White list construction method and device and process filtering method and device

By generalizing the process path and command line parameters, generating process fingerprints and building a whitelist, the malicious process misreporting problem caused by single and parent process judgments in the existing technology is solved, and a higher quality malicious process judgment is achieved.

CN120372602APending Publication Date: 2025-07-25BEIJING VENUS INFORMATION SECURITY TECH +2
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510472885.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, the process whitelist generation scheme has the problems of single process normality measurement indicators, parent process information determination leads to underreporting malicious processes, and lack of key parameters leads to underreporting malicious processes, affecting the quality of malicious processes judgment.

Method used

By generalizing the user process paths and command line parameters in the history and log records to be tested, generating process fingerprints, building a process whitelist with normality indicators, adding command line parameters and parent process monitoring, reducing the risk of underreporting malicious processes.

Benefits of technology

It improves the accuracy and effectiveness of process whitelisting, reduces the misreport of malicious processes, and improves the quality of malicious process judgment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372602A_ABST
    Figure CN120372602A_ABST
Patent Text Reader

Abstract

According to the white list construction method and device and the process filtering method and device, user process paths which are not used for safety judgment are generalized, and the complexity of data comparison during safety judgment is reduced; the generalized command line parameter is command line value range information, and process security judgment is realized based on the generalized command line parameter; a command line parameter is added in the first process fingerprint, so that more complete normality indexes are obtained; the path and command line parameters of the second process are added in the first process fingerprint, monitoring of the second process is added, and data support is provided for reducing missed report of malicious processes; through the paths and command line parameters of the first process and the second process, the risk of missing report of the pseudo normal process is reduced; the first process is distinguished, the first process fingerprint of the corresponding first process is selected according to the normality index to construct the process white list, and data support is provided for reducing missing report of malicious processes; in conclusion, the process white list for improving the malicious process judgment quality is constructed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to computer security technologies, particularly to a method for constructing a whitelist, a method for process filtering, and an apparatus therefor. Background Art

[0002] Before detecting malicious processes on a terminal, in order to reduce data noise and improve detection efficiency, normal processes are usually filtered so that the detection system can focus more on potential threats. Common normal process filtering methods include whitelist mechanisms, hash value verification, digital signature verification, system call sequence analysis, etc. In related technologies, process whitelist generation schemes based on process logs are mainly divided into two categories: The first category is the scheme based on process normality, and its processing includes: counting indicators such as the startup frequency of a process to determine the normality of the process. If the normality of the process exceeds a preset threshold, it is determined as a normal process; The second category is the scheme based on parent process information, and its processing includes: if the path or ID of the target process is not in the whitelist, then determine whether the path or ID of the parent process is in the whitelist. If the path or ID of the parent process is in the whitelist, then determine the target process as a normal process.

[0003] The process whitelist generation solution based on process logs mainly has the following deficiencies: (1) The selected process normality measurement indicators are too single, which may lead to the calculated normality being difficult to accurately reflect the security or legality of the process. For example, in the method disclosed in the application document with the application number CN201911292727.0, the selected process normality indicator is "the weighted sum of the frequencies of the process appearing on different servers", where the definition of the frequency weight of the process on a given server is "the proportion of the total number of processes on this server in the total number of all server processes"; the application document with the application number CN202410002884.8 proposes a normal process determination solution: when the number of days a process appears on a single host exceeds a preset value, then the process is determined to be a normal process. (2) Determining all child processes of a normal parent process as normal processes may lead to missed reports of malicious processes. When the related technology uses the parent process information of the target process to determine the security of the target process, it usually determines all child processes of the normal parent process as normal processes, and this approach may lead to missed reports of malicious processes. For example, the previous applications with the application numbers CN201911416395.2 and CN202310123360.X proposed normal process recognition methods based on the process whitelist. These two methods assume that all child processes of a normal process are also normal. The application document with the application number CN201911416395.2 records: when the path and hash value of the target process are not in the whitelist, determine whether the path and hash value of the parent process are in the whitelist. If the path and hash value of the parent process are in the whitelist, then determine the target process as a normal process; the application document with the application number CN202310123360.X records: match its parent process ID with the process IDs in each process whitelist. If the match is successful, it means the child process is trustworthy. The above processing assumes that the child processes of a normal process are all normal processes, which does not conform to the actual situation. For example, an attacker may inject a virus or trojan into a normal program, or create malicious child processes by passing malicious parameters and exploiting program vulnerabilities. If all child processes of a normal process are determined as normal processes, it may lead to missed reports of malicious processes. (3) The process whitelist lacks key filtering parameters, which may lead to missed reports of malicious processes.

[0004] In summary, how to obtain a process whitelist that can improve the quality of malicious process judgment has become a problem to be solved. Summary of the Invention

[0005] The embodiment of this application provides a method for constructing a whitelist, including:

[0006] Generalize the user process paths in the historical log records, where the user process paths include the paths belonging to the user processes among the following: the path of the first process, the path of the second process, the paths included in the first command-line argument of the first process, and the paths included in the second command-line argument of the second process. The first process refers to the process corresponding to the historical log record, and the second process is the parent process of the first process;

[0007] Generalize the third command-line argument for the historical log records after generalizing the user process paths, where the third command-line argument includes the first command-line argument and the second command-line argument;

[0008] Generate the first process fingerprint corresponding to each historical log record based on the historical log records after generalizing the third command-line argument. The first process fingerprint includes the following fields: the first process name, the path of the first process, the first command-line argument of the first process, the second process name, the path of the second process, and the second command-line argument of the second process;

[0009] Distinguish each first process according to the first process fingerprint and extract the normality index of each distinguished first process. The normality index includes: the statistical information on the startup and running conditions of the first process within a preset duration;

[0010] Select the corresponding first processes according to the normality index of each first process, and construct a process whitelist based on the first process fingerprints of the selected first processes.

[0011] On the other hand, an embodiment of the present application also provides a method for process filtering, including:

[0012] Generalize the user process paths in the log to be tested, where the user process paths include the paths belonging to the user processes among the following: the path of the third process, the path of the fourth process, the paths included in the fourth command-line argument of the third process, and the paths included in the fifth command-line argument of the fourth process. The third process refers to the process corresponding to the log to be tested, and the fourth process is the parent process of the third process;

[0013] Generalize the sixth command-line argument for the log to be tested after generalizing the user process paths, where the sixth command-line argument includes the fourth command-line argument and the fifth command-line argument;

[0014] Generate the third process fingerprint of the log to be tested based on the log to be tested after generalizing the sixth command-line argument. The third process fingerprint includes the following fields: the third process name, the path of the third process, the fourth command-line argument of the third process, the fourth process name, the path of the fourth process, and the fifth command-line argument of the fourth process;

[0015] Detect the generated third process fingerprint through a pre - constructed process whitelist to determine whether the log to be tested is a malicious process;

[0016] Among them, the process whitelist includes the whitelist constructed according to the method of constructing the whitelist described above.

[0017] On the other hand, an embodiment of the present application also provides a computer storage medium, in which a computer program is stored. When the computer program is executed by a processor, it implements the method of constructing the whitelist described above, or when the computer program is executed by a processor, it implements the method of process filtering described above.

[0018] On yet another hand, an embodiment of the present application also provides a terminal, including: a memory and a processor, where a computer program is stored in the memory; among them,

[0019] The processor is configured to execute the computer program in the memory;

[0020] When the computer program is executed by the processor, it implements the method of constructing the whitelist or the method of process filtering as described above.

