Code detection method and device, equipment and storage medium
By obtaining the firmware instruction address sampling results in the performance monitoring unit or debugging controller within the CPU, the problem of malicious code detection resource occupation and security vulnerabilities in the prior art is solved, and efficient and secure malicious code detection is achieved without intrusion.
Patent Information
- Application Number
- CN202510393731.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-08
AI Technical Summary
When detecting malicious code in firmware, the prior art needs to deploy virus protection software to the CPU, resulting in resource occupation and system pause, and there is a security vulnerability attack surface, making it difficult to achieve non-invasion detection.
The performance monitoring unit or debugging controller in the CPU obtains the instruction address sampling results of the firmware runtime, determines the distribution characteristics, and compares them with the pre-stored or real-time acquired distribution characteristics to determine whether there is malicious code.
It realizes non-invasive malicious code detection, avoids CPU resource occupation and system pauses, reduces the attack surface of security vulnerabilities, and improves the accuracy and security of detection.
Smart Images

Figure CN120277667A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a code detection method, apparatus, device, and storage medium. Background Art
[0002] Malicious code generally refers to harmful computer applications that aim to create or exploit system vulnerabilities, make harmful changes to, damage, or continuously access a computer, which may lead to the emergence of security vulnerabilities, theft of information data, or other potential damages to files and computer systems.
[0003] Currently, when detecting malicious code in newly developed firmware (programs), it is first necessary to deploy the firmware to the CPU, and then install virus protection software in the firmware for detection. Virus protection software is a type of software designed to protect a computer from viruses, malware, and other network threats, and can perform real-time monitoring, virus scanning, virus signature analysis, and virus removal on the computer based on a virus library. One detection method is to perform detection control and release after intercepting through the CPU kernel mode, and another method is to determine whether there is malicious code by scanning the signatures in the executable files of the firmware. However, both of these methods will occupy the resources of the CPU and may cause problems such as system pauses; moreover, virus protection software needs to intrude into a highly privileged privilege state, such as the kernel mode. If the virus protection software is used improperly, it may cause a larger vulnerability attack surface, and once the virus protection software crashes, it may lead to the crash of the entire system.
[0004] Therefore, there is an urgent need for a method to detect whether there is malicious code in the firmware without intrusion. Summary of the Invention
[0005] This application provides a code detection method, apparatus, device, and storage medium to achieve non-intrusive detection of whether there is malicious code in the firmware.
[0006] In a first aspect, this application provides a code detection method, which is applicable to an execution flow monitoring unit and includes: Obtain a first distribution feature of the firmware; the first distribution feature characterizes the variation law of the sampling results of instruction addresses in the running state of the firmware; Through the performance monitoring unit PMU in the CPU or the debug controller in the CPU, obtain each instruction address sampled by the CPU during a first time period when running the firmware; Determine a second distribution feature according to each instruction address sampled during the first time period; Compare the second distribution feature with the first distribution feature to determine whether there is malicious code in the firmware.
[0007] This application uses the PMU within the CPU or the debug controller within the CPU to obtain each instruction address sampled by the CPU during the first time period of running the firmware. The instruction address is the address of the instruction that the CPU is executing when the sampling occurs, and determines the second distribution feature, and then compares the second distribution feature with the first distribution feature to determine whether there is malicious code in the firmware. Compared with the method of detecting the code of the firmware by installing malicious code detection software on the firmware, this application samples the running state of the CPU using the PMU or debug controller built into the CPU, and through a series of analysis, processing, and comparison of the sampling results, realizes non-invasive detection of the firmware, does not occupy the resources of the CPU, and avoids phenomena such as system stalls; in addition, non-invasive detection of the firmware can avoid creating a larger security vulnerability attack surface and is more secure and reliable.
[0008] In a possible design, the first distribution feature is the variation law of the sampling results of the instruction addresses stored in advance when there is no malicious code in the firmware; Alternatively, the first distribution feature is obtained according to the sampling results of the CPU for each instruction address during the second time period of running the firmware; the end time of the second time period is earlier than the start time of the first time period.
[0009] The first distribution feature can be stored in advance. However, considering that the variation law of the sampling results of the instruction addresses is not immutable and may change with the change of some internal or external factors, therefore, the first distribution feature can also be obtained according to the sampling results of the CPU for each instruction address during the second time period of running the firmware, improving the flexibility and accuracy of the first distribution feature.
[0010] In a possible design, obtaining the sampling results of the CPU for each instruction address during the first time period of running the code through the PMU within the CPU includes: Sending at least one first instruction to the test access port TAP of the CPU; Obtaining at least one sampling value for the instruction address from the PMU within the CPU through the at least one first instruction; the at least one sampling value represents the sampling results of the computing core of the CPU during the first time period of running the firmware.
[0011] In a possible design, the execution flow monitoring unit is a debug host located outside the CPU; Sending at least one first instruction to the TAP of the CPU includes: Instructing the debug probe to send the at least one first instruction to the TAP of the CPU; the debug probe and the CPU interact using the same debug protocol.
[0012] In a possible design, the execution flow monitoring unit is a debug probe located outside the CPU.
[0013] In a possible design, the execution flow monitoring unit is located inside the CPU.
[0014] The execution flow monitoring unit can be a debug host located outside the CPU, can also be a debug probe located outside the CPU, or can also be located inside the CPU. The position setting of the execution flow monitoring unit is very flexible and has good compatibility.
