Malicious program detection method and device based on log and system call sequence
By combining Windows log analysis and system call sequence analysis, using rules-based methods and two-way long and short-term memory network model, the accuracy and efficiency of malicious program detection in the Windows operating system are solved, and efficient detection of new malicious programs is achieved.
Patent Information
- Application Number
- CN202510446384.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-07-25
AI Technical Summary
The existing Windows operating system malicious program detection methods are difficult to effectively analyze the behavior patterns of new malicious programs. Traditional log analysis methods are limited to coarse-grained information and have limited detection capabilities.
Combined with Windows log analysis and system call sequence analysis, a rule-based log analysis method is used to initially detect malicious programs, system call sequence data is obtained through sandbox testing, and further analysis is used using a malicious program detection model based on a two-way long and short-term memory network.
It improves the accuracy and efficiency of malicious program detection, enhances the detection ability of new malicious programs, and reduces the misjudgment rate.
Smart Images

Figure CN120372613A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and particularly to a malicious program detection method and device based on logs and system call sequences. Background Art
[0002] With the rapid development of information technology, the scale and complexity of modern computer systems, network devices, and application programs are increasing day by day. However, the threats of relevant malicious programs are also increasing day by day, and the complexity of their attack means is getting higher and higher. When the system is attacked by malicious programs, a large number of alarm logs and system call data will be generated, recording information such as status, events, and errors. In order to detect malicious program attacks in a timely and accurate manner, the analysis based on logs and system call data is the research focus for dealing with malicious program threats.
[0003] For the Windows operating system, traditional log analysis methods mainly perform analysis through rule matching and manual analysis. The existing Windows log data records malicious programs only in terms of coarse-grained information such as location and command line. However, as the concealment and complexity of malicious programs are getting higher and higher, it is difficult to analyze the behavior patterns of malicious programs only by using traditional methods, and the detection ability for new types of malicious program attacks is limited. As an important part of dynamic analysis methods, system call sequences record the interaction process between programs and the operating system kernel, including fine-grained information such as the behavior patterns of programs. In such a background, the analysis method combining logs and system call sequences can perform a more comprehensive analysis of potential malicious programs, thereby improving the detection accuracy and reducing misjudgment, and playing a greater role in malicious program detection. Summary of the Invention
[0004] Aiming at the problems existing in the prior art, a malicious program detection method based on logs and system call sequences is provided, which combines the analysis of Windows log data and system call sequence data to improve the performance and generalization ability of malicious program detection, constructs a malicious program detection model with better robustness, and realizes accurate malicious program detection.
[0005] The first aspect of the present invention proposes a malicious program detection method based on logs and system call sequences, including:
[0006] Collect and store log data;
[0007] Formulate a rule set based on a rule template, and analyze the log data through the rule set to obtain a log analysis result; the log analysis result includes a preliminary judgment result of a malicious program and the location information of the program;
[0008] Obtain the PE format program initially judged as a malicious program from the terminal according to the log analysis results, and obtain the system call sequence data through sandbox testing;
[0009] Use the trained malicious program detection model based on the bidirectional long short-term memory network to detect the system call sequence data to obtain the program category analysis results; the malicious program detection model includes a word embedding network and a system call sequence classification network, and the word embedding network is used to convert the input system call sequence data into word embedding vectors, and the system call sequence classification network is used to judge the corresponding PE format program category according to the word embedding vectors;
[0010] Integrate the log analysis results and the program category analysis results to determine the final malicious program detection results.
[0011] As a preferred solution, before storing the log data, it also includes preprocessing the collected log data, and the preprocessing includes: removing redundant information irrelevant to malicious program detection in the log data, and converting the format to an easy-to-process json or txt format.
[0012] As a preferred solution, the rule templates include regular expression templates, keyword matching templates, conditional rule templates, and threshold rule templates; among them, the regular expression templates are used to match specific patterns in the log data; the keyword matching templates are used to identify specific keywords in the log data; the conditional rule templates are used to filter the log data based on certain specified logical conditions; the threshold rule templates are used to set specified thresholds.
[0013] As a preferred solution, the log analysis results are represented in json format data, and each analysis result includes at least the path of the executable file and the threat level.