[0021] On yet another hand, an embodiment of the present application also provides a device for constructing a whitelist, including: a first generalization unit, a first generation unit, an extraction index unit, and a construction unit; among them,

[0022] The first generalization unit is configured to: perform generalization processing on the user process paths in the historical log records, where the user process paths include the paths belonging to the user processes in the following contents: the path of the first process, the path of the second process, the paths included in the first command - line parameter of the first process, and the paths included in the second command - line parameter of the second process. The first process refers to the process corresponding to the historical log record, and the second process is the parent process of the first process; perform generalization processing on the third command - line parameter for the historical log records after the generalization processing of the user process paths, where the third command - line parameter includes the first command - line parameter and the second command - line parameter;

[0023] The first generation unit is configured to: generate a first process fingerprint corresponding to each historical log record according to the historical log records after the generalization processing of the third command - line parameter, where the first process fingerprint includes the following fields: the name of the first process, the path of the first process, the first command - line parameter of the first process, the name of the second process, the path of the second process, and the second command - line parameter of the second process;

[0024] The extraction unit is configured to: distinguish each first process according to the first process fingerprint, and extract the normality index of each distinguished first process, where the normality index includes: statistical information on the start and operation of the first process within a preset time period;

[0025] The building unit is configured to: select corresponding first processes according to the normality metrics of each first process, and construct a process whitelist based on the first process fingerprints of the selected first processes.

[0026] On the other hand, an embodiment of the present application further provides a device for process filtering, including: a second generalization unit, a second generation unit, and a detection unit; wherein,

[0027] The second generalization unit is configured to: perform generalization processing on the user process paths in the to-be-tested log, where the user process paths include the paths belonging to user processes among the following: the path of the third process, the path of the fourth process, the paths included in the fourth command-line parameter of the third process, and the paths included in the fifth command-line parameter of the fourth process, the third process refers to the process corresponding to the to-be-tested log, and the fourth process is the parent process of the third process; perform generalization processing on the sixth command-line parameter of the to-be-tested log after the generalization processing of the user process paths, where the sixth command-line parameter includes the fourth command-line parameter and the fifth command-line parameter;

[0028] The second generation unit is configured to: generate a third process fingerprint of the to-be-tested log according to the to-be-tested log after the generalization processing of the sixth command-line parameter, where the third process fingerprint includes the following fields: the name of the third process, the path of the third process, the fourth command-line parameter of the third process, the name of the fourth process, the path of the fourth process, and the fifth command-line parameter of the fourth process;

[0029] The detection unit is configured to: detect the generated third process fingerprint through a pre-constructed process whitelist to determine whether the to-be-tested log is a malicious process;

[0030] Wherein, the process whitelist includes the whitelist generated by the above-mentioned whitelist generation device.

[0031] In the embodiments of the present disclosure, in view of a large amount of data such as newly added command-line parameters in the subsequent build process whitelist and monitoring of the parent process (the second process) of the first process, since users can freely select the installation path for the executable program, the user process paths are generally diverse and difficult to fully cover, and the user process paths generally have no direct association with the security of the process and cannot be used for the security judgment of the process. By generalizing the user process paths, the data of the user process paths that are not used for security judgment is simplified, the complexity of the data to be compared when performing process security judgment for the newly added command-line parameters and the second process monitoring is reduced, and the influence of diverse user process paths on the process security judgment is reduced; through the generalization of the command-line parameters, the command-line parameters are processed into information covering all command-line value ranges, and the process security judgment is realized through the generalized command-line parameters; the command-line parameters are added as a component of the fingerprint of the first process, and a more comprehensive normality index is obtained compared with the process whitelist without command-line parameters in the related art; the path and command-line parameters of the second process are added to the fingerprint of the first process, and the monitoring of the second process is increased, providing data support for reducing the false negatives of malicious first processes; through the paths and command-line parameters of the first process and the second process, the risk of false negatives of malicious processes disguised as normal processes is reduced; compared with the related art that determines all child processes of a normal second process as normal processes, which may lead to false negatives of malicious processes, after distinguishing each first process according to the process fingerprint, the process whitelist is constructed by selecting the fingerprint of the first process of the corresponding first process according to the normality index, providing a data basis for realizing the recognition of normal first processes and providing data support for reducing false negatives of malicious processes; in summary, a process whitelist for improving the quality of malicious process judgment is constructed.

[0032] Other features and advantages of the present application will be described in the subsequent specification, and part of them will become obvious from the specification or be understood by implementing the present application. Other advantages of the present application can be realized and obtained through the solutions described in the specification and the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The drawings are used to provide an understanding of the technical solutions of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the technical solutions of the present application and do not constitute a limitation to the technical solutions of the present application.

[0034] Figure 1 It is a flowchart of the method for constructing a whitelist in the embodiments of the present disclosure;

[0035] Figure 2 It is a flowchart of the method for process filtering in the embodiments of the present disclosure;

[0036] Figure 3 It is a block diagram of the structure of the device for constructing a whitelist in the embodiments of the present disclosure;

[0037] Figure 4 This is a structural block diagram of the device for process filtering according to an embodiment of the present disclosure. Detailed implementation manners

[0038] This application describes multiple embodiments, but the description is exemplary rather than restrictive, and it will be obvious to those of ordinary skill in the art that there can be more embodiments and implementation solutions within the scope covered by the embodiments described in this application. Although many possible feature combinations are shown in the drawings and discussed in the detailed implementation manners, many other combination ways of the disclosed features are also possible. Unless specifically restricted, any feature or element of any embodiment can be combined with any other feature or element in any other embodiment, or can replace any other feature or element in any other embodiment.

[0039] This application includes and contemplates combinations with features and elements known to those of ordinary skill in the art. The embodiments, features, and elements already disclosed in this application can also be combined with any conventional features or elements to form a unique invention solution. Any feature or element of any embodiment can also be combined with features or elements from other invention solutions to form another unique invention solution. Therefore, it should be understood that any feature shown and / or discussed in this application can be implemented alone or in any suitable combination. Therefore, except for the limitations made according to the appended claims and their equivalent replacements, the embodiments are not subject to other limitations. In addition, various modifications and changes can be made within the protection scope of the appended claims.

[0040] In addition, when describing representative embodiments, the specification may have presented the method and / or process as a specific sequence of steps. However, to the extent that the method or process does not depend on the specific order of the steps described herein, the method or process should not be limited to the specific order of steps described. As will be understood by those of ordinary skill in the art, other step sequences are possible. Therefore, the specific order of steps set forth in the specification should not be construed as a limitation on the claims. In addition, the claims directed to the method and / or process should not be limited to performing their steps in the order written, and those skilled in the art can easily understand that these orders can be changed and still remain within the spirit and scope of the embodiments of this application.

[0041] The inventors of this application analyzed and found that: in the above process whitelist generation technology, the process identifiers used usually do not include command-line parameters; for example, in the technical solution protected by application number CN201911292727.0, the process identifier is not defined; the process identifier given in the application document with application number CN201911416395.2 includes the process path and hash value, while in the solution disclosed in application number CN202310123360.X, the process identifier is the process ID; in the method disclosed in application number CN202410002884.8, the process identifier includes the process name, process ID, and server IP. The command-line parameters of a process are key information for determining the security of the process; for example, some malware may disguise itself as a legitimate program and perform malicious operations by passing in specific parameters; in addition, attackers may exploit vulnerabilities in the program to conduct attacks by passing malicious parameters to the program. In this case, the process is identified as a malicious process; therefore, if the command-line parameters of a process are missing from the whitelist, it may lead to missed reports of malicious processes when using the whitelist to filter processes.

