Hidden kernel module detection method and device, electronic equipment and storage medium

By obtaining the start address of the kernel module and the hooked objective function, it detects whether there is a hidden Rootkit kernel module in the system, solving the problem that the existing technology is difficult to identify hidden kernel modules, and achieving efficient and accurate detection results.

CN120180429AInactive Publication Date: 2025-06-20CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510668233.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-06-20
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

How to detect whether there are hidden Rootkit kernel modules in the system, it is difficult for the existing technology to effectively identify these hidden kernel modules.

Method used

By obtaining the start address of each kernel module, determining the target function that is hooked in the preset function set, determining the target address of the target function, and comparing it based on the predicted start address and the start address set, to detect whether the kernel module corresponding to the target address is a hidden kernel module.

Benefits of technology

This method is simple and efficient, and can start from the hook function in the system to accurately detect whether there is a hidden Rootkit kernel module in the system. It has a shorter running time and more accurate detection results than traditional detection ideas.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180429A_ABST
    Figure CN120180429A_ABST
Patent Text Reader

Abstract

The invention relates to a hidden kernel module detection method and device, electronic equipment and a storage medium, and relates to the technical field of computers. The method comprises the following steps: acquiring an initial address of each kernel module to obtain an initial address set; determining a hooked target function in a preset function set; determining a target address of the target function; determining a predicted initial address of the kernel module corresponding to the target address; and detecting whether the kernel module corresponding to the target address is a hidden kernel module or not according to the predicted initial address and the initial address set. According to the method and the device, whether the hidden Rootkit kernel module exists in the system or not is further detected by starting with the hook function in the detection system. Compared with a traditional detection thought, the method is simpler and more efficient.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a method, apparatus, electronic device, and storage medium for detecting hidden kernel modules. Background Art

[0002] Linux is a popular operating system kernel, and multiple kernel modules run inside its system. They have the same permissions as the operating system code, and these modules can perform different functions, such as driving a graphics card to display images, driving a sound card to play sounds, etc. Rootkit is also a type of kernel module, which is designed to implement malicious functions.

[0003] How to detect Rootkits is a problem that needs to be solved. Summary of the Invention

[0004] Embodiments of the present disclosure provide a method, apparatus, electronic device, and storage medium for detecting hidden kernel modules.

[0005] In a first aspect, embodiments of the present disclosure provide a method for detecting hidden kernel modules, including: obtaining the starting addresses of each kernel module to obtain a set of starting addresses; determining the target functions that are hooked in a preset set of functions; determining the target addresses of the target functions; determining the predicted starting addresses of the kernel modules corresponding to the target addresses; and detecting whether the kernel modules corresponding to the target addresses are hidden kernel modules according to the predicted starting addresses and the set of starting addresses.

[0006] In a second aspect, embodiments of the present disclosure provide a device for detecting hidden kernel modules, including: an address acquisition unit configured to obtain the starting addresses of each kernel module to obtain a set of starting addresses; a function determination unit configured to determine the target functions that are hooked in a preset set of functions; an address determination unit configured to determine the target addresses of the target functions; an address prediction unit configured to determine the predicted starting addresses of the kernel modules corresponding to the target addresses; and a module detection unit configured to detect whether the kernel modules corresponding to the target addresses are hidden kernel modules according to the predicted starting addresses and the set of starting addresses.

[0007] In a third aspect, embodiments of the present disclosure provide an electronic device, including a memory, a processor, a bus, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method for detecting hidden kernel modules described in the first aspect is implemented.

[0008] In a fourth aspect, embodiments of the present disclosure provide a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method for detecting hidden kernel modules described in the first aspect is implemented.

[0009] Applying the technical solution of the present disclosure, starting from the hook function in the detection system, further detect whether there is a hidden Rootkit kernel module in the system. Compared with the traditional detection idea, this method is simpler and more efficient.

