DCS upper computer malicious executable file detection method and system

By using the top command and /proc directory scanning process in DCS host computers, combined with blacklist database and behavioral analysis, the problem of unknown malicious file detection is solved, and automated, real-time and low resource consumption malicious file detection is realized to ensure system security and stability.

CN120579183APending Publication Date: 2025-09-02XIAN THERMAL POWER RES INST CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510709773.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

The existing malicious executable file detection methods cannot effectively detect unknown files, and the security requirements for DCS hosted computers have not been met. Traditional methods consume a lot of resources and cannot realize automated detection.

Method used

Use the top command and /proc directory to scan the DCS host machine processes regularly to query the process PID that occupies too much CPU/memory, obtain process paths and resources by scanning the corresponding directory of the PID, combine the blacklist database and behavior analysis to determine whether it is a malicious file, and notify the administrator by email.

Benefits of technology

It realizes automated, real-time, and low resource consumption malicious executable file detection of DCS host computers, and can promptly discover and feedback unknown malicious files to ensure the stable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120579183A_ABST
    Figure CN120579183A_ABST
Patent Text Reader

Abstract

The invention discloses a DCS upper computer malicious executable file detection method and system, and belongs to the field of computer security, the method comprises the following steps: using a top command to regularly scan the process of a DCS upper computer, and querying the pid of the process occupying too high CPU / memory; according to the pid, acquiring a path of the process and accessed resources by scanning information under a / proc / pid directory; judging whether the process is a malicious executable file or not by analyzing the path of the process and accessed resources; and according to a judgment result, summarizing and sending an executable file name corresponding to the malicious executable file, an occupied CPU (Central Processing Unit), an occupied memory quantity, an absolute path and file information opened by a process. Through the method, the malicious executable file can be effectively and accurately found and fed back to a system administrator in time, so that the hidden danger of system operation is eliminated, and normal and reliable operation of the upper computer is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer security and relates to a method and system for detecting malicious executable files on a DCS host computer. Background Art

[0002] In the field of computer security, detecting malicious executable files is an important research area. Malicious executable files include viruses, worms, Trojan horses, spyware, and ransomware. They can infect computer systems through various channels, stealing sensitive information, damaging system data, occupying system resources, and even controlling computers to perform malicious activities. Traditional methods for detecting malicious executable files rely primarily on signature libraries, comparing file hash values ​​or signatures with signatures of known malicious executable files to determine if a file is malicious. However, this approach suffers from the inability to detect unknown malicious executable files. In software engineering, process management is a crucial component of operating systems. Processes are the basic units of resource allocation in operating systems, each with its own memory space, file descriptors, signal handlers, and other functions. A distributed control system (DCS) typically consists of multiple control stations, each responsible for controlling a specific piece of equipment or process. A DCS host computer is a computer running on a DCS control station. It typically runs the Linux operating system and is installed with various industrial control software. Because the DCS host computer has network connectivity, it is also at risk from network attacks and infection by malicious executable files.

[0003] Existing malicious executable file detection methods mainly rely on signature libraries and therefore cannot detect unknown malicious executable files. In addition, existing behavior-based detection methods, such as sandbox technology, although they can detect unknown malicious executable files, require a large amount of computing resources and may affect system performance. In the Linux operating system, although the top command and the / proc directory can be used to view process information, this information needs to be manually analyzed, and automated malicious executable file detection cannot be achieved. In addition, existing malicious executable file detection methods are mainly targeted at personal computers or servers, rather than DCS host computers in industrial control systems. Therefore, existing malicious executable file detection methods cannot meet the security requirements of DCS host computers. Summary of the Invention

[0004] To address the aforementioned issues, the present invention proposes a method and system for detecting malicious executable files on a DCS host computer. This method uses the Linux top command and / proc directory scan to detect malicious executable files. By regularly scanning the command lines output by the top command, the PID of the process that consumes excessive CPU and memory is retrieved. Furthermore, by scanning the directory corresponding to the PID, the path of the process and the resources it accesses are located, thereby achieving the purpose of detecting malicious executable files. Finally, the detection results are notified to the system administrator via email or other means, so that measures can be taken to ensure the normal operation of the host computer.