[0015] In a possible design, obtaining each instruction address sampled by the CPU during a first time period of running the firmware through a debug controller inside the CPU includes: Pausing the operation of the computing core of the CPU through a debug controller inside the CPU and reading the program counter PC inside the CPU, where the PC stores the instruction address; the computing core of the CPU is in the first time period of running the firmware.
[0016] In a possible design, comparing the second distribution feature with the first distribution feature includes: Comparing the second distribution feature with the first distribution feature according to a preset rule; the preset rule includes at least one of an instruction address increment rule, an execution frequency rule of each function, an execution frequency rule of each address range, a jump rule, and a kernel mode entry rule.
[0017] Comparing the second distribution feature with the first distribution feature in detail and comprehensively from multiple aspects such as the instruction address increment rule, the execution frequency rule of each function, the execution frequency rule of each address range, the jump rule, and the kernel mode entry rule can improve the accuracy of the code detection result.
[0018] In a possible design, comparing the second distribution feature with the first distribution feature according to a preset rule includes: Comparing the second distribution feature with the first distribution feature according to a preset rule from the global dimension of the firmware, and / or comparing the second distribution feature with the first distribution feature according to a preset rule from the component dimension of the firmware; the global dimension is a dimension that does not distinguish components.
[0019] Comparing the second distribution feature with the first distribution feature according to a preset rule from a global dimension may result in a relatively high false positive or false negative due to the relatively coarse comparison granularity. Therefore, it is possible to compare the second distribution feature with the first distribution feature according to a preset rule from the dimension of the composition components of the firmware, that is, from a more refined dimension, or combine the two to comprehensively compare the second distribution feature with the first distribution feature, further improving the accuracy of the code detection result.
[0020] In a possible design, the composition components of the firmware include services and / or programs, and the services and the programs include functions and / or routines; the sampling result for each instruction address further includes an address space identifier ASID.
[0021] In a possible design, comparing the second distribution feature with the first distribution feature according to a preset rule to determine whether there is malicious code in the firmware includes: When comparing the second distribution feature with the first distribution feature using the instruction address increment rule, the absolute value of the difference between the occurrence frequency of the instruction address increment indicated by the second distribution feature and the occurrence frequency of the instruction address increment indicated by the first distribution feature is greater than a first preset value. Or, when comparing the second distribution feature with the first distribution feature using the execution frequency rule of each function, the absolute value of the difference between the execution frequency of each function indicated by the second distribution feature and the execution frequency of each function indicated by the first distribution feature is greater than a second preset value. Or, when comparing the second distribution feature with the first distribution feature using the execution frequency of each address range, the absolute value of the difference between the execution frequency of each address range indicated by the second distribution feature and the execution frequency of each address range indicated by the first distribution feature is greater than a third preset value. Or, when comparing the second distribution feature with the first distribution feature using the jump rule, the absolute value of the difference between the jump frequency indicated by the second distribution feature and the jump frequency indicated by the first distribution feature is greater than a fourth preset value. Or, when comparing the second distribution feature with the first distribution feature using the kernel mode entry rule, the absolute value of the difference between the kernel mode entry frequency indicated by the second distribution feature and the kernel mode entry frequency indicated by the first distribution feature is greater than a fifth preset value, then it is determined that there is malicious code in the firmware.
[0022] In a possible design, after determining that there is malicious code in the firmware, it further includes: Send a first signal to the reset pin of the CPU, where the first signal is used to indicate that the CPU restarts; or, send exception information to the CPU, where the exception information is determined according to the malicious code.
[0023] After determining that there is malicious code in the firmware, a first signal for indicating that the CPU restarts can be sent to the CPU, so that the CPU runs the firmware again; or, send exception information to the CPU to promptly inform the CPU that there is an exception in the currently running firmware and the CPU should immediately stop running the firmware to improve the security of the CPU.
[0024] In a second aspect, the present application further provides a code detection device, which is applicable to an execution flow monitoring unit and includes: a processing unit and a transceiver unit; The transceiver unit is used to obtain a first distribution feature of the firmware; the first distribution feature characterizes the change rule of the sampling result of the instruction address in the running state of the firmware; The transceiver unit is further used to obtain each instruction address sampled by the CPU within a first time period when running the firmware through the PMU in the CPU or the debug controller in the CPU; The processing unit is used to determine a second distribution feature according to each instruction address sampled within the first time period; The processing unit is further used to compare the second distribution feature with the first distribution feature to determine whether there is malicious code in the firmware.
[0025] In a possible design, the first distribution feature is the change rule of the sampling result of the instruction address stored in advance when there is no malicious code in the firmware; Alternatively, the first distribution feature is obtained according to the sampling results of each instruction address by the CPU within a second time period when running the firmware; the end time of the second time period is earlier than the start time of the first time period.
[0026] In a possible design, when the transceiver unit is used to obtain the sampling results of each instruction address by the CPU within a first time period when running the code through the PMU in the CPU, it is specifically used to: send at least one first instruction to the TAP of the CPU; obtain at least one sampling value for the instruction address from the PMU in the CPU through the at least one first instruction; the at least one sampling value characterizes the sampling result of the computing core of the CPU within the first time period when running the firmware.
[0027] In a possible design, the execution flow monitoring unit is a debug host located outside the CPU; the transceiver unit is specifically configured to: instruct a debug probe to send the at least one first instruction to the TAP of the CPU; the debug probe and the CPU interact using the same debug protocol.
[0028] In a possible design, the execution flow monitoring unit is a debug probe located outside the CPU.
[0029] In a possible design, the execution flow monitoring unit is located inside the CPU.
