Terminal security protection method, device and equipment and computer readable storage medium
By switching to key information at the previous moment when the terminal request is detected, the persistent backdoor file is cleared, and the problem of difficulty in completely clearing the persistent backdoor file in the terminal is solved, achieving low-cost and efficient security protection.
Patent Information
- Application Number
- CN202410129169.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-29
- Publication Date
- 2025-07-29
AI Technical Summary
The prior art is difficult to completely clear the persistent backdoor files in the terminal, resulting in the possibility of re-infection of the virus after the operating system is restarted.
When detecting that there is a security risk in the terminal request, switch to the key information at the previous moment to work, clear the persistent backdoor file, and avoid in-depth analysis of malicious files.
Thoroughly clearing the persistent backdoor file reduces the risk of terminals being reinfected with viruses, is low in cost and does not require in-depth analysis of malicious files.
Smart Images

Figure CN120387162A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of security protection, and particularly to a terminal security protection method, device, equipment, and computer-readable storage medium. Background Art
[0002] After an attacker or malicious file obtains the control right of the terminal's operating system, in order to maximize benefits, a persistent backdoor file will be implanted in the operating system to achieve persistent control over the operating system. Among them, the persistent backdoor file is used to assist the control end of the malicious file in launching a persistent attack on the terminal. To cope with the persistent attacks of attackers and malicious files on the terminal, in the related art, the terminal security protection method usually performs detection and protection through endpoint detection and response (EDR). EDR is a computer security technology that can detect potential threats in a timely manner by continuously detecting and responding to the terminal.
[0003] The principle of EDR detection and protection is: statically or dynamically scan the files on the terminal through a malicious file feature library, and monitor the execution behavior of malicious files in the operating system. Although EDR detection can detect malicious files and delete them, it fails to detect the persistent backdoor files of malicious files, and there is still a possibility of being reinfected with the virus after the operating system restarts. Summary of the Invention
[0004] This application provides a terminal security protection method, device, equipment, and computer-readable storage medium to solve the problems existing in the related art. The technical solutions are as follows:
[0005] In a first aspect, a terminal security protection method is provided. The method includes: obtaining a detection result of a first request sent by a terminal; when the detection result indicates that the first request has a security risk, controlling the terminal to work with key information at a first moment; the first moment is a moment before the sending moment of the first request, and the key information refers to information that supports the work of the terminal and supports the persistent backdoor file of the malicious file to be written to disk. This means that when the first request sent by the terminal has a security risk, the information for the terminal to work is switched from the key information at the sending moment of the first request to the key information at the first moment. Or rather, when the first request sent by the terminal has a security risk, it means that the persistent backdoor file of the malicious file is implanted in the key information at the sending moment of the first request. The terminal discards the key information at the sending moment of the first request and uses the key information at the first moment before the sending moment to work, thereby clearing the persistent backdoor file of the malicious file, eliminating the persistent backdoor file of the malicious file from the root, and achieving the purpose of completely clearing the persistent backdoor file. In addition, during the process of clearing the persistent backdoor file of the malicious file, there is no need to deeply analyze the malicious file, and the cost is relatively low.
[0006] In a possible implementation manner, the obtaining a detection result of a first request sent by a terminal includes: detecting the first request sent by the terminal to obtain a detection result of the first request. The detection result of the first request can indicate two results: the first is that the first request has a security risk; the second is that the first request does not have a security risk. Among them, the execution entity for detecting the first request sent by the terminal can be the terminal or other devices.
[0007] In a possible implementation manner, the detecting the first request sent by the terminal to obtain a detection result of the first request includes: comparing the first information carried in the first request with pre-stored risk information, where the risk information includes information sent by the malicious file to the control end of the malicious file through the terminal; when the first information matches the risk information, obtaining a detection result indicating that the first request has a security risk.
[0008] In a possible implementation manner, the obtaining a detection result of the first request sent by the terminal includes: receiving a notification pushed by other devices, where the notification includes a detection result of the first request; the other devices are used to detect the first request to obtain a detection result of the first request and send a notification including the detection result of the first request.
[0009] In a possible implementation, obtaining the detection result of the first request sent by the terminal includes: sending a second request to other devices, where the second request is used to request the detection result of the first request, the other devices are used to detect the first request to obtain the detection result of the first request, and feedback the detection result of the first request according to the second request; receiving the detection result of the first request fed back by the other devices according to the second request.
[0010] In a possible implementation, obtaining the detection result of the first request sent by the terminal includes: sending a second request to other devices, where the second request is used to request the detection result of the first request, the other devices are used to detect the first request to obtain the detection result of the first request, and feedback information indicating the detection result of the first request according to the second request; receiving a terminal list fed back by the other devices according to the second request, where the terminal list includes information indicating the detection result of the first request. Exemplarily, the terminal list may include the identification information of the terminal whose sent request has a security risk. Or, the terminal list may include the identification information of the terminal whose sent request has no security risk. Or, the terminal list may include the identification information of the terminal and the detection result of the request sent by this terminal.
[0011] In a possible implementation, after controlling the terminal to work with the key information at the first moment, the method further includes: obtaining the detection result of the third request sent by the terminal; when the detection result indicates that the third request has a security risk, controlling the terminal to work with the key information at the second moment, where the second moment is the previous moment of the first moment. In this application, when the terminal still sends a third request with a security risk, the terminal discards the key information at the first moment and works with the key information at the second moment. And so on, the terminal recursively rolls back the key information until the terminal no longer sends requests with risks, so as to achieve the purpose of completely clearing the persistent backdoor file and further improving the security of the terminal.
[0012] In a possible implementation, before controlling the terminal to work with the key information at the first moment, the method further includes: obtaining the key information of the terminal working at the first moment at a specified time interval. In this application, by obtaining the key information regularly, the changes of each key information of the terminal and their corresponding time points can be clearly recorded, which is convenient for the traceability record of attack prevention and protection, so as to facilitate the terminal to trace information and provide convenience for subsequent operations.
[0013] In a possible implementation, before controlling the terminal to work with the key information at the first moment, the method further includes: when the key information at the second moment changes, obtaining the key information of the terminal working at the first moment, where the second moment is the moment before the first moment. In this application, by obtaining the key information at the next moment of the current moment when the key information at the current moment changes, the changes of each key information of the terminal and their corresponding time points can be clearly recorded, which is convenient for attack prevention and tracing records, so as to facilitate the terminal to trace information and provide convenience for subsequent operations.
[0014] In addition, in this application, when the key information changes, the terminal generates corresponding configuration item files for each key information, without generating configuration item files all the time, nor generating configuration item files with the same content repeatedly, effectively saving the power consumption of the terminal.
[0015] In a possible implementation, after obtaining the key information of the terminal working at the first moment, the method further includes: generating a corresponding configuration item file for the key information at the first moment, where the configuration item file is used to record the key information of the terminal at the first moment; and controlling the terminal to work with the key information at the first moment when the detection result indicates that the first request has a security risk includes: controlling the terminal to work with the configuration item file when the detection result indicates that the first request has a security risk. In this application, by generating configuration item files for key information, while reducing the memory occupancy of key information, the changes of each key information of the terminal and their corresponding time points can be clearly recorded, which is convenient for attack prevention and tracing records, so as to facilitate the terminal to trace information and provide convenience for subsequent operations.
[0016] In a possible implementation, the key information includes at least one of the following: registry autostart item, autostart service item, scheduled task item of the operating system, and management specification task item.