[0010] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] The drawings are used to better understand the present solution and do not constitute a limitation to the present disclosure. Among them: Figure 1 is a schematic flowchart of an embodiment of the method for detecting hidden kernel modules of the present disclosure; Figure 2 is a schematic flowchart of another embodiment of the method for detecting hidden kernel modules of the present disclosure; Figure 3 is a schematic structural diagram of an embodiment of the device for detecting hidden kernel modules of the present disclosure; Figure 4 is a schematic structural diagram of an embodiment of the electronic device of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0012] It should be noted that the following detailed description is exemplary and is intended to provide further illustration of the present disclosure. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present disclosure belongs.

[0013] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present disclosure. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0014] In the case of no conflict, the embodiments in the present disclosure and the features in the embodiments may be combined with each other.

[0015] In order to make the technical solution and advantages of the present disclosure more clear and understandable, the present disclosure will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0016] Figure 1 shows the process 100 of an embodiment of the method for detecting hidden kernel modules of the present disclosure. As Figure 1As shown in the figure, the method for detecting a hidden kernel module in this embodiment may include the following steps: Step 101: Obtain the starting addresses of each kernel module to obtain a set of starting addresses.

[0017] In this embodiment, the starting addresses of each kernel module may be obtained first to obtain a set of starting addresses. Specifically, the starting addresses of each kernel module may be obtained by executing a preset instruction. Alternatively, the starting addresses may be determined by reading the data at a preset storage location. The starting addresses of each kernel module may be stored in an array to obtain a set of starting addresses.

[0018] Step 102: Determine the target function hooked in the preset function set.

[0019] In this embodiment, a function set may be preset in advance. The functions in this function set may be functions that are easily hooked (hooked). This function set may be preset by technicians according to experience. Whether a function is hooked may be determined by analyzing the statements included in each function in the function set. For example, it may be analyzed whether the head of the function includes a jump instruction, or whether the head of the function contains a specified field. If a function includes a preset jump instruction, it is considered that the function is hooked.

[0020] Step 103: Determine the target address of the target function.

[0021] After determining the hooked target function, the target address of the target function may be further determined. Specifically, the address information included in the target function may be used as the target address. Alternatively, the target address may be obtained by performing a preset operation based on the address information included in the target function. Generally, after the target function is hooked, it will jump to a certain kernel module to execute the instructions in the kernel module. The target address here is generally located in the hidden kernel module.

[0022] Step 104: Determine the predicted starting address of the kernel module corresponding to the target address.

[0023] After determining the target address, the starting address of the corresponding kernel module may be determined according to the target address. Since this starting address is located in the hidden kernel module, a specified operation may be performed on this target address to predict the starting address of the kernel module corresponding to the target address, which is denoted as the predicted starting address here. The specified operation here may include adding a preset value to the target address, and using the sum as the predicted starting address. Alternatively, multiple addresses may be obtained by searching upward from the target address, and one of the multiple addresses may be selected as the predicted starting address.

[0024] Step 105: Detect whether the kernel module corresponding to the target address is a hidden kernel module according to the predicted starting address and the set of starting addresses.

[0025] After determining the predicted start address, in combination with the start address set, it can be determined whether the kernel module corresponding to the target address is a hidden kernel module. It can be understood that the kernel modules corresponding to the start addresses in the start address set are non-hidden kernel modules that can be detected at the application layer. If the kernel module corresponding to the target address is also non-hidden, the predicted start address should be in the start address set. If the predicted start address does not belong to the start address set, it means that the kernel module corresponding to the target address is undetectable at the application layer and belongs to a hidden kernel module.

[0026] The hidden kernel module detection method provided by the above embodiments of the present disclosure can start from the hook functions in the system to further detect whether there is a hidden Rootkit kernel module in the system. Compared with the traditional detection idea, this method is simpler and more efficient.

[0027] Continue to refer to Figure 2 , which shows the flow 200 of another embodiment of the hidden kernel module detection method according to the present disclosure. As Figure 2 shown, the method in this embodiment may include the following steps: Step 201, by executing a preset instruction, obtain the start address of the kernel module to obtain a start address set.

[0028] In this embodiment, the start address of the kernel module can be obtained by executing a preset instruction. Specifically, the cat / proc / modules command can be executed to obtain the start address of the kernel module. Through this instruction, the name of the kernel module can also be obtained. The name and start address of the kernel module can be stored in an array.