[0042] Figure 1 A flowchart of a method for constructing a whitelist for embodiments of the present disclosure, as Figure 1 shown, includes:

[0043] Step 101: Generalize the user process paths in the historical log records, where the user process paths include the paths belonging to user processes among the following: the path of the first process, the path of the second process, the paths included in the first command-line parameter of the first process, and the paths included in the second command-line parameter of the second process. The first process refers to the process corresponding to the historical log record, and the second process is the parent process of the first process;

[0044] Step 102: Generalize the third command-line parameter for the historical log records after the generalization of the user process paths, where the third command-line parameter includes the first command-line parameter and the second command-line parameter;

[0045] Step 103: Generate a first process fingerprint corresponding to each historical log record according to the historical log records after the generalization of the third command-line parameter, where the first process fingerprint includes the following fields: the first process name, the path of the first process, the first command-line parameter of the first process, the second process name, the path of the second process, and the second command-line parameter of the second process;

[0046] Step 104: Distinguish each first process according to the first process fingerprint, and extract the normality index of each distinguished first process, where the normality index includes: statistical information on the startup and running conditions of the first process within a preset duration;

[0047] Step 105: Select corresponding first processes according to the normality indicators of each first process, and construct a process whitelist based on the first process fingerprints of the selected first processes.

[0048] In view of a large amount of data such as newly added command-line parameters and monitoring of the parent processes (second processes) of the first processes in the subsequent construction of the process whitelist in the embodiments of the present disclosure, based on the fact that users can freely select the installation path for executable programs, the paths of user processes are generally diverse and difficult to fully cover. The paths of user processes generally have no direct association with the security of processes and cannot be used for the security judgment of processes. By generalizing the paths of user processes, the data of user process paths that are not used for security judgment is simplified, the complexity of the data to be compared when performing process security judgment by adding new command-line parameters and monitoring second processes is reduced, and the influence of diverse user process paths on process security judgment is reduced; by generalizing command-line parameters, the command-line parameters are processed into information covering all command-line value ranges, and the process security judgment is realized through the generalized command-line parameters; the command-line parameters are added as components of the first process fingerprints. Compared with the process whitelist without command-line parameters in the related art, more comprehensive normality indicators are obtained; the path and command-line parameters of the second process are added to the first process fingerprints, increasing the monitoring of the second process and providing data support for reducing the false negatives of malicious first processes; through the paths and command-line parameters of the first process and the second process, the risk of false negatives of malicious processes disguising as normal processes is reduced; compared with the related art that determines all child processes of a normal second process as normal processes, which may lead to false negatives of malicious processes, after distinguishing each first process according to the process fingerprints, the first process fingerprints of the corresponding first processes are selected according to the normality indicators to construct a process whitelist, providing a data basis for identifying normal first processes and providing data support for reducing false negatives of malicious processes; in summary, a process whitelist for improving the quality of malicious process judgment is constructed.

[0049] In an exemplary example, the embodiments of the present disclosure perform generalization processing on the paths of user processes in historical log records, including:

[0050] Uniformly map the paths of user processes in the historical log records to the same placeholder information, such as [OTHERS].

[0051] Before performing generalization processing on the process paths in the given historical log records, the embodiments of the present disclosure judge whether they are user process paths or system process paths based on relevant principles.

[0052] Examples of generalizing the user process path in command-line arguments are as follows: Example 1: For the command-line argument "docker run -d -p 80:80 --name webserver nginx", since no path is matched, there is no need to generalize the user process path. Example 2: For the command-line argument "grep -i \"error\" / var / log / syslog", the matched path is / var / log / syslog. Since / var / log / syslog is not in the preset Linux system path, this path is determined to be a user process path and generalized to the placeholder [OTHERS]. After the user process path is generalized, the new command-line argument is "grep -i \"error\" [OTHERS]". Example 3: For the command-line argument " / usr / bin / mysqld_safe --datadir= / var / lib / mysql --user=mysql", there are two matched paths, namely / usr / bin / mysqld_safe and / var / lib / mysql. The former is in the preset Linux system path and is determined to be a system path, while the latter is not in the preset Linux system path and is determined to be a user process path. Therefore, only the latter needs to be generalized to the placeholder [OTHERS]. After the user process path is generalized, the new command-line argument is " / usr / bin / mysqld_safe --datadir=[OTHERS] --user=mysql".

[0053] In one exemplary instance, embodiments of the present disclosure distinguish each first process according to the first process fingerprint and extract the normality index of each distinguished first process, including:

[0054] Distinguish the historical log records of each first process according to the first process fingerprint to obtain the corresponding log group for each first process;

[0055] For the log group corresponding to each first process, extract the normality index of the first process corresponding to the log group.

[0056] In one exemplary instance, the normality index in embodiments of the present disclosure may include:

[0057] One or any combination of the following for the first process within a preset duration: the median of the startup frequency, the median of the running days, and the number of hosts on which it runs;

[0058] In one exemplary instance, the preset duration in embodiments of the present disclosure may be 30 days.

[0059] In an exemplary instance, the normalcy metric can be extracted in the following manner in this embodiment:

[0060] 1. Obtain the log grouping corresponding to the first process, and perform secondary grouping on the logs in this log grouping based on the host IP; the size of the secondary grouping, that is, the number of different host IPs, represents the number of hosts running the first process;

[0061] 2. For the log grouping corresponding to each host IP, count the number of times the first process is started on this host; the number of start times usually equals the number of logs in this grouping; add the number of start times on each host to a list, and the median of this list is the median of the start frequencies of the first process on all hosts running the first process;

[0062] 3. For the log grouping corresponding to each host IP, count the number of days the first process runs on this host; the number of running days equals the size of the deduplicated set of all start dates in this grouping; add the number of running days of each host to a list, and the median of this list is the median of the running days of the first process on all hosts running the first process.

[0063] In an exemplary instance, the embodiments of the present disclosure select corresponding first processes according to the normalcy metrics of each first process, and construct a process whitelist based on the first process fingerprints of the selected first processes, including:

[0064] Determine the normalcy of the first process according to the normalcy metric of each first process;

[0065] Select the first processes with the top preset proportion in the normalcy ranking according to the normalcies of all determined first processes, and construct a process whitelist based on the first process fingerprints of the selected first processes.

[0066] In an exemplary instance, the embodiments of the present disclosure can identify and detect whether the process path is a user process path with reference to related technologies. Given that the system path can be used for the security judgment of processes, the embodiments of the present disclosure do not perform generalization processing on the system path.

[0067] The command-line parameters in the embodiments of the present disclosure may contain paths; for example, when the path of a process is not in the system environment variables, the path of this process usually appears at the beginning of its command-line parameters; in addition, the command-line parameters of some processes may also contain file paths as parameter values; for example, the same user process may exist in the D:\ or E:\ paths; the set of user process paths in related technologies cannot cover all its possible paths.

