Software identification method and related device
By monitoring the directory traversal and read and write operations of the process, candidate processes that are not in the directory traversal whitelist are identified, and processes that are not in the directory traversal and read and write exceptions are selected, which solves the problem of difficult to identify ransomware in the existing technology, and accurately identify and protect the ransomware.
Patent Information
- Application Number
- CN202510474319.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-08
AI Technical Summary
现有技术难以有效识别和防护勒索软件,尤其是对未知勒索软件和抗诱饵文件的勒索软件无法全面的识别。
By monitoring the directory traversal and read and write operations of the process, candidate processes that are not in the directory traversal whitelist are identified, processes with abnormal directory traversal numbers are filtered out, and their read and write operation information are obtained, and target processes with ransomware risk are filtered based on this information.
Accurate and comprehensive identification of ransomware is achieved, and it can identify known and unknown ransomware, reduce false positives, and improve detection accuracy.
Smart Images

Figure CN120277669A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of software analysis, and more specifically, to a software identification method and related device. Background Art
[0002] Ransomware is a malicious program. After the attacker spreads the ransomware through vulnerability exploitation, emails, IM (Instant Messaging), etc., the files in the user's computer are encrypted, posing a risk to the use of the user's device.
[0003] Currently, in order to protect user devices, it is necessary to identify ransomware to perform corresponding protection operations on it. Therefore, how to identify ransomware is a technical problem that needs to be urgently solved by those skilled in the art. Summary of the Invention
[0004] In view of this, this application provides a software identification method and related device to solve the problem of urgently needed ransomware identification.
[0005] To solve the above technical problems, this application adopts the following technical solutions:
[0006] A software identification method includes:
[0007] Identifying candidate processes that perform directory traversal operations and are not in the directory traversal whitelist;
[0008] Obtaining the directory traversal record of the candidate process; the directory traversal record includes: directory traversal information that meets the directory traversal interval time requirement when the candidate process historically performs directory traversal operations;
[0009] Screening out candidate processes in the directory traversal record where the number of directories traversed is greater than a first quantity threshold, and using them as intermediate processes;
[0010] Obtaining the read and write operation information of the intermediate process;
[0011] Based on the read and write operation information, screening out target processes with ransom risk from the intermediate processes, and regarding the software corresponding to the target processes as ransomware.
[0012] Optionally, the update process of the directory traversal record includes:
[0013] Obtaining the directory traversal information when the candidate process performs directory traversal operations; the directory traversal information includes the directory path and the directory traversal timestamp;
[0014] Obtaining the directory traversal record of the candidate process;
[0015] In the case that the time difference between the directory traversal timestamp in the latest historical directory traversal information and the directory traversal timestamp in the directory traversal information in the directory traversal record is greater than the first time difference threshold, add the directory traversal information to the directory traversal record of the candidate process.
[0016] Optionally, after adding the directory traversal information to the directory traversal record of the candidate process, it further includes:
[0017] Perform a duplicate removal operation on the directory paths in the directory traversal record of the candidate process.
[0018] Optionally, after screening out the candidate processes in the directory traversal record where the number of directories traversed is greater than the first quantity threshold and using them as intermediate processes, before obtaining the read and write operation information of the intermediate processes, the software recognition method further includes:
[0019] Obtain the function call path of the intermediate process through a stack backtrace operation;
[0020] In the case that the function call path meets the ransomware risk recognition policy, obtain the read and write operation information of the intermediate process.
[0021] Optionally, obtaining the read and write operation information of the intermediate process includes:
[0022] Obtain the read operation information corresponding to the intermediate process through a pre - callback function for read operations; the read operation information is in the form of key - value pairs, where in the key - value pairs, the primary key is the process identifier, and the data value is the deduplicated file path of the file on which the read operation is performed and the timestamp of the file path;
[0023] Obtain the write operation information corresponding to the intermediate process through a pre - callback function for write operations; the write operation information is in the form of key - value pairs, where in the key - value pairs, the primary key is the process identifier, and the data value is the deduplicated file path of the file on which the write operation is performed and the timestamp of the file path.
[0024] Optionally, the update process of the read operation information corresponding to the intermediate process includes:
[0025] In the case that the process performing the read operation is the intermediate process, obtain the file stream context information in the file operation object of the intermediate process; the file stream context information includes the file path and timestamp of the file on which the read operation is performed;
[0026] Obtain the read operation information corresponding to the intermediate process;
[0027] When the time difference between the timestamp in the file stream context information and the latest timestamp stored in the read operation information is not greater than the second time difference threshold, add the file path and timestamp in the file stream context information to the read operation information.
[0028] Optionally, based on the read and write operation information, screen out target processes with ransomware risks from the intermediate processes, including:
[0029] Screen out processes from the intermediate processes where the number of file paths in the read operation information is greater than the second quantity threshold and the number of file paths in the write operation information is greater than the third quantity threshold;
[0030] Take the screened-out processes as target processes with ransomware risks.
[0031] A software identification device, including:
[0032] A process identification module, configured to identify candidate processes that perform directory traversal operations and are not in the directory traversal whitelist;
[0033] A record acquisition module, configured to acquire the directory traversal records of the candidate processes; the directory traversal records include: directory traversal information that meets the directory traversal interval time requirement when the candidate processes historically perform directory traversal operations;
[0034] A process screening module, configured to screen out candidate processes in the directory traversal records where the number of directories traversed is greater than the first quantity threshold and use them as intermediate processes;
[0035] A read and write information acquisition module, configured to acquire the read and write operation information of the intermediate processes;
[0036] A software identification module, configured to screen out target processes with ransomware risks from the intermediate processes based on the read and write operation information, and regard the software corresponding to the target processes as ransomware.
[0037] An electronic device, including at least one processor and a memory connected to the processor, where:
[0038] The memory is used to store a computer program;
[0039] The processor is configured to execute the computer program so that the electronic device can implement the above software identification method.