[0030] In a possible design, when the transceiver unit is used to obtain each instruction address sampled by the CPU during a first time period of running the firmware through a debug controller inside the CPU, it is specifically configured to: pause the operation of the computing core of the CPU through the debug controller inside the CPU and read the program counter PC inside the CPU, where the PC stores the instruction address; the computing core of the CPU is in the first time period of running the firmware.
[0031] In a possible design, when the processing unit is used to compare the second distribution feature with the first distribution feature, it is specifically configured to: compare the second distribution feature with the first distribution feature according to a preset rule; the preset rule includes at least one of an instruction address increment rule, an execution frequency rule for each function, an execution frequency rule for each address range, a jump rule, and a kernel mode entry rule.
[0032] In a possible design, when the processing unit is used to compare the second distribution feature with the first distribution feature according to a preset rule, it is specifically configured to: compare the second distribution feature with the first distribution feature according to a preset rule from the global dimension of the firmware, and / or compare the second distribution feature with the first distribution feature according to a preset rule from the component dimension of the firmware; the global dimension is a dimension that does not distinguish components.
[0033] In a possible design, the components of the firmware include services and / or programs, and the services and the programs include functions and / or routines; the sampling result for each instruction address further includes an address space identifier ASID.
[0034] In a possible design, when the processing unit is used to compare the second distribution feature with the first distribution feature according to a preset rule to determine whether there is malicious code in the firmware, it is specifically used for: when comparing the second distribution feature with the first distribution feature by using the instruction address increment rule, the absolute value of the difference between the occurrence frequency of the instruction address increment indicated by the second distribution feature and the occurrence frequency of the instruction address increment indicated by the first distribution feature is greater than a first preset value. Or, when comparing the second distribution feature with the first distribution feature by using the execution frequency rule of each function, the absolute value of the difference between the execution frequency of each function indicated by the second distribution feature and the execution frequency of each function indicated by the first distribution feature is greater than a second preset value. Or, when comparing the second distribution feature with the first distribution feature by using the execution frequency of each address range, the absolute value of the difference between the execution frequency of each address range indicated by the second distribution feature and the execution frequency of each address range indicated by the first distribution feature is greater than a third preset value. Or, when comparing the second distribution feature with the first distribution feature by using the jump rule, the absolute value of the difference between the jump frequency indicated by the second distribution feature and the jump frequency indicated by the first distribution feature is greater than a fourth preset value. Or, when comparing the second distribution feature with the first distribution feature by using the kernel mode entry rule, the absolute value of the difference between the kernel mode entry frequency indicated by the second distribution feature and the kernel mode entry frequency indicated by the first distribution feature is greater than a fifth preset value, then it is determined that there is malicious code in the firmware.
[0035] In a possible design, the transceiver unit is further configured to send a first signal to the reset pin of the CPU, where the first signal is used to indicate the CPU to restart; or send exception information to the CPU, and the exception information is determined according to the malicious code.
[0036] In a third aspect, the present application further provides a code detection device, which includes: a processor, and a memory communicatively connected to the processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory to implement the method described in the first aspect above.
[0037] In a fourth aspect, the present application further provides a computer-readable storage medium, where the readable storage medium includes a program, and when the program is executed on a device, the device is caused to execute the method described in any one of the first aspects above.
[0038] Fifth aspect, the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the method described in the first aspect above. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0040] Figure 1 Schematic diagram of the malicious code execution process provided by the embodiment of the present application; Figure 2 Schematic diagram of the code detection method process provided by the embodiment of the present application; Figure 3 Schematic diagram of the variation law of the sampling results of instruction addresses when the firmware provided by the embodiment of the present application does not have malicious code; Figure 4 Schematic diagram when the execution flow monitoring unit provided by the embodiment of the present application is a debug host outside the CPU; Figure 5 Schematic diagram when the execution flow monitoring unit provided by the embodiment of the present application is a debug probe outside the CPU; Figure 6 Schematic diagram when the execution flow monitoring unit provided by the embodiment of the present application is inside the CPU; Figure 7 Schematic diagram of the variation law of the sampling results of instruction addresses when the firmware provided by the embodiment of the present application has malicious code; Figure 8 Schematic structure of the code detection device provided by the embodiment of the present application Figure One ; Figure 9 Schematic structure of the code detection device provided by the embodiment of the present application Figure Two 。 DETAILED DESCRIPTION OF THE EMBODIMENTS
[0041] In order to make the objectives, technical solutions and advantages of the present application clearer, the following will further describe the present application in detail with reference to the drawings. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts belong to the scope of protection of the present application.
[0042] The application scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. It is known to those skilled in the art that with the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems. In the description of the present application, unless otherwise specified, the meaning of "multiple" is two or more.
[0043] Currently, most of the mainstream malicious code attacks are remote code execution (RCE) attacks. The execution process is as follows: Figure 1 As shown in the figure, its characteristics are usually to use the network to send maliciously constructed requests to the vulnerable programs installed in the target victim computer, inject malicious payloads, and use software vulnerabilities to make the program call dangerous Syscall to infect the computer. Syscall refers to the operation that a program running in user space requests higher permissions from the operating system kernel to perform, such as interacting with hardware and applying for memory. Virtual memory is divided into two segments: kernel space and user space. Since both the kernel and user programs need memory to run, both the kernel and user programs need to occupy a certain amount of virtual memory space. In other words, the kernel runs in the kernel space and the user program runs in the user space. Since the kernel has privileges, it can access the user space; conversely, since the user space does not have privileges, the user space accessing the kernel space will cause an exception.
[0044] Since user programs should not be able to directly access physical memory, it is necessary to establish a mapping that allows user programs to indirectly access physical memory. After the mapping is established, the memory address used by the user program can become a virtual memory address or virtual address.