[0017] In a possible implementation, the first request is used to request to connect to the control end of a malicious file.
[0018] In a second aspect, a terminal security protection device is provided, and the device includes: an acquisition module and a processing module, where the acquisition module is used to acquire the detection result of the first request sent by the terminal; the processing module is used to control the terminal to work with the key information at the first moment when the detection result indicates that the first request has a security risk; the first moment is the moment before the sending moment of the first request, and the key information refers to the information that supports the terminal to work and supports the persistent backdoor file of the malicious file to be stored on disk.
[0019] In a possible implementation, the obtaining module is further configured to: detect the first request sent by the terminal to obtain a detection result of the first request.
[0020] In a possible implementation, the obtaining module is further configured to: compare the first information carried in the first request with pre-stored risk information, where the risk information includes information sent by a malicious file to a control end of the malicious file through the terminal; in a case where the first information matches the risk information, obtain a detection result indicating that the first request has a security risk.
[0021] In a possible implementation, the obtaining module is further configured to: receive a notification pushed by another device, where the notification includes a detection result of the first request; the other device is configured to detect the first request to obtain a detection result of the first request, and send a notification including the detection result of the first request.
[0022] In a possible implementation, the obtaining module is further configured to: send a second request to another device, where the second request is used to request to obtain a detection result of the first request, the other device is configured to detect the first request to obtain a detection result of the first request, and feedback the detection result of the first request according to the second request; receive the detection result of the first request fed back by the other device according to the second request.
[0023] In a possible implementation, the obtaining module is further configured to: send a second request to another device, where the second request is used to request to obtain a detection result of the first request, the other device is configured to detect the first request to obtain a detection result of the first request, and feedback information indicating the detection result of the first request according to the second request; receive a terminal list fed back by the other device according to the second request, where the terminal list includes information indicating the detection result of the first request.
[0024] In a possible implementation, the obtaining module is further configured to obtain a detection result of a third request sent by the terminal. The processing module is further configured to, in a case where the detection result indicates that the third request has a security risk, control the terminal to work with key information at a second moment, where the second moment is a previous moment of the first moment.
[0025] In a possible implementation, the obtaining module is further configured to obtain key information of the terminal working at the first moment at a specified time interval.
[0026] In a possible implementation, the obtaining module is further configured to obtain the key information of the terminal at the first moment when the key information at the second moment changes, where the second moment is the previous moment of the first moment.
[0027] In a possible implementation, the obtaining module is further configured to generate a corresponding configuration item file for the key information at the first moment, where the configuration item file is used to record the key information of the terminal at the first moment; the processing module is further configured to: when the detection result indicates that the first request has a security risk, control the terminal to work using the configuration item file.
[0028] In a possible implementation, the key information includes at least one of the following: registry auto-start item, auto-start service item, scheduled task item of the operating system, and management specification task item.
[0029] In a possible implementation, the first request is used to request to connect to the control end of a malicious file.
[0030] In a third aspect, an electronic device is provided, where the electronic device includes a memory and a processor; at least one instruction is stored in the memory, and the at least one instruction is loaded and executed by the processor to enable the electronic device to implement the methods in the above aspects.
[0031] In a fourth aspect, a computer program (product) is provided, where the computer program (product) includes: computer program code, and when the computer program code is run on a computer, the computer is enabled to execute the methods in the above aspects.
[0032] In a fifth aspect, a computer-readable storage medium is provided, where the computer-readable storage medium stores a program or an instruction, and when the program or the instruction is run on a computer, the methods in the above aspects are executed.
[0033] In a sixth aspect, a chip is provided, including a processor, configured to call and run an instruction stored in a memory, so that a communication device installed with the chip executes the methods in the above aspects.
[0034] In a seventh aspect, another chip is provided, including: an input interface, an output interface, a processor, and a memory, where the input interface, the output interface, the processor, and the memory are connected through an internal connection path, and the processor is configured to execute the code in the memory, and when the code is executed, the processor is configured to execute the methods in the above aspects.
[0035] It should be understood that for the beneficial effects obtained by the technical solutions of the second to seventh aspects of this application and the corresponding possible implementation manners, reference may be made to the technical effects of the first aspect and its corresponding possible implementation manners described above, and details are not described herein again. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 FIG. is a schematic structural diagram of a terminal provided by an embodiment of this application;
[0037] Figure 2 FIG. is a schematic structural diagram of the software of a terminal in a terminal security protection solution provided by an embodiment of this application;
[0038] Figure 3 FIG. is a schematic flowchart of a terminal security protection method provided by an embodiment of this application;
[0039] Figure 4 FIG. is a schematic structural diagram of a system composed of a terminal and a network device provided by an embodiment of this application;
[0040] Figure 5 FIG. is a schematic flowchart of a terminal security protection method provided by an embodiment of this application;
[0041] Figure 6 FIG. is a structural block diagram of a terminal security protection device provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] The terms used in the embodiments of this application are only for explaining the specific embodiments of this application, and are not intended to limit this application.
[0043] With the continuous enhancement of the attack capabilities of attackers or malicious files, and the continuous emergence of new fileless attacks and backdoor persistence technologies. After an attacker or malicious file obtains the control authority of the terminal's operating system, in order to maximize benefits, a persistent backdoor file will be implanted in the operating system to achieve continuous control of the operating system. If the attacker or the backdoor persistence file does not perform a persistent attack and only runs simply. Then, the terminal's operating system only needs to perform a restart operation to close the process of the malicious file. Therefore, how to solve the problem of persistent attacks on the terminal by attackers or malicious files has become a technical problem to be solved by those skilled in the art.
[0044] To solve the problem of persistent attacks on terminals by attackers and malicious files, in related technologies, terminal security protection methods usually detect and protect through EDR. Specifically, static or dynamic file scanning of files on the terminal is performed through a malicious file feature library, and the execution behavior of malicious files is monitored in the operating system. Although EDR detection can detect malicious files and delete them, the persistent backdoor files of malicious files cannot be detected, and there is still a possibility of being reinfected with the virus after the operating system restarts.
[0045] To solve the above technical problems, an embodiment of the present application provides a terminal security protection method, and the execution subject of this method can be a terminal. The method includes: the terminal obtains the detection result of the first request sent by the terminal. When the detection result indicates that the first request has a security risk, the terminal controls the terminal to work with the key information at the first moment. The first moment is the moment before the sending moment of the first request, and the key information refers to the information that supports the terminal to work and supports the persistent backdoor file of the malicious file to be written to disk. The persistent backdoor file is used to assist the control end of the malicious file to perform a persistent attack on the terminal. That is, when the first request sent by the terminal has a security risk, the information for the terminal to work is switched from the key information at the sending moment of the first request to the key information at the first moment. Or, when the first request sent by the terminal has a security risk, it means that the persistent backdoor file of the malicious file is implanted in the key information at the sending moment of the first request. The terminal discards the key information at the sending moment of the first request and works with the key information at the first moment before the sending moment, thereby clearing the persistent backdoor file of the malicious file, eliminating the persistent backdoor file of the malicious file from the root cause, and achieving the purpose of completely clearing the persistent backdoor file. In addition, in the process of clearing the persistent backdoor file of the malicious file, there is no need to deeply analyze the malicious file, and the cost is relatively low.