[0040] A computer storage medium, which carries one or more computer programs, and when the one or more computer programs are executed by an electronic device, can enable the electronic device to implement the above software identification method.
[0041] The present application provides a software recognition method and related devices. In the present application, candidate processes that perform directory traversal operations and are not in the directory traversal whitelist are recognized, directory traversal records of the candidate processes are obtained, candidate processes in the directory traversal records where the number of directories traversed is greater than a first quantity threshold are filtered out and used as intermediate processes, read and write operation information of the intermediate processes is obtained, and based on the read and write operation information, target processes with ransomware risks are filtered out from the intermediate processes, and the software corresponding to the target processes is taken as ransomware. In this embodiment, for ransomware, its directory traversal and read and write operations are abnormal, so directory traversal and read and write operations can be used as the main behavioral characteristics for identifying ransomware. Therefore, identifying ransomware from the perspectives of directory traversal and read and write operations can accurately identify ransomware. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on the provided drawings without creative efforts.
[0043] Figure 1 It is a flowchart of a software recognition method provided by an embodiment of the present application;
[0044] Figure 2 It is a flowchart of a method for record update provided by an embodiment of the present application;
[0045] Figure 3 It is a flowchart of a method for information update provided by an embodiment of the present application;
[0046] Figure 4 It is a scenario schematic diagram of a software recognition method provided by an embodiment of the present application;
[0047] Figure 5 It is a flowchart of another software recognition method provided by an embodiment of the present application;
[0048] Figure 6 It is a schematic structural diagram of a software recognition device provided by an embodiment of the present application;
[0049] Figure 7 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0050] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0051] Ransomware is a malicious program. After the attacker spreads the ransomware through vulnerability exploitation, emails, IM, etc., the files in the user's computer are encrypted, posing a risk to the use of the user's device. In recent years, ransomware has spread rapidly, and even formed a SAAS (Software as a Service) service and industrial chain. New types and new variants of ransomware emerge in an endless stream, causing extensive harm.
[0052] Currently, in order to protect user devices, it is necessary to identify ransomware to perform corresponding protection operations. Then, how to identify ransomware is a technical problem that those skilled in the art urgently need to solve.
[0053] To identify ransomware, the method of killing ransomware based on static features can be adopted. However, this method can only target known ransomware and kill it based on its known features. It cannot deal with new and unknown ransomware.
[0054] In addition, decoy files can also be placed in positions such as the disk root directory, desktop, and user directory, and an alarm is triggered when the ransomware operates on the decoy files. However, with the development of ransomware, the ransomware can specifically bypass the decoy files without triggering an alarm. Currently, with the development of ransomware, there have emerged various types of ransomware that can counter decoys. Therefore, this method cannot comprehensively identify ransomware.
[0055] In order to be able to comprehensively identify ransomware, in the embodiments of the present invention, the behaviors of ransomware are analyzed, and it is found that ransomware generally has a large number of directory traversal operations and read-write operations. Therefore, ransomware can be identified from the perspectives of directory traversal operations and read-write operations.
[0056] To this end, the embodiments of the present application provide a software identification method and related devices. In the present application, candidate processes that perform directory traversal operations and are not in the directory traversal whitelist are identified, directory traversal records of the candidate processes are obtained, candidate processes in the directory traversal records where the number of directories traversed is greater than a first quantity threshold are filtered out and used as intermediate processes, read and write operation information of the intermediate processes is obtained, and based on the read and write operation information, target processes with ransomware risks are filtered out from the intermediate processes, and the software corresponding to the target processes is used as ransomware. In this embodiment, for ransomware, its directory traversal and read and write operations will be abnormal, so directory traversal and read and write operations can be used as the main behavioral characteristics for identifying ransomware. Therefore, identifying ransomware from the perspectives of directory traversal and read and write operations can accurately and comprehensively identify ransomware.
[0057] Based on the above, an embodiment of the present application provides a software identification method, and the execution entity may be a device such as a controller or a server. Referring to Figure 1 , a software identification method may include:
[0058] S11. Identify candidate processes that perform directory traversal operations and are not in the directory traversal whitelist.
[0059] In this embodiment, by analyzing the behaviors of various ransomwares such as Maze, Sodinokibi, Maze, Sodinokibi, DoppelPaymer, Conti, Netwalker, Pysa, Nefilim, Clop, Ako, Suncrypt, Ragnar_Locker, Sekhmet, Avaddon, DarkSide, etc., the following core behavioral characteristics are extracted for all ransomwares within a short period of time:
[0060] Traverse a large number of different directories, read a large number of different files, and write a large number of different files.
[0061] Therefore, in this embodiment, analyze whether a software is ransomware from three perspectives: traversing directories, reading files, and writing files.
[0062] When identifying ransomware from the perspective of directory traversal, since a software will create corresponding processes during operation to perform corresponding operations using these processes. Therefore, in this embodiment, analyze from the process perspective and identify processes with directory traversal operations.
[0063] In one implementation, a driver program such as a Minifilter (Minifilter Driver, micro-filter driver) driver program can be used to perform directory detection operations.
[0064] To implement the monitoring of directory traversal, it is necessary to set callbacks for file operations in the Minifilter driver: the Precallback (Preoperation Callback Function) and PostCallback (Postoperation Callback Function) operations of IRP_MJ_DIRECTORY_CONTROL.
[0065] Among them, IRP_MJ_DIRECTORY_CONTROL in this embodiment is a type corresponding to the operation on the file directory in the IRP (I / O Request Packet, input / output request packet).
[0066] In one implementation, the directory traversal information of the process during directory traversal can be obtained only through the precallback. In addition, the directory traversal information during directory traversal can also be obtained by combining the precallback and the postcallback. Which implementation method to choose specifically is configured according to actual needs.
