Memory horse attack behavior detection method and device and electronic equipment

By building an associated constant pool in memory horse detection and dynamic rule learning, identifying data with memory horse attack characteristics, the problem of unrecognizing segmentation and transmissive memory horse injection attacks in the existing technology is solved, and efficient and accurate memory horse detection is achieved.

CN120162784APending Publication Date: 2025-06-17HILLSTONE NETWORKS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510308396.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

In the prior art, constant pool scanning is performed based on a single Class object, and the memory horse injection attack behavior using bypassing techniques such as segmentation and transmissibility cannot be identified, resulting in low detection efficiency of memory horse attack behavior.

Method used

By determining the method call relationship between class objects based on the method area of ​​each class object in memory, combining the constant pool corresponding to the method call data between associated class objects, building an associated constant pool, and learning to identify data with known memory horse attack characteristics through dynamic rules.

Benefits of technology

It improves the efficiency of memory horse detection and the accuracy of recognition, can effectively defend against the segmentation and transmissive injection methods of memory horses, and significantly improves terminal protection and emergency response capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162784A_ABST
    Figure CN120162784A_ABST
Patent Text Reader

Abstract

The invention discloses a memory horse attack behavior detection method and device and electronic equipment, and relates to the field of network security. The method comprises the following steps: determining a method calling relationship between different class objects according to a method region of each class object in a memory; according to the method calling relation between different class objects, determining associated class objects, and combining the constant pools corresponding to the method calling data between the associated class objects to obtain an associated constant pool; and under the condition of detecting that the data in the association constant pool has the known memory horse attack characteristics, determining that the associated class object has a memory horse attack behavior. According to the memory horse attack behavior detection method and device, the technical problem that the memory horse attack behavior detection efficiency is low due to the fact that the memory horse injection attack behavior using bypassing techniques such as segmentation and unvarnished transmission cannot be recognized when constant pool scanning is carried out based on a single Class object in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security. Specifically, it relates to a method, device, and electronic device for detecting memory horse attack behaviors. Background Art

[0002] In the field of network security technology, especially in the specific area of memory horse detection, existing threat detection technologies such as antivirus software based on file signatures or traditional detection methods for program injection have difficulty in identifying and preventing malicious code executed in memory. Memory horse, as an attack method that utilizes vulnerabilities in Java applications or the Java Runtime Environment (JRE) to directly run malicious code in the memory of the target system, has become a major challenge in network security because it does not rely on the file system and circumvents traditional detection means.

[0003] However, in recent years, with the frequent occurrence and increasing complexity of software supply chain attacks, attackers have started to adopt more advanced bypass techniques, such as segmented memory horse injection and pass-through memory horse attacks. Therefore, the existing method of scanning the constant pool based on a single Class object cannot identify memory horse injection attack behaviors using bypass techniques such as segmentation and pass-through, resulting in the technical problem of low detection efficiency of memory horse attack behaviors.

[0004] For the above problems, no effective solution has been proposed yet. Summary of the Invention

[0005] Embodiments of this application provide a method, device, and electronic device for detecting memory horse attack behaviors, so as to at least solve the technical problem of low detection efficiency of memory horse attack behaviors caused by the inability to identify memory horse injection attack behaviors using bypass techniques such as segmentation and pass-through when scanning the constant pool based on a single Class object in the prior art.

[0006] According to one aspect of the embodiments of this application, a method for detecting memory horse attack behaviors is provided, including: determining the method call relationship between different class objects according to the method area of each class object in the memory, where the method area of each class object is used to store the method call data when the target process loads the class object; determining the associated class objects according to the method call relationship between different class objects, and merging the constant pools corresponding to the method call data between the associated class objects to obtain an associated constant pool, where the constant pool is used to store the literal information and symbolic reference information used by the class object; and determining that there is a memory horse attack behavior in the associated class objects when it is detected that the data in the associated constant pool has known memory horse attack characteristics.

[0007] Optionally, before determining the method call relationships between different class objects based on the constant pools and method areas of each class object in memory, the method for detecting memory horse attack behavior further includes: after detecting the startup of the target process, performing a first scan on all class objects loaded by the target process to obtain a first scan result; when performing the Nth scan on the class objects loaded by the target process, comparing the first scan result with the Nth scan result to obtain a comparison result, where N is an integer greater than 1; determining the newly loaded class objects of the target process according to the comparison result, where the newly loaded class objects include the following first type of objects and / or second type of objects; the first type of objects are class objects with qualified names different from known names; the second type of objects are class objects with qualified names as known names, but with differences in constant pools from known constant pools.

[0008] Optionally, after performing a first scan on all class objects loaded by the target process to obtain a first scan result, the method for detecting memory horse attack behavior further includes: when performing the Nth scan on the class objects loaded by the target process, if it is detected that the ith class object loaded by the target process is a newly loaded class object of the target process discovered during this scan, then detecting whether the method area of the ith class object includes the method call data of the target class object, where the target class object is the first type of object or the second type of object determined by comparing with the first scan result during any one of the previous N scans, and where i is an integer greater than or equal to 1; in the case where it is detected that the method area of the ith class object includes the method call data of the target class object, taking all the constant pools corresponding to the ith class object as the first constant pool; taking all the constant pools corresponding to the target class object as the second constant pool; merging the first constant pool and the second constant pool; in the case where it is detected that the method area of the ith class object does not include the method call data of the target class object, determining that no method call relationship is detected between the ith class object and the target class object during the Nth scan.