[0014] As a preferred solution, using the malicious program detection model based on the bidirectional long short-term memory network to detect the system call sequence data to obtain the program category analysis results specifically includes:
[0015] Preprocess the input paired system call sequence data to obtain the standard input;
[0016] Convert the standard input into word embedding vectors through the word embedding network, and the word embedding vectors include multiple feature vectors, and each feature vector includes three-dimensional information of character-level information, word-level information, and function library information;
[0017] Input the word embedding vectors into the system call sequence classification network for classification, and output the results to the fully connected network to obtain the final output label; the system call sequence classification network uses a bidirectional long short-term memory network with 2 hidden layers;
[0018] The final output label includes a normal program, a malicious program of a certain predefined common category, or other malicious programs.
[0019] As a preferred solution, the comprehensive log analysis result and the program category analysis result are used to determine the final malicious program detection result, which specifically includes:
[0020] Judge whether the program category analysis result is a malicious program of a certain predefined common category. If so, the detection result is output as the malicious program of this category; otherwise, judge whether the threat level in the corresponding log analysis result is less than the preset threshold. If it is less, the detection result is output as a normal program, and if it is greater, the detection result is output as other malicious programs.
[0021] A second aspect of the present invention proposes a malicious program detection device based on logs and system call sequences, including:
[0022] A Windows log collector, which is used to collect and preprocess log data and perform persistent storage;
[0023] A log analyzer, which formulates a rule set based on a rule template and analyzes log data through the rule set to obtain a log analysis result; the log analysis result includes a preliminary judgment result of a malicious program and the location information of the program;
[0024] A system call sequence collector, which is used to obtain a PE format program initially judged as a malicious program from the terminal according to the log analysis result and obtain system call sequence data through sandbox testing;
[0025] A system call sequence analyzer, which is used to detect system call sequence data by using a trained malicious program detection model based on a bidirectional long short-term memory network to obtain a program category analysis result; the malicious program detection model includes a word embedding network and a system call sequence classification network, and the word embedding network is used to convert the input system call sequence data into a word embedding vector, and the system call sequence classification network is used to judge the corresponding PE format program category according to the word embedding vector;
[0026] A malicious program discriminator, which is used to comprehensively analyze the log analysis result and the program category analysis result to determine the final malicious program detection result.
[0027] As a preferred solution, the rule template includes a regular expression template, a keyword matching template, a conditional rule template, and a threshold rule template; among them, the regular expression template is used to match specific patterns in log data; the keyword matching template is used to identify specific keywords in log data; the conditional rule template is used to filter log data based on certain specified logical conditions; the threshold rule template is used to set a specified threshold.
[0028] As a preferred solution, the specific working process of the system call sequence analyzer includes:
[0029] Preprocess the input paired system call sequence data to obtain the standard input;
[0030] Convert the standard input into word embedding vectors through a word embedding network. The word embedding vectors include multiple feature vectors, and each feature vector includes three-dimensional information: character-level information, word-level information, and function library information;
[0031] Input the word embedding vectors into the system call sequence classification network for classification, and output the results to the fully connected network to obtain the final output label; the system call sequence classification network adopts a bidirectional long short-term memory network with 2 hidden layers;
[0032] The final output label includes a normal program, a malicious program of a predefined common category, or other malicious programs.
[0033] As a preferred solution, the specific working process of the malicious program discriminator includes:
[0034] Judge whether the program category analysis result is a malicious program of a predefined common category. If so, the detection result is output as the malicious program of this category; otherwise, judge whether the threat level in the corresponding log analysis result is less than the preset threshold. If it is less, the detection result is output as a normal program, and if it is greater, the detection result is output as other malicious programs.
[0035] The present invention combines two methods of Windows log analysis and system call sequence analysis to detect malicious programs in the Windows system. It initially detects malicious programs through Windows log analysis and locates potential malicious programs. It also uses a malicious program detection model based on a bidirectional long short-term memory network to analyze its system call sequence to further judge the type of malicious program, greatly improving the detection efficiency of malicious programs in the Windows system. Compared with existing solutions, it mainly has the following beneficial effects and advantages:
[0036] 1. Adopt a log analysis method based on a rule engine to initially detect malicious programs, which takes less time and has higher detection efficiency compared to existing deep learning-based malicious program detection models.