[0046] In some embodiments, the terminal obtains the detection result of the first request sent by the terminal, which can be implemented as: the terminal detects the first request to obtain the detection result of the first request. Or, other devices detect the first request to obtain the detection result of the first request. The implementation solution can refer to the relevant descriptions in the following text and will not be elaborated here.
[0047] The above key information may include at least one of a registry self-start item, a self-start service item, a scheduled task item of the operating system, and a management specification task item. It should be understood that these information can be combined arbitrarily. Exemplarily, the key information may include a registry self-start item and a self-start service item. Or, the key information may include a scheduled task item of the operating system and a management specification task item. Or, the key information may include a registry self-start item, a self-start service item, a scheduled task item of the operating system, and a management specification task item. It is not specifically limited in the embodiments of the present application.
[0048] Among them, malicious files can be understood as virus files. For example, in the relevant technology, it is said that the total number of virus samples can reach 1.234 billion, involving hundreds of thousands of families. Different virus families have different ways of persisting backdoors. At the same time, as the attack and defense confrontation continues to improve, it is difficult to achieve 100% resolution of all virus files with persistent backdoors through positive methods (such as deleting the registry, deleting the process, deleting the file, etc.). Based on the analysis of typical virus events, it was found that more than 60% of malicious files have persistence functions. The detailed statistical results are shown in Table 1:
[0049] Table 1
[0050]
[0051] It can be seen that the persistent backdoor files of the above-mentioned virus files are embedded in key information such as the registry auto-start items, auto-start service items, scheduled task items of the operating system, and management specification task items. In the embodiment of the present application, once it is discovered that the information sent by the terminal has a security risk, it means that the persistent backdoor files have been embedded in the key information. It is only necessary to overwrite the key information at the time of the security risk discovery. In this way, the persistent backdoor files of the malicious files are eliminated at the root, without the need for in-depth analysis of the malicious files, and at a low cost.
[0052] The terminal security protection method provided in the embodiments of the present application can be applied to malicious file protection scenarios in Windows (Windows operating system) and Linux operating systems, or to deployment scenarios such as firewalls and network intrusion prevention systems (IPS). This is not specifically limited in the embodiments of the present application.
[0053] In some embodiments, Figure 1 A schematic diagram of the structure of a terminal provided in an embodiment of the present application. Figure 1 As shown, the terminal 100 may include a processor 110 , a memory 120 , a universal serial bus (USB) interface 130 , a charging management module 140 , a power management module 141 , a battery 142 , an antenna 1 , a wireless communication module 150 , and a display screen 160 .
[0054] It is understood that the structures illustrated in the embodiments of the present application do not constitute specific limitations on the terminal. In other embodiments of the present application, the terminal may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0055] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors.
[0056] The controller can generate operation control signals according to the instruction operation code and timing signals to complete the control of fetching and executing instructions.
[0057] A memory may also be provided in the processor 110 for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can save the instructions or data that the processor 110 has just used or recycled. If the processor 110 needs to use the instruction or data again, it can directly call it from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0058] The memory 120 can be used to store computer-executable program code, and the executable program code includes instructions. The memory 120 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.). The data storage area can store data created during the use of the terminal (such as audio data, a phone book, etc.). In addition, the memory 120 may include a high-speed random access memory and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc. The processor 110 executes various functional applications and data processing of the terminal by running the instructions stored in the memory 120 and / or the instructions stored in the memory provided in the processor.
[0059] The charging management module 140 is used to receive charging input from a charger. Herein, the charger can be a wireless charger or a wired charger. In some embodiments of wired charging, the charging management module 140 can receive the charging input from the wired charger through the USB interface 130. In some embodiments of wireless charging, the charging management module 140 can receive the wireless charging input through the wireless charging coil of the terminal. While charging the battery 142, the charging management module 140 can also supply power to the terminal through the power management module 141.
[0060] The power management module 141 is used to connect the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives the input from the battery 142 and / or the charging management module 140 and supplies power to the processor 110, the display screen 160, the wireless communication module 150, etc. The power management module 141 can also be used to monitor parameters such as the battery capacity, the number of battery cycles, and the battery health status (leakage, impedance). In some other embodiments, the power management module 141 can also be disposed in the processor 110. In some other embodiments, the power management module 141 and the charging management module 140 can also be disposed in the same device.
[0061] The wireless communication function of the terminal can be implemented through the antenna 1, the wireless communication module 150, the modulation and demodulation processor, and the baseband processor, etc.
[0062] The antenna 1 is used to transmit and receive electromagnetic wave signals. Each antenna in the terminal can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example: The antenna 1 can be multiplexed as the diversity antenna of the wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.
[0063] The wireless communication module 150 can provide solutions for wireless communications applied to the terminal, including wireless local area networks (WLANs) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc. The wireless communication module 150 can be one or more devices integrating at least one communication processing module. The wireless communication module 150 receives electromagnetic waves via the antenna 1, performs frequency modulation and filtering processing on the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 150 can also receive the signals to be sent from the processor 110, perform frequency modulation and amplification on them, and convert them into electromagnetic waves through the antenna 1 for radiation. In some embodiments, the wireless communication module 150 receives application information sent by the server.
[0064] The terminal realizes the display function through the GPU, the display screen 160, and the application processor, etc. The GPU is a microprocessor for image processing, connected to the display screen 160 and the application processor. The GPU is used to execute mathematical and geometric calculations for graphics rendering. The processor 110 may include one or more GPUs, which execute program instructions to generate or change the display information.
[0065] The display screen 160 is used to display images, videos, etc. The display screen 160 includes a display panel. The display panel can adopt a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the terminal may include 1 or N display screens 160, where N is a positive integer greater than 1.
[0066] Of course, the terminal may also include other functional units, which are not limited in the embodiments of the present application.
[0067] In addition, actions, terms, etc. involved between the embodiments of this application can be referred to each other without limitation. The names of each message or the parameter names in the message in the embodiments of this application are only examples, and other names can also be used in specific implementations without limitation.
[0068] Among them, the above terminal can be a computer, desktop computer, mobile phone, tablet computer, laptop, notebook computer, ultra-mobile personal computer (UMPC), handheld computer, netbook, personal digital assistant (PDA), wearable terminal and other devices. The specific form of the terminal is not specially limited in the embodiments of this application.
[0069] Figure 2 It is a schematic structural diagram of the software of the terminal 100 in a terminal security protection solution provided by the embodiments of this application. As Figure 2 shown, in some embodiments, the operating system of the terminal 100 may include a configuration generation module, an alarm linkage module, and a configuration rollback module. Among them, the alarm linkage module is electrically connected to the configuration generation module and the configuration rollback module respectively. The configuration generation module is used to obtain the key information of the terminal at each moment. The alarm linkage module may include an IPS. Of course, the IPS may also be located on other devices (such as network devices), as described in the relevant description below, and is not specifically limited in the embodiments of this application. The alarm linkage module is used to detect the information sent by the terminal, and inform the configuration rollback module to perform the key information rollback operation when the information sent by the terminal has a security risk. The configuration rollback module is used to control the terminal to work with the key information at the first moment when the first request sent by the terminal has a security risk, and the first moment is the previous moment of the sending moment of the first request. Further, the operating system of the terminal 100 may also include a monitoring module. The monitoring module is electrically connected to the configuration generation module and the alarm linkage module respectively. The monitoring module is used to generate corresponding configuration item files for the key information at each moment. The configuration item file is used to record the key information of the terminal at a certain moment.