[0009] Optionally, after detecting whether the method area of the ith class object includes the method call data of the target class object, the method for detecting memory horse attack behavior further includes: in the case where it is detected that the method area of the ith class object includes the method call data of the target class object, detecting whether the method area of the target class object includes the method call data of a third-party class object related to the target class object, where the third-party class object is the first type of object or the second type of object determined earlier than the target class object; when it is detected that the method area of the target class object includes the method call data of the third-party class object, taking all the constant pools corresponding to the third-party class object as the third constant pool; merging the first constant pool, the second constant pool, and the third constant pool.

[0010] Optionally, after merging the data in the constant pools of associated class objects according to the method call relationships between different class objects to obtain an associated constant pool, the method for detecting memory horse attack behavior further includes: when it is detected that the constant pool of the j-th class object that composes the associated constant pool is updated, detecting whether the j-th class object has a method call relationship with the previously determined first type of object or second type of object, where j is an integer greater than or equal to 1; when it is detected that the j-th class object has a method call relationship with the previously determined first type of object or second type of object, updating the associated constant pool according to the updated constant pool of the j-th class object.

[0011] Optionally, before merging the constant pools corresponding to the method call data between associated class objects to obtain an associated constant pool, determining the call methods of the associated class objects from the method areas of the associated class objects; determining the constant pool index for executing the call method according to the operation codes included in the attribute information of the call methods of the associated class objects, where the constant pool index is used to determine the position of the constant pool corresponding to the call method; according to the constant pool index, determining the constant pools of the associated class objects from the memory.

[0012] Optionally, after performing a first scan on all class objects loaded by the target process to obtain a first scan result, the method for detecting memory horse attack behavior further includes: when performing the k-th scan on the class objects loaded by the target process, detecting whether there are differences between the class object information obtained in the k-th scan and the class object information obtained in the (k - 1)-th scan, where k is an integer greater than 1; when it is detected that there are differences between the class object information obtained in the k-th scan and the class object information obtained in the (k - 1)-th scan, determining that the target process has loaded new class objects during the time interval between the k-th scan and the (k - 1)-th scan.

[0013] Optionally, the memory horse attack features include at least one of the following features: a first feature, which is used to characterize the method call feature of the class object that implements the memory horse attack behavior; a second feature, which is used to characterize the constant pool data feature of the class object that implements the memory horse attack behavior.

[0014] According to another aspect of the embodiments of the present application, there is also provided a detection device for memory horse attack behavior, including: a determination unit, which determines the method call relationship between different class objects according to the method area of each class object in the memory, where the method area of each class object is used to store the method call data when the target process loads the class object; an acquisition unit, which is used to determine the associated class objects according to the method call relationship between different class objects, and merge the constant pools corresponding to the method call data between the associated class objects to obtain an associated constant pool, where the constant pool is used to store the literal information and symbolic reference information used by the class object; a first detection unit, which determines that there is a memory horse attack behavior in the associated class objects when it detects that the data in the associated constant pool has known memory horse attack characteristics.

[0015] According to another aspect of the embodiments of the present application, there is also provided a computer-readable storage medium, in which a computer program is stored. When the computer program runs, it causes the device where the computer-readable storage medium is located to execute the above-mentioned detection method for memory horse attack behavior.

[0016] According to another aspect of the embodiments of the present application, there is also provided an electronic device, including one or more processors and a memory. The memory is used to store one or more programs. When one or more programs are executed by one or more processors, it causes one or more processors to execute the above-mentioned detection method for memory horse attack behavior.

[0017] As can be seen from the above, the memory horse detection method, system and storage medium of the present application can automatically identify and comprehensively analyze a cluster of class objects with malicious behavior characteristics from a complex Java running environment by introducing mechanisms based on class bytecode association scanning, constant pool and method area analysis, associated constant pool construction and dynamic rule learning, avoiding the limitations and resource waste of single class object scanning. At the same time, according to the method call relationship between different class objects, the associated constant pool is intelligently merged, greatly improving the efficiency of memory horse detection and the accuracy of identification. It can be seen that through the technical solution of the present application, the technical problem of low detection efficiency of memory horse attack behavior caused by the inability to identify memory horse injection attack behaviors using bypass techniques such as segmentation and pass-through by scanning the constant pool based on a single Class class object in the prior art is solved. The technical solution of the present application provides an innovative and systematic method to efficiently handle complex and changeable memory horse injection attacks through mechanisms such as class bytecode association scanning, in-depth analysis of the constant pool and method area, construction of the associated constant pool, and comprehensive detection, enabling security detection and response to be more accurate and efficient, effectively defending against segmentation and pass-through injection techniques of memory horses, and significantly improving terminal protection and emergency response capabilities. Description of the Drawings

[0018] The accompanying drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0019] Figure 1 is a flowchart of a method for detecting memory horse attack behavior according to an embodiment of the present application;

[0020] Figure 2 is a schematic diagram of a method for constructing an associated constant pool according to an embodiment of the present application;

[0021] Figure 3 is a schematic diagram of a memory horse scanning system according to an embodiment of the present application;

[0022] Figure 4 is a schematic diagram of a device for detecting memory horse attack behavior according to an embodiment of the present application. Detailed implementation manners

[0023] In order to enable those skilled in the art of the present technology to better understand the present application solution, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned accompanying drawings are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0025] It should also be noted that the information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) collected in this application are information and data that have been authorized by the user or fully authorized by all parties. Moreover, the processing of relevant data, such as collection, storage, use, processing, transmission, provision, disclosure, and application, complies with the relevant laws, regulations, and standards of the relevant regions, adopts necessary confidentiality measures, does not violate public order and good customs, and provides corresponding operation entrances for users to choose to authorize or refuse. For example, there is an interface set between this system and relevant users or institutions. Before obtaining relevant information, a request for acquisition needs to be sent to the aforementioned users or institutions through the interface, and after receiving the consent information feedback from the aforementioned users or institutions, the relevant information is obtained.