[0005] To achieve the above purpose, the present invention adopts the following technical means: The first aspect of the present invention is to provide a method for detecting malicious executable files on a DCS host computer, comprising: Use the top command to regularly scan the processes of the DCS host computer and find the PID of the process that occupies too much CPU / memory; According to pid, by scanning the information in the directory corresponding to pid, the path of the process and the resources it accesses are obtained; By analyzing the process path and the resources accessed, determine whether the process is a malicious executable file; Based on the judgment results, the executable file name, CPU occupied, memory occupied, absolute path, and file information opened by the process corresponding to the malicious executable file are summarized and sent.

[0006] As a further improvement of the present invention, the process of periodically scanning the DCS host computer using the top command is that the detection program is started through a timer task and the top command is executed to periodically scan all processes of the DCS host computer.

[0007] As a further improvement of the present invention, the configuration file of the detection program includes filtering rules, detection time intervals, email recipients and email servers. The filtering rules are used to filter out normally running processes, including: whitelist, blacklist, behavior analysis, time pattern, user permissions and inter-process communication.

[0008] As a further improvement of the present invention, the querying of the PID of the process that occupies too much CPU / memory includes: Execute the top command to display the real-time resource usage of each process in the current system, including CPU and memory usage; Sort the processes by CPU usage from high to low; In the sorted list, get the processes that occupy CPU / memory exceeding the threshold; and record the corresponding PID.

[0009] As a further improvement of the present invention, the path of the process and the resources accessed are obtained by scanning the information in the directory corresponding to the pid according to the pid, including: a) Get the absolute path of the executable file from cmdline; b) Get the files and sockets accessed by the process from fd; c) Memory information, swap space usage, and virtual memory usage; d) Information about files opened by other processes.

[0010] As a further improvement of the present invention, the process of determining whether a process is a malicious executable file by analyzing the process path and the resources accessed includes: After obtaining process information through the top command and the / proc directory, extract the full path of the process; Compare the extracted process path with the entries in the pre-established blacklist database; If a match is found, the process is marked as suspicious or malicious; Perform the following comprehensive analysis on the marked processes: a. Read network connection information and obtain the network connection status of the process; b. Check whether the network connection status points to the malicious IP address, domain name, or port of the marked process; c. Monitor and analyze network traffic content; d. List the files opened by the marked process and obtain all file handles opened by the process by reading the links in the / proc / [pid] / fd directory; e. Check if the opened file path points to sensitive areas or matches known malware behavior patterns; f. Monitor the read, write, and delete operations of marked processes on files; Combined with the analysis results of network connections and file access, a comprehensive assessment of the process is performed: if there is a situation that exceeds the suspicious behavior threshold, the process is determined to be a malicious executable file.

[0011] As a further improvement of the present invention, the pre-established blacklist database is a blacklist database containing known malware paths, names, and hash value information; the pre-established blacklist database is stored in a local file, a database management system, or a cloud storage service.

[0012] The second aspect of the present invention is to provide a DCS host computer malicious executable file detection system, comprising: The scanning query module is used to periodically scan the processes of the DCS host computer using the top command to query the PID of the process that occupies too much CPU / memory; The acquisition module is used to obtain the path of the process and the resources it accesses by scanning the information in the directory corresponding to the pid; A judgment module is used to determine whether a process is a malicious executable file by analyzing the process path and accessed resources; The sending module is used to summarize and send the executable file name, occupied CPU, occupied memory amount, absolute path, and file information opened by the process corresponding to the malicious executable file based on the judgment result.

[0013] Optionally, in the scanning query module, using the top command to periodically scan the processes of the DCS host computer is to start the detection program through a scheduled task and execute the top command to periodically scan all processes of the DCS host computer.

[0014] Further optionally, the configuration file of the detection program includes filtering rules, detection time intervals, email recipients and email servers, and the filtering rules are used to filter out normally running processes, including: whitelist, blacklist, behavior analysis, time pattern, user permissions and inter-process communication.

[0015] Optionally, in the scanning query module, querying the PID of the process that occupies too much CPU / memory includes: Execute the top command to display the real-time resource usage of each process in the current system, including CPU and memory usage; Sort the processes by CPU usage from high to low; In the sorted list, get the processes that occupy CPU / memory exceeding the threshold; and record the corresponding PID.

