows service and started as the system administrator.

[0058] In the Windows operating system, each running process lives in its own program space (protected mode). In theory, each process running on the operating system does not interfere with each other, that is, each process will have an independent address space. For example, if process B modifies the data at the address 0x4000000, then the data at the address 0x4000000 of process C does not change with the modification of B, and process C may not have the memory at the address 0x4000000, that is, the operating system may not map this memory for process C.

[0059] Precisely because the address space of a process is independent (protected mode), it is very difficult to write an application program that can control other processes.

[0060] In this application, the so-called DLL injection means forcing program A to load a.dll given by program B and execute the code inside a.dll given by program B, as Figure 2 shown. Note that a.dll given by program B was not originally actively loaded by program A. However, when program B uses some means to make program A "load" a.dll, program A will execute the code in a.dll. At this time, a.dll enters the address space of program A, and the program logic of the a.dll module is designed by the developer of program B. Therefore, the developer of program B can modify the behavior of program A.

[0061] In this application, DLL injection is performed on the target process started in the Windows operating system in the service.

[0062] The DLL injection operation mechanism of this service module is as follows:

[0063] Step 1: The service module allocates a memory space in the target process and writes the path of the injected DLL into the memory space.

[0064] Step 2: Create a remote thread in the target process, that is, an execution unit within the process, and let the target process call LoadLibrary with the parameter being the memory space allocated in Step 1.

[0065] Step 3: LoadLibrary triggers the DllMain function in the DLL program. In this function, the Windows operating system's API is hooked.

[0066] Step 4: The service module sends a service completion message to the driver module. The driver callback function exits and the process resumes running. In this application, for this service completion message, the service module and the driver module can agree on a piece of data. For example, sending the number 0 indicates success, the number 1 indicates injection failure, the number 2 indicates hook failure, etc.

[0067] This technology has many advantages. First, it obtains the address space before the application program starts to execute. Second, since the application program is not a debugger, it is very easy to debug the application program and the injected DLL, and it is relatively difficult to be discovered.

[0068] In an exemplary embodiment, S4 can be replaced by the following steps.

[0069] S41: When the application opens the file corresponding to the target process, intercept the NTCreateFile API of the Windows operating system, and call the classification judgment logic of the hook function to determine the user classification and the file classification.

[0070] S42: Determine whether the user classification can open the file corresponding to the target process according to the user classification and the file classification.

[0071] In an exemplary embodiment, S42 can be replaced by the following steps.

[0072] S411: Determine whether the file classification is lower than the user classification. If so, execute S412; if not, execute S413.

[0073] S412: Call the NTCreateFile API to open the file corresponding to the target process.

[0074] S413: Directly return an error.

[0075] In practical applications, Windows API Hook is a technology used to intercept and modify the calls of application programs to Windows APIs. Through API Hook, developers can insert custom code before and after API calls to achieve various functions, such as debugging, monitoring, security protection, performance analysis, etc.

[0076] The basic principle of API Hook is to modify the entry address of the target API so that it points to a custom hook function, as Figure 3 shown.

[0077] This API HOOK module is the core module of this application. By hooking the file operation APIs of the Windows operating system, when the application opens a file, it intercepts the NTCreateFile API of the Windows operating system and calls the classification judgment logic.

[0078] As Figure 4 shown, the mechanism of this API HOOK module, that is, the specific process of step 3 in the service module is as follows: Step 1: When the application program calls the NTCreateFile API, it actually calls our hook function.

[0079] Step 2: Obtain the file classification to be opened from the database or other systems in the hook function.

[0080] Step 3: Obtain the user classification from the database or other systems in the hook function.

[0081] Step 4: If the file security level is lower than the user's security level, call the system's native NTCreateFile API, and the application will open the file normally. Otherwise, directly return an error.

[0082] Based on the same inventive concept, an embodiment of the present application further provides a file security level checking device based on the windows operating system API HOOK for implementing the file security level checking method based on the windows operating system API HOOK involved above. The implementation solutions provided by this device to solve problems are similar to the implementation solutions described in the above method. Therefore, the specific limitations in one or more embodiments of the file security level checking device based on the windows operating system API HOOK provided below can refer to the limitations on the file security level checking method based on the windows operating system API HOOK in the above text, and will not be repeated here.

[0083] In an exemplary embodiment, as Figure 5 - Figure 6 shown, the present application provides a file security level checking device based on the windows operating system API HOOK, including: a driver module, a service module, and an API HOOK module.

[0084] The driver module is used to register a callback function. When the windows operating system creates a process, the process ID created is sent to the service module in the user mode within the callback function, and the service completion message of the service module is received; the driver module runs in the kernel layer of the windows operating system; the created process is a task directly opened by the user in the windows operating system.

[0085] The service module is used to inject the dll of the API HOOK module into the memory space of the created process based on the dll injection mechanism, and when the application opens the file corresponding to the target process, call the security level judgment logic of the hook function to judge whether the user's security level can open the file corresponding to the target process.

[0086] The API HOOK module is used to modify the entry address of the target process API and point the entry address to a custom hook function after the dll injection program is injected; the target process is the created process.

[0087] In an exemplary embodiment, a computer device is provided, which may be a server or a terminal. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store file classification check data based on the operating system API HOOK. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a method for checking the classification of files based on the windows operating system API HOOK.

[0088] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the above method is implemented.