[0026] According to an embodiment of the present application, an embodiment of a method for detecting memory horse attack behavior is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0027] Optionally, a scanning system associated with the constant pool (hereinafter referred to as the system) can be used as the execution entity for detecting memory horse attack behavior in the embodiments of the present application. Among them, the detection system for memory horse attack behavior can be a software system or an embedded system combining software and hardware. Of course, the execution entity of the technical method of the present application can also be other forms of devices, equipment, etc. Those skilled in the art should know that the present application does not make special limitations on the specific manifestation forms of the execution entity.

[0028] According to an embodiment of the present application, an embodiment of a method for detecting memory horse attack behavior is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0029] Figure 1 is a flowchart of the method for detecting memory horse attack behavior according to an embodiment of the present application, as Figure 1 shown, the method includes the following steps:

[0030] Step S101, determine the method call relationship between different class objects according to the method area of each class object in the memory, where the method area of each class object is used to store the method call data when the target process loads the class object.

[0031] Optionally, the target process can be a Java process. The class object can be a Class class object (also known as a class object).

[0032] Optionally, the method area is dynamically generated during class loading and contains all method call information and operation codes. By parsing the method area in this application, it is possible to determine which operation codes identify method calls, thereby capturing the specific data of method calls. By analyzing the method call data, especially those method calls that point to external classes or interfaces, this application can identify the direct or indirect call relationships existing between different class objects. This is crucial for constructing a complete attack link graph and capturing hidden memory horse injection behaviors.

[0033] Step S102: According to the method call relationships between different class objects, determine the associated class objects, and merge the constant pools corresponding to the method call data between the associated class objects to obtain an associated constant pool.

[0034] Among them, the constant pool is used to store the literal information and symbolic reference information used by the class object.

[0035] Optionally, in combination with the identified method call relationships, this application merges the constant pool information of the class objects involved in the call relationships to construct an associated constant pool that contains all relevant literal and symbolic reference information. This constant pool can reflect a complete attack behavior, even if the attack code is scattered in multiple class objects. The constant pool stores literal information at compile time, such as strings, numerical values, etc. This application extracts this literal information by parsing the constant pool for subsequent attack feature detection. Literal information is an important clue for identifying memory horse attacks, and attackers often perform malicious operations through specific strings or numerical values. Symbolic reference information includes references to other classes, interfaces, methods, and fields. By deeply analyzing the constant pool in this application, these symbolic reference information are obtained for constructing a method call relationship graph. This method can capture complex attack behaviors of cross-class calls, increasing the comprehensiveness and accuracy of detection.

[0036] Optionally, by parsing the constant pools and method areas of all newly added Class objects, the method call relationships between different Class objects are identified, thereby constructing a constant pool that contains all constants related to the complete function.

[0037] Optionally, the following is an example of code for concise parsing of a constant pool and a method area according to an embodiment of this application:

[0038]

[0039]

[0040] The following code is an example of the parsing results of a constant pool and a method area according to an embodiment of the present application:

[0041]

[0042]

[0043]

[0044] As can be seen from the above, parsing the constant pool and the method area includes: obtaining the Class object from memory, directly reading the corresponding constant pool attributes, from which all relevant class names, all called method names, index names, etc. within the current Class can be obtained; obtaining the method list from the Class object and traversing each method; obtaining all attributes from the attributes field of each method, and identifying the method body attribute content according to the attribute type, which contains the bytecode instructions in the method body; parsing the operation code of the instruction, identifying the operation code indicating method calls, and continuing to read the next 2-bit operation code, and after parsing, the constant pool index for executing the method can be obtained; through the constant pool index, obtaining the corresponding class name and method name from the constant pool, and persistently storing the called class name and method name together with the method name of the current class parsed before as the internal method call data, and the data includes the method name and the set of called method names; parsing the operation code of the instruction, identifying the operation code indicating basic content constants such as characters, and continuing to read the next operation code, and after parsing, the constant pool index for basic content constants such as characters can be obtained, and obtaining the corresponding constant pool basic content data through the constant pool index; combining the internal method call data and the constant pool basic content data to form the complete constant pool data associated within a certain method.

[0045] Optionally, Figure 2 is a schematic diagram of a method for constructing an associated constant pool according to an embodiment of the present application, as Figure 2 shown, the method for constructing an associated constant pool includes: First, the system parses the constant pools and method areas of Class objects A and B from their memory, and extracts all literal information, symbolic reference information, and method call indexes.

[0046] Then, by analyzing the external call indexes included in the method area of Class object A, it is identified that it calls a specific method in Class object B, thereby determining the method call relationship from A to B. Synchronously store the current constant pool information of Class object A. At the same time, since the method of Class object B is called, the system synchronizes the relevant information (including literals and symbolic references) called in the constant pool of Class object B and merges it with the constant pool information of Class object A to form an associated constant pool.

[0047] Optionally, the system can further analyze whether there is a situation where a third-party Class object C is called through Class object B. If so, it continues to merge the constant pool information of C to build a more complete associated constant pool. For example, if A calls the X method of B, and the X method of B calls the Y method of C, then the constant pools corresponding to X and Y need to be merged into the constant pool of A.

[0048] Step S103, when it is detected that the data in the associated constant pool has known memory horse attack characteristics, it is determined that there is a memory horse attack behavior in the associated class object.

[0049] Optionally, this application maintains a memory horse attack feature library, which contains known attack patterns and features. These features may include, but are not limited to, literal information and method call sequences of behaviors such as executing system commands, reading or writing sensitive system files, and conducting network communications. The feature library is the basis for determining whether the data in the associated constant pool has attack characteristics.

[0050] Optionally, the method for constructing the memory horse attack feature library is to write the method call features and basic content constant features that a memory horse Class may contain based on existing attack samples or by analyzing the memory horse attack principle.