[0070] The following combines Figure 1 and Figure 2 the shown terminal to introduce in detail a terminal security protection method provided by the embodiments of this application.
[0071] Figure 3 It is a schematic flowchart of a terminal security protection method provided by the embodiments of this application. As Figure 3 shown, the method may include: S301 - S305 (some steps are optional).
[0072] S301. The terminal obtains the key information of the terminal at each moment.
[0073] Exemplarily, S301 can be implemented as: the terminal obtains the key information of the terminal at the first moment.
[0074] The key information can be information that can support the persistent backdoor file of the malicious file to be written to disk. The key information can include at least one of the following: registry autostart items, autostart service items, scheduled task items of the operating system, and management specification task items. Of course, the key information is not limited to the above-listed items, and no specific limitation is made in the embodiments of the present application.
[0075] Exemplarily, the terminal can obtain the above registry autostart items. For example, the terminal can obtain the registry autostart item "attack" according to the path "Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run". Exemplarily, the terminal can obtain the above autostart service items. For example, the terminal can obtain the autostart service item according to the path "Services (Local)\FRServer". Exemplarily, the terminal can obtain the above scheduled task items of the operating system. For example, the terminal can add "Service Autostart Test" to the path "Computer Management (Local)\System Tools\Task Scheduler\Task Scheduler Summary\Active Tasks\", and then obtain the scheduled task items of the operating system. Exemplarily, the terminal can obtain the above management specification task items. For example, the terminal can receive a command input by the user to obtain the Windows Management Instrumentation (WMI) task items. The terminal can display the WMI task items according to this command.
[0076] After the terminal executes S301, in order to prevent the key information at each moment from occupying too much memory on the terminal, and in order to trace the changes of the key information, a terminal security protection method provided by an embodiment of the present application may further include: S302. The terminal generates corresponding configuration item files for the key information at each moment. It should be understood that the terminal generates a configuration item file for the key information at the first moment, the terminal generates a configuration item file for the key information at the second moment,... the terminal generates a configuration item file for the key information at the i-th moment, where i is a positive integer greater than 2.
[0077] Continuing with the above example, the key information may include registry autostart items, autostart service items, scheduled task items of the operating system, and management specification task items. Since the storage paths of these information are different, in order to ensure the accuracy of information collection and classification, the terminal may store this information in a json structure to facilitate data classification, parsing, and storage. Exemplarily, the code representation of the configuration item file in json structure may be:
[0078]
[0079] In one possible implementation, as Figure 2 shown, S301 may be implemented as: Step ① The configuration generation module of terminal 100 may obtain the key information of the terminal at each moment.
[0080] In some embodiments, the generation of the configuration item file and the collection of key information may be synchronous. In other words, while the terminal collects key information, it generates its corresponding configuration item file. Exemplarily, the terminal collects key information at a preset time interval and generates its corresponding configuration item file. Exemplarily, when the key information of the terminal changes, the terminal collects the key information and generates its corresponding configuration item file.
[0081] In some other embodiments, the generation of the configuration item file and the collection of key information may be asynchronous, that is, after the terminal collects key information, the terminal generates a configuration item file according to a trigger condition. Exemplarily, the configuration item file may be automatically generated regularly or generated when the key information changes. The following details the generation method of the configuration item file.
[0082] In one possible implementation, S302 may be implemented as: The terminal generates corresponding configuration item files for each key information at a specified time interval. Exemplarily, assume that the key information at each moment may include: key information at moment 1, key information at moment 2, key information at moment 3,..., key information at moment 10. Among them, moment 1 may be 2023-11-28-20:41, moment 2 may be 2023-11-28-20:42,..., moment 5 is 2023-11-28-20:45,..., moment 10 is 2023-11-28-20:50. The specified time interval is 5 minutes. Then, the terminal generates a configuration item file every five minutes, and the naming format of this configuration item file may be: configuration item file + timestamp. For example, the terminal generates the key information at moment 5 into configuration item file 1, that is, configuration item file-2023-11-28-20:45.txt. Similarly, the terminal generates the key information at moment 10 into configuration item file 2, that is, configuration item file-2023-11-28-20:50.txt.
[0083] In an embodiment of the present application, by periodically generating a configuration item file, the changes of each key information of the terminal and the corresponding time points can be clearly recorded, which is convenient for attack prevention traceability recording, so as to facilitate the terminal to trace information and provide convenience for subsequent operations.
[0084] In another possible implementation, S302 can be implemented as follows: when the key information changes, the terminal generates a corresponding configuration item file for each key information. Exemplarily, taking the terminal's operating system as Microsoft Windows operating system as an example, the terminal monitors the usage changes of the application programming interface (API) (which can be abbreviated as Win32 API) in the 32-bit environment of the Windows operating system through the Detours tool. When the value of the Win32 API changes, the terminal can generate a corresponding configuration item file for each key information. Exemplarily, taking the Linux operating system as an example, the terminal monitors the running threads. When the running threads change, the terminal can generate a corresponding configuration item file for each key information.
[0085] In an embodiment of the present application, when the key information changes, the terminal generates a corresponding configuration item file for each key information, without generating the configuration item file all the time and without repeatedly generating configuration item files with the same content, effectively saving the power consumption of the terminal.
[0086] In a possible implementation, as Figure 2 shown, S302 can be implemented as follows: Step ① The configuration generation module of the terminal 100 sends the collected key information to the monitoring module of the terminal 100. The monitoring module generates a corresponding configuration item file for the key information at each moment.
[0087] After the malicious file implants the persistent backdoor file into the terminal's operating system, the malicious file will try to initiate a control request to the control end of the malicious file to connect to the remote control end of the malicious file. At this time, the malicious file will send a request through the terminal. Thus, in order to prevent the malicious file from connecting to the remote control end to control the terminal, it is necessary to perform a security check on the request sent by the terminal.
[0088] Among them, the execution subject for detecting the request sent by the terminal can be the terminal or other devices, such as network devices. There is no specific limitation in the embodiment of the present application. Exemplarily, in the embodiment of the present application, it is described by taking the terminal can detect the request sent by the terminal as an example. Therefore, before the terminal executes S304, a terminal security protection method provided by the embodiment of the present application may include:
[0089] S303. The terminal detects the first request sent by the terminal and obtains the detection result of the first request.
[0090] The detection result of the first request can indicate the following two results: First, there is a security risk in the first request sent by the terminal; Second, there is no security risk in the first request sent by the terminal.
[0091] In an example, risk information is pre-stored in the terminal, and the risk information may include information sent by a malicious file to the control end of the malicious file through the terminal. Exemplarily, the risk information may include the IP address (Internet Protocol Address), port, identifier of the malicious file, etc. of the control end of the malicious file. If the terminal analyzes that the information carried in the first request sent by the terminal matches the risk information, the detection result obtained by the terminal is that the information carried in the first request has a security risk. In this case, the terminal does not allow the terminal to send the first request; if the terminal analyzes that the first request sent by the terminal does not carry the information of the malicious file, the detection result obtained by the terminal is that the information carried in the first request has no security risk. In this case, the terminal allows the terminal to send the first request.
[0092] Exemplarily, for the first request sent by the terminal, the first request carries information such as the source IP address, destination IP address, source port, and destination port. Among them, if the domain name, source IP address, or source port matches the risk information pre-stored in the terminal, the terminal determines that the first request has a security risk. At this time, the terminal returns the first request and does not allow the terminal to send the first request. For example, if the terminal detects that the domain name carried in the first request is H-WORM|xxxxxxxx, which matches the risk information pre-stored in the terminal, the terminal determines that the first request has a security risk and does not allow the first request to be sent.