[0067] In one example, the process that is performing the directory traversal operation can be obtained by using the precallback of IRP_MJ_DIRECTORY_CONTROL. Specifically, when implementing, in the precallback of IRP_MJ_DIRECTORY_CONTROL, only the operation whose IRP's MinorFunction (Minor Function) is IRP_MN_QUERY_DIRECTORY is obtained, and this operation is the directory traversal operation.
[0068] In the actual scenario, there may be some software processes that perform directory traversal operations multiple times, but this software process is a compliant software. To avoid identifying such software as ransomware, a directory traversal whitelist can be preconfigured, and some software processes that are not ransomware are stored in the directory traversal whitelist. Therefore, in the directory traversal callback during ransomware identification, the precallback of IRP_MJ_DIRECTORY_CONTROL should be used to obtain the processes that perform directory traversal operations and are not in the directory traversal whitelist. These processes can be called candidate processes, and then the processes corresponding to ransomware are screened out from these candidate processes.
[0069] S12. Obtain the directory traversal records of the candidate processes.
[0070] In an actual scenario, after determining the candidate processes, it is necessary to obtain the directory traversal records of the candidate processes. Among them, the directory traversal records include: directory traversal information that meets the requirements of the directory traversal interval time when the candidate process historically performs directory traversal operations.
[0071] In this embodiment, when a candidate process performs directory traversal, there will be corresponding directory traversal times, such as directory traversal timestamps. When ransomware performs directory traversal, there will be a situation where it traverses a large number of different directories in a short period of time. Therefore, in this embodiment, for a candidate process, not all directory traversal information of all directories traversed by the process will be stored in the directory traversal record. Instead, through the directory traversal time interval limit, only some directory traversal information that meets the requirements of the directory traversal interval time is stored in the directory traversal record. For example, if the time difference between two directory traversals of a candidate process is large and does not conform to the characteristic of ransomware traversing a large number of different directories in a short period of time, the directory traversal information historically stored in the directory traversal record can be deleted, and only the current directory traversal information is stored. If the time difference between two directory traversals of a candidate process is small and conforms to the characteristic of ransomware traversing a large number of different directories in a short period of time, the current directory traversal information can be stored in the directory traversal record.
[0072] S13. Screen out candidate processes in the directory traversal records where the number of directories traversed is greater than the first quantity threshold, and use them as intermediate processes.
[0073] Specifically, after obtaining the directory traversal record of the candidate process, each directory data traversed by the candidate process at a short time interval is stored in the directory traversal record. At this time, the first quantity threshold can be obtained. The first quantity threshold is the threshold of the number of directory traversals that can be identified as ransomware obtained through the analysis of ransomware.
[0074] If the number of directories traversed is greater than the first quantity threshold, it means that the candidate process has performed multiple different directory traversals in a short period of time and is suspected of being ransomware. Therefore, the candidate process is used as an intermediate process for subsequent analysis operations to further determine whether it is ransomware.
[0075] S14. Obtain the read and write operation information of the intermediate process.
[0076] Specifically, through the analysis of the behaviors of various ransomwares such as Maze, Sodinokibi, Maze, Sodinokibi, DoppelPaymer, Conti, Netwalker, Pysa, Nefilim, Clop, Ako, Suncrypt, Ragnar_Locker, Sekhmet, Avaddon, DarkSide, etc., the core operation behaviors of all ransomwares can be extracted:
[0077] Traverse directories, read files, and write files.
[0078] In terms of the operation behavior dimension of reading and writing files, further breakdown reveals several methods:
[0079] a. Read File A and then write File A, that is, encrypt and rewrite the original File A.
[0080] b. Read File A, write to File B, and then delete File A, that is, read File A, encrypt it and write it as a new file, and then delete the original file.
[0081] Regarding the file suffixes of encrypted files, different types of ransomware also have different handling methods, mainly divided into two types:
[0082] 1) Use the original file suffix.
[0083] 2) Use specific suffixes, such as Maze, Sodinokibi, DoppelPaymer, Conti, Netwalker, Pysa, Nefilim, Clop, Ako, Suncrypt, Ragnar_Locker, Sekhmet, Avaddon, DarkSide, etc.
[0084] As can be seen from the above, for ransomware, there are a large number of operations of reading different files and writing different files. Therefore, the read and write operation information of the intermediate process can be obtained to analyze whether there are a large number of read file operations and write file operations in the process.
[0085] Among them, the read and write operation information includes read operation information and write operation information.
[0086] The read operation information includes the file path when reading the file and the timestamp when reading the file, and the write operation information includes the file path when writing the file and the timestamp when writing the file.
[0087] In one implementation, when ransomware reads and writes files, it generally reads and writes a large number of different files. Therefore, in the embodiments of this application, when a candidate process repeatedly reads and writes the same file, the file path will be de-duplicated so that the read and write operation information only includes the de-duplicated different file paths and the corresponding timestamps.
[0088] S15. Based on the read and write operation information, screen out the target processes with ransom risk from the intermediate processes, and regard the software corresponding to the target processes as ransomware.
[0089] In this embodiment, after obtaining the read / write operation information, the target processes that perform frequent read / write operations in a short period of time are filtered out, and the software corresponding to the target processes is the ransomware with ransom risk.
[0090] Based on the above operations, it is possible to filter out the ransomware that traverses a large number of different directories, reads a large number of different files, and writes a large number of different files in a short period of time.
[0091] In this embodiment, the candidate processes that perform directory traversal operations and are not in the directory traversal whitelist are identified, the directory traversal records of the candidate processes are obtained, and among the directory traversal records, the candidate processes with the number of traversed directories greater than the first quantity threshold are filtered out and used as intermediate processes. The read / write operation information of the intermediate processes is obtained, and based on the read / write operation information, the target processes with ransom risk are filtered out from the intermediate processes, and the software corresponding to the target processes is used as the ransomware. In this embodiment, for the ransomware, its directory traversal and read / write operations will be abnormal, so the directory traversal and read / write operations can be used as the main behavioral characteristics for identifying the ransomware. Therefore, identifying the ransomware from the perspective of directory traversal and the perspective of read / write operations can accurately identify the ransomware.