[0045] Malicious code detection software prevents the execution of malicious code by setting up checkpoints on the path that malicious code must take to launch an attack. However, malicious code detection software has problems with detection blind spots. For example, the detection of zero-day vulnerability attacks is delayed due to the failure to update the detection software's database in a timely manner. Malware has also developed many technologies to evade detection, such as obfuscating or encrypting malicious code to cover up its malicious characteristics. If users who install malicious code detection software do not update the detection software in a timely manner, the false positive rate and missed positive rate of the detection software will continue to rise.
[0046] As viruses continue to evolve, detection software also needs to constantly update its algorithms and databases, which inevitably leads to increasingly bloated algorithms and databases, which in turn reduces CPU resource utilization and affects CPU performance.
[0047] In addition, common malicious code detection software has serious system dependencies. It usually needs to run as a background service permanently and relies on specific system Application Programming Interfaces (APIs) to audit and intercept important calls. It may also conflict with other security software or even software that is running normally. The serious system dependencies result in poor compatibility of malicious code detection software with major operating system updates.
[0048] This application proposes a code detection method to achieve non-invasive firmware malicious code detection for firmware. As Figure 2 shown, the execution entity of this method is the execution flow monitoring unit, that is, this method is applicable to the execution flow monitoring unit, and specifically includes: Step 201: Obtain the first distribution feature of the firmware; the first distribution feature characterizes the change rule of the sampling result of the instruction address in the running state of the firmware.
[0049] Exemplarily, the firmware can be understood as a bare-metal program. A bare-metal program refers to a program running on computer hardware and needs to directly operate computer hardware devices. For example, the firmware in this application runs on the CPU. In computer technology, an instruction is a single CPU operation defined by an instruction set architecture. In a traditional instruction set architecture, an instruction includes an opcode and zero or more operands. The length of an instruction can be fixed or variable, but it is usually an integer multiple of a byte or half a byte. The instructions that make up a program are rarely directly used in their numerical form inside the machine and generally need to be represented by developers in assembly language or generated by a compiler.
[0050] Since it is unknown whether there is malicious code in the firmware and what kind of malicious code exists, but relevant technical personnel can determine the change rule of the sampling result of the instruction address when there is no malicious code in the firmware. Therefore, the first distribution feature can be the change rule of the sampling result of the instruction address stored in advance when there is no malicious code in the firmware; where the instruction address is the address of the instruction that the CPU is executing when sampling occurs.
[0051] Exemplarily, since the change rule of the sampling result of the instruction address may change with the change of some internal or external factors, using the pre-stored first distribution feature for subsequent comparison may not be accurate enough and may affect the code detection result. Therefore, the first distribution feature can also be obtained according to the sampling results of each instruction address by the CPU in the second time period of running the firmware. The first distribution feature can be represented in the form of a picture or other data structure forms readable by the server, and this application does not make any limitations in this regard. For example, Figure 3As an example when the first distribution feature is represented in the form of a picture, generally speaking, a normally running program has logic, and the execution flow generally has coherence and repeatability. Within a short duration, as long as there is no jump, the sampled addresses will show incrementality. Most programs are composed of multiple functions. Due to the different call frequencies of each function, the sampled addresses will also show significant distribution characteristics.
[0052] Step 202: Obtain each instruction address sampled by the CPU within the first time period when running the firmware through the Performance Monitoring Unit (PMU) in the CPU or the debug controller in the CPU.
[0053] Exemplarily, modern CPU architectures generally integrate complex debugging and performance monitoring systems. The core is the debug controller. As an independent hardware unit, the debug controller can communicate directly with the CPU core and can also access various status registers of the CPU in real time, including the special register group in the PMU. Among them, the CPU core can also be called the computing core.
[0054] The debug controller is connected to the CPU core through a dedicated debug bus. In addition to being able to temporarily interrupt the program execution according to the wishes of technicians to detect or modify the state of the program at any time, it can also sample runtime statistical data without interrupting the normal execution of the program. Even when the CPU is in the kernel mode, the debug controller can interrupt the execution of the CPU, detect or modify the state of the program. Since the debug controller can also access the bus, the debug controller can bypass the privilege restrictions of the Memory Management Unit (MMU) and access physical memory. Thus, the debug controller can be regarded as having higher privileges than the kernel mode. In short, any software vulnerability will not affect the debug controller. If the debug mechanism is used to implement vulnerability detection and protection, attackers cannot bypass it.
[0055] This application provides multiple ways to obtain each instruction address sampled by the CPU within the first time period when running the firmware, where the end time of the second time period is earlier than the start time of the first time period: (1) Method 1: The execution flow monitoring unit is a debug host located outside the CPU, such as Figure 4As shown, the execution flow monitoring unit instructs the debug probe to send at least one first instruction to the Test Access Port (TAP) of the CPU, and obtain at least one sampling value for the instruction address from the PMU within the CPU through the at least one first instruction. The at least one sampling value characterizes the sampling result of the computing core of the CPU during the first time period of running the firmware. In other words, the at least one sampling value constitutes the sampling result of the computing core of the CPU during the first time period of running the firmware, and then the at least one sampling value is transmitted to the execution flow monitoring unit for performing step 203. Among them, the first instruction does not affect the normal execution of the CPU.