[0093] In a possible implementation manner, as Figure 2 shown, S303 can be implemented as follows: The alarm linkage module of the terminal 100 includes an IPS. In this way, the alarm linkage module can detect the first request sent by the terminal. In step ③, when the alarm linkage module determines that there is a security risk in the first request sent by the terminal 100, at this time, the alarm linkage module sends the detection result of the first request to the configuration return module.
[0094] In S303, the terminal detects that there is a security risk or no security risk in the first request sent by the terminal. When there is no security risk in the first request sent by the terminal, the terminal allows the request to be sent. When there is a security risk in the first request sent by the terminal, the terminal does not allow the request to be sent. Exemplarily, as in S304.
[0095] S304. When the detection result indicates that the first request has a security risk, the terminal controls the terminal to work with the key information at the first moment, where the first moment is a moment before the sending moment of the first request, and the key information refers to the information that supports the terminal to work and supports the persistent backdoor file of the malicious file to be written to disk.
[0096] It should be understood that when the detection result indicates that the first request has a security risk, it means that the persistent backdoor file of the malicious file is implanted in the key information at the sending moment of the first request. At this time, the terminal discards the key information at the sending moment of the first request and works with the key information at the first moment before the sending moment.
[0097] The first moment is a moment before the sending moment of the first request, and it should be understood that: the first moment is close to the sending moment of the first request, and the first moment is the previous moment of the sending moment of the first request. Exemplarily, the first moment can be 2022-11-12 09:00, the second moment can be 2022-11-12 08:00, and the sending moment of the first request is 2022-11-12 10:00. Of course, there can be other examples, which will not be listed one by one in the embodiments of this application.
[0098] For example, S304 can be implemented as: when the first request sent by the terminal at 2022-11-12 10:00 has a security risk, the terminal discards the key information at 2022-11-12 10:00 and works with the key information at 2022-11-12 09:00.
[0099] In an example, the terminal generates a configuration item file with the above key information. Then, when the first request sent by the terminal has a security risk, the terminal deletes the configuration item file at the sending moment of the first request and works with the configuration item file at the previous moment (i.e., the first moment) of the sending moment of the first request. Continuing with the above example, when the first request sent by the terminal at 2022-11-12 10:00 has a security risk, the terminal discards the configuration item file at 2022-11-12 10:00 and works with the configuration item file at 2022-11-12 09:00.
[0100] In a possible implementation manner, as Figure 2 shown, S304 can be implemented as: the configuration return module controls the terminal to work with the key information at the first moment according to the detection result of the first request sent by the alarm linkage module. And in step ④, the configuration return module notifies the alarm linkage module that the terminal has returned to work with the key information at the first moment.
[0101] In an embodiment of the present application, once it is found that there is a security risk in the request sent by the terminal, it means that a persistent backdoor file is implanted in the key information at the moment when the request is sent. The terminal only needs to overwrite the key information at the moment when the security risk is found and work with the key information at the previous moment. In this way, the persistent backdoor file of the malicious file is removed from the root, without the need for in-depth analysis of the malicious file, and the cost is relatively low.
[0102] However, there may be a situation where, after the terminal overwrites the key information at the moment when the security risk is found, it is found that the third request sent also has a security risk. Then, the terminal needs to continue to roll back the key information until there are no more requests with security risks. Exemplarily, after the terminal executes S304, a terminal security protection method provided by an embodiment of the present application further includes:
[0103] S305. When the third request sent by the terminal has a security risk, the terminal works with the key information at the second moment, and the second moment is the previous moment of the first moment.
[0104] The third request can be used to request a connection to the control end of the malicious file.
[0105] It can be understood that after the terminal rolls back the key information once, the terminal detects again that the third request sent by the terminal has a security risk. In this case, the terminal overwrites the key information at the first moment and works with the key information at the second moment. In other words, when the third request sent by the terminal also has a security risk, the terminal will continue to roll back the information, that is, work with the key information at the second moment. And so on, the terminal recursively rolls back the key information until the terminal no longer sends requests with risks.
[0106] In a possible implementation manner, as Figure 2 shown, S305 can be implemented as follows: The alarm linkage module continues to detect the third request sent by the terminal. When the alarm linkage module detects again that the third request has a security risk, the alarm linkage module sends the detection result of the third request to the configuration rollback module, and the configuration rollback module controls the terminal to work with the key information at the second moment according to the detection result. And, in step ④, the configuration rollback module notifies the alarm linkage module that it has been rolled back to the key information at the second moment.
[0107] In an embodiment of the present application, when the terminal still sends the third request with a security risk, the terminal discards the key information at the first moment and works with the key information at the second moment. And so on, the terminal recursively rolls back the key information until the terminal no longer sends requests with risks, so as to achieve the purpose of completely clearing the persistent backdoor file and further improving the security of the terminal.
[0108] The difference from the above embodiments is that the terminal can also detect the requests sent by the terminal through other devices. Therefore, Figure 4 FIG. is a schematic structural diagram of a system composed of a terminal and a network device provided in an embodiment of the present application. As Figure 4 shown, the difference from the terminal shown in Figure 2 is that Figure 4 the alarm linkage module of the terminal shown in does not include an IPS. In other words, the alarm linkage module of the terminal does not have the function of an IPS, and the IPS is embodied in other devices (such as network device 200). In this structure, Figure 5 FIG. is another flowchart of a terminal security protection method provided in an embodiment of the present application. As Figure 5 shown, the method may include: S501-S509 (some steps are optional).
[0109] S501. The terminal obtains the key information of the terminal at each moment.
[0110] In a possible implementation manner, as Figure 4 shown, S501 may be implemented as: Step ① The configuration generation module of terminal 100 can obtain the key information of the terminal at each moment.
[0111] For the implementation of S501, reference may be made to the relevant description in S301 in the above embodiments, which will not be elaborated here.
[0112] After the terminal executes S501, in order to prevent the key information at each moment from occupying too much memory on the terminal and in order to trace the changes of the key information, a terminal security protection method provided in an embodiment of the present application may further include: The terminal generates a corresponding configuration item file for the key information at each moment. Reference may be made to the relevant description in S302 above, which will not be elaborated here. In a possible implementation manner, as Figure 4 shown, Step ② The configuration generation module of terminal 100 sends the collected key information to the monitoring module of terminal 100. The monitoring module generates a corresponding configuration item file for the key information at each moment.
[0113] S502. The terminal sends a first request to other devices. Correspondingly, the other devices receive the first request sent by the terminal.
[0114] In a possible implementation manner, as Figure 4 shown, Step ⑤ The terminal sends a first request to other devices (i.e., network device 200).
[0115] Other devices may refer to devices other than the terminal. For example, network devices. Network devices may include, but are not limited to, associated firewall devices, or IPS devices / intrusion detection system (IDS) network detection devices, etc. Other devices include IPS functions to detect requests sent by the terminal, such as S503.
[0116] In S503, other devices detect the first request sent by the terminal to obtain the detection result of the first request.
[0117] For the implementation of S503, reference may be made to the relevant description in S303 of the above embodiments, which will not be elaborated here.
[0118] The detection result of the first request may indicate two results: First, there is a security risk in the first request sent by the terminal; Second, there is no security risk in the request sent by the terminal.