[0037] 2. Adopt a malicious program detection model based on a bidirectional long short-term memory network to further judge the type of potential malicious programs, improving the generalization ability and effectiveness of the malicious program detection method.
[0038] 3. Adopt a malicious program discriminator to jointly judge by combining the log analysis result and the system call sequence analysis result, further improving the accuracy of malicious program detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The drawings herein are incorporated into and form a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application. Obviously, the drawings in the following description are only some embodiments of the present application, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.
[0040] Figure 1 It is a flowchart of a malicious program detection method based on logs and system call sequences in an embodiment of the present invention.
[0041] Figure 2 It is a schematic diagram of log analysis in an embodiment of the present invention.
[0042] Figure 3 It is a schematic diagram of rules in an embodiment of the present invention.
[0043] Figure 4 It is a schematic diagram of obtaining system call sequence data in an embodiment of the present invention.
[0044] Figure 5 It is a schematic diagram of a malicious program detection model in an embodiment of the present invention.
[0045] Figure 6 It is a flowchart of joint judgment in an embodiment of the present invention.
[0046] Figure 7 It is a schematic diagram of a malicious program detection device based on logs and system call sequences in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0047] To make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some, rather than all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts fall within the scope of protection of the present application. Without conflict, the embodiments in the present application and the features in the embodiments can be arbitrarily combined with each other. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0048] In the description and claims of this application and the above-mentioned drawings, the terms "first" and "second" are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any variations thereof are intended to cover non-exclusive protection. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include steps or units not listed, or may optionally further include other steps or units inherent to these processes, methods, products, or devices.
[0049] The present invention mainly proposes a solution to the problem of detecting malicious programs in the Windows operating system, and specifically proposes solutions to the following aspects of problems:
[0050] 1), How to use a rule-based log analysis method to implement malicious program alerts for Windows log data, determine the location of potential malicious programs, and solve the problem of detecting malicious programs in the Windows operating system based on log data;
[0051] 2), How to obtain the system call sequence data generated during the runtime of a potential malicious program based on it, and solve the problem of automated acquisition of system call sequence data;
[0052] 3), Build a fine-grained malicious program data feature based on the system call sequence data and build a classification model, and solve the problems of low information volume of traditional system call sequence data features and low model accuracy.
[0053] In response to the above problems, the embodiments of the present invention propose a malicious program detection method based on logs and system call sequences. The Sysmon application log of the Windows operating system can record information related to program operations such as process creation and termination. Analyzing it can achieve a preliminary identification of malicious programs; the system call sequence can record sensitive operations requested by user programs to the operating system. Analyzing it can improve the accuracy of malicious program detection. Please refer to Figure 1 , and the specific solution is as follows:
[0054] Step 1, collect and store log data.
[0055] In the Windows operating system, the Sysmon application log can record information related to program operations such as process creation and termination. In this embodiment, the collection of logs can be achieved by configuring a log collection service. Specifically, the configuration of the log collection service includes setting the target host IP, target log location, collection frequency, target log time range, target log type, etc.; the collection methods include using the task scheduler of the Windows system to send logs regularly, and using Winlogbeat and logstash for real-time collection, etc.
[0056] After the data collection is completed, in order to improve the detection efficiency, it is also necessary to perform preprocessing operations such as removing redundant information and format conversion, and convert the original log format into an easy-to-process format such as json or txt. For example, information such as the FileVersion and Company fields in Sysmon logs is redundant information for malicious program detection, and it can be removed by means of regular expression matching or the like.
[0057] After the preprocessing operation is completed, a relational database such as MySQL or a non-relational database such as ElasticSearch can be used to achieve persistent storage of log data.
[0058] Step 2: Develop a rule set based on the rule template, and analyze the log data through the rule set to obtain the log analysis result; the log analysis result includes the preliminary judgment result of the malicious program and the location information of the program.
[0059] Please refer to Figure 2 In this embodiment, the Sysmon logs are analyzed in a rule-based manner to preliminarily detect malicious programs. If a malicious program is detected, the analysis result is given, and subsequent analysis operations can be performed. Specifically, the preliminary detection is mainly based on the rule template to develop a rule set, including regular expression templates, keyword matching templates, conditional rule templates, and threshold rule templates. Among them, the regular expression template is used to match specific patterns in the log data, such as IP addresses, status codes, etc.; the keyword matching template is used to identify specific keywords in the log data, such as Computer (hostname), SystemTime (system time), etc.; the conditional rule template is used to filter the log data based on certain specified logical conditions, such as logs within a specified time period, logs of a specified event type; the threshold rule template is used to set a specified threshold, such as triggering an alarm when the occurrence frequency of certain error fields exceeds the specified threshold.