[0016] Optionally, the acquisition module is specifically configured to: a) Get the absolute path of the executable file from cmdline; b) Get the files and sockets accessed by the process from fd; c) Memory information, swap space usage, and virtual memory usage; d) Information about files opened by other processes.

[0017] Optionally, the judgment module is specifically configured to: After obtaining process information through the top command and the / proc directory, extract the full path of the process; Compare the extracted process path with the entries in the pre-established blacklist database; If a match is found, the process is marked as suspicious or malicious; Perform the following comprehensive analysis on the marked processes: a. Read network connection information and obtain the network connection status of the process; b. Check whether the network connection status points to the malicious IP address, domain name, or port of the marked process; c. Monitor and analyze network traffic content; d. List the files opened by the marked process and obtain all file handles opened by the process by reading the links in the / proc / [pid] / fd directory; e. Check if the opened file path points to sensitive areas or matches known malware behavior patterns; f. Monitor the read, write, and delete operations of marked processes on files; Combined with the analysis results of network connections and file access, a comprehensive assessment of the process is performed: if there is a situation that exceeds the suspicious behavior threshold, the process is determined to be a malicious executable file.

[0018] Optionally, the pre-established blacklist database is a blacklist database containing known malware paths, names, and hash value information; the pre-established blacklist database is stored in a local file, a database management system, or a cloud storage service.

[0019] The third aspect of the present invention is to provide an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the DCS host computer malicious executable file detection method when executing the computer program.

[0020] A fourth aspect of the present invention is to provide a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method for detecting malicious executable files on a DCS host computer is implemented.

[0021] Compared with the prior art, the present invention has the following beneficial effects: The background detection program of the present invention periodically scans the command line output by the top command to query the process PID that occupies too much CPU / memory. Then, by scanning the information under the directory corresponding to the PID, the path of the process and the resources accessed are found, thereby achieving the purpose of detecting malicious executable files. Finally, the detection results are notified to the system administrator via email or other means so that measures can be taken to ensure the normal operation of the host computer. Through this method, malicious executable files can be effectively and accurately discovered and fed back to the system administrator in a timely manner, thereby eliminating system operation risks and ensuring the normal and reliable operation of the host computer. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 This is a flow chart of a method for detecting malicious executable files on a DCS host computer provided by the present invention; Figure 2 Schematic diagram of a method for detecting malicious executable files on a DCS host computer in an embodiment; Figure 3 The present invention provides a DCS host computer malicious executable file detection system. DETAILED DESCRIPTION

[0023] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0024] It should be noted that the terms "first," "second," and the like in the description and claims of the present invention and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, such that the embodiments of the present invention described herein can be practiced in an order other than that illustrated or described herein.

[0025] In addition, the terms "comprises" and "having" and any variations thereof are intended to cover a non-exclusive inclusion. For example, a process, method, system, product or apparatus that includes a series of steps or elements is not necessarily limited to those steps or elements expressly listed but may include other steps or elements not expressly listed or inherent to such process, method, product or apparatus.

[0026] The first purpose of the present invention is to provide a DCS host computer malicious executable file detection method, such as Figure 1 As shown, the following steps are included: S1, use the top command to regularly scan the processes of the DCS host computer and query the PID of the process that occupies too much CPU / memory; S2, according to pid, obtains the path of the process and the resources it accesses by scanning the information in the directory corresponding to pid; S3, determines whether the process is a malicious executable file by analyzing the process path and accessed resources; S4, based on the judgment result, the executable file name, occupied CPU, occupied memory amount, absolute path, and file information opened by the process corresponding to the malicious executable file are summarized and sent.

[0027] The principles of each step of the present invention are as follows: Automatic detection of suspicious malicious executable files: This invention writes a background detection program, uses the top command to regularly scan the system processes, queries the process PID that occupies too much CPU / memory, and then scans the information in the / proc / pid directory to find the path of the process and the resources it accesses, thereby realizing automatic detection of malicious executable files.

[0028] Automatically identify malicious executable files based on policy judgment: By setting certain policies, it automatically determines which executable files are suspicious of malicious behavior, thereby achieving accurate judgment of malicious executable files.