[0119] After other devices obtain the detection result of the first request in S503, other devices may send the detection result of the first request to the terminal. Exemplarily, other devices may actively send the detection result of the first request to the terminal, or send the detection result of the first request to the terminal when the terminal needs it. The following will be introduced separately:
[0120] First, other devices actively send the detection result of the first request to the terminal.
[0121] In S504, when the detection result indicates that there is a security risk in the first request, other devices push a notification to the terminal. Correspondingly, the terminal receives the notification pushed by other devices.
[0122] The notification includes the detection result indicating that there is a security risk in the first request. The notification is used to inform the terminal that there is a security risk in the first request sent. Exemplarily, the notification may include the terminal identifier, the request identifier, and the first request with a security risk. For example, the content of the notification may be expressed as "GET / ?activation=1?code=xxxxxx". activation=1 indicates that there is a security risk in the first request, and 1 indicates fallback. code=xxxxxx represents the key for communication between other devices and the terminal.
[0123] In a possible implementation, as Figure 4 shown, in step ⑥, other devices (i.e., network device 200) send a notification to the alarm linkage module of the terminal. The alarm linkage module determines that there is a security risk in the first request sent by the terminal according to the notification.
[0124] Second, other devices send the detection result of the first request to the terminal when the terminal needs it.
[0125] S505. The terminal sends a second request to other devices to obtain the detection result of the first request. Correspondingly, the other devices receive the second request.
[0126] In one example, the terminal can send a second request to other devices in real time to request the detection result of the first request.
[0127] In another example, the terminal can also send a second request to other devices at regular intervals to request the detection result of the first request.
[0128] Exemplarily, the terminal sends a second request to other devices at a predetermined time interval to request the detection result of the first request. The predetermined time interval can be 5 minutes, 10 minutes or 4 hours, which is not specifically limited in the embodiments of the present application.
[0129] In addition, the detection result sent by other devices to the terminal can be the detection result of the terminal itself or the detection results of all terminals. Or rather, other devices can send all the detection results to the terminal or send the detection result of the terminal itself to the terminal. The details are as follows:
[0130] First, other devices send the detection result of the terminal itself to the terminal.
[0131] S506. According to the second request, other devices send the detection result corresponding to the first request sent by the terminal to the terminal. Correspondingly, the terminal receives the detection result of the first request.
[0132] Exemplarily, the second request may carry the IP address of the terminal, such as 192.168.1.1. Other devices look up the detection result of the terminal according to the IP address of the terminal and send the detection result to the terminal.
[0133] The second request is also used to request the detection result corresponding to the first request sent by the terminal.
[0134] Second, other devices send all / part of the detection results to the terminal.
[0135] S507. According to the second request, other devices send a terminal list to the terminal, and the terminal list includes information indicating the detection result of the first request. Correspondingly, the terminal receives the terminal list.
[0136] It should be understood that other devices can also detect the information sent by other terminals. When the terminal requests to obtain the detection result, other devices send all / part of the detection results to the terminal, and the terminal can look up its own detection result from these detection results.
[0137] In a possible implementation, other devices determine the terminals corresponding to these detection results and generate a terminal list. The terminal list includes information indicating the detection results of the first request.
[0138] Exemplarily, the terminal list may include the identification information of the terminals whose sent requests have security risks. Or, the terminal list may include the identification information of the terminals whose sent requests do not have security risks. Or, the terminal list may include the identification information of the terminals and the detection results of the requests sent by these terminals. The embodiments of the present application do not make specific limitations.
[0139] For example, the terminal list may record the identification or IP address, etc. of the terminals that need fallback information. Assume that the IP address of a terminal is 192.168.1.1, and the terminal list sent by other devices received by the terminal may be as shown in Table 2.
[0140] Table 2
[0141] IP address Rollback flag 192.168.1.1 1 192.168.1.2 1 192.168.1.3 1 192.168.1.4 1 192.168.1.5 1 192.168.1.6 1
[0142] It can be seen that the terminal can find its own IP address in the terminal list shown in Table 2. This means that the detection result obtained by the terminal is that the information sent by the terminal has security risks.
[0143] After that, other devices send the terminal list to the terminal. The terminal can search for the information of the terminal in the terminal list.
[0144] In S504 - S507 above, after other devices send the detection results to the terminal. When the detection result indicates that "the request sent by the terminal does not have security risks", the terminal can send the request. When the detection result indicates that "the request sent by the terminal has security risks", the terminal executes S508.
[0145] S508: When the first request sent by the terminal has security risks, the terminal works with the key information at the first moment, and the first moment is the previous moment of the sending moment of the first request.
[0146] In a possible implementation, as Figure 4 shown, S508 can be implemented as follows: Step ③ Configure the fallback module to control the terminal to work with the key information at the first moment according to the detection result of the first request sent by the alarm linkage module. And, Step ④ Configure the fallback module to inform the alarm linkage module that the terminal has fallen back to work with the key information at the first moment.
[0147] For the implementation of S508, reference can be made to the relevant description in S304 in the above embodiments, and details are not described herein again.
[0148] In the embodiment of the present application, once it is found that there is a security risk in the first request sent by the terminal, it means that a persistent backdoor file is implanted in the key information at the sending time of the first request. The terminal only needs to overwrite the key information at the sending time of the first request and work with the key information at the previous moment (i.e., the first moment) of the sending time of the first request. In this way, the persistent backdoor file of the malicious file is removed from the root, achieving the purpose of completely clearing the persistent backdoor file. In addition, during the process of clearing the persistent backdoor file of the malicious file, there is no need to deeply analyze the malicious file, and the cost is relatively low.
[0149] However, there may be a situation where, after the terminal overwrites the key information at the moment when the security risk is discovered, it is found that there is still a security risk in the sent request. Then, the terminal needs to continue to roll back the key information until there are no more requests with security risks. Exemplarily, after the terminal executes S508, a terminal security protection method provided by the embodiment of the present application further includes:
[0150] S509. When there is also a security risk in the third request sent by the terminal, the terminal works with the key information at the second moment, and the second moment is the previous moment of the first moment.
[0151] For the implementation of S509, reference can be made to the relevant description in S305 in the above embodiment, which will not be elaborated here.
[0152] In S508 or S509, the terminal cannot send requests through other devices. In this way, as Figure 4 shown, in step ⑦, other devices cannot send information to the attacker. Similarly, in step ⑧, the attacker cannot send information to the terminal through other devices. Therefore, the malicious file on the terminal cannot be connected to the outside world.
[0153] In the embodiment of the present application, when the terminal still sends a third request with a security risk, the terminal overwrites the key information at the first moment and works with the key information at the second moment. And so on, the terminal recursively rolls back the key information until the terminal no longer sends requests with risks, so as to achieve the purpose of completely clearing the persistent backdoor file and further improving the security of the terminal.
[0154] As Figure 6As shown in the figure, an embodiment of the present application further provides a terminal security protection device 600, and the device 600 includes: an acquisition module 601 and a processing module 602. Among them, the acquisition module 601 is used to acquire the detection result of the first request sent by the terminal. The processing module 602 is used to control the terminal to work with the key information at the first moment when the detection result indicates that the first request has a security risk; the first moment is the moment before the sending moment of the first request, and the key information refers to the information that supports the work of the terminal and supports the persistent backdoor file of the malicious file to be written to disk.