[0056] The performance monitoring unit has a PC sampling register, and the computing core of the CPU has a PC register. In a computer architecture, the PC register is an important component, and the PC register can also be called the Program Counter (PC), which is used to store the address of an instruction and indicate which instruction the processor should execute next. The performance monitoring unit and the computing core can communicate directly. The PC sampling register stores the sampling result of the instruction address, and the instruction address in the PC register is periodically synchronized to the PC sampling register to update the sampling. Accessing the PC sampling register does not affect the normal execution of the CPU and does not require pausing the operation of the CPU.
[0057] The debug probe interacts with the CPU using the same debug protocol. The debug protocol is a hardware-level debug interface standard, mainly including protocol families such as Joint Test Action Group (JTAG) and SerialWire Debug (SWD). The debug protocol allows an external debugger to directly access the TAP of the CPU through a dedicated port, thereby realizing non-intrusive real-time monitoring and control of the processor core registers, system bus, and on-chip peripherals.
[0058] (2) Method 2: The execution flow monitoring unit is a debug probe located outside the CPU. As Figure 5 shown, the execution flow monitoring unit sends at least one first instruction to the TAP of the CPU. Similar to the above Method 1, it obtains the sampling result for the instruction address from the PMU within the CPU through the at least one first instruction, and then transmits the sampling result to the execution flow monitoring unit. Among them, the first instruction does not affect the normal execution of the CPU.
[0059] (3) Method 3: The execution flow monitoring unit is located within the CPU. As Figure 6 shown, the execution flow monitoring unit can directly obtain the sampling result for the instruction address from the PMU within the CPU.
[0060] (4)Method 4: Although most existing CPUs currently have a PMU, there are still a few CPUs that do not have a PMU. Or, even if there is a PMU, it does not provide the instruction address sampling (PC pointer sampling) function. Or, even if the PMU provides instruction address sampling, the sampling results cannot be directly read through the TAP. For CPUs that do not have a PMU, do not provide instruction address sampling, or cannot directly read the sampling results, the operation of the computing core of the CPU can be paused through the debug controller in the CPU, and the PC register in the CPU can be read, and then the operation of the computing core of the CPU can be resumed; where the PC stores the instruction address, and the computing core of the CPU is in the first time period of running the firmware; that is, each instruction address sampled by the CPU during the first time period of running the firmware is obtained through the debug controller.
[0061] When the CPU has a PMU, the code detection method proposed in this application obtains the required sampling results through the PMU. At this time, the execution flow monitoring unit can be a debug host or a debug probe located outside the CPU, or can be located inside the CPU; for CPUs that do not have a PMU, the required sampling results can also be obtained through the debug controller in the CPU. Therefore, the code detection method proposed in this application has good compatibility.
[0062] Step 203: Determine the second distribution feature according to each instruction address sampled during the first time period.
[0063] Exemplarily, through step 202, each instruction address sampled during the first time period can be obtained, and statistical analysis is performed on the sampled instruction addresses, then the second distribution feature can be determined; similarly, the second distribution feature can also be represented in the form of a picture. For example, assume that the second distribution feature is as Figure 7 shown.
[0064] Step 204: Compare the second distribution feature with the first distribution feature to determine whether there is malicious code in the firmware.
[0065] Exemplarily, after obtaining the second distribution feature through step 203, the second distribution feature can be compared with the first distribution feature according to a preset rule; where the preset rule includes at least one of the instruction address increment rule, the execution frequency rule of each function, the execution frequency rule of each address range, the jump rule, and the rule of entering the kernel state.
[0066] The following explains the above several rules: (1)Instruction address increment rule: When there is no jump, instructions are executed one after another. At this time, the instruction address (i.e., the value of the PC pointer) continuously monotonically increases by the instruction length as the step size each time. Both backward jumps and instruction address increments will result in a positive difference between the two consecutive instruction address sampling values (while forward jumps will result in a negative difference). However, the magnitude of the difference can be used to distinguish them: Since the instruction address increment occurs with the instruction length as the step size, the difference between the two consecutive instruction address sampling values should be close to the time difference between the two samplings multiplied by the operating frequency (main frequency) of the CPU multiplied by the instruction length, which is called the target value; if a forward jump has occurred in between, the difference between the two consecutive instruction address sampling values will be significantly less than the target value; if a backward jump has occurred in between, the difference between the two consecutive instruction address sampling values will be significantly greater than the target value. Since jumps do not occur very frequently, the occurrence frequency of instruction address increments should be maintained within a suitable numerical range; (2)Execution frequency rule of each function: Different functions are located at different addresses. By analyzing metadata such as the symbol table of the program, the address range where each function is located can be determined; therefore, the currently executing function can be determined through the instruction address; in the firmware, some functions are used more frequently, while some functions are rarely used. If there are no major factor changes, the execution frequency of each function should be relatively stable; (3)Execution frequency rule of each address range: Similar to the execution frequency rule of functions, except that the address range is divided evenly or unevenly not based on functions but based on a specified length. For example, every 128 bytes are divided into an address range, and then the frequency of the sampled instruction addresses falling into different address ranges is counted. The frequency of falling into different address ranges should be maintained within a suitable numerical range; (4)Jump rule: Jumps are divided into two types: forward jumps and backward jumps. A forward jump refers to a jump from a larger memory address to a smaller memory address (so it will reduce the two consecutive instruction address sampling values, even making them negative). When there is a loop in a function, a considerable number of forward jumps will occur, and calls to other functions will also cause some forward jumps. The occurrence frequency of forward jumps should be maintained within a suitable numerical range; a backward jump refers to a jump from a smaller memory address to a larger memory address. When there are branches in a function, a significant number of backward jumps will occur. The occurrence frequency of backward jumps should also be maintained within a suitable numerical range; (5) Law of entering the kernel mode: Due to the occurrence of exceptions, interrupts, or traps (including system calls as well), the CPU will enter the kernel mode and hand over the handling of exceptions, interrupts, or traps to the kernel; when the CPU enters the kernel mode, the instruction address will point to the kernel space. Therefore, it is possible to determine whether the CPU is in the kernel mode based on the sampled instruction address; since entering the kernel mode will cause additional performance overhead, most firmware will avoid the too frequent occurrence of exceptions, interrupts, traps, or system calls, that is, the frequency of the CPU entering the kernel mode should be maintained within a suitable numerical range.