[0060] Based on the provided rule template, the corresponding rule set can be developed. Specifically:
[0061] (1) Develop a regular expression rule S according to the regular expression template R R , such as the regular matching of IP addresses. The specific regular expression is as follows:
[0062] (\d{1,3}\.){3}\d{1,3}
[0063] (2) Develop a keyword matching rule S according to the keyword matching template K K , and the specific keywords include Computer (hostname), SystemTime (system time), etc.;
[0064] (3)Form condition rule S according to condition rule template C C , specifically including time condition, log event type condition, etc.;
[0065] (4)Form threshold rule S according to threshold rule template T T , specifically including the threshold of the occurrence frequency of log event types, etc.;
[0066] (5)Integrate all the above rules to form a rule set {S R ; S K ; S C ; S T}}.
[0067] The specific rule S includes 4 elements: rule type (Type), rule name (Rulename), description (Description), rule (Rule), where the rule (Rule) can be implemented by a programming language, and the format of rule S is as Figure 3 shown.
[0068] By constructing the rule set, the log data can be analyzed to obtain the log analysis result. In this embodiment, the log analysis result is represented by json format data, and each analysis result contains multiple parameters, as shown in Table 1 below.
[0069] Table 1 Log analysis result parameters
[0070]
[0071]
[0072] The "Level" parameter in the log analysis result defines the threat level, which is a positive integer between 1 and 10; the higher the value, the higher the harm degree of the potential malicious program, and the more likely it is to be a certain malicious program.
[0073] Step 3: Obtain the PE format program initially judged as a malicious program from the terminal according to the log analysis result, and obtain the system call sequence data through sandbox testing.
[0074] Please refer to Figure 4 , after obtaining the log analysis result, it can be initially judged whether the program described in the analyzed log data is a malicious program. If it is not a malicious program, continue to analyze the next log analysis result. If it is a malicious program, the location information of the malicious program needs to be obtained, and the PE format program is obtained according to this location information.
[0075] Then, isolate and run the PE format program through sandbox detection to obtain the system call sequence data.
[0076] Step 4: Use the trained malicious program detection model based on bidirectional long short-term memory network to detect the system call sequence data, and obtain the program category analysis result.
[0077] In this embodiment, a malicious program detection model based on system call function features is used to analyze the program through system call sequence data. This model mainly includes two parts: a word embedding network and a system call sequence classification network. The word embedding network is used to understand the semantic information in the system call function name and convert the system call sequence text into a word embedding vector; the system call sequence classification network is used to classify the word embedding vector, determine whether the target PE format program is a malicious program, and output the category of the malicious program for subsequent processing.
[0078] Please refer to Figure 5 , and the specific process of detection using the malicious program detection model is as follows:
[0079] First, perform preprocessing operations such as cleaning, removing redundant items, and unifying formats on the system call sequence data in the input layer to obtain the standard input where \(i,n\in\{1,2,3,...\}\), \(i\) represents the system call sequence position, \(n\) represents the position of the system call function, \(F\) represents the specific system call function, and \(X\) represents the system call sequence.
[0080] Then, the input sequence can obtain the word embedding vector after passing through the word embedding network Among them, the word embedding network is used to construct the input system call sequence into a word embedding vector \(E\). The word embedding vector is composed of multiple feature vectors, and each feature vector contains information in three dimensions: character-level information, word-level information, and library information. The feature vector is defined as \(V = V_{ t}+V_{ s}+V_{ d}\), where \(t\), \(s\), and \(d\) represent character-level information, word-level information, and library information respectively.
[0081] Finally, input the word embedding vector \(E\) into the system call sequence classification network. The output of the system call sequence classification network can obtain the final output label after passing through the fully connected network. The fully connected network uses the Softmax function to convert the original output into a probability distribution, and its formula is as follows:
[0082]
[0083] where \(p_{ j,c}\) represents the probability value of class sample \(j\) in class \(c\), and \(o_{ j,c}\) represents the original output of the model for sample \(j\) in class \(c\). In this embodiment, the system call sequence classification network uses a bidirectional long short-term memory network (LSTM) with 2 hidden layers.