[0051] Optionally, this application also includes a dynamic update mechanism, that is, when a newly loaded or modified class object is detected, the corresponding associated constant pool will be updated, and the feature matching process will be carried out again. This ensures that even if an attacker tries to bypass detection by modifying class objects or loading malicious code in stages, the system can discover and determine the attack behavior in a timely manner.

[0052] Optionally, in subsequent scans, this application only constructs and updates the associated constant pool for newly detected or modified class objects, avoiding repeated detection of all class objects, improving the detection efficiency. Among them, the newly detected or modified class objects are determined by comparing with the results of the first scan. At the same time, by focusing on method call data rather than the state of the entire process or system, this technology can quickly identify attack behaviors and reduce the possibility of false positives and false negatives.

[0053] In this embodiment, Figure 3 is a schematic diagram of a memory horse scanning system according to an embodiment of this application, as Figure 3 shown, the memory horse scanning system includes an associated constant pool scanning module 301 and an associated constant pool detection module 302.

[0054] Optionally, an associated constant pool scanning module 301 is used to identify the method call relationships between different Class objects by parsing the constant pools and method areas of all newly added Class objects, so as to construct a constant pool containing all constants related to the complete function.

[0055] Optionally, an associated constant pool detection module 302 is used to detect memory horse injection behaviors in the non-associated constant pool and the associated constant pool. The detection process is to match the constant pool data with the memory horse attack characteristics. If there is a match, an alarm is generated.

[0056] As can be seen from the above, the memory horse detection method, system and storage medium of the present application can automatically identify and comprehensively analyze a cluster of class objects with malicious behavior characteristics from a complex Java running environment by introducing mechanisms based on class bytecode association scanning, constant pool and method area analysis, associated constant pool construction and dynamic rule learning, avoiding the limitations and resource waste of single class object scanning. At the same time, according to the method call relationships between different class objects, the associated constant pools are intelligently merged, greatly improving the efficiency of memory horse detection and the accuracy of identification. In addition, through the strategy of dynamic update and processing, the real-time maintenance of the associated constant pool can be realized, ensuring the timeliness and effectiveness of the detection rules. At the same time, the systematization and intelligence of in-depth analysis can reveal the complex injection patterns behind memory horses, further enhancing the depth and breadth of threat detection and reducing the risks of false positives and false negatives. In practical applications, this solution can significantly improve the performance of the security protection system, quickly respond to memory horse injection attacks, and provide a more comprehensive and accurate overview of attack behaviors for security administrators, facilitating the timely discovery and handling of highly concealed memory horse attacks. At the same time, it also provides a more efficient and accurate network security protection service for the organization.

[0057] Thus, through the technical solution of the present application, the technical problem of low detection efficiency of memory horse injection attack behaviors caused by the inability to identify memory horse injection attack behaviors using bypass techniques such as segmentation and pass-through when scanning the constant pool based on a single Class class object in the prior art is solved. The technical solution of the present application provides an innovative and systematic method for efficiently handling complex and variable memory horse injection attacks through class bytecode association scanning, in-depth analysis of the constant pool and method area, construction of the associated constant pool, dynamic rule learning and generation of a comprehensive detection mechanism, enabling security detection and response to be more accurate and efficient, effectively defending against segmentation and pass-through injection techniques of memory horses, and significantly enhancing the terminal protection and emergency response capabilities.

[0058] In this embodiment, before determining the method call relationship between different class objects according to the constant pool and method area of each class object in the memory, the detection method for memory horse attack behavior further includes: after detecting the startup of the target process, performing a first scan on all class objects loaded by the target process to obtain a first scan result. When performing the Nth scan on the class objects loaded by the target process, comparing the first scan result with the Nth scan result to obtain a comparison result, where N is an integer greater than 1. Determining the newly loaded class objects of the target process according to the comparison result, where the newly loaded class objects include the following first type of objects and / or second type of objects: the first type of objects are class objects with a qualified name different from the known name; the second type of objects are class objects with a qualified name being the known name, but with a difference in the constant pool from the known constant pool.

[0059] Optionally, the associated constant pool scanning module can scan all classes currently loaded by the target process after the startup of the target process to be protected for the first time, identify the fully qualified name and constant pool of the classes, and cache the content into the first scan result. At this time, all class objects are safe. For those that have delivered class object entity files containing memory horses, they already belong to the contaminated supply chain and are not within the scope of memory horses.

[0060] Optionally, the associated constant scanning module can also perform a periodic scan on the class objects in the target process. When performing the Nth scan, similarly parse the constant pool and method area of each class object, and compare the scanned class object content with the first scan result to identify the newly loaded class objects. Where N is an integer greater than 1.

[0061] Optionally, the newly loaded class objects include: class objects with a new qualified name (i.e., the above-mentioned first type of objects); class objects with an existing qualified name, but with a constant pool inconsistent with the previous one (i.e., the above-mentioned second type of objects); where the qualified name refers to the complete class identifier including the package name and class name. Since the first scan result is used as the benchmark for the normal state when the system starts, any newly emerged class objects with a qualified name and modified class objects may represent potential attack vectors or supply chain contamination and need further analysis and detection.

[0062] In an alternative embodiment, after the first scan of all class objects loaded by the target process to obtain the first scan result, the method for detecting memory horse attack behavior includes: when performing the Nth scan of the class objects loaded by the target process, if it is detected that the ith class object loaded by the target process is a newly loaded class object of the target process found during the current scan, then it is detected whether the method area of the ith class object includes the method call data of the target class object, where the target class object is the first type of object or the second type of object determined by comparing with the first scan result during any one of the previous N scans, and i is an integer greater than or equal to 1. In the case where it is detected that the method area of the ith class object includes the method call data of the target class object, all constant pools corresponding to the ith class object are used as the first constant pool; all constant pools corresponding to the target class object are used as the second constant pool; the first constant pool and the second constant pool are merged. In the case where it is detected that the method area of the ith class object does not include the method call data of the target class object, it is determined that no method call relationship is detected between the ith class object and the target class object during the Nth scan.