[0029] Step 202, for each function in the preset function set, detect the head of the function to determine whether there is a jump instruction; in response to determining that there is a jump instruction in the head of the function, determine that the function is hooked.

[0030] In this embodiment, the preset function set may include multiple functions that are often hooked. The heads of these functions can be detected to determine whether there is a jump instruction. Specifically, the head of the function can be analyzed to determine whether there is a specific format string. If it exists, it is considered that there is a jump instruction.

[0031] If there is a jump instruction in the head of a certain function, it is considered that the function is hooked.

[0032] Step 203, parse the jump instruction to determine the address information contained therein; determine the type of the jump instruction; according to the type and the address information, determine the target address.

[0033] After determining the objective function, the jump instructions of the objective function can be further parsed to determine the address information contained therein. The address information here can be a relative address or an absolute address. At the same time, the type of the jump instruction can also be determined. If it is an absolute jump, it can be determined that the address information therein is an absolute address, and the address information can be directly used as the target address. If it is a relative jump, it can be determined that the address information therein is a relative jump, and the address information can be added to the current address to obtain the target address.

[0034] Step 204: Perform a memory page alignment search upward from the target address to determine multiple search addresses; determine a predicted starting address from the multiple search addresses.

[0035] After obtaining the target address, in order to determine the starting address of the corresponding kernel module, a memory page alignment search can be performed upward from the target address to determine multiple search addresses. Then, a predicted starting address is determined from the multiple search addresses. In the system kernel space, the memory space is page-aligned in units of 0x1000, and the module starting address is located at the start of the memory page. If the address we found is inside the module, such as 0x40332A, then we can successively round up in units of 0x1000 and determine whether 0x403000, 0x402000, 0x401000 are legal module addresses respectively. If they are legal, the predicted starting address can be obtained.

[0036] Step 205: In response to determining that the predicted starting address is different from each starting address in the starting address set, determine that the kernel module corresponding to the target address is a hidden kernel module.

[0037] If the predicted starting address is different from each starting address in the starting address set, it indicates that the kernel module corresponding to the target address is a hidden kernel module.

[0038] Step 206: In response to determining that the predicted starting address is the same as any one of the starting addresses in the starting address set, determine that the kernel module corresponding to the target address is not a hidden kernel module.

[0039] If the predicted starting address is the same as any one of the starting addresses in the starting address set, determine that the kernel module corresponding to the target address is not a hidden kernel module.

[0040] The hidden kernel module detection method provided by the above embodiments of the present disclosure, through the kernel module data obtained by the application layer and the kernel module data obtained by the kernel layer, is simple, effective, and free of false alarms. Compared with the traditional detection idea, this method has a shorter running time and more accurate detection.

[0041] Further reference Figure 3, as an implementation of the methods shown in the above figures, the present disclosure provides an embodiment of a hidden kernel module detection device, which corresponds to the method embodiment shown in Figure 1 and can be specifically applied to various electronic devices.

[0042] As shown in Figure 3 , the hidden kernel module detection device 300 of this embodiment includes: an address acquisition unit 301, a function determination unit 302, an address determination unit 303, an address prediction unit 304, and a module detection unit 305.

[0043] The address acquisition unit 301 is configured to acquire the starting addresses of each kernel module to obtain a set of starting addresses.

[0044] The function determination unit 302 is configured to determine the target function hooked in the preset function set.

[0045] The address determination unit 303 is configured to determine the target address of the target function.

[0046] The address prediction unit 304 is configured to determine the predicted starting address of the kernel module corresponding to the target address.

[0047] The module detection unit 305 is configured to detect whether the kernel module corresponding to the target address is a hidden kernel module according to the predicted starting address and the set of starting addresses.

[0048] In addition, in the technical solution of the present application, an electronic device is also proposed.

[0049] Figure 4 shows a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure.