[0084] The categories output by the system call sequence classification network can be expressed as {α, ω1, ω2, …, ω i , γ}. Among them, α represents a normal program; ω i represents the malicious program of the i-th predefined common category (such as Trojan virus, Backdoor, Spyware, Worms, Phishing, Dropper, Downloader, etc.), and there are i kinds in total; γ represents other malicious programs other than the defined i kinds of malicious programs.
[0085] It should be added that in this embodiment, the cross-entropy loss function is used to calculate the loss during the training of the malicious program detection model. Among them, L represents the cross-entropy loss, and y j,m represents the true label of sample j. The formula of the cross-entropy loss function is as follows:
[0086]
[0087] Step 5: Combine the log analysis result and the program category analysis result to determine the final malicious program detection result.
[0088] After obtaining the program category analysis result through the malicious program detection model, the log analysis result can be combined for joint judgment of malicious programs. In this embodiment, the log analysis result is ε n , which takes a positive integer value corresponding to the Level parameter, that is, it represents the threat level obtained by log analysis. The larger the value, the higher the threat level; the program category analysis result is ω, which represents the predefined common malicious program category, α represents the normal program, γ represents other malicious programs, and θ represents the predefined threat level threshold. Please refer to Figure 6 , and the specific process of joint judgment is as follows:
[0089] (1) Receive the log analysis result ε n and the program category analysis result ω respectively;
[0090] (2) If the program category analysis result ω is the normal program α, it means that there is a deviation between the log analysis result and the system call sequence analysis result (the log analysis result is abnormal and the sequence analysis result is normal), and further verification is required. Otherwise, the output result is the malicious program ω;
[0091] (3) If the log analysis result ε n is less than the predefined threshold θ, it means that the threat level of the log analysis result is low, and the output result is the normal program α; otherwise, the output result is other malicious programs γ.
[0092] The present invention combines two methods, namely Windows log analysis and system call sequence analysis, to detect malicious programs in the Windows system. It preliminarily detects malicious programs through Windows log analysis and locates potential malicious programs. Then, it uses a malicious program detection model based on bidirectional long short-term memory network to analyze their system call sequences to further determine the types of malicious programs, greatly improving the detection efficiency of malicious programs in the Windows system.
[0093] An embodiment of the present invention also proposes a malicious program detection device based on logs and system call sequences, which mainly includes components such as a Windows log collector, a log analyzer, a system call sequence collector, a system call sequence analyzer, a malicious program discriminator, and a Windows terminal. These components are connected to the network in a networking manner to form a complete malicious program detection device based on logs and system call sequences. The working principle implemented by this system is independent of the specific deployment method. Therefore, only Figure 7 the description of a malicious program detection method and device based on Windows logs and system call sequences is given for the working principle.
[0094] Specifically, the Windows log collector is mainly used to collect and preprocess log data and perform persistent storage. The Windows log collector mainly includes three parts: log collection service configuration, log data preprocessing, and log data storage. The log collection service configuration includes setting the target host IP, target log location, collection frequency, target log time range, target log type, etc.; specific log collection methods include using the task scheduler of the Windows system to send logs regularly, and using Winlogbeat and logstash for real-time collection, etc. The specific method of log data preprocessing is as follows: perform preprocessing operations such as removing redundant information and format conversion, and convert the original log format into an easy-to-process format such as json or txt. For example, information such as the FileVersion and Company fields in Sysmon logs is redundant information for malicious program detection, and it is removed by using methods such as regular expression matching. The database used for the persistent storage of log data can be a relational database such as MySQL or a non-relational database such as ElasticSearch, etc.