[0063] Optionally, in the Nth scan, if the associated constant pool scanning module detects that the ith class object is loaded in the target process and this class object does not exist in the first scan result or its constant pool content is different from that during the first scan, then this class object is regarded as the target class object. Among them, the target class object refers to a newly loaded class object that is compared with the first scan result excluding itself, and can also be called an externally newly added Class class object. This recognition mechanism is based on the changes in the fully qualified class name and the constant pool content, ensuring that the system can accurately find new changes in the target process.

[0064] Optionally, for the ith class object identified as newly loaded, the associated constant pool scanning module can further analyze the constant pool and method area of the newly loaded class object to confirm whether the method internal call data contains the method call of the target class object, thereby avoiding the attacker's segmented attack over a long period, that is, first uploading a part of the payload, and then uploading another part of the attack payload after a period of time, with an interval exceeding the scanning period, resulting in the timed scan misidentifying the class object uploaded last time as not newly added.

[0065] Optionally, if the method area of the ith class object contains the method call of the target class object, the associated constant pool scanning module can also find the constant pool data (parsed) contained in the called method of the target class object, and merge this data with the constant pool content of the currently detected newly loaded class object to form a complete associated constant pool.

[0066] Optionally, the associated constant pool scanning system can comprehensively analyze attack behaviors involving multiple Class objects through the associated constant pool scanning module, including memory horse injection behaviors executed segmentally through multiple Class objects. Since only the information directly related to malicious behaviors is included in the merging process, this avoids a large number of false positives caused by merging irrelevant constants.

[0067] Optionally, if no method call data for the target class object is detected in the method area of the i-th class object, that is, there is no method call opcode in the bytecode instructions of the i-th class object that points to the target class object, then the associated constant pool scanning module can determine that there is no direct method call relationship between the i-th class object and the target class object during the N-th scan. This step is crucial for eliminating false positives and improving detection efficiency.

[0068] Optionally, when there is no method call relationship between the i-th class object and the target class object, the associated constant pool scanning module will skip the step of constructing the associated constant pool and directly submit the constant pool information of the i-th class object to the associated constant pool detection module for subsequent feature matching. If the constant pool information contains known malicious behavior features, an alarm will be generated; if no abnormal features are found, then the i-th class object is considered safe, which helps to quickly process Class objects under normal circumstances and avoid unnecessary in-depth analysis.

[0069] In an alternative embodiment, after detecting whether the method area of the i-th class object includes method call data of the target class object, the method for detecting memory horse attack behaviors includes: in the case where it is detected that the method area of the i-th class object includes method call data of the target class object, detecting whether the method area of the target class object includes method call data of a third-party class object related to the target class object, where the third-party class object is a first type of object or a second type of object determined earlier than the target class object. When it is detected that the method area of the target class object includes method call data of the third-party class object, taking all the constant pools corresponding to the third-party class object as the third constant pool; merging the first constant pool, the second constant pool, and the third constant pool.

[0070] Optionally, the third-party class object is, in any one of the previous N scans, a first type of object or a second type of object determined after comparing with the first scan result. In the case where it is detected that the i-th class object has a call relationship with the target class object, further detecting whether the target class object calls the third-party class object can construct a more comprehensive view of attack behaviors and ensure that every link of the attack behavior can be captured by the system.

[0071] Optionally, if the method area of the target class object indeed contains call data related to the third-party class object, the associated constant pool scanning module will perform in-depth association analysis, specifically including merging the relevant constant pool content of the third-party class object into the current associated constant pool to construct an in-depth associated constant pool. This in-depth associated constant pool contains all the associated constant information from the i-th class object to the target class object and then to the third-party class object, and can reveal the complex attack strategies that attackers may adopt in multiple stages and involving multiple types of objects.

[0072] For example, if A calls the X method of B, and the X method of B calls the Y method of C, then the constant pools corresponding to X and Y need to be merged into the constant pool of A.

[0073] Optionally, the associated constant pool scanning module improves the detection rate of memory horse injection behavior by progressively detecting method call relationships and constructing an in-depth associated constant pool. That is, even if the attacker tries to split the malicious code into multiple class objects or inject different parts of the malicious code at different time points, the associated constant pool scanning module can identify the entire attack chain through in-depth association analysis, avoiding the limitations of single-class-object detection and reducing false negatives.

[0074] In an optional embodiment, after merging the data in the constant pools of associated class objects according to the method call relationships between different class objects to obtain an associated constant pool, the detection method for memory horse attack behavior further includes: when it is detected that the constant pool of the j-th class object that composes the associated constant pool is updated, detecting whether the j-th class object has a method call relationship with the previously determined first class object or second class object, where j is an integer greater than or equal to 1; when it is detected that the j-th class object has a method call relationship with the previously determined first class object or second class object, updating the associated constant pool according to the updated constant pool of the j-th class object. Optionally, in the subsequent N scans, if the associated constant pool scanning module detects that the constant pool content of any j-th class object (j is an integer greater than or equal to 1) that composes the associated constant pool has been updated, this indicates that the j-th class object may have been modified, and its constant pool may contain new literal and symbolic reference information, which may be related to the attack behavior.

[0075] Optionally, when the constant pool content associated with the method area of the newly loaded class object changes and this method is called by the previously newly loaded class object, the associated constant pool scanning module can also synchronously update the previous associated constant pool and resubmit the associated constant pool to the detection module for detection to prevent the attacker from submitting the call payload first and then the called payload, thus bypassing the associated detection logic.