[0067] Exemplarily, when comparing the second distribution feature with the first distribution feature according to a preset rule, the second distribution feature can be compared with the first distribution feature according to the preset rule from the global dimension of the firmware, or the second distribution feature can be compared with the first distribution feature according to the preset rule from the component dimension of the firmware, or the second distribution feature can be compared with the first distribution feature according to the preset rule from both the global dimension and the component dimension of the firmware; among them, the global dimension is the dimension that does not distinguish components, and the components of the firmware include services and / or programs, and services and programs in turn include functions and / or routines, and a program is the upper concept of functions and routines; the sampling result for each instruction address also includes an Address Space Identifier (ASID). According to the instruction address, it is possible to determine which function or routine is the component of the currently running firmware, and according to the ASID, it is possible to determine which service or program is the component of the currently running firmware.
[0068] Exemplarily, when comparing the second distribution feature with the first distribution feature according to a preset rule from the component dimension of the firmware: If it is determined from the instruction address in the sampling result that the component of the firmware currently running by the CPU is a function, then compare the second distribution feature with the first distribution feature according to the preset rule from the function dimension; If it is determined from the instruction address in the sampling result that the component of the firmware currently running by the CPU is a routine, then compare the second distribution feature with the first distribution feature according to the preset rule from the routine dimension.
[0069] If it is determined from the ASID in the sampling result that the component of the firmware currently running by the CPU is a service, then compare the second distribution feature with the first distribution feature according to the preset rule from the service dimension; If it is determined from the ASID in the sampling result that the component of the firmware currently running by the CPU is a program, then compare the second distribution feature with the first distribution feature according to the preset rule from the program dimension.
[0070] Exemplarily, when comparing the second distribution feature with the first distribution feature according to a preset rule, if any of the following conditions is met, it can be considered that there is malicious code in the firmware: When comparing the second distribution feature with the first distribution feature using the instruction address increment rule, the absolute value of the difference between the occurrence frequency of the instruction address increment indicated by the second distribution feature and the occurrence frequency of the instruction address increment indicated by the first distribution feature is greater than a first preset value; When comparing the second distribution feature with the first distribution feature using the execution frequency rule of each function, the absolute value of the difference between the execution frequency of each function indicated by the second distribution feature and the execution frequency of each function indicated by the first distribution feature is greater than a second preset value; When comparing the second distribution feature with the first distribution feature using the execution frequency rule of each address range, the absolute value of the difference between the execution frequency of each address range indicated by the second distribution feature and the execution frequency of each address range indicated by the first distribution feature is greater than a third preset value; When comparing the second distribution feature with the first distribution feature using the jump rule, the absolute value of the difference between the jump frequency indicated by the second distribution feature and the jump frequency indicated by the first distribution feature is greater than a fourth preset value; When comparing the second distribution feature with the first distribution feature using the kernel mode entry rule, the absolute value of the difference between the kernel mode entry frequency indicated by the second distribution feature and the kernel mode entry frequency indicated by the first distribution feature is greater than a fifth preset value.
[0071] Further exemplarily, after determining that there is malicious code in the firmware, a first signal can be sent to the reset pin of the CPU, and the first signal is used to instruct the CPU to restart and run the firmware again; or, an exception message can be sent to the CPU to promptly inform the CPU that the running firmware is abnormal and the firmware should be stopped immediately; wherein, the exception message is determined according to the malicious code existing in the firmware.
[0072] When the CPU of the code detection method proposed in this application has a PMU, the required sampling results are obtained through the PMU. At this time, the execution flow monitoring unit can be used as a debugging host or a debugging probe located outside the CPU, or can be located inside the CPU; for a CPU without a PMU, this application also provides an alternative solution, that is, the required sampling results are obtained through the debugging controller inside the CPU. Therefore, the code detection method proposed in this application has good compatibility; in addition, the code detection method proposed in this application innovatively migrates the threat protection mechanism from the traditional attack surface to an independent execution environment, thereby effectively avoiding the situation where malware or malicious code makes the threat protection mechanism ineffective through vulnerability exploitation or bypass technology, and improving the effectiveness of the code detection method.
[0073] Figure 8and Figure 9 FIG. 2 is a schematic structural diagram of a possible code detection device provided for an embodiment of the present application. These code detection devices can be used to implement the functions of the execution flow monitoring unit in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments.
[0074] As Figure 8 shown, the code detection device 800 includes a processing unit 810 and a transceiver unit 820. The code detection device 800 is used to implement the functions of the execution flow monitoring unit in the above Figure 2 shown method embodiments.
[0075] When the code detection device 800 is used to implement the functions of the execution flow monitoring unit in the Figure 3 shown method embodiments: The transceiver unit 820 is configured to obtain a first distribution feature of the firmware; the first distribution feature characterizes the variation law of the sampling results of the instruction addresses in the running state of the firmware; The transceiver unit 820 is further configured to obtain each instruction address sampled by the CPU within a first time period of running the firmware through a PMU in the CPU or a debug controller in the CPU; The processing unit 810 is configured to determine a second distribution feature according to each instruction address sampled within the first time period; The processing unit 810 is further configured to compare the second distribution feature with the first distribution feature to determine whether there is malicious code in the firmware.