[0068] In an exemplary instance, embodiments of the present disclosure can determine the user process path in the command-line arguments through existing methods in related technologies. For example, the user process path in the command-line arguments can be determined by regular expression matching.

[0069] In an exemplary instance, for processes on a Windows system in embodiments of the present disclosure, if the process path is not located under the preset Windows system path (i.e., C:\Windows), it is considered the user process path. For processes on a Linux system, if the process path is not located under the preset Linux system paths (i.e., / bin, / sbin, / usr / bin, / usr / sbin, / etc, or / lib, etc.), it is considered the user process path.

[0070] In an exemplary instance, embodiments of the present disclosure distinguish different first processes through the following four fields in the first process fingerprint: the first process name, the second process name, the path of the first process, and the path of the second process.

[0071] The first process fingerprint in embodiments of the present disclosure may further include the following list of parameter names:

[0072] The list of parameter names of the enumerated parameters in the first command-line argument of the first process;

[0073] The list of parameter names of the non-enumerated parameters in the first command-line argument of the first process;

[0074] The list of parameter names of the enumerated parameters in the second command-line argument of the second process;

[0075] The list of parameter names of the non-enumerated parameters in the second command-line argument of the second process.

[0076] In an exemplary instance, embodiments of the present disclosure determine the normality of a first process according to the normality index of each first process, including:

[0077] Performing normalization (Min-Max) processing on each normality index of each first process;

[0078] After weighting the normalized normality indexes according to a preset weighting strategy and summing them, the normality of the first process is obtained.

[0079] The generalization principles of the first command-line argument of the first process and the second command-line argument of the second process in embodiments of the present disclosure are the same.

[0080] In an exemplary instance, among the first command-line parameters of many first processes and the second command-line parameters of a second process in embodiments of the present disclosure, there are parameters with values of non-enumerated types such as numbers and hexadecimals. The value sets of such parameters are not finite sets. If the values of these non-enumerated type parameters are directly added to the whitelist, other normal parameter values may be missed, reducing the effectiveness of the whitelist. To avoid this situation, in embodiments of the present disclosure, when constructing a process whitelist, the third command-line parameters are generalized, the value patterns of each parameter are extracted, and these value patterns are added to the process whitelist. Such value patterns can cover most normal values of the first command-line parameters and the second command-line parameters, even if these parameter values are not exactly the same.

[0081] In an exemplary instance, embodiments of the present disclosure generalize the third command-line parameters, including: for each log in each log group:

[0082] Obtain all parameter pairs in the third command-line parameters in the historical log records;

[0083] Determine the types of all parameters in the third command-line parameters in the historical log records;

[0084] According to the obtained all parameter pairs and the types of all parameters in the third command-line parameters, determine the value pattern of the third command-line parameters;

[0085] Replace the third command-line parameters in each historical log record with the value pattern of the third command-line parameters.

[0086] In an exemplary instance, embodiments of the present disclosure obtain all parameter pairs in the third command-line parameters in the log, including:

[0087] Respectively take the first command-line parameters of the first process and the second command-line parameters of the second process as target fields, and obtain the value sets of the target fields;

[0088] For the value sets of the target fields, obtain all parameter pairs in each element (i.e., process command-line parameters or parent process command-line parameters) in the value sets, where each parameter pair includes a parameter name and the corresponding parameter value.

[0089] The parameter pairs in embodiments of the present disclosure are value sets of parameter names.

[0090] All parameter pairs in the embodiments of the present disclosure need to be obtained by parsing command-line parameters (the first command-line parameter and the second command-line parameter). This can be achieved by: splitting the string of the command-line parameter into parameter pairs according to the data format of the command-line parameter, and extracting the parameter name and the corresponding parameter value in each parameter pair; in the command-line parameter, the first space is usually used to separate the main command and the parameter; for example, in "find / home / xyz -name \"*.log\"", find is the command, and " / home / xyz -name \"*.log\"" is the parameter string; some commands may contain subcommands. To better parse such commands, a subcommand library of some common commands needs to be prepared. For example, in "git commit -m \"add readme\"", git is the main command, commit is the subcommand, and "-m \"add readme\"" is the parameter. Split the string of the command-line parameter into parameter pairs according to the data format of the command-line parameter; common parameter formats include but are not limited to: "--param value", "--param=value", "-param value", "-param=value", "param=value", " / param:value", " / param=value", "--param" (parameter value is empty), "-param" (parameter value is empty), "value" (parameter name is empty). When the parameter value is empty, it is usually an option parameter, also known as a switch parameter. These parameters do not require a value and only affect the behavior of the process; for example, the -r or --recursive parameter of the grep command is used to recursively retrieve text without requiring an accompanying parameter value; when the parameter name is empty, it is usually a positional parameter, and the corresponding parameter value is generally a file path; for example, in the command "vim main.py", main.py is the positional parameter, and at this time, the position of the parameter is used to represent the parameter name.

[0091] In an exemplary example, the embodiments of the present disclosure determine the value-taking mode of the third command-line parameter according to all parameter pairs and the types of all parameters in the third command-line parameter, including:

[0092] Determine the value-taking mode of the parameter value according to all parameter pairs in the third command-line parameter;

[0093] Concatenate the value-taking modes of all parameter values in the third command-line parameter according to all parameter names in the third command-line parameter to obtain the value-taking mode of the command-line parameter;

[0094] Among them, the value-taking mode of the enumerated parameter is the concatenation of the parameter name and the parameter value, and the value-taking mode of the non-enumerated parameter is the concatenation of the parameter name and all preset features; the embodiments of the present disclosure sort and concatenate the value-taking modes of all parameters in the order of the parameter names to obtain the value-taking mode of the third command-line parameter.

[0095] In an exemplary instance, the embodiments of the present disclosure determine the value-taking mode of parameter values according to all parameter pairs in the third command-line parameter, including:

[0096] Successively extract the features of each parameter value in each parameter pair in the third command-line parameter;

[0097] Perform binning processing on the extracted features of the parameter values. The binning processing includes mapping the feature values of the features within a preset interval to the same numerical value;

[0098] Concatenate the feature values of the features of all parameter values after binning processing to obtain the value-taking mode of the parameter values.

[0099] In order for the same value-taking mode to match strings with differences but conforming to this mode, the embodiments of the present disclosure need to ensure that the features of these parameters are the same; therefore, after extracting the features of the parameter values, binning processing is performed on the features. The binning processing methods adopted by the embodiments of the present disclosure may include equal-width binning, equal-frequency binning, and quantile-based binning, etc.

[0100] In an exemplary instance, the features extracted by the embodiments of the present disclosure include but are not limited to one or any combination of the following: the number of characters, the proportion of digits, the proportion of letters, the proportion of special characters, the number of distinct digits, the number of distinct letters, the number of distinct special characters, the number of paths, the encryption type, the digit-letter switching rate, the switching rate between special characters and digits / letters, etc.; among them, the encryption type refers to the encoding type, which may include encoding types such as Base64, Base32, hexadecimal, etc.; the digit-letter switching rate refers to the proportion of the number of switches between digits and letters in the string to the total number of characters in the string; the switching rate between special characters and digits / letters refers to the proportion of the number of conversions between special characters and digits or letters in the string to the total number of characters in the string; the features extracted by the embodiments of the present disclosure may also be subsets of these features.