[0092] Based on any of the above embodiments, it is necessary to create a directory traversal record and update the directory traversal record according to the continuous directory traversal operations of the process. In one implementation, referring to Figure 2 , the update process of the directory traversal record includes:
[0093] S21. Obtain the directory traversal information when the candidate process performs the directory traversal operation.
[0094] Among them, the directory traversal information includes the directory path and the directory traversal timestamp.
[0095] When the Minifilter driver filters the operation where the MinorFunction of the IRP is IRP_MN_QUERY_DIRECTORY, obtain the PID (Process Identifier), directory path, directory traversal timestamp, etc. of the process that is currently performing directory traversal. The Minifilter driver sends the directory traversal information (including the directory path corresponding to the process PID and the directory traversal timestamp, etc.) to the Windows (Microsoft Windows) service program at the application layer. Among them, the Windows service program is an application program module.
[0096] S22. Obtain the directory traversal record of the candidate process.
[0097] For each candidate process, the Windows service program at the application layer maintains a MAP (a data structure of key-value pair), where the key of the MAP is the process PID, and the value includes the directory path and the directory traversal timestamp. The directory path and the directory traversal timestamp can be in string format. Here, multiple directory paths and their corresponding directory traversal timestamps can be stored in the value, and at this time, the multiple directory paths and their corresponding directory traversal timestamps form a string set SET. Among them, the MAP in this embodiment is the directory traversal record of the candidate process.
[0098] It should be noted that for each candidate process, its corresponding MAP can be created, or the directory traversal records of all candidate processes can be stored in the same MAP.
[0099] Before the candidate process performs a directory traversal operation, the Windows service program does not create the MAP. After the candidate process performs a directory traversal operation, the MAP creation operation is carried out.
[0100] Specifically, after the Windows service program receives the directory traversal record reported by the Minifilter driver, it first checks whether there is a record of the process PID in the MAP. If not, it creates the data structure of the value and establishes the corresponding string set, and then stores the directory path and the corresponding directory traversal timestamp in the directory traversal record into the set.
[0101] S23. When the time difference between the directory traversal timestamp in the latest historical directory traversal information and the directory traversal timestamp in the directory traversal information in the directory traversal record is greater than the first time difference threshold, add the directory traversal information to the directory traversal record of the candidate process.
[0102] Specifically, if there is already a record of the process PID in the MAP, the Windows service program first obtains the latest timestamp in the value, which is the time when the candidate process last performed a directory traversal. If the directory traversal timestamp in the current directory traversal information differs greatly from this latest timestamp, such as being greater than the first time difference threshold, it indicates that a relatively long time has passed since the last directory traversal, and it also indicates that the candidate process does not have the behavior of performing a large number of directory traversals in a short period of time. At this time, the existing string set in the value can be cleared, and the directory path and timestamp in the current directory traversal record are inserted into the set, that is, starting from this directory traversal, analyze whether there will be a large number of directory traversal behaviors subsequently.
[0103] If the directory traversal timestamp in the directory traversal information differs from the latest timestamp by no more than the first time difference threshold, it indicates that the candidate process has performed a large number of directory traversals in a short period of time. At this time, the directory path and directory traversal timestamp in the directory traversal information are inserted into the string set in the value.
[0104] In one implementation, after adding the directory traversal information to the directory traversal record of the candidate process, it further includes:
[0105] Perform a deduplication operation on the directory paths in the directory traversal record of the candidate process.
[0106] Specifically, in order to avoid misidentifying a process as a ransomware process due to repeated traversal of the same directory, in this embodiment, a deduplication operation is performed on the duplicate directory paths. In the specific implementation, the string set in the value is set to not allow duplicate values. Then, when inserting the directory path and directory traversal timestamp in the directory traversal information into the string set in the value in this embodiment, the directory path will be automatically deduplicated. When deduplicating, if there are two or more duplicate directory paths, the latest directory path and the corresponding timestamp are retained, and the previous directory path and timestamp are deleted.
[0107] After continuously updating the directory traversal record through the above steps, the number of directory paths in the string set in the value can be detected in real time. If the number exceeds the first quantity threshold, it indicates that the process has performed a large number of traversals of different directories in a short period of time. The Windows service program takes the candidate process as an intermediate process, encapsulates information such as the process PID and directory path of the intermediate process into a message, and sends it to the Minifilter driver to detect the read and write operation information of the intermediate process.
[0108] After receiving the intermediate process information sent by the Windows service program, the Minifilter driver stores information such as the process PID and directory path of the intermediate process in the process array of the global variable.
[0109] In one implementation, after identifying the intermediate process, it is also possible to further determine whether the intermediate process is a suspicious ransomware through the stack backtrace method.
[0110] Specifically, in this embodiment, the function call path of the intermediate process can be obtained through the stack backtrace operation. When the function call path meets the ransomware risk identification policy, the read and write operation information of the intermediate process is obtained.
[0111] Specifically, after identifying a candidate process as an intermediate process by traversing the directory behavior, the code in the memory of the process can be dumped (Memory Dump), and the key data and encryption algorithms in the memory can be extracted. The system API (Application Programming Interface) or kernel-level debugging tools can be used for stack backtracking to backtrack the call stack of the intermediate process and trace the function call path related to encryption.
[0112] Generally speaking, for ransomware, it uses corresponding encryption methods to encrypt data. Therefore, the encryption methods and key management methods used by existing ransomware can be analyzed and used as the basis for judging ransomware in the ransomware risk identification strategy. The basis for judging ransomware in the ransomware risk identification strategy can be configured as a malicious behavior feature library for subsequent calls.