[0076] In an alternative embodiment, before merging the constant pools corresponding to the method call data between associated class objects to obtain an associated constant pool, the calling methods of the associated class objects are determined from the method areas of the associated class objects. For example, according to the operation codes included in the attribute information of the calling methods of the associated class objects, the constant pool index for executing the calling methods is determined, where the constant pool index is used to determine the position of the constant pool corresponding to the calling methods; according to the constant pool index, the constant pools of the associated class objects are determined from the memory.

[0077] Optionally, the associated constant pool scanning module can obtain the method list from the class object and traverse each method; obtain all attributes from the attributes field of each method, and identify the method body attribute content according to the attribute type, which contains the bytecode instructions in the method body. Among them, the attributes field in each method is a set of attributes.

[0078] Optionally, the associated constant pool scanning module can also identify the operation code indicating a method call, and continue to read the next 2-bit operation code. After parsing, the constant pool index for executing the method can be obtained.

[0079] Optionally, the associated constant pool scanning module can also obtain the corresponding class name and method name from the constant pool through the constant pool index, and persistently store the called class name and method name together with the method name of the current class parsed previously as the internal method call data, which contains the method name and the set of called method names.

[0080] Optionally, the associated constant pool scanning module can also parse the operation code of the instruction, identify the operation code of basic content constants such as identification characters, and continue to read the subsequent operation code. After parsing, the constant pool index of basic content constants such as characters can be obtained, and the corresponding constant pool basic content data can be obtained through the constant pool index.

[0081] Optionally, the associated constant pool scanning module can also combine the internal method call data and the constant pool basic content data to form the complete constant pool data associated with a certain method.

[0082] In an alternative embodiment, after performing the first scan on all class objects loaded by the target process to obtain the first scan result, the method for detecting the memory horse attack behavior further includes: when performing the kth scan on the class objects loaded by the target process, detecting whether there are differences between the class object information obtained from the kth scan and the class object information obtained from the (k - 1)th scan, where k is an integer greater than 1. When it is detected that there are differences between the class object information obtained from the kth scan and the class object information obtained from the (k - 1)th scan, it is determined that the target process has loaded new class objects during the interval between the kth scan and the (k - 1)th scan.

[0083] Optionally, when the associated constant pool scanning module scans again later, it only needs to detect the newly loaded class objects obtained by comparing the current scan with the previous scan, thereby improving the detection performance.

[0084] It should be noted that the result of the newly added Class class object (i.e., the above-mentioned target class object) externally is still obtained by comparing with the result of the first scan.

[0085] Optionally, the associated constant pool scanning module can detect the differences in class object information by comparing the information of two scans. These differences include: the appearance of a class object with a new fully qualified name (i.e., the above-mentioned first type of object), which indicates that the target process has loaded a new class object during the time interval between the two scans; the change in the constant pool content of a known Class object with a fully qualified name (i.e., the above-mentioned second type of object), which indicates that the class object has been modified and there may be a potential memory horse injection behavior.

[0086] Optionally, if the associated constant pool scanning module detects that a class object with a new fully qualified name appears in the class object information obtained from the k-th scan compared to the class object information obtained from the (k - 1)-th scan, the associated constant pool scanning module will again determine that the target process has indeed loaded new class objects during the time interval between the two scans, and perform further associated constant pool scanning and detection on these newly loaded class objects.

[0087] Optionally, the time interval between the k-th scan and the (k - 1)-th scan executed by the associated constant pool scanning module is a key parameter in the system's dynamic monitoring mechanism. This time interval needs to be set according to the running characteristics of the target process and the possible frequency of potential attacks to ensure that both the event of newly loaded class objects can be captured in a timely manner and excessive resources will not be consumed due to overly frequent scanning.

[0088] In an optional embodiment, the memory horse attack features include at least one of the following features: the first feature, which is used to characterize the method call feature of the class object implementing the memory horse attack behavior. The second feature, which is used to characterize the constant pool data feature of the class object implementing the memory horse attack behavior.

[0089] Optionally, the method call feature refers to the specific method call patterns and behaviors that malicious code will exhibit when implementing a memory horse attack behavior. These features include the commonly used and representative call behaviors of attackers, such as calling the system command execution interface, calling network communication methods, reading or writing files, etc.

[0090] Optionally, to accurately characterize the method call features, the system needs to build a feature library for in-memory malware attack behaviors. The method for building the in-memory malware attack feature library is to write the method call features and basic content constant features that may be included in the in-memory malware class objects based on existing attack samples or by analyzing the principles of in-memory malware attacks.

[0091] Optionally, the associated constant pool scanning module can identify the method call relationships between different class objects by deeply parsing the constant pools and method areas of all newly added external Class class objects (i.e., the above-mentioned target class objects). The operating mechanism of this module is to merge the data in the constant pools of associated class objects to form an associated constant pool. During this process, the associated constant pool scanning module determines the calling methods of the associated class objects from the method areas of the class objects.

[0092] Optionally, the associated constant pool detection module can detect in-memory malware injection behaviors for non-associated constant pools and associated constant pools. The detection process is to match the constant pool data with the in-memory malware attack features, and if there is a match, an alarm is issued.

[0093] In an alternative embodiment, Figure 4 is a schematic diagram of a detection device for in-memory malware attack behaviors according to an embodiment of the present application. As Figure 4 shown, the detection device for in-memory malware attack behaviors includes: a determination unit 401, an acquisition unit 402, and a first detection unit 403;

[0094] Optionally, the determination unit 401 is configured to determine the method call relationships between different class objects according to the method areas of each class object in the memory, where the method area of each class object is used to store the method call data when the target process loads the class object; the acquisition unit 402 is configured to determine the associated class objects according to the method call relationships between different class objects, and merge the constant pools corresponding to the method call data between the associated class objects to obtain an associated constant pool, where the constant pool is used to store the literal information and symbolic reference information used by the class object; the first detection unit 403 is configured to determine that there is an in-memory malware attack behavior in the associated class objects when it is detected that the data in the associated constant pool has known in-memory malware attack features.