[0101] Embodiments of the present disclosure select a set of features with appropriate parameter values based on the trade-off between the accuracy requirements of the features and the computational efficiency of feature extraction. If too many features are selected, although the accuracy of parameter value pattern matching may be improved, the computational complexity will increase and the computational efficiency will decrease. On the other hand, if too few features are selected, the features of the parameter values may not be fully captured, resulting in a decrease in the accuracy of parameter value pattern matching. Therefore, it is necessary to comprehensively consider the accuracy of parameter value pattern matching and the computational efficiency, and select a set of features that can balance the two. Embodiments of the present disclosure can set the value pattern of the enumerated type parameter. For example, it is set to use a preset splicing symbol Sep1 to splice the parameter name and the parameter value to obtain the value pattern of the parameter, such as {ParaName}{Sep1}{ParaValue}. For the value pattern of the non-enumerated type parameter, first, the feature vector of the parameter value is extracted, and it is set to use the preset splicing symbol Sep2 to splice all the values in the feature vector to obtain the value pattern of the parameter value, denoted as ParaPattern. Then, the preset splicing symbol Sep1 is used to splice the parameter name and the value pattern of the parameter value to obtain the value pattern of the parameter, such as {ParaName}{Sep1}{ParaPattern}. Sort the value patterns of all the parameters in the command line parameter according to the order of the parameter names to obtain the sorted parameter value patterns. Assume that the preset splicing symbol Sep3 is used to splice the value patterns of all the parameters in the command line parameter, that is, splice the patterns in the sorted parameter value pattern list to obtain the value pattern corresponding to the command line parameter, such as {ParaName1}{Sep1}{ParaValue1}{Sep3}{ParaName2}{Sep1}{ParaPattern2}{Sep3}{ParaName1}{Sep1}{ParaValue1}. When the features of the selected parameter values include the number of characters, the proportion of digits, the proportion of letters, the proportion of special characters, the number of paths, and the encryption type, the value pattern (ParaPattern) of the parameter value can be expressed as: {CharCnt}{Sep2}{DigitPct}{Sep2}{LetterPct}{Sep2}{SpecialChartPct}{Sep2}{PathCnt}{Sep2}{EncodingTypes}.

[0102] In an exemplary example, embodiments of the present disclosure determine the types of all the parameters in the third command line parameter in the historical log record, including:

[0103] Obtain the value set corresponding to the parameter names of each pair of command line parameters of the parent-child processes, where the parent-child processes include the first process and the second process belonging to its parent process,

[0104] Detect and remove the outliers in the value set of the parameter name;

[0105] Judge whether the parameter is an enumeration type according to the value set after removing the outliers.

[0106] There may be non-compliant or malicious abnormal inputs in the command-line parameters based on the historical process logs. To reduce the impact of these abnormal inputs on the enumeration type judgment, the embodiments of the present disclosure detect and remove the outliers in the parameter value set, find the command-line parameters in the historical process logs that contain these outliers, and then remove the relevant records from the logs.

[0107] In the embodiments of the present disclosure, when the value set of a parameter name simultaneously satisfies the following two conditions, it can be determined that the parameter is an enumeration type: 1. The number of parameter values (i.e., the size of the value set of the parameter name) is less than the first preset value; because the values of enumeration-type parameters are limited; 2. The number of hosts corresponding to each parameter value is greater than the second preset value; because each parameter value of the enumeration-type parameter of the process will appear on multiple hosts; The embodiments of the present disclosure give a parameter value, the log set of the process corresponding to the parameter value, and the command-line parameter name of the corresponding first process or second process, find the logs that contain the parameter name and the corresponding parameter value is the parameter value from the log set, and form a log subset; count the number of hosts corresponding to the log subset, and the number of hosts corresponding to the parameter value can be obtained.

[0108] In an example instance, the outliers in the value set of the parameter name of the embodiments of the present disclosure are detected through the following processing:

[0109] Extract the features of each parameter value;

[0110] Normalize each feature of each parameter value; for example, use Min-Max normalization to scale each feature value to the same range, usually [0,1];

[0111] Perform outlier detection on the parameter values after feature normalization to determine the outliers in the value set of the parameter name.

[0112] Common outlier detection algorithms in the related art include, but are not limited to: distance- or similarity-based methods: common string distance calculation algorithms include Euclidean distance, Manhattan distance, and cosine similarity, etc.; calculate the average distance between each parameter value and other parameter values in the set; if the average distance of a certain parameter value is significantly higher than other parameter values, then consider that parameter value as an outlier. Clustering-based methods, such as K-means or DBSCAN; model-based methods, such as Isolation Forest.

[0113] In an exemplary instance, when the embodiments of the present disclosure detect and remove outliers in the value set of the parameter name, the method of the embodiments of the present disclosure further includes:

[0114] Removing the historical log records corresponding to the removed outliers.

[0115] In an exemplary instance, the method of the embodiments of the present disclosure further includes storing some or all of the data in the process of constructing the process whitelist through a hash table.

[0116] The hash table in the embodiments of the present disclosure may be a hierarchical hash table; the embodiments of the present disclosure use a hierarchical hash table to store the process whitelist, and the hierarchical hash table can achieve layer-by-layer matching. Compared with the whitelist composed of a list of strings, by comparing the whitelist entries one by one, the hierarchical hash table can significantly improve the matching efficiency.

[0117] In an exemplary instance, the embodiments of the present disclosure use a hash table to store the above process whitelist; taking the hierarchical hash table as an example, the above parameter name list can be stored in layers in the hash table; the hash table can distinguish different processes through the first process name, the second process name, the path of the first process, and the path of the second process. The first four layers of the hierarchical hash table can respectively correspond to four fields in the process identifier, namely the first process name, the first process path, the second process name, and the second process path; the fifth layer is used to distinguish the command line parameter name list and the value pattern of the command line parameter, that is, the command line parameter after generalization processing. The last two layers contain four parameter name lists and the last two fields in the process fingerprint, which are the value pattern of the process command line parameter and the value pattern of the parent process command line parameter, that is, the generalized process command line parameter and the generalized parent process command line parameter; to improve the matching efficiency of the process whitelist, parameter names that are not included in all common first command line parameters of the first process and the second command line parameters of the second process in the whitelist can be removed from the four parameter name lists in the hash table; the embodiments of the present disclosure can use different hash tables to store data according to different processing performed in different stages.

[0118] The following is an example of storing the process whitelist through a hash table.

[0119]

[0120] Figure 2 It is a flowchart of the method for process filtering in the embodiments of the present disclosure, as Figure 2 shown, including:

[0121] Step 201: Generalize the user process paths in the log to be tested. Among them, the user process paths include the paths belonging to user processes in the following: the path of the third process, the path of the fourth process, the paths included in the fourth command-line argument of the third process, and the paths included in the fifth command-line argument of the fourth process. The third process refers to the process corresponding to the log to be tested, and the fourth process is the parent process of the third process;

[0122] Step 202: Generalize the sixth command-line argument for the log to be tested after generalizing the user process paths. Among them, the sixth command-line argument includes the fourth command-line argument and the fifth command-line argument;

[0123] Step 203: Generate the fingerprint of the third process of the log to be tested according to the log to be tested after generalizing the sixth command-line argument. Among them, the fingerprint of the third process includes the following fields: the name of the third process, the path of the third process, the fourth command-line argument of the third process, the name of the fourth process, the path of the fourth process, and the fifth command-line argument of the fourth process;

[0124] Step 204: Detect the generated fingerprint of the third process through a pre-constructed process whitelist to determine whether the log to be tested is a malicious process;

[0125] Among them, the process whitelist includes the whitelist constructed according to the method of constructing the whitelist above.