[0113] Based on the function call path of the intermediate process, the encryption function called by the intermediate process during the encryption operation can be analyzed, and then the encryption method and key management method used by the intermediate process can be determined. If they are the same as or highly similar to the encryption method and key management method in the basis for judging ransomware in the ransomware risk identification strategy, it indicates that the encryption behavior of the intermediate process conforms to the known malicious patterns or attack characteristics, and it is considered that the process has potential malicious operations. Furthermore, it is considered that the software corresponding to the process may be ransomware. At this time, the read and write operation information of the intermediate process can be obtained for subsequent ransomware identification operations.
[0114] In this way, the detection accuracy of ransomware and other malicious programs can be improved. In addition, by extracting memory data and analyzing stack information, the encryption process can be further restored, providing support for subsequent sample preservation and decryption analysis and helping to recover encrypted files.
[0115] It should be noted that the method of identifying ransomware based on stack backtracking in this embodiment is only an optional step. After obtaining the intermediate process, it can be further determined whether it is suspected to be ransomware through stack backtracking. If so, the read and write operation information of the intermediate process is obtained. In another implementation, the stack backtracking step can also be directly skipped, and the read and write operation information of the intermediate process can be directly obtained. Which method to use specifically depends on the actual configuration.
[0116] In one implementation, obtaining the read and write operation information of the intermediate process includes:
[0117] Obtain the read operation information corresponding to the intermediate process through the pre - callback function of the read operation; the read operation information is in the form of key - value pairs. Among them, in the key - value pairs, the primary key is the process identifier, and the data value is the deduplicated file path corresponding to the file on which the read operation is performed and the timestamp of the file path.
[0118] Obtain the write operation information corresponding to the intermediate process through the pre - callback function of the write operation; the write operation information is in the form of key - value pairs. Among them, in the key - value pairs, the primary key is the process identifier, and the data value is the deduplicated file path corresponding to the file on which the write operation is performed and the timestamp of the file path.
[0119] Specifically, in the Minifilter driver, in addition to setting the Precallback and PostCallback operations of IRP_MJ_DIRECTORY_CONTROL as described above, it is also possible to set the PreCallback of IRP_MJ_READ (IRP type, corresponding to the read behavior for files) and the PreCallback of IRP_MJ_WRITE (IRP type, corresponding to the write behavior for files).
[0120] After setting the above - mentioned callback functions, monitoring can be enabled in the Minifilter driver to monitor the corresponding operations of all processes in the system on files. Specifically, use the pre - callback function of the read operation, that is, the PreCallback of IRP_MJ_READ mentioned above, to monitor the file - reading operations of processes, and use the pre - callback function of the write operation, that is, the PreCallback of IRP_MJ_WRITE mentioned above, to monitor the file - writing operations of processes.
[0121] A Windows service program maintains a read operation information and a write operation information respectively. Among them, the read operation information can be implemented using a suspicious read MAP, and the write operation information can be implemented through a suspicious write MAP. Both the suspicious write MAP and the suspicious read MAP are in the form of key - value pairs.
[0122] In the suspicious read MAP, the primary key is the process identifier, that is, the process PID, and the data value value is the deduplicated file path corresponding to the file on which the read operation is performed and the timestamp of the file path. Among them, value is in string format and stores the file path and the corresponding timestamp in a set. Similarly, since ransomware has the behavior of reading and writing different files, the file paths in this set are not allowed to repeat.
[0123] In the suspicious write MAP, the primary key is the process identifier, i.e., the process PID, and the value is the deduplicated file path corresponding to the file on which the write operation is performed and the timestamp of the file path. Among them, the value is in string format and uses a set to store the file path and the corresponding timestamp. Similarly, since ransomware has the behavior of reading and writing different files, the file paths in this set are not allowed to repeat either.
[0124] In one implementation, before the process has the behavior of reading and writing files, the read operation information and write operation information of the process are not established. Only when the process has the behavior of reading and writing files, the Windows service program will establish the read operation information and write operation information of the process, and continuously update the read operation information and write operation information of the process according to the continuous reading and writing file behavior of the process.
[0125] In one implementation, referring to Figure 3 , the update process of the read operation information corresponding to the intermediate process includes:
[0126] S31. When the process performing the read operation is the intermediate process, obtain the file stream context information in the file operation object of the intermediate process.
[0127] In specific implementation, use the PreCallback of IRP_MJ_READ of the Minifilter driver to determine the triggering process of the current read operation, and at the same time, use the PreCallback of IRP_MJ_WRITE to determine the triggering process of the current write operation, and judge whether the triggering process is the intermediate process.
[0128] In one implementation, since in the above implementation, after the Minifilter driver receives the intermediate process information sent by the Windows service program, it stores information such as the process PID and directory path of the intermediate process in the process array of the global variable. Therefore, in this embodiment, it can be judged whether the PID of the triggering process is located in the process array of the global variable. If it is not located, it means that the triggering process is not the intermediate process, and at this time, no file read and write analysis is performed on this process. If it is located, it means that the triggering process is the intermediate process, and it is necessary to further determine whether this process is a ransomware process through file read and write analysis.
[0129] When performing file read / write analysis, one can attempt to obtain the file stream context of the file operation object FileObject (FileObject, file object) of the process. The StreamContext records the file path and the current timestamp during a file read operation, or the file path and the current timestamp during a file write operation. Therefore, one can analyze this StreamContext to determine whether the process has the behavior of frequently reading and writing different files.
[0130] It should be noted that when a process reads a file, there is corresponding file stream context information of the file operation object. When the process writes a file, there is also corresponding file stream context information of the file operation object. Therefore, if a process reads a file, one can obtain the file stream context information of the file operation object during the file read operation. This file stream context information includes the file path and the timestamp of the file on which the read operation is performed. If a process writes a file, one can obtain the file stream context information of the file operation object during the file write operation.