[0029] Automatic feedback of test results: The test results are notified to the system administrator via email or other means so that measures can be taken to ensure the normal operation of the host computer.

[0030] The entire process has no interference with the system, is executed silently, and has silent notifications: During the detection process, there is no interference with the system, it is executed silently, and after the detection is completed, the system administrator is silently notified to ensure the normal operation of the system.

[0031] Real-time monitoring of the running status of processes in the DCS host computer: Use the top command to monitor the running status of processes in the DCS host computer in real time, promptly discover and feedback processes that occupy too much CPU / memory, thereby eliminating system operation risks and ensuring the normal and reliable operation of the host computer.

[0032] Efficiently obtain process-related information: By scanning the / proc / pid directory, you can obtain process-related information, such as the absolute path of the executable file, the files and sockets accessed by the process, as well as memory information, swap space usage, virtual memory usage, etc., for in-depth analysis.

[0033] Summarize the detection results and send them to the designated mailbox: Summarize the executable file name, CPU occupied, memory occupied, absolute path, files opened by the process and other information corresponding to the process and send them to the designated mailbox so that the system administrator can understand the system operation status in a timely manner.

[0034] Implement periodic detection of the DCS host computer: By repeating the above steps, continuous monitoring of the system operation status is achieved to ensure long-term stable operation of the system.

[0035] Specific embodiments are given below to describe the steps of the present invention in detail: The steps of the entire method of this embodiment are as follows: Figure 2 As shown, the following steps are included: 1) Start the detection program.

[0036] 2) Run the top command in the detection program to analyze the process that uses too much CPU and memory and find its pid.

[0037] 3) Based on pid, search the / proc / pid directory to obtain the following information: a) Get the absolute path of the executable file from cmdline; b) Get the files, sockets, etc. accessed by the process from fd; c) Memory information, swap space usage, and virtual memory usage; d) other information; 4) Collect the information of the executable file name, CPU usage, memory usage, absolute path, and files opened by the process, and send it to the designated mailbox; 5) Repeat steps 2-4 above to perform cyclic testing; 6) Stop the detection service and exit the detection program.

[0038] The present invention provides a specific embodiment, which provides a method for detecting malicious executable files on a DCS host computer. The specific steps are as follows: Step 1: Start the detection program. The detection program is started through a scheduled task, for example, at 3 am every day to avoid interference with the system.

[0039] Step 2: Run the top command on the detection program to identify the process that is consuming excessive CPU and memory, and find the PID. The top command parameter can be set to n1, which means that the result is output only once to avoid excessive system resource usage.

[0040] Step 3: Search the / proc / pid directory based on pid to obtain the following information: a) Get the absolute path of the executable file from cmdline; b) Get the files, sockets, etc. accessed by the process from fd; c) Memory information, swap space usage, virtual memory usage; d) Other information; Step 4: Collect the executable file name, CPU usage, memory usage, absolute path, and open files corresponding to the process and send it to a designated email address. The email recipient can be a system administrator, who can take timely action.

[0041] Step 5: Repeat steps 2 to 4 above to perform a cyclic detection. The cyclic detection interval can be set to 1 hour, that is, a detection is performed every 1 hour to ensure that malicious executable files are discovered in a timely manner.

[0042] Step 6: Stop the detection service and exit the detection program. The detection program can be stopped manually when the system administrator needs it, or automatically stopped through a scheduled task.

[0043] In this embodiment, the detection program is written in Python and uses the psutil library to obtain process information. The psutil library is a cross-platform library that can obtain various information in the system, such as process, CPU, memory, disk, network, etc.

[0044] For example, the steps to find the PID (process identifier) ​​of a process that is consuming too much CPU or memory include: 1. Use the top command to search: Open the terminal: First, open the command line interface in the terminal of the Linux system.

[0045] Execute the top command: Enter the top command, which will display the real-time resource usage of each process in the current system, including CPU and memory usage.

[0046] Sort by: Sort processes by CPU usage from high to low. The process with the highest CPU usage will be at the top of the list.

[0047] Identify the PID: In the sorted list, find the process with high CPU or memory usage and write down its PID (usually in the first column of the list).