[0126] The generalization process of the user process paths of the log to be tested in the embodiments of the present disclosure is the same as the processing principle of the generalization process of the user process paths of historical log records, and the embodiments of the present disclosure will not elaborate on this.

[0127] In an exemplary example, the generalization of the sixth command-line argument in the embodiments of the present disclosure includes:

[0128] Obtain the parameter values corresponding to each parameter name in the sixth command-line argument;

[0129] Determine the types of all parameters in the sixth command-line argument of the log to be tested;

[0130] Determine the value-taking mode of the sixth command-line argument according to all parameter pairs and the types of all parameters in the sixth command-line argument.

[0131] In an exemplary example, the determination of the types of all parameters in the sixth command-line argument of the log to be tested in the embodiments of the present disclosure includes:

[0132] By matching the third process name, the fourth process name, the path of the third process, and the path of the fourth process in the log to be tested with the process whitelist, the positions of the four parameter name lists of this process in the process whitelist are located, including the enumerated parameter table of the command-line parameters of the first process, the non-enumerated parameter table of the command-line parameters of the first process, the enumerated parameter table of the first process command line, and the non-enumerated parameter table of the second process command line; then, the parameter names of the command-line parameters of each third process and the parameter names of the command-line parameters of each fourth process in the log to be tested are respectively matched with the corresponding enumerated parameter table and non-enumerated parameter table in the process whitelist to determine the type of each command-line parameter; the judgment results are divided into three types: enumerated parameter, non-enumerated parameter, and non-existent; when the judgment result is non-existent, the embodiments of the present disclosure determine that the log to be tested is not a normal log and no further analysis is performed.

[0133] In an exemplary instance, the embodiments of the present disclosure can store the log to be tested with the generalization processing of the user process path and command-line parameters in a list.

[0134] During the process of detecting the log to be tested by the embodiments of the present disclosure, first, the third process name, the fourth process name, the third process path, and the fourth process path of the log to be tested are matched with the process whitelist; next, the generalized fourth command-line parameter and fifth command-line parameter are respectively matched with the corresponding fields in the process whitelist; if these six fields in the log to be tested can all be successfully matched in the process fingerprint of the process whitelist, it is determined that the log belongs to a normal process; otherwise, it is determined that the process to be tested is an abnormal process, and a malicious process detection system can be used for further analysis.

[0135] When the embodiments of the present disclosure filter the log to be tested, only the value-taking mode of the command-line parameters of the process to be tested needs to be compared with the parameter value-taking mode of the corresponding process in the process whitelist.

[0136] With the increasing complexity of network attacks, the requirements of enterprises, government agencies, and industries with highly sensitive data (such as finance and healthcare) for the security of internal networks are continuously increasing, and the demand for fine-grained and real-time process control technologies is growing; the embodiments of the present disclosure aim to enhance the abnormal behavior analysis ability of large models in the security field; through the above process filtering method, a normal process dataset can be constructed as the training input for the abnormal behavior analysis of large models; the embodiments of the present disclosure help to ensure the security of the operating environment of large models and ensure that only normal or specified processes are allowed to run; based on the process whitelist, normal processes in the operating environment can be started, enabling the malicious process detection system to focus on the identification of potential threats.

[0137] An embodiment of the present disclosure also provides a computer storage medium storing a computer program, which, when executed by a processor, implements the method for constructing a whitelist as described above.

[0138] An embodiment of the present disclosure also provides a terminal, including: a memory and a processor, where the memory stores a computer program;

[0139] Wherein,

[0140] the processor is configured to execute the computer program in the memory;

[0141] the computer program, when executed by the processor, implements the method for constructing a whitelist as described above.

[0142] An embodiment of the present disclosure also provides a computer storage medium storing a computer program, which, when executed by a processor, implements the method for process filtering as described above.

[0143] An embodiment of the present disclosure also provides a terminal, including: a memory and a processor, where the memory stores a computer program;

[0144] Wherein,

[0145] the processor is configured to execute the computer program in the memory;

[0146] the computer program, when executed by the processor, implements the method for process filtering as described above.

[0147] Figure 3 is a structural block diagram of a device for constructing a whitelist according to an embodiment of the present disclosure. As Figure 3 shown, it includes: a first generalization unit, a first generation unit, an extraction index unit, and a construction unit; wherein,

[0148] The first generalization unit is configured to: perform generalization processing on the user process paths in the historical log records, where the user process paths include the paths belonging to user processes among the following contents: the path of the first process, the path of the second process, the paths included in the first command-line parameter of the first process, and the paths included in the second command-line parameter of the second process. The first process refers to the process corresponding to the historical log record, and the second process is the parent process of the first process; perform generalization processing on the third command-line parameter for the historical log records after the generalization processing of the user process paths, where the third command-line parameter includes the first command-line parameter and the second command-line parameter;

[0149] The first generation unit is configured to: generate a first process fingerprint corresponding to each historical log record according to the historical log records generalized by the third command line parameter, where the first process fingerprint includes the following fields: the first process name, the path of the first process, the first command line parameter of the first process, the second process name, the path of the second process, and the second command line parameter of the second process;

[0150] The extraction unit is configured to: distinguish each first process according to the first process fingerprint and extract the normality index of each distinguished first process, where the normality index includes: statistical information on the startup and running conditions of the first process within a preset duration;

[0151] The construction unit is configured to: select corresponding first processes according to the normality index of each first process and construct a process whitelist according to the first process fingerprints of the selected first processes.

[0152] In an exemplary instance, the first generalization unit of the embodiment of the present disclosure is configured to:

[0153] Uniformly map the user process paths in the historical log records to the same placeholder information.

[0154] In an exemplary instance, the extraction unit of the embodiment of the present disclosure is configured to:

[0155] Distinguish the historical log records of each first process according to the first process fingerprint to obtain a log group corresponding to each first process;

[0156] For the log group corresponding to each first process, extract the normality index of the first process corresponding to the log group.

[0157] In an exemplary instance, the normality index in the embodiment of the present disclosure includes one or any combination of the following of the first process within a preset duration:

[0158] The median of the startup frequency, the median of the running days, and the number of hosts on which it runs.

[0159] In an exemplary instance, the construction unit of the embodiment of the present disclosure is configured to:

[0160] Determine the normality of the first process according to the normality index of each first process;

[0161] Select the first processes with a preset proportion ranked in the front according to the normality of all the determined first processes, and construct a process whitelist according to the first process fingerprints of the selected first processes.

[0162] In an exemplary instance, the construction unit of the embodiment of the present disclosure is configured to determine the normality of the first process according to the normality index of each first process, including:

[0163] Normalize (Min - Max) each normality index of each first process;

[0164] Sum the weighted normalized normality indices according to a preset weighting strategy to obtain the normality of the first process.

[0165] In an exemplary instance, the first generalization unit of the embodiment of the present disclosure is set to perform generalization processing on the third command - line parameter, including:

[0166] Obtain all parameter pairs in the third command - line parameter from the historical log record;

[0167] Determine the types of all parameters in the third command - line parameter in the historical log record;

[0168] Determine the value - taking pattern of the third command - line parameter according to all parameter pairs and all parameter types obtained from the third command - line parameter;

[0169] Replace the third command - line parameter in each historical log record with its value - taking pattern.