[0050] As shown in Figure 4 , the electronic device may include a processor 401, a memory 402, a bus 403, and a computer program stored on the memory 402 and executable on the processor 401. Among them, the processor 401 and the memory 402 complete mutual communication through the bus 403. When the processor 401 executes the computer program, the steps of the above method are implemented, for example, including: acquiring the starting addresses of each kernel module to obtain a set of starting addresses; determining the target function hooked in the preset function set; determining the target address of the target function; determining the predicted starting address of the kernel module corresponding to the target address; and detecting whether the kernel module corresponding to the target address is a hidden kernel module according to the predicted starting address and the set of starting addresses.

[0051] In addition, in an embodiment of the present disclosure, a non-transitory computer-readable storage medium is further provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method are implemented, for example, including: obtaining the starting addresses of each kernel module to obtain a set of starting addresses; determining the target function hooked in a preset function set; determining the target address of the target function; determining the predicted starting address of the kernel module corresponding to the target address; and detecting whether the kernel module corresponding to the target address is a hidden kernel module according to the predicted starting address and the set of starting addresses.

[0052] In summary, in the technical solution of the present disclosure, starting from detecting the hook function in the system, it is further detected whether there is a hidden Rootkit kernel module in the system. Compared with the traditional detection idea, this method is simpler and more efficient.

[0053] The foregoing is only a preferred embodiment of the present disclosure and is not intended to limit the present disclosure. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present disclosure shall be included within the scope of protection of the present disclosure.

Claims

1. A method for detecting a hidden kernel module, comprising: Obtain the starting addresses of each kernel module to obtain a set of starting addresses; Determine the target function hooked in the preset function set; Determine the target address of the target function; Determine the predicted starting address of the kernel module corresponding to the target address; According to the predicted starting address and the set of starting addresses, detect whether the kernel module corresponding to the target address is a hidden kernel module.

2. The method according to claim 1, wherein, The obtaining the starting addresses of each kernel module includes: Execute a preset instruction to obtain the starting address of the kernel module.

3. The method according to claim 1, wherein, The determining the target function hooked in the preset function set includes: For each function in the preset function set, detect the head of the function to determine whether there is a jump instruction; In response to determining that there is a jump instruction at the head of the function, determine that the function is hooked.

4. The method according to claim 3, wherein, The determining the target address of the target function includes: Parse the jump instruction to determine the address information contained therein; Determine the type of the jump instruction; According to the type and the address information, determine the target address.

5. The method according to claim 4, wherein, The determining the predicted starting address of the kernel module corresponding to the target address includes: Perform a memory page alignment search upward from the target address to determine a plurality of search addresses; Determine the predicted starting address from the plurality of search addresses.

6. The method according to any one of claims 1-5, wherein, The detecting whether the kernel module corresponding to the target address is a hidden kernel module according to the predicted starting address and the set of starting addresses includes: In response to determining that the predicted starting address is different from each starting address in the set of starting addresses, determine that the kernel module corresponding to the target address is a hidden kernel module.

7. The method according to claim 6, wherein, The detecting whether the kernel module corresponding to the target address is a hidden kernel module according to the predicted starting address and the set of starting addresses includes: In response to determining that the predicted starting address is the same as any one of the starting addresses in the set of starting addresses, determine that the kernel module corresponding to the target address is not a hidden kernel module.

8. A device for detecting a hidden kernel module, comprising: An address acquisition unit configured to obtain the starting addresses of each kernel module to obtain a set of starting addresses; A function determination unit configured to determine the target function hooked in the preset function set; An address determination unit configured to determine the target address of the target function; An address prediction unit configured to determine the predicted starting address of the kernel module corresponding to the target address; A module detection unit configured to detect whether the kernel module corresponding to the target address is a hidden kernel module according to the predicted starting address and the set of starting addresses.

9. An electronic device, comprising a memory, a processor, a bus, and a computer program stored on the memory and executable on the processor, wherein, When the processor executes the computer program, it implements the hidden kernel module detection method according to any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by the processor, it implements the hidden kernel module detection method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Evidence obtaining method and device based on kernel layer Rootkit of Linux system

    CN111695116A

  • Method and device for detecting kernel thread with disguised initial address

    CN113010885A

  • Processing method and device under condition of being hooked of function

    CN113918935A

  • Kernel-level Rootkit detection system and method

    CN116484374A

  • Method and device for detecting malicious software in operating system and storage medium

    CN117744082A