[0089] In an exemplary embodiment, a computer-readable storage medium is provided, storing a computer program, and when the computer program is executed by a processor, the above method is implemented.

[0090] In an exemplary embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the above method is implemented.

[0091] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAM), magnetoresistive random access memories (MRAM), ferroelectric random access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0092] In this application, all actions of obtaining signals, information, or data are carried out on the premise of complying with the corresponding data protection regulations and policies of the country where the location is located and obtaining authorization from the owner of the corresponding device.

[0093] The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0094] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0095] In this article, specific examples are used to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. To sum up, the content of this specification should not be construed as a limitation to this application.

Claims

1. A file confidentiality checking method based on Windows operating system API HOOK, characterized in that: The file classification checking method based on Windows operating system API HOOK includes: The driver module is used to register a callback function. When the Windows operating system creates a process, the created process ID is sent to the user-mode service module in the callback function, and a service completion message of the service module is received. The driver module runs in the kernel layer of the Windows operating system. The created process is a task directly opened by the user in the Windows operating system. In the service module, based on the dll injection mechanism, the dll injection program of the API HOOK module is injected into the memory space of the created process; After the dll injection program is injected, the API HOOK module is used to modify the entry address of the target process API and point the entry address to the custom hook function; the target process is the created process; When the application opens the file corresponding to the target process, the confidentiality level judgment logic of the hook function is called to judge whether the user's confidentiality level is sufficient to open the file corresponding to the target process.

2. The file confidentiality checking method based on Windows operating system API HOOK according to claim 1 is characterized in that: The driver module is used to register the callback function. When the Windows operating system creates a process, the created process ID is sent to the user-mode service module in the callback function, and the service completion message of the service module is received, which specifically includes: In the driver module, a custom callback function is registered through PsSetCreateProcessNotifyRoutineEx to monitor the CreateProcessAPI call of the Windows operating system; When the Windows operating system creates a process, the callback function is triggered, and the created process ID is sent to the user-state service module in the callback function. At the same time, the created process is suspended until the callback function receives the service completion message from the service module, restores the process state, and continues to run the process.

3. The file confidentiality checking method based on Windows operating system API HOOK according to claim 1 is characterized in that: In the service module, based on the dll injection mechanism, the dll injection program of the API HOOK module is injected into the memory space of the created process, which also includes: The dll injection program is used as a windows service and started as a system administrator; the dll injection program has the highest authority.

4. The file confidentiality checking method based on Windows operating system API HOOK according to claim 1 is characterized in that: In the service module, based on the dll injection mechanism, the dll injection program of the API HOOK module is injected into the memory space of the created process, and then it also includes: Create a remote thread in the target process, and make the target process call LoadLibrary to trigger the dllmain function of the dll injection program; HOOK the target process API based on the dllmain function; When HOOK is completed, a service completion message is sent to the driver module; the service completion message indicates HOOK success or HOOK failure.

5. The file confidentiality checking method based on Windows operating system API HOOK according to claim 1 is characterized in that: When the application opens the file corresponding to the target process, the confidentiality level judgment logic of the hook function is called to judge whether the user's confidentiality level is sufficient to open the file corresponding to the target process, specifically including: When the application opens the file corresponding to the target process, the NTCreateFileAPI of the Windows operating system is intercepted, and the confidentiality level judgment logic of the hook function is called to determine the user confidentiality level and the file confidentiality level; It is determined whether the user level is sufficient to open the file corresponding to the target process according to the user level and the file level.

6. The file confidentiality checking method based on Windows operating system API HOOK according to claim 5 is characterized in that: Determining whether the user level can open the file corresponding to the target process according to the user level and the file level specifically includes: Determining whether the file classification level is lower than the user classification level; If yes, call the NTCreateFile API to open the file corresponding to the target process; If not, return an error directly.

7. A file confidentiality checking device based on Windows operating system API HOOK, characterized in that: The file confidentiality level checking device based on Windows operating system API HOOK includes: a driver module, a service module and an API HOOK module; The driver module is used to register a callback function. When the Windows operating system creates a process, the created process ID is sent to the user-mode service module in the callback function, and a service completion message of the service module is received. The driver module runs in the kernel layer of the Windows operating system. The created process is a task that the user directly opens in the Windows operating system. The service module is used to inject the dll injection program of the API HOOK module into the memory space of the created process based on the dll injection mechanism, and when the application opens the file corresponding to the target process, call the confidentiality judgment logic of the hook function to judge whether the user's confidentiality level can open the file corresponding to the target process; The API HOOK module is used to modify the entry address of the target process API after the dll injection program is injected, and point the entry address to the custom hook function; the target process is the created process.

8. A computer device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the file confidentiality checking method based on the Windows operating system API HOOK as described in any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the file confidentiality level checking method based on the Windows operating system API HOOK described in any one of claims 1 to 6 is implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the file confidentiality level checking method based on the Windows operating system API HOOK described in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Configurable and integratable Hook system in Windows environment and method thereof

    CN107688747A

  • File security application management method and system based on LINUX system

    CN111310231A

  • Binary executable file change monitoring method based on Windows kernel

    CN112597492A

  • Ransomware encryption leakage detection method based on Windows kernel

    CN116305117A

  • Dynamic link library file injection detection method and device

    CN117150487A

Cited By

  • UWP application outgoing management and control function compatibility adaptation method, system and device and medium

    CN120653467A