[0170] In an exemplary instance, the first generalization unit of the embodiment of the present disclosure is set to obtain all parameter pairs in the third command - line parameter from the historical log record, including:

[0171] Respectively use the first command - line parameter of the first process and the second command - line parameter of the second process as target fields, and obtain the value set of the target field;

[0172] For the value set of the target field, for each element in the value set, all parameter pairs, where each parameter pair contains a parameter name and its corresponding parameter value.

[0173] In an exemplary instance, the first generalization unit of the embodiment of the present disclosure is set to determine the value - taking pattern of the third command - line parameter according to all parameter pairs and all parameter types obtained from the third command - line parameter, including:

[0174] Determine the value - taking pattern of the parameter value according to all parameter pairs in the third command - line parameter;

[0175] Concatenate the value - taking patterns of all parameter values in the third command - line parameter according to the parameter names of all parameters in the third command - line parameter to obtain the value - taking pattern of the command - line parameter;

[0176] Among them, the value-taking mode of the enumerated parameter is the concatenation of the parameter name and the parameter value, and the value-taking mode of the non-enumerated parameter is the concatenation of the parameter name and all preset features; sort and concatenate the value-taking modes of all parameters in the order of the parameter names to obtain the value-taking mode of the third command-line parameter.

[0177] In an exemplary instance, the first generalization unit of the embodiment of the present disclosure is configured to determine the value-taking mode of the parameter value according to all parameter pairs in the third command-line parameter, including:

[0178] Successively extract the features of each parameter value in each parameter pair in the third command-line parameter;

[0179] Perform binning processing on the extracted features of the parameter value, and the binning processing includes mapping the feature values of the features within the preset interval to the same numerical value;

[0180] Concatenate the feature values of the features of all parameter values after binning processing to obtain the value-taking mode of the parameter value.

[0181] In an exemplary instance, the first generalization unit of the embodiment of the present disclosure is configured to determine the types of all parameters in the third command-line parameter in the historical log record, including:

[0182] Obtain the value set corresponding to the parameter name of each pair of command-line parameters of the parent-child processes, where the parent-child processes include the first process and the second process belonging to its parent process;

[0183] Detect and remove the outliers in the value set of the parameter name;

[0184] Judge whether the parameter is an enumerated type according to the value set after removing the outliers.

[0185] In an exemplary instance, the first generalization unit of the embodiment of the present disclosure is configured to detect the outliers in the value set of the parameter name through the following processing:

[0186] Extract the features of each parameter value;

[0187] Standardize each feature of each parameter value;

[0188] Perform outlier detection on the parameter values after feature standardization to determine the outliers in the value set of the parameter name.

[0189] In an exemplary instance, the first generalization unit of the embodiment of the present disclosure is further configured to:

[0190] When detecting and removing the outliers in the value set of the parameter name, remove the historical log record corresponding to the removed outliers.

[0191] In an exemplary example, the device according to the embodiments of the present disclosure further includes a storage unit, which is configured to:

[0192] Store some or all of the data during the construction process of the process whitelist through a hash table.

[0193] Figure 4 It is a structural block diagram of the device for process filtering according to the embodiments of the present disclosure. As Figure 4 shown, it includes: a second generalization unit, a second generation unit, and a detection unit; wherein,

[0194] The second generalization unit is configured to: perform generalization processing on the user process path in the to-be-tested log, where the user process path includes the paths belonging to the user process among the following contents: the path of the third process, the path of the fourth process, the path included in the fourth command-line parameter of the third process, and the path included in the fifth command-line parameter of the fourth process. The third process refers to the process corresponding to the to-be-tested log, and the fourth process is the parent process of the third process; perform generalization processing on the sixth command-line parameter for the to-be-tested log after the generalization processing of the user process path, where the sixth command-line parameter includes the fourth command-line parameter and the fifth command-line parameter;

[0195] The second generation unit is configured to: generate a third process fingerprint of the to-be-tested log according to the to-be-tested log after the generalization processing of the sixth command-line parameter, where the third process fingerprint includes the following fields: the name of the third process, the path of the third process, the fourth command-line parameter of the third process, the name of the fourth process, the path of the fourth process, and the fifth command-line parameter of the fourth process;

[0196] The detection unit is configured to: detect the generated third process fingerprint through a pre-constructed process whitelist to determine whether the to-be-tested log is a malicious process;

[0197] Among them, the process whitelist includes the whitelist generated by the device for generating the whitelist as described above.

[0198] Those of ordinary skill in the art will understand that all or some of the steps in the methods disclosed above, and the functional modules / units in systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof. In the hardware implementation, the division of functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, one physical component can have multiple functions, or one function or step can be executed by several physical components in cooperation. Some or all components can be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term "computer storage medium" includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media include but are not limited to RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those of ordinary skill in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium.

Claims

1. A method for constructing a whitelist, characterized in that, Including: Generalize the user process paths in the historical log records, where the user process paths include the paths belonging to user processes among the following: the path of the first process, the path of the second process, the paths included in the first command-line argument of the first process, and the paths included in the second command-line argument of the second process. The first process refers to the process corresponding to the historical log record, and the second process is the parent process of the first process; Generalize the third command-line argument for the historical log records after generalizing the user process paths, where the third command-line argument includes the first command-line argument and the second command-line argument; Generate a first process fingerprint corresponding to each historical log record based on the historical log records after generalizing the third command-line argument, where the first process fingerprint includes the following fields: the name of the first process, the path of the first process, the first command-line argument of the first process, the name of the second process, the path of the second process, and the second command-line argument of the second process; Distinguish each first process according to the first process fingerprint, and extract the normality index of each distinguished first process, where the normality index includes: statistical information on the startup and running conditions of the first process within a preset duration; Select corresponding first processes according to the normality index of each first process, and construct a process whitelist based on the first process fingerprints of the selected first processes.

2. The method according to claim 1, characterized in that, The generalization process of the user process paths in the historical log records includes: Uniformly map the user process paths in the historical log records to the same placeholder information.

3. The method according to claim 1, wherein The process of distinguishing each first process according to the first process fingerprint and extracting the normality index of each distinguished first process includes: Distinguish the historical log records of each first process according to the first process fingerprint to obtain the log group corresponding to each first process; For the log group corresponding to each first process, extract the normality index of the first process corresponding to this log group.

4. The method according to claim 3, wherein The normality index includes one or any combination of the following for the first process within a preset duration: The median of the startup frequency, the median of the running days, and the number of hosts on which it runs.

5. The method according to claim 1, characterized in that The process of selecting corresponding first processes according to the normality index of each first process and constructing a process whitelist based on the first process fingerprints of the selected first processes includes: Determine the normality of the first process according to the normality index of each first process; Select the first processes with the top preset proportion in terms of normality ranking according to the normality of all the determined first processes, and construct the process whitelist based on the first process fingerprints of the selected first processes.

6. The method according to claim 5, wherein The process of determining the normality of the first process according to the normality index of each first process includes: Normalize each normality index of each first process; Sum up the normalized normality indexes according to a preset weighting strategy to obtain the normality of this first process.