[0095] Optionally, the detection device for in-memory horse attack behavior further includes: a first scanning unit, configured to perform a first scan on all class objects loaded by a target process after detecting the startup of the target process, and obtain a first scan result; a first comparison unit, configured to compare the first scan result with the Nth scan result when performing the Nth scan on the class objects loaded by the target process, and obtain a comparison result, where N is an integer greater than 1; a first determination unit, configured to determine, according to the comparison result, the newly loaded class objects of the target process, where the newly loaded class objects include the following first type of objects and / or second type of objects: the first type of objects are class objects with a qualified name different from a known name; the second type of objects are class objects with a qualified name being a known name, but having a difference in the constant pool from a known constant pool.

[0096] Optionally, the detection device for in-memory horse attack behavior further includes: a second detection unit, configured to, when performing the Nth scan on the class objects loaded by the target process, detect whether method call data of a target class object is included in the method area of the ith class object loaded by the target process when it is detected that the ith class object loaded by the target process is a newly loaded class object of the target process found during the current scan, where the target class object is the first type of object or the second type of object determined by comparing with the first scan result during any one of the previous N scans, and where i is an integer greater than or equal to 1; a second determination unit, configured to, when it is detected that the method area of the ith class object includes the method call data of the target class object, use all the constant pools corresponding to the ith class object as a first constant pool; use all the constant pools corresponding to the target class object as a second constant pool; and merge the first constant pool and the second constant pool; a third determination unit, configured to, when it is detected that the method area of the ith class object does not include the method call data of the target class object, determine that no method call relationship is detected between the ith class object and the target class object during the Nth scan.

[0097] Optionally, the detection device for in-memory horse attack behavior further includes: a third detection unit, configured to, when it is detected that the method area of the ith class object includes the method call data of the target class object, detect whether method call data of a third-party class object related to the target class object is included in the method area of the target class object, where the third-party class object is the first type of object or the second type of object determined earlier than the target class object; a first processing unit, configured to, when it is detected that the method area of the target class object includes the method call data of the third-party class object, use all the constant pools corresponding to the third-party class object as a third constant pool; and merge the first constant pool, the second constant pool, and the third constant pool.

[0098] Optionally, the detection device for in-memory horse attack behavior further includes: a fourth detection unit, configured to detect whether there is a method call relationship between the j-th class object whose constant pool that merges to form the associated constant pool is updated and the previously determined first type of object or second type of object, where j is an integer greater than or equal to 1; a second processing unit, configured to update the associated constant pool according to the updated constant pool of the j-th class object when it is detected that there is a method call relationship between the j-th class object and the previously determined first type of object or second type of object.

[0099] Optionally, the acquisition unit 402 includes: a first determination subunit, configured to determine the call method of the associated class object from the method area of the associated class object; a second determination subunit, configured to determine the constant pool index for executing the call method according to the operation code included in the attribute information of the call method of the associated class object, where the constant pool index is used to determine the position of the constant pool corresponding to the call method; a third determination subunit, configured to determine the constant pool of the associated class object from the memory according to the constant pool index.

[0100] Optionally, the detection device for in-memory horse attack behavior further includes: a fifth detection unit, configured to detect whether there is a difference between the class object information obtained from the k-th scan and the class object information obtained from the (k - 1)-th scan when performing the k-th scan on the class objects loaded by the target process, where k is an integer greater than 1; a fourth determination unit, configured to determine that a new class object is loaded by the target process during the time interval between the k-th scan and the (k - 1)-th scan when it is detected that there is a difference between the class object information obtained from the k-th scan and the class object information obtained from the (k - 1)-th scan.

[0101] Optionally, the in-memory horse attack feature at least includes one of the following features: a first feature, used to characterize the method call feature of the class object implementing the in-memory horse attack behavior; a second feature, used to characterize the constant pool data feature of the class object implementing the in-memory horse attack behavior.

[0102] According to another aspect of the present application, there is also provided a computer-readable storage medium, where a computer program is stored in the computer-readable storage medium, and when the computer program runs, it causes the device where the computer-readable storage medium is located to execute the above-mentioned detection method for in-memory horse attack behavior.

[0103] According to another aspect of the present application, there is also provided an electronic device, where the electronic device includes one or more processors and a memory, and the memory is used to store one or more programs, and when the one or more programs are executed by the one or more processors, it causes the one or more processors to execute the above-mentioned detection method for in-memory horse attack behavior.

[0104] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.

[0105] In the above embodiments of the present application, the descriptions of the various embodiments each have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0106] The above-described embodiments or examples disclosed in the present application are not exhaustive. They are only schematic of some embodiments or examples and do not constitute a specific limitation on the scope of protection disclosed in the present application. Without conflict, each step in a certain embodiment or example in the present application can be implemented as an independent embodiment, and the steps can be combined arbitrarily. For example, the solution after removing some steps in a certain embodiment or example can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment or example can be arbitrarily exchanged. Additionally, the optional modes or optional examples in a certain embodiment or example can be combined arbitrarily; furthermore, the various embodiments or examples can be combined arbitrarily. For example, some or all of the steps of different embodiments or examples can be combined arbitrarily, and a certain embodiment or example can be combined arbitrarily with the optional modes or optional examples of other embodiments or examples.

[0107] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.

[0108] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0109] In addition, the functional units in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0110] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs.

[0111] The above are only the preferred embodiments of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of this application.