[0076] In a possible design, the first distribution feature is a variation law of the sampling results of instruction addresses stored in advance in the case that there is no malicious code in the firmware; Alternatively, the first distribution feature is obtained according to the sampling results of each instruction address by the CPU within a second time period of running the firmware; the end time of the second time period is earlier than the start time of the first time period.
[0077] In a possible design, when the transceiver unit 820 is configured to obtain the sampling results of each instruction address by the CPU within a first time period of running the code through the PMU in the CPU, it is specifically configured to: send at least one first instruction to the TAP of the CPU; obtain at least one sampling value for the instruction address from the PMU in the CPU through the at least one first instruction; the at least one sampling value characterizes the sampling results of the computing core of the CPU within the first time period of running the firmware.
[0078] In a possible design, the execution flow monitoring unit is a debug host located outside the CPU; the transceiver unit 820 is specifically configured to: instruct a debug probe to send the at least one first instruction to the TAP of the CPU; the debug probe and the CPU interact using the same debug protocol.
[0079] In a possible design, the execution flow monitoring unit is a debug probe located outside the CPU.
[0080] In a possible design, the execution flow monitoring unit is located inside the CPU.
[0081] In a possible design, when the transceiver unit 820 is configured to obtain each instruction address sampled by the CPU during a first time period of running the firmware through a debug controller inside the CPU, it is specifically configured to: pause the operation of the computing core of the CPU through the debug controller inside the CPU and read the program counter PC inside the CPU, where the PC stores the instruction address; the computing core of the CPU is in the first time period of running the firmware.
[0082] In a possible design, when the processing unit 810 is configured to compare the second distribution feature with the first distribution feature, it is specifically configured to: compare the second distribution feature with the first distribution feature according to a preset rule; the preset rule includes at least one of an instruction address increment rule, an execution frequency rule of each function, an execution frequency rule of each address range, a jump rule, and a kernel mode entry rule.
[0083] In a possible design, when the processing unit 810 is configured to compare the second distribution feature with the first distribution feature according to a preset rule, it is specifically configured to: compare the second distribution feature with the first distribution feature from the global dimension of the firmware according to the preset rule, and / or compare the second distribution feature with the first distribution feature from the component dimension of the firmware according to the preset rule; the global dimension is a dimension that does not distinguish components.
[0084] In a possible design, the components of the firmware include services and / or programs, and the services and the programs include functions and / or routines; the sampling result for each instruction address further includes an address space identifier ASID.
[0085] In a possible design, when the processing unit 810 is used to compare the second distribution feature with the first distribution feature according to a preset rule to determine whether there is malicious code in the firmware, it is specifically used for: when comparing the second distribution feature with the first distribution feature by using the instruction address increment rule, the absolute value of the difference between the occurrence frequency of the instruction address increment indicated by the second distribution feature and the occurrence frequency of the instruction address increment indicated by the first distribution feature is greater than a first preset value. Or, when comparing the second distribution feature with the first distribution feature by using the execution frequency rule of each function, the absolute value of the difference between the execution frequency of each function indicated by the second distribution feature and the execution frequency of each function indicated by the first distribution feature is greater than a second preset value. Or, when comparing the second distribution feature with the first distribution feature by using the execution frequency of each address range, the absolute value of the difference between the execution frequency of each address range indicated by the second distribution feature and the execution frequency of each address range indicated by the first distribution feature is greater than a third preset value. Or, when comparing the second distribution feature with the first distribution feature by using the jump rule, the absolute value of the difference between the jump frequency indicated by the second distribution feature and the jump frequency indicated by the first distribution feature is greater than a fourth preset value. Or, when comparing the second distribution feature with the first distribution feature by using the kernel mode entry rule, the absolute value of the difference between the kernel mode entry frequency indicated by the second distribution feature and the kernel mode entry frequency indicated by the first distribution feature is greater than a fifth preset value, then it is determined that there is malicious code in the firmware.
[0086] In a possible design, the transceiver unit 820 is further configured to send a first signal to the reset pin of the CPU, where the first signal is used to instruct the CPU to restart; or send an exception message to the CPU, where the exception message is determined according to the malicious code.
[0087] For a more detailed description of the above processing unit 810 and transceiver unit 820, reference can be directly made to Figure 2 the relevant descriptions in the method embodiment shown, which will not be elaborated here.
[0088] Such as Figure 9As shown, the code detection device 900 includes a processor 910 and an interface circuit 920. The processor 910 and the interface circuit 920 are coupled to each other. It can be understood that the interface circuit 920 can be a transceiver or an input / output interface. Optionally, the code detection device 900 may further include a memory 930, which is used to store the instructions executed by the processor 910, or the input data required for the processor 910 to run the instructions, or the data generated after the processor 910 runs the instructions.
[0089] When the code detection device 900 is used to implement Figure 2 the method shown, the processor 910 is used to implement the functions of the above-mentioned processing unit 810, and the interface circuit 920 is used to implement the functions of the above-mentioned transceiver unit 820.
[0090] The division of units in the embodiments of the present application is illustrative. It is only a logical function division. In actual implementation, there may be other division methods. In addition, in each embodiment of the present application, each functional unit may be integrated in a processor, or may exist physically alone, or two or more units may be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0091] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they know the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications falling within the scope of the present application.
[0092] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.