[0048] 2. Use other commands to assist in searching: If the information in the top command is not sufficient to identify the problem process, or if more detailed process information is needed, you can use the following command for auxiliary search: ps command: Use the ps -ef | grep [process name] command to find related processes by process name and display their PIDs and other information. This helps further identify the problematic process when the top command's results are unclear.

[0049] The htop command (if installed): provides a graphical interface and more features. In htop, you can directly view the CPU and memory usage of each process and sort and filter them with a click of the mouse or using keyboard shortcuts. If htop is not installed on your system, you can install it through a package manager such as yum or apt-get.

[0050] Through the above steps, you can effectively query the PID of the process that consumes too much CPU or memory.

[0051] In addition, detection program can also utilize the Smtplib storehouse to send mail, so that timely notification system administrator.In the present embodiment, the configuration file of detection program can comprise information such as detection time interval, mail recipient, mail server, so that adapt to different demands.In addition, detection program can also comprise some filtering rules, so that filter out some normally run processes, in order to avoid causing false alarm.

[0052] Filtering rules are a crucial part of this, as they help the detection program distinguish malicious activity from normal or expected system operations. Filtering rules include: Whitelist: Process Name: Monitor only processes not on a predefined whitelist. A whitelist can contain all known and trusted process names. File Path: Scan only executable files located outside of specific paths (e.g., system directories, application installation directories). Signature Verification: Check the file's digital signature and only analyze files that are unverified or have a mismatched signature.

[0053] Blacklist: Process Name: Monitors and flags process names associated with known malware. File Hash: Stores and checks file hashes against a library of known malware hashes. Network Behavior: Monitors a process's network activity, such as attempts to connect to known malicious IP addresses or domains.

[0054] Behavioral Analysis: Resource Consumption: Monitors the CPU, memory usage, and disk I / O activity of processes. Abnormally high resource consumption may indicate malicious activity. File Operations: Monitors file read and write operations by processes, particularly attempts to write to system directories, startup items, or execute unknown files. Registry Modifications: Monitors modifications to the registry, particularly those that affect system startup, security policies, or network configuration.

[0055] Time Patterns: Non-working hours activity: Processes running outside of typical working hours may be considered suspicious. Periodic activity: Detects unusual activity that is performed regularly, which may indicate the presence of a scheduled or scheduled task being exploited maliciously.

[0056] User Privileges: High-Privilege Processes: Monitors processes running with high privileges, such as administrator privileges, as malware often requires these privileges to perform its malicious activities.

[0057] Inter-process communication: Analyze communication patterns between processes, especially those associated with known malware.

[0058] By combining these filtering rules, the DCS host computer's malicious executable file detection system can more accurately distinguish between malicious activities and normal operations, thereby reducing false positives and improving the overall security of the system. At the same time, these rules also need to be updated regularly to adapt to new threats and attack methods.

[0059] The above are the specific steps of this embodiment. Through these steps, malicious executable files in the DCS host computer can be effectively detected and the system administrator can be notified in a timely manner, thereby ensuring the security and stability of the system.

[0060] As a preferred solution, by analyzing the process path and the resources accessed, it is determined whether the process is a malicious executable file. Specifically, the following steps are included: Step 31, blacklist check step: Build a blacklist database: Create a blacklist database containing information such as known malware paths, names, hash values, etc. This database can be obtained from various security agencies, communities, or commercial threat intelligence services.

[0061] The database can be stored in a local file, a database management system (such as SQLite, MySQL), or a cloud storage service.

[0062] Extract process information: After obtaining process information through the top command and the / proc directory, extract the full path of the process (from the / proc / [pid] / exe symbolic link or by parsing / proc / [pid] / cmdline).

[0063] Compare to blacklist: Compare the extracted process path with the entries in the blacklist database.

[0064] If a match is found, the process is marked as suspicious or malicious.

[0065] Result comparison: Based on the matching results, decide whether further analysis is needed or whether to take immediate response measures (such as logging, sending alerts, killing processes, etc.).

[0066] Step 32, the behavior analysis step, includes the following steps: Network connection analysis: Read network connection information: Obtain the network connection status of the process (such as IP address, port number, status, etc.) by accessing files such as / proc / [pid] / net / tcp and / proc / [pid] / net / udp.

[0067] Analyze connections: Check if they point to known malicious IP addresses, domains, or ports. This may require comparison with another blacklist (such as an IP blacklist).