Claims

1. A method for detecting memory horse attack behavior, characterized in that: include: Determine the method call relationship between different class objects according to the method area of ​​each class object in the memory, wherein the method area of ​​each class object is used to store the method call data when the target process loads the class object; Determine associated class objects according to the method call relationship between the different class objects, and merge constant pools corresponding to the method call data between the associated class objects to obtain an associated constant pool, wherein the constant pool is used to store literal information and symbol reference information used by the class objects; When it is detected that the data in the associated constant pool has known memory horse attack characteristics, it is determined that the associated class object has memory horse attack behavior.

2. The method for detecting memory horse attack behavior according to claim 1, characterized in that: Before determining the method call relationship between different class objects according to the constant pool and method area of ​​each class object in the memory, the memory horse attack behavior detection method further includes: After detecting that the target process is started, performing a first scan on all class objects loaded by the target process to obtain a first scan result; When performing an Nth scanning on the class object loaded by the target process, a comparison is performed based on the first scanning result and the Nth scanning result to obtain a comparison result, wherein N is an integer greater than 1; Determine the class object newly loaded by the target process according to the comparison result, wherein the newly loaded class object includes the following first class object and / or second class object: The first class object is a class object whose qualified name is different from the known name; The second type of object is a class object whose qualified name is a known name, but whose constant pool is different from the known constant pool.

3. The method for detecting memory horse attack behavior according to claim 2, characterized in that: After performing a first scan on all class objects loaded by the target process and obtaining the first scan result, the memory horse attack behavior detection method further includes: When performing the Nth scanning on the class objects loaded by the target process, if it is detected that the i-th class object loaded by the target process is a class object newly loaded by the target process found in this scanning process, then detecting whether the method area of ​​the i-th class object includes method call data of the target class object, wherein the target class object is a first class object or a second class object determined after comparison with the first scanning result in any scanning process of the first N scannings, wherein i is an integer greater than or equal to 1; In the case where it is detected that the method area of ​​the i-th class object includes the method call data of the target class object, all constant pools corresponding to the i-th class object are used as the first constant pool; Using the constant pool corresponding to the method call data of the target class object as the second constant pool; Merging the first constant pool and the second constant pool; When it is detected that the method area of ​​the i-th class object does not include the method calling data of the target class object, it is determined that no method calling relationship between the i-th class object and the target class object is detected during the N-th scanning process.

4. The method for detecting memory horse attack behavior according to claim 3 is characterized in that: After detecting whether the method area of ​​the i-th class object includes method call data of the target class object, the memory horse attack behavior detection method further includes: In the case where it is detected that the method area of ​​the i-th class object includes the method call data of the target class object, detecting whether the method area of ​​the target class object includes the method call data of a third-party class object related to the target class object, wherein the third-party class object is a first-class object or a second-class object determined earlier than the target class object; When it is detected that the method area of ​​the target class object includes the method call data of the third-party class object, a constant pool corresponding to the method call data of the third-party class object is used as a third constant pool; The first constant pool, the second constant pool, and the third constant pool are merged.

5. The method for detecting memory horse attack behavior according to claim 1, characterized in that: After merging the data in the constant pools of the associated class objects according to the method call relationship between the different class objects to obtain the associated constant pool, the memory horse attack behavior detection method further includes: When it is detected that the constant pool of the j-th class object combined to form the associated constant pool is updated, detecting whether the j-th class object has a method call relationship with the previously determined first class object or second class object, where j is an integer greater than or equal to 1; When it is detected that the j-th class object has a method call relationship with the previously determined first class object or second class object, the associated constant pool is updated according to the updated constant pool of the j-th class object.

6. The method for detecting memory horse attack behavior according to claim 1, characterized in that: Before merging the constant pools corresponding to the method call data between the associated class objects to obtain the associated constant pool, the method further includes: Determine, from the method area of ​​the associated class object, a calling method of the associated class object; Determining a constant pool index for executing the calling method according to an operation code included in the attribute information of the calling method of the associated class object, wherein the constant pool index is used to determine a position of a constant pool corresponding to the calling method; According to the constant pool index, a constant pool of the associated class object is determined from the memory.

7. The method for detecting memory horse attack behavior according to claim 2, characterized in that: After performing a first scan on all class objects loaded by the target process and obtaining the first scan result, the memory horse attack behavior detection method further includes: When performing a k-th scan on the class object loaded by the target process, detecting whether there is a difference between the class object information obtained by the k-th scan and the class object information obtained by the k-1-th scan, where k is an integer greater than 1; When it is detected that there is a difference between the class object information obtained by the kth scan and the class object information obtained by the k-1th scan, it is determined that the target process has loaded a new class object within an interval between executing the kth scan and the K-1th scan.

8. The method for detecting memory horse attack behavior according to any one of claims 1 to 7, characterized in that: The memory horse attack features include the following features: At least one of: The first feature is used to characterize the method call feature of the class object that implements the memory horse attack behavior; The second feature is used to characterize the constant pool data features of the class object that implements the memory horse attack behavior.

9. A device for detecting memory horse attack behavior, characterized in that: include: a determining unit, configured to determine a method calling relationship between different class objects according to a method area of ​​each class object in a memory, wherein the method area of ​​each class object is used to store method calling data when a target process loads the class object; an acquisition unit, configured to determine associated class objects according to the method call relationship between the different class objects, and merge constant pools corresponding to the method call data between the associated class objects to obtain an associated constant pool, wherein the constant pool is used to store literal information and symbol reference information used by the class objects; The first detection unit determines that the associated class object has a memory horse attack behavior when it is detected that the data in the associated constant pool has a known memory horse attack feature.

10. An electronic device, characterized in that: It includes one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors execute the memory horse attack behavior detection method described in any one of claims 1 to 8.