[0095] The log analyzer is the key to realizing the preliminary detection of malicious programs. It preliminarily detects malicious programs by analyzing Sysmon logs in a rule-based manner. If a malicious program is detected, it gives an analysis result and sends the analysis result to the system call sequence collector and the malicious program discriminator. This module contains 4 types of rule templates: regular expression templates, keyword matching templates, conditional rule templates, and threshold rule templates. Among them, regular expression templates are used to match specific patterns in log data, such as IP addresses, status codes, etc.; keyword matching templates are used to identify specific keywords in log data, such as Computer (hostname), SystemTime (system time), etc.; conditional rule templates are used to filter log data based on certain specified logical conditions, such as logs within a specified time period, logs of a specified event type; threshold rule templates are used to set specified thresholds, such as triggering an alarm if the occurrence frequency of certain error fields exceeds the specified threshold.
[0096] Specify the corresponding rule set through the rule template, and log analysis can be realized through the rule set. The Path (executable file path) in the log analysis result records the location of the potential malicious program and will be passed to the system call sequence collector for collecting system call sequence data; the log analysis result will also be passed to the malicious program discriminator for joint judgment of malicious programs.
[0097] The system call sequence collector is mainly used to collect system call sequence data. It can obtain the PE-format program from the terminal according to the log analysis result, and then obtain the system call sequence generated during the operation of the potential malicious program through sandbox testing; the system call sequence data will be passed to the system call sequence analyzer for analysis to further determine the type of malicious program.
[0098] The system call sequence analyzer is mainly used to detect the system call sequence data by using a trained malicious program detection model based on bidirectional long short-term memory network to obtain the program category analysis result. Among them, the malicious program detection model mainly includes two parts: the word embedding network and the system call sequence classification network. The word embedding network is used to understand the semantic information in the system call function name and convert the system call sequence text into a word embedding vector; the system call sequence classification network is used to classify the word embedding vector to determine whether the target PE-format program is a malicious program and output the category of the malicious program to the next malicious program discriminator.
[0099] A malicious program discriminator is used to determine the final malicious program detection result by integrating the log analysis result and the program category analysis result. Specifically, the malicious program discriminator determines whether the program category analysis result is a certain predefined common type of malicious program. If so, the detection result is output as the malicious program of this type; if not, it then determines whether the threat level in the corresponding log analysis result is less than a preset threshold. If it is less, the detection result is output as a normal program, and if it is greater, the detection result is output as other malicious programs.
[0100] In particular, according to the embodiments of the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments of the present application include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts.
[0101] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. And in the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0102] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Among them, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above-mentioned module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, as well as the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0103] The units involved in the embodiments described in the present application can be implemented in software or in hardware, and the described units can also be provided in a processor. Among them, the names of these units do not constitute a limitation to the unit itself in some cases.
[0104] As another aspect, the present application also provides a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the malicious program detection method based on logs and system call sequences described in the above embodiments.
[0105] As another aspect, the present application also provides a computer-readable medium. The computer-readable medium may be included in the electronic device described in the above embodiments; or it may exist alone without being assembled into the electronic device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by an electronic device, the electronic device implements the malicious program detection method based on logs and system call sequences described in the above embodiments.
[0106] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0107] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a touch terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.
[0108] For those of ordinary skill in the art, the specific meanings of the above terms can be understood according to specific situations; the accompanying drawings in the embodiments are used to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. Usually, the components of the embodiments of the present invention described and shown in the accompanying drawings herein can be arranged and designed in various different configurations.
[0109] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.
Claims
1. A malicious program detection method based on logs and system call sequences, characterized in that, Including: Collect and store log data; Formulate a rule set based on a rule template, and analyze the log data through the rule set to obtain a log analysis result; The log analysis result includes a preliminary judgment result of a malicious program and the location information of the program; According to the log analysis result, obtain the PE format program initially judged as a malicious program from the terminal, and obtain system call sequence data through sandbox testing; Use the trained malicious program detection model based on the bidirectional long short-term memory network to detect the system call sequence data to obtain a program category analysis result; the malicious program detection model includes a word embedding network and a system call sequence classification network, and the word embedding network is used to convert the input system call sequence data into a word embedding vector, and the system call sequence classification network is used to judge the corresponding PE format program category according to the word embedding vector; Integrate the log analysis result and the program category analysis result to determine the final malicious program detection result.
2. The malicious program detection method based on logs and system call sequences according to claim 1, characterized in that Before storing the log data, it also includes preprocessing the collected log data, and the preprocessing includes: removing redundant information irrelevant to malicious program detection in the log data, and converting the format to an easy-to-process json or txt format.