[0068] Traffic monitoring: If possible, you can use tools such as tcpdump and ss to further monitor and analyze network traffic content.

[0069] File access analysis: List open files: Get all file handles opened by the process by reading the links in the / proc / [pid] / fd directory.

[0070] Analyze file paths: Check whether these file paths point to sensitive areas (such as system directories, user documents directories, etc.) or match known malware behavior patterns.

[0071] Monitor file operations: Use tools such as auditd and inotify to monitor the reading, writing, and deletion operations of processes on files.

[0072] Comprehensive Assessment: This combines the results of network connection and file access analysis to comprehensively assess the process. If multiple suspicious behaviors are found, the process is likely to be malicious.

[0073] Specifically, the system combines the results of network connection and file access analysis to conduct a comprehensive assessment of the process. If any suspicious behavior exceeds the threshold, the process is identified as a malicious executable file. For example, if there are three or more suspicious behaviors, the process is identified as a malicious executable file.

[0074] In summary, the present invention has the following advantages: 1. Real-time Monitoring: This invention uses the top command and the / proc directory to obtain real-time information about all processes on the DCS host computer, including process IDs, names, and percentages of CPU and memory used. Compared to existing technologies, this invention can monitor the system's operating status in real time, promptly identifying abnormal behavior and thus improving system security.

[0075] 2. Automated Detection: This invention implements automated detection of malicious executable files and can send detection results to system administrators via email, reducing the workload of manual analysis. Compared to existing technologies, this invention can save labor costs and improve work efficiency.

[0076] 3. Unknown Malicious Executable File Detection: This invention can determine whether a process is malicious by analyzing relevant information about the process, such as the absolute path of the executable file and the files opened. Compared to existing technologies, this invention can detect unknown malicious executable files and improve system security.

[0077] 4. Reduced system resource usage: This invention uses a cyclic detection method to achieve real-time malicious executable file detection without increasing system resource usage. Compared with existing technologies, this invention does not affect system performance and is suitable for operation in DCS host computers with limited resources.

[0078] 5. Improved system reliability: When executing a file, the present invention provides timely feedback to the system administrator, thereby eliminating hidden dangers in system operation and ensuring the normal and reliable operation of the host computer. Compared with existing technologies, the present invention can improve system reliability and ensure the normal operation of industrial control.

[0079] like Figure 3 As shown, the present invention also provides a DCS host computer malicious executable file detection system, comprising: The scanning query module is used to periodically scan the processes of the DCS host computer using the top command to query the PID of the process that occupies too much CPU / memory; The acquisition module is used to obtain the path of the process and the resources it accesses based on the pid by scanning the information in the / proc / pid directory; A judgment module is used to determine whether a process is a malicious executable file by analyzing the process path and accessed resources; The sending module is used to summarize and send the executable file name, occupied CPU, occupied memory amount, absolute path, and file information opened by the process corresponding to the malicious executable file based on the judgment result.

[0080] A DCS host computer malicious executable file detection system of the present invention is based on the above-mentioned DCS host computer malicious executable file detection method.

[0081] The present invention provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the DCS host computer malicious executable file detection method is implemented.

[0082] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the DCS host computer malicious executable file detection method is implemented.

[0083] The present invention has broad application in fields such as computer security, software engineering, and control systems. In the computer security field, the present invention provides an automated method for detecting malicious executable files. This method can monitor system processes in real time, promptly identifying and reporting processes that consume excessive CPU / memory resources, thereby effectively detecting and defending against attacks by malicious executable files. This method can detect not only known malicious executable files but also unknown malicious executable files, thereby improving system security. In the software engineering field, the present invention provides an efficient process management method that uses the top command and the / proc directory to obtain process-related information and automatically analyzes this information, thereby achieving automated process management. This method can improve system performance, reduce manual intervention, and increase work efficiency. In the control system field, the present invention is particularly suitable for protecting the security of DCS host computers. DCS host computers run a large amount of industrial control software, and attacks by malicious executable files can have serious consequences. The present invention can monitor DCS host computer processes in real time, promptly identifying and reporting abnormalities, thereby effectively protecting the security of the DCS host computer. Overall, the present invention has broad application prospects in fields such as computer security, software engineering, and control systems.