[0155] In the embodiment of the present application, when the first request sent by the terminal has a security risk, the information for the terminal to work is switched from the key information at the sending moment of the first request to the key information at the first moment. Or rather, when the first request sent by the terminal has a security risk, it means that a persistent backdoor file of the malicious file is implanted in the key information at the sending moment of the first request. The terminal abandons the key information at the sending moment of the first request and uses the key information at the first moment before the sending moment to work, thereby clearing the persistent backdoor file of the malicious file, eliminating the persistent backdoor file of the malicious file from the root cause, and achieving the purpose of completely clearing the persistent backdoor file. In addition, during the process of clearing the persistent backdoor file of the malicious file, there is no need to deeply analyze the malicious file, and the cost is relatively low.
[0156] In one embodiment, the acquisition module 601 is further used to: detect the first request sent by the terminal to obtain the detection result of the first request. The detection result of the first request can indicate two results: the first is that the first request has a security risk; the second is that the first request has no security risk. Among them, the execution subject for detecting the first request sent by the terminal can be the terminal or other devices.
[0157] In one embodiment, the acquisition module 601 is further used to: compare the first information carried in the first request with the pre-stored risk information, and the risk information includes the information sent by the malicious file to the control end of the malicious file through the terminal; when the first information matches the risk information, obtain the detection result indicating that the first request has a security risk.
[0158] In one embodiment, the acquisition module 601 is further used to: receive the notification pushed by other devices, and the notification includes the detection result of the first request; other devices are used to detect the first request to obtain the detection result of the first request and send the notification including the detection result of the first request.
[0159] In one embodiment, the obtaining module 601 is further configured to: send a second request to other devices, where the second request is used to request to obtain the detection result of the first request, and the other devices are used to detect the first request to obtain the detection result of the first request, and feedback the detection result of the first request according to the second request; receive the detection result of the first request fed back by the other devices according to the second request.
[0160] In one embodiment, the obtaining module 601 is further configured to: send a second request to other devices, where the second request is used to request to obtain the detection result of the first request, and the other devices are used to detect the first request to obtain the detection result of the first request, and feedback the information indicating the detection result of the first request according to the second request; receive the terminal list fed back by the other devices according to the second request, where the terminal list includes the information indicating the detection result of the first request. The terminal list may include the identification information of the terminal where the sent request has a security risk. Or, the terminal list may include the identification information of the terminal where the sent request has no security risk. Or, the terminal list may include the identification information of the terminal and the detection result of the request sent by the terminal.
[0161] In one embodiment, the obtaining module 601 is further configured to obtain the detection result of the third request sent by the terminal. The processing module 602 is further configured to, when the detection result indicates that the third request has a security risk, control the terminal to work with the key information at the second moment, where the second moment is the previous moment of the first moment. In the embodiment of the present application, when the terminal still sends a third request with a security risk, the terminal discards the key information at the first moment and works with the key information at the second moment. And so on, the terminal recursively rolls back the key information until the terminal no longer sends a request with a risk, so as to achieve the purpose of completely clearing the persistent backdoor file and further improving the security of the terminal.
[0162] In one embodiment, the obtaining module 601 is further configured to obtain the key information of the terminal working at the first moment at a specified time interval. In the present application, by obtaining the key information regularly, the changes of each key information of the terminal and their corresponding time points can be clearly recorded, which is convenient for attack prevention and traceability records, so that the terminal can trace information and provide convenience for subsequent operations.
[0163] In one embodiment, the obtaining module 601 is further configured to obtain the key information of the terminal working at the first moment when the key information at the second moment changes, where the second moment is the previous moment of the first moment. In the present application, by obtaining the key information at the next moment of the current moment when the key information at the current moment changes, the changes of each key information of the terminal and their corresponding time points can be clearly recorded, which is convenient for attack prevention and traceability records, so that the terminal can trace information and provide convenience for subsequent operations.
[0164] In addition, in the present application, when key information changes, the terminal generates corresponding configuration item files for each piece of key information, eliminating the need to constantly generate configuration item files or repeatedly generate configuration item files with the same content, effectively saving the power consumption of the terminal.
[0165] In one embodiment, the obtaining module 601 is further configured to generate a corresponding configuration item file for the key information at the first moment, and the configuration item file is used to record the key information of the terminal at the first moment. The processing module 602 is further configured to: when the detection result indicates that the first request has a security risk, control the terminal to work using the configuration item file. In the present application, by generating configuration item files for key information, while reducing the memory occupancy of key information, it can clearly record the changes of each piece of key information of the terminal and their corresponding time points, facilitating the tracing record for attack prevention and protection, so as to facilitate the terminal to trace information and provide convenience for subsequent operations.
[0166] In one embodiment, the key information includes at least one of the following: registry autostart items, autostart service items, scheduled task items of the operating system, and management specification task items.
[0167] In one embodiment, the first request is used to request to connect to the control end of a malicious file.
[0168] It should be understood that when the above Figure 6 The provided device, when implementing its functions, only uses the division of the above functional modules for illustration. In practical applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the device provided in the above embodiment and the method embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.
[0169] The embodiment of the present application further provides an electronic device, which includes a processor for loading and running at least one instruction to enable the electronic device to implement the method provided by the embodiment of the present application. Optionally, the electronic device further includes a memory coupled to the processor, and the memory is used to store at least one instruction.
[0170] The embodiment of the present application further provides a computer-readable storage medium, in which at least one instruction is stored, and the instruction is loaded and executed by the processor to enable the computer to implement the method as described above in any one.
[0171] The embodiment of the present application further provides a computer program (product), when the computer program is executed by a computer, it can enable the processor or the computer to execute the corresponding steps and / or processes in the above method embodiment.
[0172] An embodiment of the present application further provides a chip, which includes a processor for calling and running instructions stored in the memory, so that a communication device installed with the chip executes any of the above-mentioned methods.
[0173] An embodiment of the present application further provides another chip, including: an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected through an internal connection path. The processor is configured to execute code in the memory. When the code is executed, the processor is configured to execute any of the above-mentioned methods.
[0174] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that includes one or more integrated available media. The available medium may be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state drive Solid State Disk), etc.
[0175] It should be noted that the information (including but not limited to user equipment information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.), and signals involved in the present application are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards of relevant countries and regions. For example, the detection results involved in the present application are obtained under full authorization.
[0176] Those of ordinary skill in the art will recognize that, in combination with the method steps and modules described in the embodiments disclosed herein, they can be implemented in software, hardware, firmware, or any combination thereof. To clearly illustrate the interchangeability of hardware and software, the steps and components of the embodiments have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0177] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above embodiments can be completed by hardware, or can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium, and the above-mentioned storage medium can be a read-only memory, a disk, an optical disc, etc.
[0178] When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer program instructions. As an example, the method of the embodiments of the present application can be described in the context of machine-executable instructions, such as program modules executed in devices on a target real or virtual processor. Generally speaking, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., which perform specific tasks or implement specific abstract data structures. In the embodiments, the functions of the program modules can be merged or split among the described program modules. The machine-executable instructions for the program modules can be executed within local or distributed devices. In a distributed device, the program modules can be located in both local and remote storage media.
[0179] The computer program code for implementing the method of the embodiments of the present application can be written in one or more programming languages. These computer program codes can be provided to the processors of general-purpose computers, special-purpose computers, or other programmable terminal security protection devices, so that when the program codes are executed by the computer or other programmable terminal security protection devices, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the computer, partially on the computer, as an independent software package, partially on the computer and partially on a remote computer, or entirely on a remote computer or server.