7. The method according to any one of claims 1 to 6, characterized in that, The generalization process of the third command-line argument includes: obtaining all parameter pairs in the third command-line argument in the historical log records; Determine the types of all parameters in the third command-line parameter in the historical log record; Determine the value-taking pattern of the third command-line parameter according to all parameter pairs and the types of all parameters in the obtained third command-line parameter; Replace the third command-line parameter in each historical log record with the value-taking pattern of this third command-line parameter.

8. The method according to claim 7, characterized in that, The obtaining all parameter pairs in the third command-line parameter in the historical log record includes: Respectively take the first command-line parameter of the first process and the second command-line parameter of the second process as target fields, and obtain the value set of the target field; For the value set of the target field, obtain all parameter pairs in each element in the value set, where each parameter pair includes a parameter name and a corresponding parameter value.

9. The method according to claim 7, wherein The determining the value-taking pattern of the third command-line parameter according to all parameter pairs and the types of all parameters in the obtained third command-line parameter includes: Determine the value-taking pattern of the parameter value according to all parameter pairs in the third command-line parameter; Concatenate the value-taking patterns of all parameter values in the third command-line parameter according to the parameter names of all parameters in the third command-line parameter to obtain the value-taking pattern of the command-line parameter; Among them, the value-taking pattern of an enumerated parameter is the concatenation of the parameter name and the parameter value, and the value-taking pattern of a non-enumerated parameter is the concatenation of the parameter name and all preset features; sort and concatenate the value-taking patterns of all parameters in the order of the parameter names to obtain the value-taking pattern of the third command-line parameter.

10. The method according to claim 9, wherein The determining the value-taking pattern of the parameter value according to all parameter pairs in the third command-line parameter includes: Successively extract the features of each parameter value in each parameter pair in the third command-line parameter; Perform binning processing on the extracted features of the parameter values, where the binning processing includes mapping the feature values of the features within a preset interval to the same numerical value; Concatenate the feature values of the features of all parameter values after the binning processing to obtain the value-taking pattern of the parameter value.

11. The method according to claim 7, wherein The determining the types of all parameters in the third command-line parameter in the historical log record includes: Obtain the value set corresponding to the parameter name of each pair of command-line parameters of parent-child processes, where the parent-child processes include the first process and the second process belonging to its parent process; Detect and remove the outliers in the value set of the parameter name; Judge whether the parameter is an enumerated type according to the value set after removing the outliers.

12. The method according to claim 11, wherein The outliers in the value set of the parameter name are detected through the following processing: Extract the features of each parameter value; Normalize each feature of each parameter value; Perform outlier detection on the parameter values after feature normalization to determine the outliers in the value set of the parameter name.

13. The method according to claim 12, characterized in that, When detecting and removing the outliers in the value set of the parameter name, the method further includes: Remove the historical log record corresponding to the removed outlier.

14. The method according to any one of claims 1 to 6, characterized in that, The method further includes: Store part or all of the data in the process of constructing the process whitelist through a hash table.

15. A method for process filtering, characterized in that, Include: Generalize the user process paths in the log to be tested. Among them, the user process paths include the paths belonging to the user process in the following: the path of the third process, the path of the fourth process, the paths included in the fourth command-line parameter of the third process, and the paths included in the fifth command-line parameter of the fourth process. The third process refers to the process corresponding to the log to be tested, and the fourth process is the parent process of the third process; Perform generalization processing on the sixth command-line parameter for the log to be tested after the generalization processing of the user process paths. Among them, the sixth command-line parameter includes the fourth command-line parameter and the fifth command-line parameter; Generate the third process fingerprint of the log to be tested according to the log to be tested after the generalization processing of the sixth command-line parameter. Among them, the third process fingerprint includes the following fields: the name of the third process, the path of the third process, the fourth command-line parameter of the third process, the name of the fourth process, the path of the fourth process, and the fifth command-line parameter of the fourth process; Detect the generated third process fingerprint through a pre-constructed process whitelist to determine whether the log to be tested is a malicious process; Among them, the process whitelist includes the whitelist constructed according to the method described in any one of claims 1 to 14.

16. A computer storage medium, in which a computer program is stored. When the computer program is executed by a processor, it implements the method for constructing a whitelist described in any one of claims 1 to 14, or the method for process filtering described in any one of claim 15.

17. A terminal, comprising: A memory and a processor, in which a computer program is stored; among them, The processor is configured to execute the computer program in the memory; When the computer program is executed by the processor, it implements the method for constructing a whitelist described in any one of claims 1 to 14, or the method for process filtering described in any one of claim 15.

18. An apparatus for constructing a whitelist, characterized in that, Including: A first generalization unit, a first generation unit, an extraction index unit, and a construction unit; among them, The first generalization unit is set to: generalize the user process paths in the historical log records. Among them, the user process paths include the paths belonging to the user process in the following: the path of the first process, the path of the second process, the paths included in the first command-line parameter of the first process, and the paths included in the second command-line parameter of the second process. The first process refers to the process corresponding to the historical log records, and the second process is the parent process of the first process; perform generalization processing on the third command-line parameter for the historical log records after the generalization processing of the user process paths. Among them, the third command-line parameter includes the first command-line parameter and the second command-line parameter; the first generation unit is set to: generate the first process fingerprint corresponding to each historical log record according to the historical log records after the generalization processing of the third command-line parameter. Among them, the first process fingerprint includes the following fields: the name of the first process, the path of the first process, the first command-line parameter of the first process, the name of the second process, the path of the second process, and the second command-line parameter of the second process; The extraction unit is configured to: distinguish each first process according to the first process fingerprint, and extract the normality index of each distinguished first process, where the normality index includes: statistical information on the startup and running conditions of the first process within a preset duration; The construction unit is configured to: select corresponding first processes according to the normality index of each first process, and construct a process whitelist according to the first process fingerprints of the selected first processes.

19. An apparatus for process filtering, characterized in that, It includes: A second generalization unit, a second generation unit, and a detection unit; where The second generalization unit is configured to: perform generalization processing on the user process paths in the log to be tested, where the user process paths include the paths belonging to user processes among the following: the path of the third process, the path of the fourth process, the paths included in the fourth command-line parameter of the third process, and the paths included in the fifth command-line parameter of the fourth process, the third process refers to the process corresponding to the log to be tested, and the fourth process is the parent process of the third process; perform generalization processing on the sixth command-line parameter on the log to be tested after the generalization processing of the user process paths, where the sixth command-line parameter includes the fourth command-line parameter and the fifth command-line parameter; The second generation unit is configured to: generate a third process fingerprint of the log to be tested according to the log to be tested after the generalization processing of the sixth command-line parameter, where the third process fingerprint includes the following fields: the name of the third process, the path of the third process, the fourth command-line parameter of the third process, the name of the fourth process, the path of the fourth process, and the fifth command-line parameter of the fourth process; The detection unit is configured to: detect the generated third process fingerprint through the pre-constructed process whitelist to determine whether the log to be tested is a malicious process; wherein, the process whitelist includes the whitelist generated by the device as described in claim 18.

Citation Information

Patent Citations

  • A method for controlling process initiation, a computer device, and a readable storage medium.

    CN111125721B

  • A method and apparatus for generating a process list

    CN111159702B

  • Server log process security detection method and system

    CN118138270A

  • White list maintenance method, host protection method and device

    CN118503965A