[0084] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0085] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0086] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0087] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0088] It will be understood by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In a hardware implementation, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or transient medium).

[0089] As is well known to those skilled in the art, the term computer storage media includes volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storage of information such as computer-readable instructions, data structures, program modules or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and that can be accessed by a computer. Furthermore, as is well known to those skilled in the art, communication media typically contains computer-readable instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

Claims

1. A method for detecting malicious executable files on a DCS host computer, characterized in that: include: Use the top command to regularly scan the processes of the DCS host computer and find the PID of the process that occupies too much CPU / memory; According to pid, by scanning the information in the directory corresponding to pid, the path of the process and the resources it accesses are obtained; By analyzing the process path and the resources accessed, determine whether the process is a malicious executable file; Based on the judgment results, the executable file name, CPU occupied, memory occupied, absolute path, and file information opened by the process corresponding to the malicious executable file are summarized and sent.

2. A DCS host computer malicious executable file detection method according to claim 1, characterized in that: The process of periodically scanning the DCS host computer using the top command is that the detection program is started through a scheduled task and the top command is executed to periodically scan all processes of the DCS host computer.

3. A DCS host computer malicious executable file detection method according to claim 2, characterized in that: The configuration file of the detection program includes filtering rules, detection time intervals, mail recipients and mail servers. The filtering rules are used to filter out normally running processes, including: whitelist, blacklist, behavior analysis, time pattern, user permissions and inter-process communication.

4. A DCS host computer malicious executable file detection method according to claim 1, characterized in that: The query finds the PIDs of processes that use too much CPU or memory, including: Execute the top command to display the real-time resource usage of each process in the current system, including CPU and memory usage; Sort the processes by CPU usage from high to low; In the sorted list, get the processes that occupy CPU / memory exceeding the threshold; and record the corresponding PID.

5. A DCS host computer malicious executable file detection method according to claim 1, characterized in that: The process path and the resources accessed by the process are obtained by scanning the information in the directory corresponding to the pid, including: a) Get the absolute path of the executable file from cmdline; b) Get the files and sockets accessed by the process from fd; c) Memory information, swap space usage, and virtual memory usage; d) Information about files opened by other processes.

6. A DCS host computer malicious executable file detection method according to claim 1, characterized in that: The process of analyzing the path of the process and the resources accessed to determine whether the process is a malicious executable file includes: After obtaining process information through the top command and the / proc directory, extract the full path of the process; Compare the extracted process path with the entries in the pre-established blacklist database; If a match is found, the process is marked as suspicious or malicious; Perform the following comprehensive analysis on the marked processes: a. Read network connection information and obtain the network connection status of the process; b. Check whether the network connection status points to the malicious IP address, domain name, or port of the marked process; c. Monitor and analyze network traffic content; d. List the files opened by the marked process and obtain all file handles opened by the process by reading the links in the / proc / [pid] / fd directory; e. Check if the opened file path points to sensitive areas or matches known malware behavior patterns; f. Monitor the read, write, and delete operations of marked processes on files; Combined with the analysis results of network connections and file access, a comprehensive assessment of the process is performed: if there is a situation that exceeds the suspicious behavior threshold, the process is determined to be a malicious executable file.

7. A DCS host computer malicious executable file detection method according to claim 6, characterized in that: The pre-established blacklist database is a blacklist database containing known malware paths, names, and hash value information; the pre-established blacklist database is stored in a local file, a database management system, or a cloud storage service.

8. A DCS host computer malicious executable file detection system, characterized in that: include: The scanning query module is used to periodically scan the processes of the DCS host computer using the top command to query the PID of the process that occupies too much CPU / memory; The acquisition module is used to obtain the path of the process and the resources it accesses by scanning the information in the directory corresponding to the pid; A judgment module is used to determine whether a process is a malicious executable file by analyzing the process path and accessed resources; The sending module is used to summarize and send the executable file name, CPU occupied, memory occupied, absolute path, and file information opened by the process corresponding to the malicious executable file based on the judgment result.

9. An electronic device, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method for detecting malicious executable files on a DCS host computer according to any one of claims 1 to 8 is implemented.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the DCS host computer malicious executable file detection method according to any one of claims 1 to 8 is implemented.