3. The malicious program detection method based on logs and system call sequences according to claim 1 or 2, characterized in that, The rule template includes a regular expression template, a keyword matching template, a conditional rule template, and a threshold rule template; among them, the regular expression template is used to match specific patterns in the log data; the keyword matching template is used to identify specific keywords in the log data; the conditional rule template is used to filter the log data based on certain specified logical conditions; the threshold rule template is used to set a specified threshold.
4. The malicious program detection method based on logs and system call sequences according to claim 1, characterized in that, The log analysis result is represented in json format data, and each analysis result includes at least the path of the executable file and the threat level.
5. The malicious program detection method based on logs and system call sequences according to claim 1, characterized in that The step of using the trained malicious program detection model based on the bidirectional long short-term memory network to detect the system call sequence data to obtain a program category analysis result specifically includes: Preprocess the input paired system call sequence data to obtain a standard input; Convert the standard input into a word embedding vector through the word embedding network, and the word embedding vector includes multiple feature vectors, and each feature vector includes three-dimensional information of character-level information, word-level information, and function library information; Input the word embedding vector into the system call sequence classification network for classification, and output the result to the fully connected network to obtain the final output label; the system call sequence classification network uses a bidirectional long short-term memory network including 2 hidden layers; The final output label includes a normal program, a malicious program of a certain predefined common category, or other malicious programs.
6. The malicious program detection method based on logs and system call sequences according to claim 1, characterized in that, The step of integrating the log analysis result and the program category analysis result to determine the final malicious program detection result specifically includes: Judge whether the program category analysis result is a malicious program of a certain predefined common category. If so, the detection result is output as the malicious program of this category; otherwise, judge whether the threat level in the corresponding log analysis result is less than the preset threshold. If it is less, the detection result is output as a normal program. If it is greater, the detection result is output as other malicious programs.
7. A malicious program detection device based on logs and system call sequences, characterized in that Including: A Windows log collector for collecting and preprocessing log data and performing persistent storage; A log analyzer for formulating a rule set based on a rule template and analyzing log data through the rule set to obtain a log analysis result; The log analysis result includes a preliminary judgment result of a malicious program and the location information of the program; A system call sequence collector for obtaining a PE format program initially judged as a malicious program from a terminal according to the log analysis result and obtaining system call sequence data through sandbox testing; A system call sequence analyzer for detecting the system call sequence data by using a trained malicious program detection model based on a bidirectional long short-term memory network to obtain a program category analysis result; the malicious program detection model includes a word embedding network and a system call sequence classification network, and the word embedding network is used to convert the input system call sequence data into a word embedding vector, and the system call sequence classification network is used to judge the corresponding PE format program category according to the word embedding vector; A malicious program discriminator for comprehensively determining the final malicious program detection result based on the log analysis result and the program category analysis result.
8. The malicious program detection device based on logs and system call sequences according to claim 7, characterized in that, The rule template includes a regular expression template, a keyword matching template, a conditional rule template, and a threshold rule template; among them, the regular expression template is used to match a specific pattern in the log data; the keyword matching template is used to identify specific keywords in the log data; the conditional rule template is used to filter the log data based on certain specified logical conditions; the threshold rule template is used to set a specified threshold.
9. The malicious program detection device based on logs and system call sequences according to claim 7, characterized in that, The specific working process of the system call sequence analyzer includes: Preprocessing the input paired system call sequence data to obtain a standard input; Converting the standard input into a word embedding vector through the word embedding network, and the word embedding vector includes multiple feature vectors, and each feature vector includes three-dimensional information of character-level information, word-level information, and function library information; Inputting the word embedding vector into the system call sequence classification network for classification, and outputting the result to the fully connected network to obtain the final output label; the system call sequence classification network adopts a bidirectional long short-term memory network including 2 hidden layers; The final output label includes a normal program, a malicious program of a certain predefined common category, or other malicious programs.
10. The malicious program detection device based on logs and system call sequences according to claim 9, wherein, The specific working process of the malicious program discriminator includes: Judging whether the program category analysis result is a malicious program of a certain predefined common category. If so, the detection result is output as the malicious program of this category; otherwise, judging whether the threat level in the corresponding log analysis result is less than a preset threshold. If it is less, the detection result is output as a normal program, and if it is greater, the detection result is output as other malicious programs.