[0131] It should be noted that the StreamContext does not exist initially and is only created when the process reads or writes a file. Therefore, when the Minifilter driver obtains the StreamContext, it first determines whether the StreamContext exists. If it does not exist, it creates the StreamContext, attaches it to the FileObject, then obtains the file path of the file operation and the current timestamp, adds them to the StreamContext and proceeds to the next step. If the StreamContext exists, it determines whether the difference between the latest timestamp field in it and the timestamp of the current file read operation exceeds the time threshold. If it does not exceed the time threshold, no processing is performed to write data into the StreamContext according to this time threshold to avoid the problem of a large amount of data in the StreamContext caused by writing a large amount of data in a short period. If the difference exceeds the time threshold, it proceeds to the next step, packs the process PID, file path, and timestamp data into a suspicious read or write message, and sends it to the Windows service program at the application layer.
[0132] S32. Obtain the read operation information corresponding to the intermediate process.
[0133] In a specific implementation manner, the Windows service program receives suspicious read or write messages. If a suspicious read message is received, it is determined whether there is a suspicious read MAP corresponding to the process PID. If not, a suspicious read MAP corresponding to the process PID is created, and the process PID, file path, and timestamp data in the current suspicious read message are written into the suspicious read MAP. When writing, the process PID is used as the primary key, and the file path and timestamp are written into the set of values in string form.
[0134] If it is determined that there is a suspicious read MAP corresponding to the process PID, the suspicious read MAP is directly obtained, and this suspicious read MAP is the read operation information in this embodiment.
[0135] S33. When the time difference between the timestamp in the file stream context information and the latest timestamp stored in the read operation information is not greater than the second time difference threshold, the file path and timestamp in the file stream context information are added to the read operation information.
[0136] Specifically, if the time difference between the timestamp in the file stream context information and the latest timestamp stored in the read operation information is not greater than the second time difference threshold, that is, the time difference between the timestamp in the suspicious read message reported by the Minifilter driver this time and the latest timestamp stored in the suspicious read MAP is not greater than the second time difference threshold, it indicates that there is a file read operation by this process in a short period of time. At this time, the process PID, file path, and timestamp data in the current suspicious read message are written into the suspicious read MAP.
[0137] It should be noted that since the values in the suspicious read MAP are not allowed to be repeated, if the process PID and file path in the current suspicious read message are the same as the existing data in the suspicious read MAP, a duplicate removal operation is performed to delete the historical data, and only the current process PID, file path, and timestamp data are stored, that is, only the latest data of the same file path is retained.
[0138] If the time difference between the timestamp in the suspicious read message and the latest timestamp stored in the suspicious read MAP is greater than the second time difference threshold, it indicates that the time for this process to read the file this time is relatively long since the last time it read the file, and this process does not have an operation of reading a large number of different files in a short period of time. Then, the data in the value is cleared.
[0139] The above embodiments introduce the update process of the read operation information. For the write operation information, the update process is similar. When there is a file write behavior, the corresponding write operation information is updated.
[0140] In this embodiment, when updating the read operation information and the write operation information, only the file paths and timestamps when reading and writing different files within a short period are stored in the MAP, so as to analyze whether there is a behavior of reading and writing a large number of different files by a process within a short period. If so, it is considered that the process may be the process corresponding to the ransomware.
[0141] In one implementation manner, after obtaining the above-mentioned read and write operation information (including the above-mentioned read operation information and write operation information), the target processes with ransom risks can be screened out from the intermediate processes based on the read and write operation information. The specific implementation is as follows:
[0142] From the intermediate processes, screen out the processes in which the number of file paths in the read operation information is greater than the second quantity threshold and the number of file paths in the write operation information is greater than the third quantity threshold, and use the screened processes as the target processes with ransom risks.
[0143] Specifically, since the ransomware has the behavior of reading and writing a large number of different files within a short period, it is necessary to simultaneously satisfy that the number of file paths in the read operation information is greater than the second quantity threshold and the number of file paths in the write operation information is greater than the third quantity threshold. If this requirement is met, it means that the process reads and writes a large number of different files within a short period and has the behavioral characteristics of the ransomware, then it is considered that the intermediate process is the target process with ransom risks, and subsequently, the software corresponding to the target process is regarded as the ransomware.
[0144] Refer to Figure 4 , according to the above description, the execution entities of the entire solution include the Minifilter driver program and the application program module. Among them, the application program module specifically refers to the above-mentioned Windows service program. The Minifilter driver program monitors and records the traversal behavior of the process for different directories and reports it to the Windows service program. After the Windows service program conducts the initial detection, it hands the suspicious intermediate process information to the Minifilter driver program for further monitoring. The Minifilter driver program collects the read and write behaviors of the process for files in different paths and reports them to the Windows service program. Finally, the application layer conducts another process detection to identify the ransomware. The specific implementation process is as follows:
[0145] The Minifilter driver monitors candidate processes performing directory traversal operations and reports them to the Windows service program in the application layer. The Windows service program in the application layer analyzes the directory traversal operation behaviors of the same process in different directories to determine whether the directory traversal behavior reaches the thresholds required in terms of time and quantity. Processes that reach the thresholds are marked as processes to be detected (i.e., the intermediate processes mentioned above) and are passed to the Minifilter driver for further monitoring of file reading and writing operations.
[0146] The Minifilter driver monitors the read and write operations of the processes to be detected and reports them to the Windows service program in the application layer. The Windows service program in the application layer analyzes the read and write operations of the same process to determine whether the number and time of different files read and written by the process reach the thresholds. If the number of files read and written within a short period of time both reach the thresholds, it is determined to be ransomware. The overall implementation process is as Figure 5 shown.