[0180] In the context of the embodiments of the present application, the computer program code or related data can be carried by any suitable carrier so that the device, apparatus, or processor can execute the various processes and operations described above. Examples of the carrier include signals, computer-readable media, and so on.
[0181] Examples of signals can include electrical, optical, radio, acoustic, or other forms of propagated signals, such as carrier waves, infrared signals, and the like.
[0182] A machine-readable medium can be any tangible medium that contains or stores a program for or relevant to an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination thereof. More specific examples of machine-readable storage media include electrical connections with one or more wires, portable computer disks, hard disks, random access memories (RAMs), read-only memories (ROMs), erasable programmable read-only memories (EPROMs or flash memories), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0183] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0184] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there can be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings or direct couplings or communication connections to each other can be indirect couplings or communication connections through some interfaces, devices, or modules, and can also be electrical, mechanical, or other forms of connections.
[0185] The modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they can be located in one place, or can be distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the embodiments of this application.
[0186] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically alone, or two or more modules can be integrated into one module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules.
[0187] When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0188] In this application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and effects. It should be understood that there is no logical or chronological dependency between "first", "second", and "nth", nor are the quantity and execution order limited. It should also be understood that although the following description uses terms such as first and second to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of various examples, the first request can be referred to as the second request, and similarly, the second request can be referred to as the first request. Both the first request and the second request can be requests, and in some cases, they can be separate and different requests.
[0189] It should also be understood that in various embodiments of this application, the magnitude of the sequence numbers of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of this application.
[0190] In this application, the meaning of the term "at least one" refers to one or more, and the meaning of the term "multiple" refers to two or more. For example, multiple second messages refer to two or more second messages. In this article, the terms "system" and "network" are often used interchangeably.
[0191] It should be understood that the terms used in the description of various examples in this article are only for describing specific examples and are not intended to be limiting. As used in the description of various examples and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0192] It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. The term "and / or" is a correlative relationship describing associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Additionally, the character " / " in this application generally represents an "or" relationship between the associated objects before and after.
[0193] It should also be understood that the term "comprises" (also known as "includes", "including", "comprises", and / or "comprising") when used in this specification specifies the presence of the stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their groups.
[0194] It should also be understood that the terms "if" and "when" can be interpreted to mean "when" ("when" or "upon") or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if it is determined..." or "if [the stated condition or event] is detected" can be interpreted to mean "when it is determined..." or "in response to determining..." or "when [the stated condition or event] is detected" or "in response to detecting [the stated condition or event]".
[0195] It should be understood that determining B based on A does not mean determining B solely based on A. B can also be determined based on A and / or other information.
[0196] It should also be understood that the "one embodiment", "an embodiment", "a possible implementation" mentioned throughout the specification mean that the specific features, structures, or characteristics related to the embodiment or implementation are included in at least one embodiment of this application. Therefore, the "in one embodiment" or "in an embodiment", "a possible implementation" that appear throughout the specification do not necessarily refer to the same embodiment. Additionally, these specific features, structures, or characteristics can be combined in one or more embodiments in any suitable manner.
Claims
1. A terminal security protection method, characterized in that: The method includes: Obtaining a detection result of a first request sent by a terminal; When the detection result indicates that the first request has a security risk, controlling the terminal to work with key information at a first moment; the first moment is a moment before the sending moment of the first request, and the key information refers to information that supports the work of the terminal and supports the persistent backdoor file of the malicious file to be written to disk.
2. The method according to claim 1, characterized in that, The obtaining a detection result of a first request sent by a terminal includes: Detecting the first request sent by the terminal to obtain a detection result of the first request.
3. The method according to claim 2, wherein The detecting the first request sent by the terminal to obtain a detection result of the first request includes: Comparing first information carried in the first request with pre-stored risk information, where the risk information includes information sent by the malicious file to the control end of the malicious file through the terminal; When the first information matches the risk information, obtaining a detection result indicating that the first request has a security risk.
4. The method according to claim 1, characterized in that: The obtaining a detection result of a first request sent by a terminal includes: Receiving a notification pushed by another device, where the notification includes a detection result of the first request; the other device is used to detect the first request to obtain a detection result of the first request and send a notification including the detection result of the first request.
5. The method according to claim 1, wherein The obtaining a detection result of a first request sent by a terminal includes: Sending a second request to another device, where the second request is used to request to obtain a detection result of the first request, and the other device is used to detect the first request to obtain a detection result of the first request and feedback the detection result of the first request according to the second request; Receiving the detection result of the first request fed back by the other device according to the second request.
6. The method according to claim 1, characterized in that The obtaining a detection result of a first request sent by a terminal includes: Sending a second request to another device, where the second request is used to request to obtain a detection result of the first request, and the other device is used to detect the first request to obtain a detection result of the first request and feedback information indicating the detection result of the first request according to the second request; Receiving a terminal list fed back by the other device according to the second request, where the terminal list includes information indicating the detection result of the first request.
7. The method according to any one of claims 1-6, characterized in that, After controlling the terminal to work with key information at a first moment, the method further includes: Obtaining a detection result of a third request sent by the terminal; When the detection result indicates that the third request has a security risk, controlling the terminal to work with key information at a second moment, where the second moment is the moment before the first moment.
8. The method according to any one of claims 1-7, characterized in that, Before controlling the terminal to work with key information at a first moment, the method further includes: Obtaining the key information of the terminal working at the first moment at a specified time interval.
9. The method according to any one of claims 1 to 7, characterized in that, Before controlling the terminal to work with key information at a first moment, the method further includes: In the case where the key information at the second moment changes, the key information of the terminal operation at the first moment is obtained, and the second moment is a moment before the first moment.
10. The method according to claim 8 or 9, characterized in that After obtaining the key information of the terminal operation at the first moment, the method further includes: generating a corresponding configuration item file based on the key information at the first moment, wherein the configuration item file is used to record the key information of the terminal at the first moment; When the detection result indicates that the first request has a security risk, controlling the terminal to operate using the key information at the first moment includes: If the detection result indicates that the first request has a security risk, the terminal is controlled to operate using the configuration item file.
11. The method according to any one of claims 1-10, characterized in that, The key information includes at least one of the following: a registry self-starting item, a self-starting service item, an operating system scheduled task item, and a management specification task item.
12. The method according to any one of claims 1 to 11, characterized in that The first request is used to request a connection to a control end of the malicious file.
13. A terminal security protection device, characterized in that, The device includes: an acquisition module and a processing module, wherein: The acquisition module is configured to acquire the detection result of the first request sent by the terminal; The processing module is used to control the terminal to operate using key information at a first moment when the detection result indicates that the first request has a security risk; the first moment is a moment before the first request is sent, and the key information refers to information that supports the operation of the terminal and supports the persistent backdoor file of malicious files to be dropped onto the disk.
14. An electronic device, characterized in that: The electronic device includes a memory and a processor; the memory stores at least one instruction, and the at least one instruction is loaded and executed by the processor, so that the electronic device implements any one of the methods described in claims 1-12.
15. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one instruction, which is loaded and executed by a processor to enable a computer to implement the method according to any one of claims 1 to 12.
16. A computer program product, characterized in that The computer program product comprises a computer program / instructions, and the computer program / instructions are executed by a processor to enable a computer to implement the method according to any one of claims 1 to 12.