Claims
1. A code detection method, characterized in that, The method is applicable to an execution flow monitoring unit, including: Obtaining a first distribution feature of the firmware; the first distribution feature characterizes the variation law of the sampling results of instruction addresses in the running state of the firmware; Obtaining each instruction address sampled by the CPU within a first time period when running the firmware through a performance monitoring unit (PMU) in the CPU or a debug controller in the CPU; Determining a second distribution feature according to each instruction address sampled within the first time period; Comparing the second distribution feature with the first distribution feature to determine whether there is malicious code in the firmware.
2. The method according to claim 1, characterized in that The first distribution feature is a pre-stored variation law of the sampling results of instruction addresses in the case where there is no malicious code in the firmware; Alternatively, the first distribution feature is obtained according to the sampling results of each instruction address by the CPU within a second time period when running the firmware; the end time of the second time period is earlier than the start time of the first time period.
3. The method according to claim 1, wherein Obtaining the sampling results of each instruction address by the CPU within a first time period when running the firmware through the PMU in the CPU, including: Sending at least one first instruction to the test access port (TAP) of the CPU; Obtaining at least one sampling value for the instruction address from the PMU in the CPU through the at least one first instruction; the at least one sampling value characterizes the sampling results of the computing core of the CPU within the first time period when running the firmware.
4. The method according to claim 3, wherein The execution flow monitoring unit is a debug host located outside the CPU; Sending at least one first instruction to the TAP of the CPU, including: Instructing a debug probe to send the at least one first instruction to the TAP of the CPU; The debug probe and the CPU interact using the same debug protocol.
5. The method according to claim 3, characterized in that The execution flow monitoring unit is a debug probe located outside the CPU.
6. The method according to claim 1, wherein The execution flow monitoring unit is located within the CPU.
7. The method according to claim 1, characterized in that, The obtaining each instruction address sampled by the CPU within a first time period when running the code through the debug controller in the CPU includes: Pausing the operation of the computing core of the CPU through the debug controller in the CPU and reading the program counter (PC) in the CPU, where the PC stores the instruction address; the computing core of the CPU is in the first time period when running the firmware.
8. The method according to any one of claims 1 to 7, characterized in that, The comparing the second distribution feature with the first distribution feature includes: Comparing the second distribution feature with the first distribution feature according to a preset rule; the preset rule includes at least one of an instruction address increment rule, an execution frequency rule of each function, an execution frequency rule of each address range, a jump rule, and a rule of entering the kernel mode.
9. The method according to claim 8, wherein Comparing the second distribution feature with the first distribution feature according to a preset rule includes: Comparing the second distribution feature with the first distribution feature from the global dimension of the firmware according to a preset rule, and / or comparing the second distribution feature with the first distribution feature from the component dimension of the firmware according to a preset rule; the global dimension is a dimension that does not distinguish components.
10. The method according to claim 9, wherein The composition of the firmware includes services and / or programs, and the services and the programs include functions and / or routines; the sampling result for each instruction address further includes an address space identifier ASID.
11. The method according to claim 8, characterized in that, Comparing the second distribution feature with the first distribution feature according to a preset rule to determine whether there is malicious code in the firmware, including: When comparing the second distribution feature with the first distribution feature using the instruction address increment rule, the absolute value of the difference between the occurrence frequency of the instruction address increment indicated by the second distribution feature and the occurrence frequency of the instruction address increment indicated by the first distribution feature is greater than a first preset value. Or, when comparing the second distribution feature with the first distribution feature using the execution frequency rule of each function, the absolute value of the difference between the execution frequency of each function indicated by the second distribution feature and the execution frequency of each function indicated by the first distribution feature is greater than a second preset value. Or, when comparing the second distribution feature with the first distribution feature using the execution frequency of each address range, the absolute value of the difference between the execution frequency of each address range indicated by the second distribution feature and the execution frequency of each address range indicated by the first distribution feature is greater than a third preset value. Or, when comparing the second distribution feature with the first distribution feature using the jump rule, the absolute value of the difference between the jump frequency indicated by the second distribution feature and the jump frequency indicated by the first distribution feature is greater than a fourth preset value. Or, when comparing the second distribution feature with the first distribution feature using the kernel state entry rule, the absolute value of the difference between the kernel state entry frequency indicated by the second distribution feature and the kernel state entry frequency indicated by the first distribution feature is greater than a fifth preset value, then it is determined that there is malicious code in the firmware.
12. The method according to any one of claims 1 to 8, characterized in that, After determining that there is malicious code in the firmware, it further includes: Sending a first signal to the reset pin of the CPU, where the first signal is used to indicate the CPU to restart; or, sending an exception message to the CPU, where the exception message is determined according to the malicious code.
13. A code detection device, characterized in that, The device is applicable to an execution flow monitoring unit, including: a processing unit and a transceiver unit; The transceiver unit is used to obtain the first distribution feature of the firmware; the first distribution feature characterizes the change rule of the sampling result of the instruction address in the running state of the firmware. The transceiver unit is further used to obtain each instruction address sampled by the CPU within a first time period when the firmware is running through the PMU in the CPU or the debug controller in the CPU. The processing unit is used to determine a second distribution feature according to each instruction address sampled within the first time period. The processing unit is further used to compare the second distribution feature with the first distribution feature to determine whether there is malicious code in the firmware.
14. A code detection device, characterized in that, It includes: A processor, and a memory communicatively connected to the processor; The memory stores computer execution instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1-12.
15. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, they are used to implement the method according to any one of claims 1-12.
16. A computer program product, characterized in that, It includes a computer program which, when executed by a processor, implements the method according to any one of claims 1-12.