[0147] In this embodiment, based on the composite detection of the driver layer and the application layer, and by using a composite detection algorithm for high-frequency directory traversal and read / write behaviors to identify ransomware. During specific identification, it judges based on monitoring the core behaviors of ransomware at the kernel layer, does not rely on the static features of known ransomware, does not need to pre-collect the suffix names of ransomware, is equally effective for ransomware using new suffix names in the future, is equally effective for ransomware that does not modify the original file suffix name, can effectively detect both known and unknown ransomware, and improves the detection rate of ransomware. And through verification, it can effectively solve the false alarm problem and greatly improve the accuracy of detection.
[0148] In addition, this application associates three operations: directory traversal, file reading, and file writing to identify ransomware, which is more in line with the behavioral characteristics of ransomware. Compared with only detecting write operations for ransomware judgment, the accuracy is greatly improved.
[0149] This embodiment can be widely applied to antivirus software and ransomware protection scenarios. It can provide protection without relying on ransomware samples, reducing the impact scope of ransomware.
[0150] In another implementation manner of this application, in addition to comprehensively identifying ransomware through the common behavioral characteristics of ransomware mentioned above, it can also analyze the behaviors of known ransomware to identify the specific behavioral characteristics of the ransomware, so as to achieve precise identification of ransomware based on the common behavioral characteristics and specific behavioral characteristics, and achieve precise ransomware detection (Ransomware detection) for subsequent ransomware protection (Anti Ransomware).
[0151] Based on the embodiments of the above software recognition method, another embodiment of the present application provides a software recognition device. Referring to Figure 6 , it may include:
[0152] A process recognition module 11, configured to recognize candidate processes that perform directory traversal operations and are not in the directory traversal whitelist;
[0153] A record acquisition module 12, configured to acquire the directory traversal records of the candidate processes; the directory traversal records include: directory traversal information that meets the directory traversal interval time requirement when the candidate processes historically perform directory traversal operations;
[0154] A process screening module 13, configured to screen out candidate processes in the directory traversal records where the number of directories traversed is greater than a first quantity threshold, and use them as intermediate processes;
[0155] A read / write information acquisition module 14, configured to acquire the read / write operation information of the intermediate processes;
[0156] A software recognition module 15, configured to, based on the read / write operation information, screen out target processes with ransomware risks from the intermediate processes, and use the software corresponding to the target processes as ransomware.
[0157] In one implementation, it further includes:
[0158] A record update module, and the record update module includes:
[0159] An information acquisition sub-module, configured to acquire the directory traversal information when the candidate processes perform directory traversal operations; the directory traversal information includes the directory path and the directory traversal timestamp;
[0160] A record acquisition sub-module, configured to acquire the directory traversal records of the candidate processes;
[0161] A record addition sub-module, configured to add the directory traversal information to the directory traversal records of the candidate processes when the time difference between the directory traversal timestamp in the latest historical directory traversal information and the directory traversal timestamp in the directory traversal information in the directory traversal records is greater than a first time difference threshold.
[0162] In one implementation, the record update module further includes:
[0163] A deduplication sub-module, configured to perform deduplication operations on the directory paths in the directory traversal records of the candidate processes.
[0164] In one implementation, it further includes:
[0165] A stack backtrace module, which is used to obtain the function call path of the intermediate process through stack backtrace operations, and obtain the read and write operation information of the intermediate process when the function call path meets the ransomware risk identification policy.
[0166] In one implementation, the read and write information acquisition module 14 includes:
[0167] A read information acquisition sub-module, which is used to obtain the read operation information corresponding to the intermediate process through a pre-callback function of the read operation; the read operation information is in the form of key-value pairs, where in the key-value pairs, the primary key is the process identifier, and the data value is the deduplicated file path of the file on which the read operation is performed and the timestamp of the file path;
[0168] A write information acquisition sub-module, which is used to obtain the write operation information corresponding to the intermediate process through a pre-callback function of the write operation; the write operation information is in the form of key-value pairs, where in the key-value pairs, the primary key is the process identifier, and the data value is the deduplicated file path of the file on which the write operation is performed and the timestamp of the file path.
[0169] In one implementation, it further includes an information update module, and the information update module includes:
[0170] A file stream data acquisition sub-module, which is used to obtain the file stream context information in the file operation object of the intermediate process when the process performing the read operation is the intermediate process; the file stream context information includes the file path and timestamp of the file on which the read operation is performed;
[0171] A read operation information acquisition sub-module, which is used to obtain the read operation information corresponding to the intermediate process;
[0172] An information update sub-module, which is used to add the file path and timestamp in the file stream context information to the read operation information when the time difference between the timestamp in the file stream context information and the latest timestamp stored in the read operation information is not greater than the second time difference threshold.
[0173] In one implementation, the software identification module 15 is specifically used for:
[0174] Filter out the processes in the intermediate process whose number of file paths in the read operation information is greater than the second quantity threshold and whose number of file paths in the write operation information is greater than the third quantity threshold, and use the filtered processes as the target processes with ransom risks.
[0175] In this embodiment, candidate processes that perform directory traversal operations and are not in the directory traversal whitelist are identified, the directory traversal records of the candidate processes are obtained, and among the directory traversal records, candidate processes with the number of directories traversed greater than the first quantity threshold are filtered out and used as intermediate processes. The read / write operation information of the intermediate processes is obtained, and based on the read / write operation information, target processes with ransomware risks are filtered out from the intermediate processes, and the software corresponding to the target processes is used as ransomware. In this embodiment, for ransomware, its directory traversal and read / write operations are abnormal, so directory traversal and read / write operations can be used as the main behavioral characteristics for identifying ransomware. Therefore, identifying ransomware from the perspectives of directory traversal and read / write operations can accurately identify ransomware.
[0176] It should be noted that for the working processes of each module and sub-module in this embodiment, please refer to the corresponding descriptions in the above embodiments and will not be elaborated here.
[0177] An electronic device is also provided in an embodiment of the present application for implementing the above software identification method.
[0178] Refer to Figure 7 As shown, it shows a schematic structural diagram of an electronic device suitable for implementing the electronic device in the embodiment of the present application. The electronic device in the embodiment of the present application may include, but is not limited to, fixed terminals such as mobile phones, laptop computers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), desktop computers, and the like. Figure 7 The electronic device shown is only an example and should not bring any limitations to the functions and usage scopes of the embodiments of the present application.
[0179] As Figure 7 shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage device 608 into the random access memory (RAM) 603. When the electronic device is powered on, various programs and data required for the operation of the electronic device are also stored in the RAM 603. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.
[0180] Typically, the following devices can be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a memory card, a hard disk, etc.; and a communication device 609. The communication device 609 can allow the electronic device to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 7 an electronic device with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. More or fewer devices can be alternatively implemented or had.
[0181] An embodiment of the present application also provides a computer program product including computer-readable instructions. When the computer-readable instructions run on an electronic device, the electronic device is enabled to implement any one of the software recognition methods provided by the embodiments of the present application.
[0182] An embodiment of the present application also provides a computer-readable storage medium. The storage medium carries one or more computer programs. When the one or more computer programs are executed by an electronic device, the electronic device can be enabled to implement any one of the software recognition methods provided by the embodiments of the present application.
[0183] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1. A software recognition method, characterized in that, Including: Identifying candidate processes that perform directory traversal operations and are not in the directory traversal whitelist; Obtaining the directory traversal records of the candidate processes; The directory traversal records include: directory traversal information that meets the directory traversal interval time requirement when the candidate processes historically perform directory traversal operations; Filtering out candidate processes in the directory traversal records where the number of directories traversed is greater than the first quantity threshold, and using them as intermediate processes; Obtaining the read and write operation information of the intermediate processes; Based on the read and write operation information, filtering out target processes with ransomware risks from the intermediate processes, and regarding the software corresponding to the target processes as ransomware.
2. The software recognition method according to claim 1, characterized in that The update process of the directory traversal records includes: Obtaining the directory traversal information when the candidate process performs a directory traversal operation; the directory traversal information includes the directory path and the directory traversal timestamp; Obtaining the directory traversal records of the candidate process; When the time difference between the directory traversal timestamp in the latest historical directory traversal information and the directory traversal timestamp in the directory traversal information in the directory traversal records is greater than the first time difference threshold, adding the directory traversal information to the directory traversal records of the candidate process.
3. The software recognition method according to claim 2, wherein After adding the directory traversal information to the directory traversal records of the candidate process, it further includes: Performing a duplicate removal operation on the directory paths in the directory traversal records of the candidate process.
4. The software recognition method according to claim 1, characterized in that After filtering out candidate processes in the directory traversal records where the number of directories traversed is greater than the first quantity threshold and using them as intermediate processes, and before obtaining the read and write operation information of the intermediate processes, the software identification method further includes: Obtaining the function call path of the intermediate process through a stack backtrace operation; When the function call path meets the ransomware risk identification policy, obtaining the read and write operation information of the intermediate process.
5. The software recognition method according to claim 1, wherein Obtaining the read and write operation information of the intermediate process includes: Obtaining the read operation information corresponding to the intermediate process through a pre - callback function for read operations; the read operation information is in the form of key - value pairs, where in the key - value pairs, the primary key is the process identifier, and the data value is the deduplicated file path of the file on which the read operation is performed and the timestamp of the file path; Obtaining the write operation information corresponding to the intermediate process through a pre - callback function for write operations; the write operation information is in the form of key - value pairs, where in the key - value pairs, the primary key is the process identifier, and the data value is the deduplicated file path of the file on which the write operation is performed and the timestamp of the file path.
6. The software recognition method according to claim 5, wherein The update process of the read operation information corresponding to the intermediate process includes: When the process performing the read operation is the intermediate process, obtaining the file stream context information in the file operation object of the intermediate process; the file stream context information includes the file path and timestamp of the file on which the read operation is performed; Obtaining the read operation information corresponding to the intermediate process; When the time difference between the timestamp in the file stream context information and the latest timestamp stored in the read operation information is not greater than the second time difference threshold, add the file path and timestamp in the file stream context information to the read operation information.
7. The software recognition method according to claim 5, characterized in that Based on the read and write operation information, screen out the target processes with ransomware risks from the intermediate processes, including: From the intermediate processes, screen out the processes in which the number of file paths in the read operation information is greater than the second quantity threshold and the number of file paths in the write operation information is greater than the third quantity threshold; Take the screened processes as the target processes with ransomware risks.
8. A software recognition device, characterized in that, Including: A process identification module for identifying candidate processes that perform directory traversal operations and are not in the directory traversal whitelist; A record acquisition module for acquiring the directory traversal records of the candidate processes; The directory traversal record includes: directory traversal information that meets the directory traversal interval time requirement when the candidate process historically performs directory traversal operations; A process screening module for screening out the candidate processes in which the number of directories traversed in the directory traversal record is greater than the first quantity threshold and taking them as intermediate processes; A read and write information acquisition module for acquiring the read and write operation information of the intermediate processes; A software identification module for screening out the target processes with ransomware risks from the intermediate processes based on the read and write operation information and taking the software corresponding to the target processes as ransomware.
9. An electronic device, characterized in that, Including at least one processor and a memory connected to the processor, where: The memory is used to store computer programs; The processor is used to execute the computer programs so that the electronic device can implement the software identification method according to any one of claims 1 to 7.
10. A computer storage medium, characterized in that, The storage medium carries one or more computer programs, and when the one or more computer programs are executed by an electronic device, the electronic device can implement the software identification method according to any one of claims 1 to 7.